Initial setup
Assigning roles and go-live checklist
Purpose
After installation you fill the ISMS roles, verify the granted permissions and walk through the go-live checklist. Only then is the ISMS truly usable for your team.
Who can do this
Changing roles and applying permissions: Jira administrators only. Everyone may view the role register.
Steps: assign the roles
- Open Roles & responsibilities in the sidebar. While top management and the information security officer are unassigned, administrators are additionally reminded by the banner “👥 The core ISMS roles are not filled yet …” with the button Assign roles.
- Enter the owners and their deputies — the organisation-wide roles are top management, information security officer (CISO), ISMS team, data protection officer, internal audit and continuity/BCM officer.
From these entries the app derives the permissions in the Confluence space: the security officer and deputies get read, create-page and space-admin rights, top management read rights, the ISMS team read and create-page rights, the scope groups read rights. Rights are only ever added, never revoked. Details: Roles and permissions.
Steps: verify permissions
- Open Setup & Configuration. After installation, the Permissions & check card shows the last permission run per role.
- If a run is incomplete or rejected, click Apply permissions again. If Jira reports “rejected by Jira – re-confirm the app permissions”, the app permissions need to be re-approved after an update first.
Go-live checklist
- The Setup page shows “✓ Setup complete” at the top; the checklist reports “All required steps are done. Your ISMS is ready to use …”
- The Jira project opens via Open ISMS project ↗ and contains the issue types.
- No “Complete filters” card visible any more — all 30 filters are in place.
- The Confluence space opens via Governance ↗; live tables show Jira data; the space logo is set.
- Role register filled; the core-roles banner is gone.
- Permissions & check card without open or rejected entries.
- Decision made: enable the RACI notifications? The master switch is OFF by default (Setting up notifications (RACI)).
- Decision made: enable the document-control notifications? (Using document control)
- Licence status in Setup is valid.
Jira Service Management only
- Link the knowledge base (one-time, manual): Atlassian offers no API for this — link the “ISMS Home” space (
ISMSTK) once by hand as the service project's knowledge base: open the knowledge base settings → Link space → select the space. - Native JSM queues (optional): the Cloud API cannot create queues. The optional setup step “Switch to native JSM queues” shows each queue's name and JQL with Copy buttons; after creating them by hand, Re-detect queues confirms the state. The work areas also function without this step.
What happens next
Your team starts with Running the ISMS. Administrators find the ongoing duties under Administration and maintenance.
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20