Security and permissions, without the marketing fog.
Resultary is a Jira Cloud Forge app. This page describes the current app architecture and requested permissions so administrators can evaluate it before installation.
Forge-hosted architecture
Core app execution and persistent application state use Atlassian Forge. Resultary does not operate a separate custom backend database for its core monitor state.
Requested Jira / Forge scopes
| Scope | Why Resultary uses it |
|---|---|
storage:app | Store monitor configuration, incident state, audit/operational state and related app data in Forge-hosted storage. |
read:jira-work | Read the Jira evidence required to verify configured business outcomes. |
write:jira-work | Create and update Resultary Jira incident records and perform the Jira writes required by configured incident handling. |
report:personal-data | Report stored Jira account identifiers through Atlassian Forge privacy mechanisms so closed or updated account references can be handled. |
Credentials and secrets
Protected heartbeat credentials and supported notification webhook URLs use Forge secret storage. Resultary does not require your Atlassian account password or a Jira Personal Access Token for normal Forge operation.
External network destinations
The app manifest currently permits backend egress only to supported Slack incoming webhooks and Microsoft Power Platform / Teams webhook endpoints. Those destinations are used only when an administrator configures the corresponding notification integration.
Data residency
Persistent Forge-hosted storage inherits Atlassian Forge data-residency capabilities. Hosted data can follow the customer’s supported Atlassian data-residency location. Optional Slack or Teams notifications are external egress and are governed by the administrator’s chosen service and configuration.
Atlassian Forge data residency documentation ↗
Tenant separation
Forge-hosted storage is partitioned by app installation and Atlassian site. Resultary does not intentionally use a shared custom database for customer monitor state.
No Jira Automation rule editing
Resultary observes protected run signals and configured Jira outcomes. It does not edit, enable, disable or delete Jira Automation rules.
Vulnerability reporting
Report a suspected security issue to support@getresultary.com with “Resultary Security” in the subject. Do not include passwords, tokens, heartbeat credentials or webhook secrets in ordinary email.
Security status during private beta
Resultary is in private beta and has not claimed certifications it does not hold. Security and Marketplace disclosures will be updated as the product progresses toward general commercial availability.