Revyz Assessment Manager
The Revyz Assessment Manager is a specialized Atlassian app designed for Solution Partners and consultants. Its main job is to help solution partners and consultants perform strong cloud governance and security assessments on their clients' Jira Cloud sites.
How the Revyz Assessment Manager Accesses Customer Sites
The Revyz Assessment Manager is an Atlassian Cloud app. Once installed in the Solution Partner Jira Cloud site, it uses an API token from the target Jira Cloud site's administrator to create a secure, remote connection. This lets the app "talk to" the target site programmatically, without needing any extra software installed on the target site. This connection happens through Atlassian APIs, which efficiently retrieve metadata (Configuration information).
Required Permissions
The app gets its permissions from the user who generates the API token. To successfully assess the target site, the API token needs site administrator permissions. This high level of access is crucial because it allows the Revyz Assessment Manager to access all the configuration details on that Jira site.
Information Retrieved from the Atlassian Jira Site
The Revyz Assessment Manager primarily gathers settings information, or metadata, from the Jira Cloud site. It's important to understand that the app does not access any data such as Jira tickets, attachments, or user comments. Its main focus is to evaluate the site's configuration from a governance and security standpoint.
Here are some examples of the configuration metadata it retrieves:
Issue types and their schemes
Workflows and workflow schemes
Screens and screen schemes
Custom fields and their contexts
Permission schemes
Notification schemes
Jira Assets (formerly Insight) CMDB schemas and settings
What Happens to the Gathered Information
Revyz allocates a dedicated compute instance in the backend for every assessment. Once the metadata is collected in memory, the Revyz Assessment Manager performs an intelligent analysis. This generates over 30+ types of actionable analytics and insights. This data is then used to create reports that help site administrators quickly pinpoint areas where they can optimize the site for better performance, governance, and security. Once the analysis is complete the gathered metadata is destroyed along the the dedicated compute instance.
Where the Information is Stored
The retrieved metadata is immediately removed from the compute instance after the necessary analysis is finished and the reports are generated. The reports are then stored in Revyz’s backend. The Revyz Assessment Manager itself is built on Amazon Web Services (AWS) and holds a SOC2 Type 2 certification.
Revyz takes robust security measures when handling metadata:
All data is encrypted in transit using TLS 1.2.
The computing resources used to retrieve the data are located in the AWS US-East datacenter.