User Guide
How to: Run a Governance Audit
A complete walkthrough for auditing people, access, and configuration health using Pulse AI. Suited for Jira admins and consultants.
What a Governance Audit Covers
A full governance audit in Pulse AI spans three areas:
| Area | Sections | Primary Concern |
|---|---|---|
| People & Access | Users, Permissions, Groups | Who has access and whether it's appropriate |
| Workflow & Config | Workflows, Schemes, Configurations | Configuration debt and cleanup risk |
| Data Integrity | Projects, Issue Integrity, Data Accuracy | Whether Jira data reflects real work |
Step 1: Start with the Dashboard
- Open Dashboard Overview
- Note the Governance pillar score - this covers Users, Permissions, and Groups
- Note the Workflows & Schemes pillar score - covers configuration health
- Open the Top Findings Table and filter by severity = High
Step 2: Audit Users
Navigate to Governance → Users.
Check each risk category:
| Risk | Condition | Recommended Action |
|---|---|---|
| Dormant | Active account, last activity > 90 days | Deactivate in Atlassian Admin Console |
| Inactive Admin | Admin, no activity ≥ 60 days | Remove from admin group |
| Overpermissioned | Admin on 15+ projects | Review and reduce project admin grants |
| No Group | No group membership | Assign to appropriate group or investigate direct grants |
User deactivation is done at admin.atlassian.com - not inside Jira.
Step 3: Audit Permissions
Navigate to Governance → Permissions.
Check for:
- Orphaned schemes - zero projects assigned. Safe to delete after confirming they are not needed.
- SD Customer Grants / App Role Grants - review whether these are intentional.
The Default Permission Scheme and Default Software Scheme are Guard objects - Pulse AI will not flag these.
Step 4: Audit Groups
Navigate to Governance → Groups.
Check for:
- Empty Groups - zero members. Delete if no longer needed.
- Unreferenced Groups - not used in any scheme. Review before deleting.
- Oversized Groups - unusually large membership. Confirm whether all members are still active.
Step 5: Audit Workflows & Schemes
Navigate to Workflows & Schemes.
| Section | What to Look For | Docs |
|---|---|---|
| Workflows | Orphaned, dead-end, duplicate workflows | Workflows → |
| Workflow Schemes | Orphaned, draft, missing default | Workflow Schemes → |
| Statuses | Orphaned statuses, missing category | States & Outcomes → |
| Resolutions | No default set, overloaded resolutions | States & Outcomes → |
| Screens | Bloated (50+ fields), duplicate, orphaned | Transition Screens → |
| Work Item Security | No security levels defined | All Schemes → |
Step 6: Audit Configurations
Navigate to Configurations.
| Section | What to Look For | Docs |
|---|---|---|
| Custom Fields | Unused (High), Risky Deletion (High), Global Bloat (Low) | Custom Fields → |
| Work Types | Unused issue types, duplicates | Work Types & Schemes → |
| Filters | Dead owner, invalid JQL, publicly shared | Global Config → |
Step 7: Document and Re-scan
- Export or note all High findings
- Assign remediation tasks to the relevant Jira admin(s)
- After fixes are applied, go to Settings → Scan Schedule → Run Now
- Review the updated Dashboard and compare Pulse Scores