PII Severity Score Distribution(5.4.10)

Visual
Where to find it:CompliancePII Detector
Ent AdvancedPii Detector add-on
Open in dashboard

Not all detections require the same response. A phone-shaped digit run detected while an issue was closed is a different matter from an email address and a digit run detected together while it was open. This breakdown classifies the detections in the selected range into four tiers so you can see how the total splits across them, from Critical down to Low.

What you can conclude

  • A high count of Critical-tier issues (email pattern and phone-shaped digits on the same event, detected while the issue was open) means the most likely personal data was written into issues while they were in use; a reviewer could ask who owns them. These are the highest-confidence detections, because two independent patterns matched the same event.
  • A large Medium-tier count (a pattern detected while the issue was closed) means patterns were recorded on issues that were already in a done status. The tier reflects the status recorded with that event: the issue may have been reopened, or the text edited out, since.
  • A dashboard that is mostly Low tier indicates that the total is being driven by bare numeric identifiers rather than by recognizable personal data.

How this chart works

KPI card grid showing detection counts grouped into four tiers: Critical (email pattern and phone-shaped digits on the same event, detected while the issue was open), High (a single pattern detected while the issue was open), Medium (a pattern detected while the issue was closed), Low (numeric ID only). Use the date and project filters to scope the assessment.

What moves a row between tiers. Only the email and phone-shaped-digit patterns band a row; the numeric ID pattern only admits it to the population. So an issue whose only match is a 6-to-12 digit identifier always lands in Low, however many times it appears. Digits that are part of an Atlassian account id, such as the one behind a mention of a colleague, or of an identifier in the standard UUID format, such as the id of a file embedded in a comment, neither admit nor band an issue. Nor do the digits Jira writes into a comment's own formatting: the file name it records for an embedded image or file (a pasted screenshot is named like image-20260421-185001.png), the editor's internal element ids, and the stored value of a date inserted with the date picker. Digits in a link address still count.

Teams preparing a GDPR review use the severity split to sequence remediation.