Last updated 2026-10-11
Audit Compass
Audit Compass puts the governance signals in your Jira events on one zoomable timeline, so a reviewer can move between a whole audit window and a single event without leaving the page. It is built for review sessions: pick a window, see where the signals cluster, and open any one of them.
Jira records every one of these events. Audit Compass reads them across projects and time, sorts them into nine kinds of signal, and keeps the detail of each one a click away.
Opening a window
Pick a time range (the last 7, 30, 90, 180 or 365 days, or a custom range) and either every project or one. The page opens on the last 7 days and all projects. Stratify by draws one lane per kind of signal, or one lane per actor: the eight actors with the most events, then everyone else, with events that name no actor in a lane of their own.
Scroll to zoom and drag to pan. Each dot is one event, colored by the severity MetaFrazo gives that kind of event.
The nine lanes
The lane names are MetaFrazo's names for what it measures. None of them is a finding about a control; each says what the events show.
- Workflow drift: a change to a workflow's definition, or the first snapshot MetaFrazo takes of a workflow.
- Workflow manipulation: an issue moved straight from a To Do-category status to a Done-category status.
- Missing approval: an issue moved to a Done-category status by the account that created it. Comments and approvals are not read.
- Permission drift: an issue's Reporter field changed.
- Sprint drift: a sprint started by one person and closed by another; a sprint closed early, closed late, or still active past its end date; a sprint's dates, name or board configuration changed while it ran; or an issue added after the sprint started.
- Assignee churn: every change of an issue's assignee, including an assignee removed.
- Reopen after close: an issue moved from a Done-category status back to one outside it.
- Configuration changes: a change to a project, component, filter, field, issue type, board or other configuration item, or to a user account.
- PII detection: an issue summary or comment containing text shaped like an email address and text shaped like a phone number while the issue is open. The issue description is not scanned.
One Jira event can be two kinds of signal at once, so it can appear in two lanes, and the lane counts can add up to more than the events behind them.
One event
Click a dot to open its details under the canvas:
- Actor and Account type: who acted, and the type of account Jira reports for that actor (a person, an app such as Automation for Jira, a service-desk customer, or no type). An action Jira records under a person's account counts as that person's, even when a tool acted on their behalf.
- Project / issue, and Open in Jira where the event names an issue or a project.
- The recorded change itself, under Diff.
- Controls affected reads Not mapped yet: the canvas does not map events to a control framework.
From there you can Pin a note to the event and Export evidence pack, which downloads the event and its pinned notes as a JSON file for your audit records.
Ask the AI
The Analyze cards (Causality, Silent rule erosion and Actor concentration) and the Ask Compass box read the 200 most recent events in view and answer in plain language. Explain impact, in an event's details, reads that one event. Each request goes to your organization's AI provider, which you choose under Integrations.
What to keep in mind
- The page reads up to 20,000 events for a window. When a window holds more, a notice says so and shows the most recent; narrow the window to read the rest.
- Sprint drift is detected from sprint records, not from one issue, so those events name no project or issue, are hidden while a project is picked, and carry the time the change was detected rather than the time of the sprint event.
- Erased accounts. When a person's Atlassian account has been erased, the events they took part in stay on the canvas without an actor, and a summary that named them shows "erased account" in their place.
The panel's Description tab and the Audit Compass 5.8.1 reference carry the same rules in full. For what the event history can and cannot show a reviewer more broadly, see GDPR, NIS2, DORA and more: what does MetaFrazo give me?.