Montro

Jira External User Discovery & Governance

Jira accounts are where contractors, agencies, and external collaborators often live - outside your identity provider, outside your offboarding process, and outside your compliance picture. Connect Jira to Montro to bring them in.

01GDPR

GDPR

Jira and GDPR - external user data needs the same protection as internal

Jira routinely holds personal data belonging to contractors, agency partners, and external collaborators - people who may never have been captured in your organisation's GDPR data inventory. Under GDPR, your organisation controls this data regardless of whether it belongs to employees or third parties. A Data Processing Agreement with Atlassian must be in place. Montro brings Jira user data into EU-hosted infrastructure under a separate DPA.

Learn more →
02EU AI Act

EU AI Act

Atlassian Intelligence in Jira and the EU AI Act

Atlassian Intelligence brings AI-powered features into Jira - issue summarisation, smart suggestions, and automated work categorisation. If your organisation has these features enabled, they qualify as AI systems under the EU AI Act and deployer obligations apply. Usage in operational decision-making, performance tracking, or resource allocation warrants a risk tier assessment. Montro surfaces Jira in your governed inventory so AI feature usage is documented.

Learn more →
03DORA

DORA

Jira and DORA - development and incident tools belong in your ICT register

Financial entities using Jira to manage development sprints, track incidents, or coordinate operational processes are using it as an ICT service supporting their business. Under DORA Article 28.3, those tools belong in the ICT Third-Party Register. Montro surfaces Jira alongside every other ICT tool in your estate, supporting register completeness and third-party risk visibility.

Learn more →
04NIS2

NIS2

Jira and NIS2 - project tools supporting critical workflows are ICT supply chain

When engineering teams track incidents, security teams manage remediation workflows, or operations teams coordinate business continuity responses through Jira, it becomes an ICT service supporting critical functions. NIS2 Article 21(3)(d) requires that ICT suppliers supporting those functions are documented and assessed. Connecting Jira to Montro ensures it is visible in your supply chain security posture.

Learn more →
05ISO 27001

ISO 27001

Jira and ISO 27001 - project tool access is an asset management obligation

ISO 27001 requires a complete asset inventory (A.5.9) and documented access control processes (A.5.15, A.5.16). Jira user accounts - particularly those belonging to contractors and external parties - are assets that frequently go undocumented. Montro imports Jira user data into your governed inventory, supporting the evidence requirements for access control and user lifecycle management that ISO 27001 audits examine.

Learn more →

Discovery

What Montro discovers from Jira

Jira holds user accounts that often do not appear elsewhere in your governed estate - contractors with direct access, legacy accounts from departed employees, and external collaborators added project by project. Connecting Jira to Montro surfaces that access and maps it against your compliance and governance obligations.

Full user discovery

Montro imports every user account in your Jira organisation - including contractors, agency staff, and external collaborators who were added directly and never passed through your identity provider. These are precisely the accounts that fall through the gaps in standard offboarding and access review processes.

Access audit readiness

Understand which users have Jira access, who is responsible for each account, and whether that access reflects current employment or project status. Montro gives you the consolidated record that access audits demand - without manually exporting from Jira admin and cross-referencing against HR data.

Offboarding and lifecycle management

Jira accounts routinely outlast the people who hold them. Montro keeps your Jira user records current within your governed inventory, making it possible to identify accounts that should have been deprovisioned and act on them before they become a security or compliance finding.

Subscription and spend visibility

Jira subscriptions frequently expand team by team without central oversight - a workspace added for one project becomes the default for ten. Montro imports Jira subscription records into your Subscriptions module alongside every other application in your estate, giving finance and IT a shared view of what you are paying, how many seats are assigned, and whether the spend is proportionate to actual usage.

Technical details

Authentication Method


Jira authenticates using an Organisation URL, email address, and API Key. Administrators generate an API Key from their Atlassian account settings and provide it alongside their Jira organisation URL and email address to authorise Montro's read-only access. 


How to connect:


  1. Open the Integrations section within Montro.
  2. Select Jira from the available integrations.
  3. Enter your Jira Organisation URL.
  4. Provide your Jira Email Address.
  5. Enter your Jira API Key.
  6. Click Connect to authorise the integration.
  7. Montro begins synchronising Jira user information automatically.
  8. Review imported user records within the Users module in Montro.


Data Synced

Users Module

Jira user identities and account information, including email addresses and account status.

Data Residency


Jira data imported into Montro is stored on AWS Frankfurt (eu-central-1), within the European Union. No customer data is transferred outside the EU. Data residency terms are specified in Montro's Data Processing Agreement.


Sync Frequency


Data can be synchronised manually at any time after the initial connection, with no limit on the number of manual syncs. Montro also provides an automatic sync option - when enabled, the platform synchronises data once every night to keep information current.


Permission Scope


Montro requests read-only access to Jira using an API Key scoped to user and account information. The integration does not access Jira projects, issues, tickets, comments, attachments, or sprint data. No changes are made to your Jira environment. All access is limited to the minimum required for user and account governance visibility.


EU Data Storage


Montro's infrastructure runs exclusively on AWS eu-central-1 (Frankfurt), governed by Irish and EU law. There is no FISA 702 exposure and no Schrems II ambiguity. Your data is never replicated outside the EU without your explicit, documented consent. EU data residency is not a configuration option - it is the architecture.

Related

Apps commonly used with Jira

Discover compliance profiles for tools in your stack.

AI Platforms

OpenAI Governance & Compliance Discovery

Most organisations using OpenAI have no visibility into who holds access, how many seats are active, or whether usage is documented against EU AI Act obligations. Montro surfaces all of it.

Learn more →

Slack Workspace Access & AI Governance

Slack is where work happens, and where ungoverned access accumulates. Guest accounts, inactive seats, and users added outside your identity provider all show up when Montro connects to your workspace.

Learn more →

Zoom Governance & Compliance Discovery

Zoom accounts grow quietly - provisioned outside your identity provider, renewed without IT review, and rarely audited. Montro discovers every user and licence in your Zoom environment and maps it against your EU compliance obligations.

Learn more →

Identity & Access Management

Okta Identity Governance & Compliance

Okta controls who gets into everything else. Without it in your governed inventory, your compliance picture has a gap at the foundation. Montro connects Okta identity data to your full application estate.

Learn more →
Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.