Review and resolve policy violations

Information protection policies give you a rule-based way to detect sensitive data in Jira and Confluence, so you can take action automatically or manually.

Read more about information protection policies

Who can do this?
Role: Organization admin, Guard Detect admin
Atlassian Cloud: Atlassian Guard Premium
Atlassian Government Cloud:Available


When a policy is active, it will continuously monitor and assess if any newly created or updated content created meets it’s configuration.

If it finds a match, the first step is to review the sensitive data detected by the policy, then resolve (or ignore) the violation. Resolving the violation redacts the information from the original content.

This approach applies to active policies with the Create a violation control.

Policies with Redact matching content control don’t create violations for review.

Read more about automatically redacted content

Before you begin

Check the policy is active and is set to Create a violation. If you haven’t set up a policy, create and test a policy first.

Understand how to build an information protection policy

Resolving a violation will redact the sensitive information from the affected content. If you don’t want to redact the data, ignore the finding and keep it unresolved.

Redacted content can only be restored through the Guard Detect API within 30 days. After 30 days, the original content is permanently deleted and can’t be recovered.

Review the violation and its findings

A violation is a record of a policy matching content within a content object, such as a Jira work item or Confluence page. A finding is an individual sensitive-data match within that violation.

One violation can contain multiple findings.

To review a violation:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Security policies, then Policy violations.

  3. Select the Open tab, then select Violation ID to view its details.

  4. Review the policy and version that raised the violation, the affected resource, and the findings.

  5. Select a finding to review the matched snippet, confidence, status, and when it was detected.

  6. Review each finding to determine whether the information should be redacted, or simply left as a finding.

From Policy violations, you can use the search and policy filters to narrow down the list. The number of findings and how long a violation has been open can help you prioritize your review.

A finding with a Present status means the protected information is still shown in the content. Removed means the information is no longer accessible.

If a match shouldn’t be redacted, you can leave the violation, or resolve it after checking which findings the action will affect.

After reviewing any policy violations, it’s worth checking the policy’s configuration and adjusting as needed to potentially reduce unintended matches.

Create and test an information protection policy

Resolve the violation

To avoid any extra effort, resolve a violation only after you’ve reviewed its findings and believe the information should actually be redacted.

To resolve a violation:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Security policies, then Policy violations.

  3. Select the Open tab, then select the Violation ID.

  4. After reviewing the findings, select Resolve.

  5. Review the confirmation, including how many findings will be affected and any other open violations on the same object.

  6. If you’re happy to continue, select Resolve to confirm the redaction.

The violation will transition to Resolving while the findings are being redacted. When all findings have been removed, the violation moves to the Resolved tab. The record remains available so you can review the policy version, affected resource, and findings at any stage.

You can also manually redact sensitive data from Jira, and Confluence.

Still need help?

The Atlassian Community is here for you.