dtwo Policy Store

Policies tagged "atlassian"

confluence · ingress

Block Secrets in Confluence Pages and Comments

Blocks Confluence write calls whose body looks like it contains a live credential — an API key, password, token, or PEM-formatted private key — before the…

confluencesecretsdlpingresssoc2atlassian

confluence · ingress

Confluence: Deny Org-Wide & Public Publication

Stops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.

confluenceatlassiandeny-public-exposurepublicationgovernanceingressfinserv-commseu-ai-actsoc2gdpr-ccpa

confluence · ingress

Confluence: Freeze Page & Attachment Deletion

Freezes the two irreversible Confluence deletion tools on the agent channel: confluence delete page and confluence delete attachment.

confluenceatlassianfreeze-destructive-opsdata-protectioningresssoc2

confluence · egress

Confluence: Redact PII from Page & Comment Responses

Scans the responses of Confluence page, comment, and search read tools and rewrites personally identifiable information to fixed redaction tokens before the…

confluenceatlassianredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

confluence · ingress

Fence Confluence Reads & Search to Non-Restricted Spaces

Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…

confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa

jira · ingress

Force Internal Visibility on JSM Comments

Keeps agent-drafted Jira Service Management (JSM) comments off the customer-facing portal by rewriting addCommentToJiraIssue calls to carry a restrictive…

jiraforce-internal-commentscommentsjsmservice-managementingresssoc2atlassian

jira · ingress

JIRA: Block Change-History Actor Spoofing

Blocks any official Jira write call — transitionJiraIssue, editJiraIssue, or createJiraIssue — that carries a historyMetadata block, before it reaches the…

jiraatlassianfreeze-destructive-opsaudit-integrityingresssoc2

jira · ingress

JIRA: Cap Field and Result Exposure on Reads

Narrows the breadth of JIRA read requests before they run, on the two read surfaces that can pull large amounts of issue data into model context:

jiraatlassiancap-bulk-exportdata-minimisationingresssoc2gdpr-ccpa

jira · ingress

JIRA: Deny Sensitive Project Search and View

Keeps issues that belong to a configurable set of "sensitive" JIRA projects out of read access through the JIRA MCP server.

jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms

jira · ingress

JIRA: Freeze Destructive Issue Operations

Freezes the three irreversible Jira operations on the agent channel: jira delete issue, jira remove issue link, and jira remove watcher.

jiraatlassianfreeze-destructive-opsrecord-integritydata-protectioningresssoc2

jira · ingress

JIRA: Protect Sensitive Projects from Writes

Blocks write operations against issues that belong to a configurable set of "sensitive" JIRA projects.

jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms

jira · egress

JIRA: Redact Sensitive Information from Issue Views

Redacts sensitive content from the responses of JIRA issue-view tools before they reach the caller.

jiraatlassianpiisecretsdlpredactionegresssoc2gdpr-ccpaiso27001-nist