Running the ISMS
Using the ISMS Agent (Rovo)
Purpose
The ISMS Agent is an AI assistant based on Atlassian Rovo. It works exclusively on your own ISMS data — the “ISMS Home” project and the “ISMS Home” Confluence space. The language model is operated by Atlassian; your data does not leave the Atlassian Cloud.
Prerequisites
- Rovo is enabled on your Atlassian site (by your Atlassian administration). If Rovo is not active, the app’s agent buttons do not appear in the first place.
- The ISMS is installed and the licence valid — otherwise the agent answers with a corresponding notice.
- After the app installation, the agent automatically appears in the Rovo chat agent list as ISMS Agent.
Entry points in the hub
| Button | Where | What it does |
|---|---|---|
| Open ISMS Agent (round button) | top right in every view | Opens the chat without a preset prompt |
| Explain this control (per item kind e.g. Explain this risk, Explain this measure) | in the detail view of an issue | Explains the open item: purpose, owners, status, evidence freshness, recommended next action |
| Analyse this area | in every work-area header | Starts an analysis tailored to that area — e.g. SoA gaps in Requirements Management, or critical and unassessed risks in Risk Management |
The chat offers four conversation starters (shipped in German): currently critical risks, open items in the SoA (ISO 27001 Annex A), a summary of the open nonconformities, and proposed risk scenarios for an asset. The agent answers in whatever language you write.
What the agent can do
| Kind | Capability |
|---|---|
| Read | Overview of language, project, space, installation state and volumes per domain |
| Search across the ISMS issues (by domain, free text, status) | |
| A single issue in detail — fields, links, comments | |
| Explain the risk model — the 1–4 scales and thresholds, exactly as the app calculates them | |
| SoA gap analysis against ISO 27001:2022 Annex A (missing / open / not applicable) | |
| Evidence gaps: requirements without evidence, or with stale evidence only | |
| Write (only after confirmation) | Create an issue — e.g. a risk scenario or a measure, linked right away if you want |
| Change fields, add comments or perform a status transition | |
| Save a document draft in the Confluence space — the agent asks for the target location (parent page) first; the draft is ready to hand over to document control |
The safety rules
- Nothing happens without your consent. Before every write the agent shows what it would do; Rovo additionally asks for an explicit confirmation.
- The agent acts in your name. All access runs with your permissions: you only see what you are allowed to see anyway, and issues it creates carry you as the author.
- AI contributions are marked. Created or updated items get the label
ai-assisted(findable via JQL), comments get the marker “🤖 AI-assisted (ISMS Agent) …”, page drafts an AI banner at the top. - Evidence instead of assertions. For factual statements the agent names the source (issue key or page title) and the data’s timestamp; where it is unsure, it says so.
- The agent never deletes anything and never changes permissions.
Deliberate limits: the agent cannot read file attachments (PDF, DOCX) — work with Confluence pages or pasted text. Triggered from automation rules it can only read; writes are excluded at platform level there. Statements about frameworks other than ISO 27001 Annex A are marked as general model knowledge.
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20