Auditwell documentation (knowledge base source)
1. Getting started
- Install Auditwell from the Marketplace. Nothing is recorded yet.
- Open Jira settings > Apps > Auditwell. Choose:
- How much to record: full detail, daily totals per person, or team totals.
- Work item views: off by default.
- How long to keep it: 7 to 730 days (default 90).
- Spaces: every space or a list.
- People never recorded: people and groups (for example a works council or HR).
- Who can read the log: Jira admins always; optionally one audit group.
- Personal view: whether everyone can see what is recorded about them (on by default).
- Notice: what everyone on the site reads in Apps > Activity log.
- Tick the box confirming people have been told, then Start recording.
Actions show up in the Activity tab a few seconds after they happen.
2. What is recorded
| Action | Detail kept (full level only) |
|---|---|
| Created | |
| Edited fields | names of the fields that changed, never their values |
| Changed status | from and to status names, plus other field names changed at the same time |
| Changed assignee | the new assignee's name |
| Commented / Edited a comment / Deleted a comment | none (comment text is never stored) |
| Logged work / Edited a work log / Deleted a work log | time spent |
| Added / Deleted an attachment | file name |
| Deleted the work item | its summary |
| Viewed (only if turned on) | none |
Not recorded, because Jira gives apps no events for them: sign-ins, searches and filters, board, backlog and dashboard views, exports from Jira, and anything before setup was finished.
3. Detail levels
- Full: person, work item, exact time, detail.
- Daily totals: person, space, action and day. No work item, no time of day, no detail.
- Team totals: space, action and day. No person.
Raising the level applies to new activity only. Lowering it rewrites every stored row to the new level straight away; that can't be undone.
4. Work item views
Turn views on when you have a reason, for example to show that people opened a security notice, or to find licensed people who only read. Turning them on asks you to confirm that people were told. The same person opening the same work item again within 30 minutes counts once (once a day at the aggregate levels).
5. Who can read the log
Jira admins and members of the audit group can search, export, list people and inactive people, and read the access log. Every search, export, people list and settings change is written to the access log with who did it and, when a search named a person, whose activity it was.
6. The personal view
Everyone can open Apps > Activity log to read your notice and a plain description of what is recorded. Unless you turn it off, they also see their own recorded activity and when someone searched or exported it, with that person's name.
7. Retention, exclusions and erasure
Rows older than the retention period are deleted every night; shortening it deletes older rows at once. Adding someone to the exclusions (directly or through a group) stops recording them and deletes what is stored about them. Group members are re-checked daily. Pausing keeps what is stored until it expires.
8. People and inactive people
People lists changes and views per person in a date range with their last active day. These counts are for audits and licence reviews, not for judging anyone's performance. Inactive people lists active people with no recorded activity for a number of days (at most your retention). Someone who only works in spaces you don't record, or who only reads while views are off, will show up, so check before you act.
9. Data and privacy
Auditwell runs on Atlassian Forge and stores its log in Forge storage on your site. Nothing is sent to Great Work or anyone else. See the privacy policy for the full list of what is stored.
10. GDPR and works councils (checklist, not legal advice)
- Write down why you record activity (security, compliance, licence management) and pick the lowest detail level that serves it.
- Keep retention as short as the purpose allows.
- Inform people before you start (the notice) and, where required, consult your works council.
- Exclude groups whose activity you must not record.
- Keep the personal view on so people can see what is recorded about them.
- Review the access log regularly.
11. Moving from Data Center
Jira Data Center apps that record user activity keep their data in your DC database; it does not migrate to Cloud, and Auditwell can't import it (Cloud apps can't read it). Export what you must keep before you migrate. Install Auditwell on the Cloud site before the cutover so recording starts on day one.