Running the ISMS

Using the ISMS Agent (Rovo)

Purpose

The ISMS Agent is an AI assistant based on Atlassian Rovo. It works exclusively on your own ISMS data — the “ISMS Home” project and the “ISMS Home” Confluence space. The language model is operated by Atlassian; your data does not leave the Atlassian Cloud.

Prerequisites

  • Rovo is enabled on your Atlassian site (by your Atlassian administration). If Rovo is not active, the app’s agent buttons do not appear in the first place.
  • The ISMS is installed and the licence valid — otherwise the agent answers with a corresponding notice.
  • After the app installation, the agent automatically appears in the Rovo chat agent list as ISMS Agent.

Entry points in the hub

ButtonWhereWhat it does
Open ISMS Agent (round button)top right in every viewOpens the chat without a preset prompt
Explain this control (per item kind e.g. Explain this risk, Explain this measure)in the detail view of an issueExplains the open item: purpose, owners, status, evidence freshness, recommended next action
Analyse this areain every work-area headerStarts an analysis tailored to that area — e.g. SoA gaps in Requirements Management, or critical and unassessed risks in Risk Management

The chat offers four conversation starters (shipped in German): currently critical risks, open items in the SoA (ISO 27001 Annex A), a summary of the open nonconformities, and proposed risk scenarios for an asset. The agent answers in whatever language you write.

Detail view of an issue: the “Explain this control” button next to “Relationships” — the entry point into the ISMS Agent from an issue.

What the agent can do

KindCapability
ReadOverview of language, project, space, installation state and volumes per domain
Search across the ISMS issues (by domain, free text, status)
A single issue in detail — fields, links, comments
Explain the risk model — the 1–4 scales and thresholds, exactly as the app calculates them
SoA gap analysis against ISO 27001:2022 Annex A (missing / open / not applicable)
Evidence gaps: requirements without evidence, or with stale evidence only
Write (only after confirmation)Create an issue — e.g. a risk scenario or a measure, linked right away if you want
Change fields, add comments or perform a status transition
Save a document draft in the Confluence space — the agent asks for the target location (parent page) first; the draft is ready to hand over to document control

The safety rules

  • Nothing happens without your consent. Before every write the agent shows what it would do; Rovo additionally asks for an explicit confirmation.
  • The agent acts in your name. All access runs with your permissions: you only see what you are allowed to see anyway, and issues it creates carry you as the author.
  • AI contributions are marked. Created or updated items get the label ai-assisted (findable via JQL), comments get the marker “🤖 AI-assisted (ISMS Agent) …”, page drafts an AI banner at the top.
  • Evidence instead of assertions. For factual statements the agent names the source (issue key or page title) and the data’s timestamp; where it is unsure, it says so.
  • The agent never deletes anything and never changes permissions.

Deliberate limits: the agent cannot read file attachments (PDF, DOCX) — work with Confluence pages or pasted text. Triggered from automation rules it can only read; writes are excluded at platform level there. Statements about frameworks other than ISO 27001 Annex A are marked as general model knowledge.

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20