Audit & governance
Quartz keeps an immutable, egress-free trail of every configuration and exception change, reviews how the mute and extension escape hatches were used, and maps your SLAs onto control clauses as instrumentation evidence — all without issue data leaving Atlassian.
What these tools are for
Three related screens help you trust the numbers Quartz reports and show your working to an auditor:
| Screen | What it does | Edition |
|---|---|---|
| Audit log | Immutable record of every config, permission and exception change | Standard |
| Governance | Review of how mute/extend exceptions were used | Advanced |
| Compliance coverage | Which ITIL / ISO/IEC 20000 / SOC 2 clauses have an SLA timer assigned | Standard |
None of these send data anywhere. The audit log is recorded in Atlassian and never transmitted; Governance reads only the audit log; Compliance reads only your SLA configuration and your met/total tallies.
The audit log
The audit log is an immutable, egress-free trail of every change that affects what Quartz reports — SLA definitions, calendars, permissions, settings, SLA-field mappings, and the mute and extend exceptions on individual issues. Each entry records the actor, the action, the target, a detail line, and a timestamp. Actor ids are resolved to display names when the log is shown.

What is recorded
| Area | Examples of recorded changes |
|---|---|
| SLAs | Create, edit, clone, enable, disable a definition |
| Calendars | Calendar changes and company-holiday changes |
| Permissions | Group × capability matrix edits |
| Settings | App-wide defaults, excluded actors |
| SLA Fields | Field-mapping changes |
| Exceptions | Every mute / unmute and every extend / clear on an issue |
How the trail behaves
Two properties matter for trustworthiness:
- Best-effort, never blocking. Auditing runs alongside the actual change. If writing the audit entry fails, it never blocks the mutation itself — the change still happens.
- Most recent first. The screen shows the most recent entries.
The audit log is the sole input to the Governance review. If something looks off in Governance, the underlying entries are here.
Who can see it
The audit log is admin-only. Permissions changes themselves are audited, so a change to who can do what leaves its own record.
Governance review Advanced
Mute and extend are deliberate escape hatches — a way to handle a one-off exception on a single issue. Mute hides one SLA goal on one issue from breach counts, the Radar, Reports, and the field write-back (the panel still shows it, flagged Muted). Extend adds or removes minutes from a goal on one issue. Both are recorded to the audit log. Governance surfaces how those hatches were used, so your compliance numbers stay trustworthy.
The review reads only the audit log — no ticket data is involved and nothing leaves Atlassian. It is an Advanced feature.

What it highlights
Governance highlights exception patterns that are worth a second look:
| Flag | What it highlights |
|---|---|
| Large single extension | An unusually long extension on one issue |
| Repeated extensions | The same issue extended several times |
| Mute / unmute churn | A goal muted and unmuted repeatedly |
| Actor concentration | One person performing a large share of the exceptions |
Muted right now
Governance also lists every SLA goal that is muted at this moment — including who muted it and when — so nothing stays silently excluded from your numbers. Headline stats summarise the picture: total exceptions, mutes, extensions, and how many goals are muted now.
A flag is a prompt to review, not a verdict. An exception can be entirely legitimate — Governance simply makes sure each one is visible and accountable rather than buried.
Edition and access
Governance is gated to the Advanced edition. Standard installs see it locked. In production, the Marketplace licence is the sole authority for the Advanced edition — no override can unlock it.
Compliance coverage
Compliance coverage maps your SLAs onto control clauses for ITIL, ISO/IEC 20000 and SOC 2. A clause counts as Instrumented when an SLA timer is assigned to it (you tag a definition with a compliance clause when you create or edit it). For each standard, the screen shows how many of its clauses are instrumented (N of M) plus the met/total for those instrumented controls.

Instrumentation, not certification
This screen reports that a timer is in place and how it has performed — coverage and evidence. It is explicitly not certification. The copy always says "Instrumented", never "Compliant", and the footer states it is not an audit, attestation, or certification.
Do not read these numbers as proof of conformance to a standard. They show which controls have an SLA instrumented and the recent met rate — useful evidence to bring to an assessment, not a substitute for one.
Why the evidence holds up
SLA status is computed on demand — nothing is stored or backfilled — so the audit log records configuration and exception changes rather than a mutable timer database that could drift. Combined with the no-egress posture (Forge storage only, no external backend), the trail is something you can hand to an assessor: every change is attributed, exceptions are reviewable, and the data never left Atlassian.
For teams under ITIL, ISO/IEC 20000 or SOC 2, keeping the audit trail, exception review and AI all inside Atlassian means one less vendor to assess.
Was this page helpful? Yes · No · Contact support