Why this matters for security teams
Security work depends on contemporaneous record. The incident ticket as it existed at the moment of the incident - comments, attributions, visibility scopes - is the most reliable evidence of what the team saw and did. Native Jira does not preserve that record. Edits overwrite. Deletions erase. Visibility changes happen silently. By the time the security team is investigating, the record may have shifted.
For incident investigation, insider-threat review, and post-incident forensics, this is the gap. The investigator cannot answer ‘what did the comment say before it was edited’ or ‘who relaxed the visibility on this comment’ or ‘what did the deleted comment contain’ - and these are exactly the questions investigations turn on.
Comment History closes the gap. The comment trail becomes versioned, attributed, immutable, and exportable. Investigators get the contemporaneous record. Insider-threat reviews get the editing history. Post-incident forensics get the original handling comments. Discovery responses get the immutable trail with provenance intact.
Where this fits in security operations
- Incident investigation - the comment trail on the incident ticket is preserved through any subsequent edits or deletions; investigators see what was really said.
- Insider-threat review - editing history with attribution lets investigators evaluate intent and behavior, not just the final state.
- Post-incident forensics - PIRs draw on the contemporaneous record rather than the post-cleanup version of the ticket.
What “good” looks like
Good is the security investigator who can answer the ‘what did this comment say before it was edited’ question with a single export - because Comment History preserved the version. The investigation moves forward on evidence rather than on indirect reconstruction. That is what Comment History delivers to security teams.
What security teams are dealing with today
- Security investigations of past incidents find that comments referencing the incident were edited or deleted - and native Jira can't reproduce the original content.
- Insider-threat reviews need the un-edited comment trail to evaluate intent and behavior - native Jira gives only the last version.
- Post-incident forensics rely on the contemporaneous record on the incident ticket - which native Jira does not preserve through edits.
- Investigators ask 'who edited this comment and what did it say before' - native Jira answers neither.
- Visibility-scope changes on security-sensitive comments are silent in native Jira, so 'who removed the restriction' is unanswerable.
- Discovery on security-related litigation finds gaps in the comment trail that the investigator can't close from native Jira data.
How Comment History helps security teams
Immutable versioned trail
Every edit creates a new version with author, timestamp, and content. The trail is immutable from the app's perspective, supporting forensic standards of evidence preservation.
Deleted-comment recovery
Deleted comments stay in Comment History with the original author and content. Investigation of deleted-comment context is straightforward instead of impossible.
Visibility-change attribution
Changes to a comment's visibility scope - especially relaxations from restricted to broad - are recorded with attribution. Insider-threat reviews of 'who exposed this comment' have an answer.
Point-in-time investigation
Reconstruct the comment state on an incident ticket as it existed during the incident window - even if comments were later edited or deleted.
Forensic-grade export
Per-ticket exports as PDF or CSV with version, author, timestamp - drop into forensic workpapers and discovery responses without additional processing.
Use cases
- Insider-threat investigation. Security team investigates an employee suspected of editing incident commentary to cover behavior. Comment History shows every comment version with attribution, including any deletions.
- Post-incident forensics. PIR on a major incident needs the original handling comments. Comment History shows the contemporaneous record even where comments were later edited as part of cleanup.
- Visibility-relaxation review. Investigation of a leak finds that an internal-only comment had its visibility relaxed. Comment History shows who relaxed it, when, and what the comment said.
- Security-incident discovery support. Litigation arising from a security incident requires comment-trail evidence. Comment History supplies the immutable per-ticket export to discovery.
Common questions from security teams
How does Comment History support insider-threat investigations?
Insider-threat investigations frequently look at whether an employee modified records to obscure activity. Native Jira's edit-overwrite model is a gift to that kind of obscuring; investigators get only the last version. Comment History captures every version with attribution, so the question 'what did this comment say before it was edited, and who edited it' has a single, defensible answer - which is essential to insider-threat work.
Is the Comment History store itself tamper-evident?
Comment History stores its data in append-only structures with timestamped version records. Standard administrative access to the underlying storage is the same as any Jira-adjacent data; for high-assurance environments, customers pair the app with their wider tamper-evidence and SIEM integration. The app is a building block - not a forensic chain-of-custody appliance by itself - but it removes the largest gap in the native Jira evidence model.
Can deleted comments be recovered after the fact?
Comment History captures comments on creation and edit, so the historic record survives deletion of the live comment - provided the app was installed before the deletion happened. If a comment was deleted in native Jira before the app was installed, that comment is gone; the app is preventative rather than forensic for pre-install data.
Will Comment History help with security-related discovery requests?
Yes. Discovery requests on security-related litigation routinely include the comment trail on incident tickets. Native Jira frequently cannot produce the trail in a form that survives challenge - because edits and deletions have erased the contemporaneous record. Comment History produces the immutable, attributed trail directly, and the per-ticket export drops into the discovery response with provenance intact.
Try Comment History for your team
Comment History works for security teams on Jira Cloud and Data Center. Install from the Atlassian Marketplace, or read the main Comment History page for the full feature list.
Try Comment History on the Atlassian Marketplace ↗ See the full Comment History overview →
Also built for
Comment History solves a different problem for each team:
- Comment History for Audit Teams
- Comment History for Banking Teams
- Comment History for Compliance Teams
- Comment History for Healthcare Teams
- Comment History for Jira Admins
- Comment History for Legal Teams
- Comment History for Legal Teams (Disputes and Litigation Hold)
- Comment History for Regulated Industries
- Comment History for Support Teams