Last updated 2026-10-09
People, automation and AI activity
For teams preparing a DORA or NIS2 review, reviewers typically ask which changes in a Jira history were made by automation rather than by a person. Jira records every change under an account and gives each account a type. MetaFrazo reads that type and shows it across the dashboard. This article explains what the type is, which visuals use it, and where it stops, including what it cannot tell you about AI.
The four account classes
Jira reports a type for each account. MetaFrazo shows it as one of four classes:
| Class | What Jira reports | Examples |
|---|---|---|
| Person | An Atlassian account (Jira's own value is atlassian) | The people in your organization |
| App | An app account | Automation for Jira, or an app that acts in Jira through its own app account |
| Customer | A Jira Service Management customer account | Someone raising a request through the customer portal |
| Unknown | No type | An account Jira returned no type for, or one that has not been looked up yet |
Unknown is shown as unknown. It is never counted as a person. Two other labels appear on some rows and are not account types: erased, for an account whose personal data has been erased, and system, for an event that records no actor. Neither counts as a person.
If you are looking for "bots", MetaFrazo's word is app account. An account counts as an app because Jira types it as one, never because of its name or how busy it is.
MetaFrazo looks up each account's type in the background and applies it to all of that account's events, including those from before the lookup. A newly seen account can read unknown until its lookup finishes. From each lookup, MetaFrazo keeps the account ID and the type, and for an app account its name, so a panel can read "Slack (app)" instead of a short ID. It never keeps the name of a person or a service-desk customer; see What we hold per organization in GDPR, NIS2, DORA — what does MetaFrazo give me?.
Which visuals separate people from apps
Each column of the matrix below is one way a visual treats app accounts:
- Shown separately. The figure that leads counts people's accounts. Apps, customers and accounts of unknown type are counted beside it and never inside it. Where an app or customer account acted, the people figure differs from an all-accounts figure.
- People only. The measure is about people, such as workload, throughput or lead time, so app and customer accounts are left out. Accounts of unknown type stay in and are labeled.
- Labeled. Nothing is removed. Each row shows the account type of the actor, so a reviewer can see which rows an app made.
- By account type. The account-change visuals count accounts being created, updated and deleted. They split by the type of the account the event is about, so an app being installed or a customer signing up is not counted as a person being added.
Each visual appears once, by its dotted ID; a KPI follows the visual it goes with, or stands on its own. Names such as Segregation of Duties Violations 5.6.6 and SoD violation rate 5.6.2 are MetaFrazo's own measurement names, defined in each visual's description. They are not findings about your organization.
| Area | Shown separately | People only | Labeled | By account type |
|---|---|---|---|---|
| Control and approval | 5.6.6KPI5.6.2KPI5.6.4 5.2.10 5.2.6KPI5.2.2 5.2.7KPI5.2.3 5.2.8KPI5.2.4 5.2.9 5.1.9 5.5.6KPI5.5.2 5.1.10KPI5.1.4 5.3.8KPI5.3.4 | 5.8.1 2.2.11 2.1.12 3.1.10 5.1.6 5.9.1² | ||
| Risk and anomaly | 5.6.7 5.1.8 5.3.6KPI5.3.2 5.6.9 5.1.7KPI5.1.3 5.3.5KPI5.3.1 KPI5.3.3 KPI5.5.4 KPI5.4.4 | 2.6.9 5.3.10 5.5.10 5.4.8 5.4.9 5.3.7 3.1.6 2.3.7 | ||
| Team and activity | 2.1.9 4.1.6 KPI4.5.1 KPI5.6.1 | 4.5.5KPI4.5.2 4.5.10KPI4.5.4 4.5.6 4.5.7¹ 4.5.8 2.4.10 3.6.6 4.1.10 2.7.10 2.7.11 KPI5.6.3 | 5.6.5 5.6.8 5.6.10 4.5.9 2.5.9 | |
| Account changes | 2.6.7 2.2.9 KPI2.2.3 KPI2.6.1 |
x.y.z visual · KPIx.y.z KPI · Each number links to its page; hover for the name.
People only: app accounts left out · By account type: account changes split by account type
¹ A pair that includes an app or customer account is left out.
² Accounts Jira reports as apps start with the bot role. A role you set yourself wins, and every other unmapped account shows as unknown.
Visuals not named here do not look at the account type. They count every account alike. Which edition includes a visual is shown on its page in the Visuals catalog.
Five figures that read differently
- Off-hours actors flagged 5.6.3. Apps and customers have no working hours of their own, so they are not flagged, and the panel shows how many such accounts had off-hours activity. Accounts of unknown type are still rated, because they may be people.
- Missing Approval Heatmap 5.2.9. The rate covers closures made by people. A comment from an app or a customer does not clear a closure; a comment from any other account does, including an account of unknown type or an erased account, and so does a comment with no recorded author.
- First Response Time 2.7.11. A response from an app or a customer account does not count as the first response, and the panel shows beside each project how many issues received one. A response from an account of unknown type still counts.
- Self-Assignment Rate by Project 5.3.8. The rate counts assignee changes made by people. Changes made by apps, customers and accounts of unknown type are shown beside the bar, never inside the rate.
- New Actor Burst Detection 5.3.6. The burst threshold is the mean plus two standard deviations of people's first-week activity. Apps, customers, accounts of unknown type and erased accounts are compared with it and can be flagged, but do not move it, and the KPI Burst actors 5.3.2 counts the people among those flagged. With fewer than three people's debuts in the range, or when they are all the same size, there is no threshold: nothing is flagged and the KPI shows a dash rather than 0.
Deep Analysis and the account type
Deep Analysis works from the account type that a panel's data carries. It does not infer automation from an account's name, ID or activity pattern, and it says so when the data does not record the type.
What Jira records when AI works on a person's behalf
Jira records an action taken on a person's behalf under that person's account. In our own tests in September and October 2026, a change made through Rovo chat and a change made by a tool connected through Atlassian's Rovo MCP server were each recorded under the signed-in person's account, and the issue and its change history carried no other marker. Atlassian's documentation describes the same for a Rovo agent that acts as the person who runs it. An Automation for Jira rule that calls Rovo is recorded under the Automation for Jira app account, so it reads as app activity.
MetaFrazo therefore counts a change made under a person's account as that person's, whatever tool acted through it. MetaFrazo does not detect AI, Rovo or AI-generated changes. It reads the account type Jira reports and nothing more.
How Jira records a Rovo agent that acts under its own identity is not covered here, and this article makes no claim about it.
Where a reviewer needs to know whether AI was involved in a change, the organization's Atlassian audit log is where Atlassian may record Rovo activity. MetaFrazo does not read that log. Your Atlassian administrator can tell you what it holds.
Questions a reviewer could ask
| Question | Where to look |
|---|---|
| Which changes were made by automation rather than a person? | The visuals above that label or split by account type, for example Configuration Change Event Audit Log 2.2.11 and Compliance Event Canvas 5.8.1 |
| Were closures, skips or batch changes made by people or by apps? | The visuals under Control and approval, for example Segregation of Duties Violations 5.6.6 and Direct Open-to-Done Skip 5.2.7 |
| Which accounts are apps? | The account type shown on a labeled row, as Jira reports it |
| Was AI involved in this change? | The events MetaFrazo receives carry the account that acted, not how the change was produced. Your Atlassian audit log is the place to ask |
Where to go from here
- GDPR, NIS2, DORA — what does MetaFrazo give me? for what MetaFrazo holds and what a reviewer can ask of the event record.
- How do I delete my account, and how is personal data erased? for how account data is removed.
- Visuals for the full catalog, with each visual's description.