Customers are able to add Internal Comments

Platform Notice: Cloud Only - This article only applies to Atlassian apps on the cloud platform.

Summary

This article addresses the reasons why customers can add Internal Comments on Issues within Jira Service Management Projects.

Solution

Permission scheme and the Core mail handler

Occasionally, project customers can include internal comments on ongoing issues, which is expected behavior.

A Jira Service Management project can receive customer requests through the email address configured in Space Settings > Email. Jira Core also has a mail handler in Settings > System > Incoming Mail. The Jira Core mail handler is intended for Jira users with application access and is not intended for Jira Service Management customers without a license.

Why this happens: If a customer email is sent to the Jira Global Mail Handler instead of the Jira Service Management project's incoming mail, and the subject contains a valid issue key, the email can be appended to the Jira Service Management issue as an Internal Comment when the customer has the explicit Add Comments permission.

What preventive measures can be implemented to avert this scenario?

  • Review the permissions scheme for the explicit Add Comments permission. The behavior has been observed when the Reporter, Service Desk Customers, or the Service Desk Team, each as a project role, is granted the Add Comments permission.

  • Advise customers not to forward emails that include the Jira Global Mail Handler in the To or CC list. Direct email requests through the Jira Service Management project's incoming mail instead.

  • Removing the public Add Comments permission is another option. However, this may prevent emails from being processed by the Jira mail handler and may require manual investigation through the logs to identify potential issues.

  • Another option is to configure a custom mail handler for incoming mail and use the custom email as the Jira notification address. Keep the existing reference to Add custom email addresses for product notifications for the configuration instructions.

Updated on August 18, 2026

Still need help?

The Atlassian Community is here for you.