Plumbworks / Evidence Pack / Jira + Confluence
Audit week should not cost you three days of screenshots.
Evidence Pack collects the artefacts auditors request from Jira and Confluence — change approvals, ticket histories, access reviews, permission snapshots — and produces one timestamped file. Define the request once; run it again next year in a minute.
The gap list is the part worth having early. Everything else is transcription.
What goes in a pack
You build a request once — a set of queries mapped to the controls your auditor cares about — and run it per period. Templates ship for SOC 2, ISO 27001 and ISO 9001; you can define your own controls for anything else.
- changesApproved change records. Every issue matching your change query, with its approval transition, who approved it, when, and the linked deployment or release.
- gapsWhat is missing. Changes that reached done without a recorded approval, approvals granted by the person who requested them, and tickets closed with mandatory fields empty.
- accessJoiners and leavers. Access request and revocation tickets matched to the date the change actually took effect, with the time between them.
- permissionsPoint-in-time snapshots. Scheme and group membership captured on a schedule, so you can show what access looked like in March rather than what it looks like today.
- documentsApproved policies. Confluence page approvals within the period, including version and approver. Reads Review Cycle data directly when both apps are installed.
- outputOne file per period. A PDF index describing each control and its sample, plus CSV appendices holding the raw rows, in a single archive with a generation timestamp.
- repeatNext year takes a minute. Saved requests re-run against a new date range. Most of audit preparation is doing the same extraction again.
It reports, it does not certify
Evidence Pack extracts and formats what is already in your Jira and Confluence data. It does not assess whether your controls are adequate, and installing it does not make you compliant with anything.
What it removes is the fortnight of manual exporting, screenshotting and spreadsheet-stitching that sits between a control request and an answer. Your auditor still decides whether the evidence is sufficient.
Pricing
One licence covers both the Jira and Confluence sides. Billed by Atlassian at your largest product's user tier. Free for instances of 10 users or fewer.
| Users | Per user / month | Monthly |
|---|---|---|
| 1 – 10 | free | $0 |
| 11 – 100 | $0.85 | $85 at 100 |
| 101 – 500 | $0.50 | $250 at 500 |
| 501 – 1,000 | $0.32 | $320 at 1,000 |
| 1,001 + | $0.20 | $400 at 2,000 |
Questions
Can I hand the output straight to an auditor?
That is the intent. The PDF index states each control, the query used to sample it, the period, and the row count, so an auditor can see how the evidence was produced rather than taking the numbers on trust.
How far back can it look?
As far as your Jira and Confluence history goes. Permission snapshots are different — those only exist from the day you start capturing them, so start early if a quarterly snapshot is in scope.
Does it work without Review Cycle?
Yes. Review Cycle data is included automatically if you have it; without it, the document-approval section draws on Confluence page history instead.
Where is the pack generated?
Inside your Atlassian tenant. The file is produced and downloaded within Forge, so evidence never transits a Plumbworks system.