Skip to main content

Spaces Audit Limitations

Spaces Audit depends on Jira APIs, app permissions, and metadata available when the audit runs. All results are designed for administrator review and planning, not automatic remediation or enforcement.

Ownership Coverage

Jira project lead is used as the owner signal. If Jira does not expose a lead or related metadata to Audit 360, ownership coverage is incomplete. In this case, spaces may show "Missing" for owner.

If a space has no lead assigned in Jira, Spaces Audit cannot determine ownership even with full API access.

Activity Signal Limitations

Count-only approach — Audit 360 does not store individual work item keys or raw work item payloads. Activity evidence is based on:

  • Total issue count (approximate, from Jira's count endpoint).
  • Most recent issue update timestamp.

These signals allow Audit 360 to flag spaces with low activity or inactivity, but cannot show which specific issues were updated or by whom.

Partial availability — Latest activity can be unavailable or incomplete when:

  • Jira search permissions restrict your visibility to some issues in a space.
  • Jira's search index is temporarily unavailable.
  • A space has no issues at all.

When activity data is unavailable, Spaces Audit may show "Not available" rather than a timestamp or count.

Feature Configuration Limitations

Feature consistency is best-effort. Coverage depends on:

  • Jira project feature API availability and response times.
  • App permissions granted to Audit 360 by your Jira site.
  • Whether feature state is retrievable from the Jira endpoint at audit time.

If Jira does not expose feature state for a space, Audit 360 marks the feature as "Unknown" rather than guessing.

Filter, Board, and Dashboard Impact Limitations

Filter dependencies — Audit 360 identifies saved filters whose JQL references a space by project key, name, or category. Some filter references may not be detected if:

  • The filter's JQL uses indirect references (e.g., a saved filter in a portal or custom app).
  • Jira search permissions hide the filter from Audit 360.

Board dependencies — Boards are connected to impacted filters when a board's board filter references a saved filter with a space dependency. Coverage is partial when:

  • Board metadata is unavailable to Audit 360.
  • Jira permissions restrict board visibility.

Dashboard dependencies — Dashboard gadgets are connected to impacted filters when gadget metadata explicitly exposes saved-filter references. Coverage is often limited because:

  • Most dashboard gadget types do not expose filter references in their metadata — this is a limitation of the Jira dashboard API, not Audit 360.
  • Some gadgets may reference filters indirectly (e.g., through board gadgets).
  • Jira permissions may restrict dashboard visibility.

If gadget metadata does not expose a filter reference, Audit 360 cannot detect that relationship, and the dashboard may not appear as impacted even if it would be affected by space changes. When dashboard coverage is limited, a coverage note appears at the bottom of Audit Details to explain the limitation.

Cleanup Candidate Limitations

Cleanup candidates are flagged based on activity thresholds and governance signals, but they are informational review candidates only. They do not:

  • Recommend automatic deletion or archival.
  • Indicate that a space is safe to remove.
  • Trigger any automatic actions in Jira or Audit 360.

Always review cleanup candidates manually before taking action. A space flagged as a cleanup candidate may have hidden dependencies or business value not visible to Audit 360.

Read-Only Scope

Spaces Audit does not delete, archive, or modify Jira spaces, projects, saved filters, boards, dashboards, or any work items. All operations are read-only. This includes:

  • No changes to space configuration, permissions, or features.
  • No changes to saved filters, boards, or dashboards.
  • No changes to any work item data.

Audit 360 gathers evidence only. All remediation decisions are yours to make outside Audit 360.

Data Retention and Privacy

Audit 360 does not store:

  • Raw Jira API responses or payloads.
  • Individual work item keys, summaries, or descriptions.
  • Credentials, tokens, or secrets.
  • Personally identifiable information beyond what Jira exposes (e.g., user display names if attached to space lead).

Stored audit results contain only normalized, aggregated data (counts, metadata, timestamps, and findings).