NF / Docs / Approval Desk
Privacy and security boundary
See what Approval Desk reads, stores and never changes in Jira Service Management.
Last updated: 2026-09-09
In this section
Short version
Approval Desk runs on Atlassian Forge. It reads the JSM requests and approvals the signed-in user is authorised to see, presents configured fields transiently and records native approval decisions through the official JSM workflow.
It does not ask for passwords, API tokens or a service account. It does not use a third-party customer-data backend or send customer data to an external analytics service.
Data stored by the app
Tenant-scoped Forge Storage contains configuration such as service projects, request types, context columns and Safe Bulk rules. Short-lived bulk-operation metadata can include the operation id, signed-in account id, timestamp, count, status and per-item result so the app can show a trustworthy outcome.
Request summaries, field values, amounts, justifications, comments and attachments are not stored permanently by Approval Desk. Jira remains the source of truth for request content and native approval state.
Security boundary
Approval reads and approval writes run as the signed-in Jira user. Every resolver re-checks authorization, configuration, plan limits and current approval state. Safe Bulk policy evaluation fails closed when it cannot be verified.
Read the Approval Desk privacy policy, security policy and data deletion page for the product-specific boundary.