Plumbworks

Plumbworks / Evidence Pack / Jira + Confluence

Audit week should not cost you three days of screenshots.

Evidence Pack collects the artefacts auditors request from Jira and Confluence — change approvals, ticket histories, access reviews, permission snapshots — and produces one timestamped file. Define the request once; run it again next year in a minute.

SOC 2 Type 2  ·  period 2026-01-01 to 2026-06-30 generated 2026-08-31 09:14 UTC
CC8.1 — Change management 412 changes, each with approver, ticket, and deployment record 412 items
CC6.2 — Access provisioning and removal Joiners and leavers with request ticket and completion date 96 items
CC8.1 — 7 changes deployed without a recorded approval Flagged before your auditor finds them 7 gaps
CC6.3 — Quarterly permission snapshots Two snapshots, full scheme and group membership 2 items
Evidence pack — PDF index plus CSV appendices 7 gaps to resolve

The gap list is the part worth having early. Everything else is transcription.

What goes in a pack

You build a request once — a set of queries mapped to the controls your auditor cares about — and run it per period. Templates ship for SOC 2, ISO 27001 and ISO 9001; you can define your own controls for anything else.

  • changesApproved change records. Every issue matching your change query, with its approval transition, who approved it, when, and the linked deployment or release.
  • gapsWhat is missing. Changes that reached done without a recorded approval, approvals granted by the person who requested them, and tickets closed with mandatory fields empty.
  • accessJoiners and leavers. Access request and revocation tickets matched to the date the change actually took effect, with the time between them.
  • permissionsPoint-in-time snapshots. Scheme and group membership captured on a schedule, so you can show what access looked like in March rather than what it looks like today.
  • documentsApproved policies. Confluence page approvals within the period, including version and approver. Reads Review Cycle data directly when both apps are installed.
  • outputOne file per period. A PDF index describing each control and its sample, plus CSV appendices holding the raw rows, in a single archive with a generation timestamp.
  • repeatNext year takes a minute. Saved requests re-run against a new date range. Most of audit preparation is doing the same extraction again.
acme.atlassian.net / jira / apps / evidence-pack SOC 2 Type 2 — 2026-01-01 to 2026-06-30 GENERATE PACK CONTROL SOURCE QUERY ITEMS STATE CC8.1 — Change management approver + deployment per change project = CHG AND status = Done 412 COMPLETE CC6.2 — Access provisioning joiners and leavers with tickets type IN (Access, Leaver) 96 COMPLETE CC8.1 — Unapproved changes done without recorded approval approval IS EMPTY 7 GAPS CC6.3 — Permission snapshots scheme + group membership quarterly capture 2 COMPLETE + 3 more controls in this request 7 GAPS TO RESOLVE GENERATED 2026-08-31 09:14 UTC
Evidence Pack, request view — simplified rendering, not a screenshot
2026-01-01 Audit period opens 2026-01-05 Permission snapshot, Q1 full scheme and group membership 2026-02-12 Change record sampled, CC8.1 approver, ticket and deployment linked 2026-03-03 Leaver ticket closed, CC6.2 access revoked 2 days after request 2026-04-06 Permission snapshot, Q2 captured on schedule 2026-05-18 Change deployed without approval flagged as a gap — 1 of 7 2026-06-30 Audit period closes 2026-08-31 Pack generated — PDF index + CSV appendices
One period, sampled once — the same request re-runs against next year's dates

It reports, it does not certify

Evidence Pack extracts and formats what is already in your Jira and Confluence data. It does not assess whether your controls are adequate, and installing it does not make you compliant with anything.

What it removes is the fortnight of manual exporting, screenshotting and spreadsheet-stitching that sits between a control request and an answer. Your auditor still decides whether the evidence is sufficient.

Pricing

One licence covers both the Jira and Confluence sides. Billed by Atlassian at your largest product's user tier. Free for instances of 10 users or fewer.

UsersPer user / monthMonthly
1 – 10free$0
11 – 100$0.85$85 at 100
101 – 500$0.50$250 at 500
501 – 1,000$0.32$320 at 1,000
1,001 +$0.20$400 at 2,000

Questions

Can I hand the output straight to an auditor?

That is the intent. The PDF index states each control, the query used to sample it, the period, and the row count, so an auditor can see how the evidence was produced rather than taking the numbers on trust.

How far back can it look?

As far as your Jira and Confluence history goes. Permission snapshots are different — those only exist from the day you start capturing them, so start early if a quarterly snapshot is in scope.

Does it work without Review Cycle?

Yes. Review Cycle data is included automatically if you have it; without it, the document-approval section draws on Confluence page history instead.

Where is the pack generated?

Inside your Atlassian tenant. The file is produced and downloaded within Forge, so evidence never transits a Plumbworks system.