Host product
Jira or Confluence identity, permissions, and authorized context.
This page describes the security standard expected for future addly apps. It does not turn concepts into audited products and claims no certification that has not been obtained.
Request the minimum, explain every access, respect host permissions, and document uninstall behavior.
A Forge app does not become secure merely by being close to the host. Every boundary remains named and testable.
Jira or Confluence identity, permissions, and authorized context.
Scopes, access controls, input validation, and secrets.
Authentication, encryption, logging, and subprocessors.
Access reviews, vulnerability management, and incident response.
| Concept | Read | Write | Expected control |
|---|---|---|---|
| Readiness for Jira | Read the issue context | Write only app-owned states | Alignment with the published manifest |
| Portfolio Insights | Read selected projects | Write only view preferences | Alignment with the published manifest |
| Page Summary | Read the current page | Write only macro configuration | Alignment with the published manifest |
| Context Linker | Read the current page | Read Jira only for accessible projects | Alignment with the published manifest |
The future channel must be private, acknowledged quickly, and separate from functional support. No SLA is invented here; the production procedure still needs publication.
View the escalation pathOpen the documentation for the selected concept to connect permissions, configuration, and data to the behavior that is actually demonstrated.