Quartz Docs
Docs › Admin & trust › Audit & governance

Audit & governance

Quartz keeps an immutable, egress-free trail of every configuration and exception change, reviews how the mute and extension escape hatches were used, and maps your SLAs onto control clauses as instrumentation evidence — all without issue data leaving Atlassian.

What these tools are for

Three related screens help you trust the numbers Quartz reports and show your working to an auditor:

ScreenWhat it doesEdition
Audit logImmutable record of every config, permission and exception changeStandard
GovernanceReview of how mute/extend exceptions were usedAdvanced
Compliance coverageWhich ITIL / ISO/IEC 20000 / SOC 2 clauses have an SLA timer assignedStandard
Note

None of these send data anywhere. The audit log is recorded in Atlassian and never transmitted; Governance reads only the audit log; Compliance reads only your SLA configuration and your met/total tallies.

The audit log

The audit log is an immutable, egress-free trail of every change that affects what Quartz reports — SLA definitions, calendars, permissions, settings, SLA-field mappings, and the mute and extend exceptions on individual issues. Each entry records the actor, the action, the target, a detail line, and a timestamp. Actor ids are resolved to display names when the log is shown.

the Audit log screen showing actor, action, target, detail and timestamp columns
Screenshot — the Audit log screen showing actor, action, target, detail and timestamp columns

What is recorded

AreaExamples of recorded changes
SLAsCreate, edit, clone, enable, disable a definition
CalendarsCalendar changes and company-holiday changes
PermissionsGroup × capability matrix edits
SettingsApp-wide defaults, excluded actors
SLA FieldsField-mapping changes
ExceptionsEvery mute / unmute and every extend / clear on an issue

How the trail behaves

Two properties matter for trustworthiness:

Tip

The audit log is the sole input to the Governance review. If something looks off in Governance, the underlying entries are here.

Who can see it

The audit log is admin-only. Permissions changes themselves are audited, so a change to who can do what leaves its own record.

Governance review Advanced

Mute and extend are deliberate escape hatches — a way to handle a one-off exception on a single issue. Mute hides one SLA goal on one issue from breach counts, the Radar, Reports, and the field write-back (the panel still shows it, flagged Muted). Extend adds or removes minutes from a goal on one issue. Both are recorded to the audit log. Governance surfaces how those hatches were used, so your compliance numbers stay trustworthy.

The review reads only the audit log — no ticket data is involved and nothing leaves Atlassian. It is an Advanced feature.

Governance screen with exception flags and a "Muted right now" list
Screenshot — Governance screen with exception flags and a "Muted right now" list

What it highlights

Governance highlights exception patterns that are worth a second look:

FlagWhat it highlights
Large single extensionAn unusually long extension on one issue
Repeated extensionsThe same issue extended several times
Mute / unmute churnA goal muted and unmuted repeatedly
Actor concentrationOne person performing a large share of the exceptions

Muted right now

Governance also lists every SLA goal that is muted at this moment — including who muted it and when — so nothing stays silently excluded from your numbers. Headline stats summarise the picture: total exceptions, mutes, extensions, and how many goals are muted now.

Note

A flag is a prompt to review, not a verdict. An exception can be entirely legitimate — Governance simply makes sure each one is visible and accountable rather than buried.

Edition and access

Governance is gated to the Advanced edition. Standard installs see it locked. In production, the Marketplace licence is the sole authority for the Advanced edition — no override can unlock it.

Compliance coverage

Compliance coverage maps your SLAs onto control clauses for ITIL, ISO/IEC 20000 and SOC 2. A clause counts as Instrumented when an SLA timer is assigned to it (you tag a definition with a compliance clause when you create or edit it). For each standard, the screen shows how many of its clauses are instrumented (N of M) plus the met/total for those instrumented controls.

Compliance coverage with N/M instrumented per standard and recent met rates
Screenshot — Compliance coverage with N/M instrumented per standard and recent met rates

Instrumentation, not certification

This screen reports that a timer is in place and how it has performed — coverage and evidence. It is explicitly not certification. The copy always says "Instrumented", never "Compliant", and the footer states it is not an audit, attestation, or certification.

Warn

Do not read these numbers as proof of conformance to a standard. They show which controls have an SLA instrumented and the recent met rate — useful evidence to bring to an assessment, not a substitute for one.

Why the evidence holds up

SLA status is computed on demand — nothing is stored or backfilled — so the audit log records configuration and exception changes rather than a mutable timer database that could drift. Combined with the no-egress posture (Forge storage only, no external backend), the trail is something you can hand to an assessor: every change is attributed, exceptions are reviewable, and the data never left Atlassian.

Note

For teams under ITIL, ISO/IEC 20000 or SOC 2, keeping the audit trail, exception review and AI all inside Atlassian means one less vendor to assess.


Was this page helpful?   Yes · No  ·  Contact support