PII Risk by Actor(5.4.8)
VisualWhen personal data appears in Jira, someone put it there. This visual identifies which actors most frequently create or update issues whose text matches a detection pattern, so the team that owns the data can see where it is being written in.
This is not a disciplinary ranking. Most people who include personal data in Jira do so accidentally, often by copy-pasting from emails or support tickets.
What you can conclude
- A high email-arm count is the most reliable reading on this chart, because the email pattern rarely matches anything else.
- An actor whose bar is almost entirely the digit arm is usually pasting build numbers, order references or account numbers. Open a couple of their issues before treating the count as an exposure.
- If detections are evenly distributed across many actors, the pattern belongs to how the team writes issues rather than to any one person.
How this chart works
Horizontal stacked bar chart ranking actors by count of events they triggered whose text matched a detection pattern, with each bar split into the email-pattern arm and the phone-shaped-digit arm. The two arms overlap: an event matching both is counted in both, so the stacked total can exceed the actor's distinct detection count. Actors are ranked by the email arm, then by the digit arm, and the top 20 are shown. Digits that are part of an Atlassian account id, such as the one behind a mention of a colleague, or of an identifier in the standard UUID format, such as the id of a file embedded in a comment, are not counted, so mentioning someone does not by itself put an actor on this chart. Nor are the digits Jira writes into a comment's own formatting: the file name it records for an embedded image or file (a pasted screenshot is named like image-20260421-185001.png), the editor's internal element ids, and the stored value of a date inserted with the date picker. Digits in a link address still count. Use the date and project filters to focus on specific teams or periods. Each actor carries the type of account Jira reports for it: person, app, customer, unknown when Jira returned no type, or erased.
Where a GDPR review turns to training and process, this is the view that informs it.