Comment History for Audit Teams

Stop reconstructing Jira evidence from Slack and screenshots - give auditors a single, verifiable comment trail per ticket.

Product: Comment History Audience: Audit Teams

Why this matters for audit teams

Audit relies on a stable, reproducible record. The single biggest weakness of native Jira as an audit source is that the comment trail is mutable: edits overwrite, deletions vanish, and visibility scope changes silently. None of this is captured in a way an auditor can sample or re-test.

For an audit team, this means every audit cycle starts with the same loss of evidence. The comment trail that existed when the control was performed is not the comment trail visible when the auditor opens the ticket six months later. Workpapers fill up with screenshots and Slack exports because the system of record cannot answer “what did this comment say before it was edited.”

Comment History changes the foundation. The comment trail becomes versioned, attributed, and exportable from the point of installation forward. Sampling plans become reproducible. Walkthroughs of historical controls become single queries. The audit cycle starts where it should - on the controls themselves - instead of on the evidence reconstruction.

Where this fits in the audit workflow

  1. Planning - the comment trail becomes a defensible audit population, so sampling can be designed against actual evidence rather than against best-guess Slack reconstructions.
  2. Fieldwork - per-ticket evidence exports drop straight into workpapers. Walkthroughs of edited or deleted comments are answered from a single screen.
  3. Follow-up - when auditors return next cycle, the evidence is still there, in the same form - so prior-year findings can be re-tested without ambiguity.

What “good” looks like

Good is the auditor asking for the comment history on ticket FOO-123 and getting a PDF in five minutes that shows every version of every comment, every deletion, and every visibility change, with authors and timestamps. Comment History exists so audit teams can answer that request without apologising.

What audit teams are dealing with today

  • External auditors ask for the decision trail on a sample of tickets, and there is no native way to produce a comment history for any of them.
  • Comment edits in Jira overwrite the previous text - so when an auditor asks 'what did the comment say before it was edited,' the answer is 'we don't know.'
  • Deleted comments leave no trace in the Jira UI, the issue index, or the activity stream - they simply vanish from the audit population.
  • Internal audit's sampling plans assume evidence is reproducible. With Jira comments, a sample drawn in Q2 may not match the same query re-run in Q4.
  • Audit walkthroughs of change-management controls stall when reviewers ask 'who approved this in writing' and the approval comment has since been edited.
  • Reconstructing the comment trail from Slack, email and reporter memory takes weeks per audit cycle and produces evidence that auditors flag as weak.

How Comment History helps audit teams

Reproducible, versioned comment trail

Every comment version is captured at creation and on every edit. A sample drawn today returns the same evidence next quarter - the audit population is stable.

Deleted-comment retention for the sample

Deleted comments stay in the Comment History store with author, timestamp, and original text. Deletions never silently shrink the audit population.

Per-ticket evidence export

Export the full comment trail for any sampled ticket as a single PDF or CSV - ready to drop into the audit workpapers without manual screenshotting.

Point-in-time comment reconstruction

Recreate the state of all comments on an issue or JQL set as of a given date. Walkthroughs of historical controls become a single query instead of a forensic exercise.

Attribution on visibility changes

When a comment's visibility scope is changed, Comment History records who did it and when - so 'restricted comment' control narratives can be evidenced, not asserted.

Use cases

  1. Q4 external audit, change-management sample. Auditor pulls a sample of 25 production releases. For each, Comment History exports the approval and risk-review comments on the change ticket - including any edits or deletions - as a single PDF per release.
  2. Internal audit walkthrough of access requests. Internal audit walks the access-request control end-to-end on a ticket from March 14. Comment History shows the original approval text, the subsequent edit, and who made each.
  3. Year-on-year audit-population stability. Re-running last year's audit query in February returns identical comment evidence to the original audit - because Comment History preserves the comment trail independent of live Jira.
  4. Auditor follow-up on a deleted comment. Auditor flags that a comment referenced in a workpaper no longer exists in Jira. Comment History shows the deletion, the deleting user, and the original content.

Common questions from audit teams

Can auditors rely on Jira's built-in activity log for the comment trail?

No. Jira's activity log shows that a comment was added, edited or deleted, but not the content of the previous version. Auditors who need to see what was said before an edit, or what a deleted comment contained, will not get that from native Jira. Comment History supplies the missing content with author and timestamp.

Does Comment History work for external audit evidence?

Yes. The point-in-time export produces a stable, signed-off PDF or CSV that drops into the workpapers. External auditors typically accept the export as evidence because it includes original timestamps, author IDs, and version numbers, and is generated from the same Jira data the live tickets are drawn from.

How does Comment History affect our audit sampling plans?

Most sampling plans assume the population is stable between draw and review. Native Jira does not give that guarantee for comments. With Comment History installed, the comment population is reproducible from any point - so samples drawn in Q1 still resolve correctly in Q4, and the audit trail is defensible.

Will Comment History help with SOX, SOC 2 and ISO 27001 audits?

Yes. All three frameworks expect evidence of decisions and approvals recorded on tracked work items. Comment History gives auditors that evidence - the versioned, attributed trail - directly from the Jira tickets the controls are documented against. It eliminates the reconstruction step that audit teams currently spend weeks on.

Try Comment History for your team

Comment History works for audit teams on Jira Cloud and Data Center. Install from the Atlassian Marketplace, or read the main Comment History page for the full feature list.

Try Comment History on the Atlassian Marketplace ↗   See the full Comment History overview →

Also built for

Comment History solves a different problem for each team: