Table of Contents
The problem
Banking and financial services teams run a significant volume of sensitive work inside Jira: regulatory compliance tracking, internal audit workflows, AML and KYC exception reviews, risk assessments, and incident response. These workflows involve multiple departments: compliance, legal, risk, operations, finance, often collaborating inside the same Jira issue.
Under Jira’s native permission model, every user with project access sees every field on every issue. That means a KYC exception flag, an internal audit finding, a sanction screening result, or a regulatory risk classification is visible to all project members; regardless of whether their role requires access to that information.
For financial institutions, that is not a controlled access environment. SOX requires that access to data relevant to financial reporting is restricted based on least privilege and that those controls are auditable. SOC 2’s CC6 criteria require logical access controls for sensitive information. A Jira environment where all project members see all field values (including regulatory and financial data) does not satisfy either requirement at the field level.
The typical workaround is a restricted project for sensitive regulatory workflows. It contains the exposure but creates a parallel record problem: two projects for the same work, duplicated automation rules, and an ongoing synchronization overhead that grows as the organization scales.
How Secure Custom Fields for Jira addresses this
Secure Custom Fields for Jira applies view and edit permissions directly to individual custom fields, independent of project and issue permissions already in place.
A regulatory workflow issue can contain both general fields (task status, assigned owner, review deadline, escalation notes) and restricted fields (AML status, KYC exception details, sanction screening results, internal audit findings, regulatory risk rating) within a single issue. Each user sees only the fields their role authorizes.
A project coordinator tracking task completion sees workflow fields. Restricted regulatory fields are present on the issue but values are withheld — displaying “You don’t have permission to view the value” — for users without the appropriate field-level permission. Compliance and risk roles configured with access see the relevant data. Admins can configure a masked display as an alternative where acknowledging a field’s existence is appropriate without revealing the value.
View and edit permissions are separate controls. A senior manager can be given read access to a risk rating without being able to modify it. Only designated compliance roles can update audit findings. That access asymmetry is enforced at the field level, not managed through separate projects or manual access reviews.
What this means in practice
A single Jira project handles the complete regulatory workflow. Sensitive compliance and risk fields are restricted to the roles that need them. General workflow fields remain visible to the broader team. There are no duplicate projects to maintain and no offline records carrying regulatory data outside Jira’s governance perimeter.
Field-level audit logs record who viewed or modified each sensitive field. When a SOX internal control assessment or a SOC 2 audit requires documentation of who had access to specific regulatory data during a given period, the log provides a specific, timestamped answer; not an inference from project membership or role assignment.
The compliance dimension
SOX requires least-privilege access to data relevant to financial reporting, with controls that are documented and auditable. SOC 2’s CC6 criteria require logical access restrictions for sensitive information. GDPR applies to any personal data in Jira workflows, including employee and customer data that appears in regulatory and risk management issues.
Field-level permissions implement least-privilege access at the data level within Jira, consistent with the access control requirements these frameworks reference. Combined with field-level audit logs, they support the evidence requirements that banking compliance and audit teams need to demonstrate controlled access to sensitive regulatory data.
Secure Custom Fields for Jira adds field-level view and edit permissions, configurable data masking, AES-256 encryption, and audit-ready logs to Jira Cloud. Built on Atlassian Forge. Your data stays within Jira Cloud infrastructure.