Start here
Install and open Audit Otter
You need a supported Jira Cloud site and a Jira or site administrator for initial setup. Confluence Cloud is required only for Confluence features such as publishing approved policies.
- Install Audit Otter from Atlassian Marketplace on the intended cloud site.
- In Jira, open Apps, then Audit Otter.
- Confirm the organization and compliance product scope shown in the header.
- Choose the framework you are working on and follow the next action on Overview.
Name one response owner and one technical confirmer. One person may hold both roles, but every approved answer should still record who verified it.
Choose a framework
CAIQ Lite, SOC 2, and ISO 27001
CAIQ Lite
Use the built-in CAIQ Lite v4.1 self-assessment with 138 questions mapped to 96 CCM Lite controls. CAIQ Lite and a CAIQ-focused Trust Center remain available without a paid license.
SOC 2
Map Trust Services Criteria requirements to your controls, policies, owners, evidence, risks, and audit requests.
ISO/IEC 27001
Run an ISO/IEC 27001:2022 program with Annex A requirements, applicability decisions, control ownership, and evidence traceability.
Paid plans add SOC 2 and ISO/IEC 27001. Audit Otter organizes readiness work but does not replace your auditor, legal counsel, or security judgment.
Define scope
Tell Audit Otter what the program covers
Start with the smallest honest boundary. Record the service, hosting providers, production environments, data types, workforce systems, and subprocessors that support it.
Add systems directly
Use Add system when no integration can supply the inventory. Give each system a clear owner, type, criticality, and scope.
Import systems from an integration
Use Connect an integration when a supported source can collect current inventory and evidence. Review what the integration imports before providing credentials.
Connect integrations
Collect from the tools you already run
- Open Integrations and select a source.
- Create the provider credential described in the setup dialog with the least privilege available.
- Validate the connection, then run a collection.
- Review connection health separately from the evidence result.
A successful API request proves connectivity, not compliance. Audit Otter keeps connection health, collected snapshots, evaluated tests, and usable evidence distinct.
Supported integrations
- Jira
- Jira Service Management
- Confluence
- Atlassian Admin
- Atlassian Guard
- GitHub
- Cloudflare
- Sentry
- Slack
- OpenAI
- Datadog
- Fastly
- Okta
- Netlify
- Render
- Mailgun
- Zendesk
- Tailscale
- JumpCloud
- CircleCI
- Twilio
- Supabase
- SendGrid
- DigitalOcean
- Terraform Cloud
- Vercel
- LaunchDarkly
- Postmark
Use dedicated, read-oriented credentials where possible. Never paste credentials into evidence, questionnaires, support tickets, URLs, or screenshots.
Controls and requirements
Keep the path from obligation to proof visible
Requirements describe what the framework asks. Controls describe what your organization does. Map them so a reviewer can follow each requirement through its control, owner, policy, test, and current evidence.
- Review whether each requirement applies to the selected scope.
- Map applicable requirements to one or more controls.
- Assign a control owner and confirm the implementation status.
- Resolve missing, failing, stale, or not-run evidence before claiming readiness.
Evidence
Review the result, source, and freshness
Evidence shows where a record came from, when it was collected, what rule evaluated it, which control it supports, and whether the result is passing, failing, stale, or not run.
- Passing
- The collected facts met the versioned test rule.
- Failing
- The source was evaluated and did not meet the rule.
- Stale
- The result is older than its allowed freshness window.
- Not run
- The source did not provide enough usable data for the test.
Upload only the smallest useful record. Do not upload raw logs, secrets, or customer data when a redacted configuration record or summary is enough.
Policies
Approve once, then publish the exact version
Draft policies in Audit Otter, map them to controls, assign an owner, and record the review date. An authorized user can publish an approved version to the selected Confluence destination.
Check the destination space and permissions before publishing. Confluence publication does not replace your internal approval process.
Risks and vendors
Keep exceptions and dependencies connected
Record risks with an owner, treatment, likelihood, impact, and due date. Track vendors and subprocessors with their purpose, review status, owner, and relevant controls. Resolve exceptions where the framework path shows a gap.
Questionnaires
Draft quickly without skipping human approval
Questionnaire drafts use exact approved answers first. When no approved source proves a response, Audit Otter marks the item for review instead of inventing a positive claim.
- Open the built-in CAIQ assessment or import a customer questionnaire.
- Draft cited answers from approved workspace material.
- Check scope, dates, provider responsibility, and every citation.
- Approve each answer, then mark the questionnaire complete.
The official 138-question assessment is already available. If you have a completed CAIQ workbook, import it as a starting point. Audit Otter previews matched, protected, and unmatched rows and keeps approved responses from being overwritten.
Trust Center
Publish only what buyers should see
Select the exact approved documents, control information, and subprocessors for the next snapshot. Draft changes do not alter the public Trust Center until an authorized user publishes again.
Keep restricted audit material behind the access-request workflow. Never publish secrets, customer data, internal-only evidence, or unnecessary personal information.
Audits
Organize the review period and requests
Create an audit for the correct framework and period, add requests, assign owners and due dates, and link the exact evidence supplied to the auditor. Keep request status current so unresolved work remains visible.
Security and privacy
Use the minimum data required
- Confirm the selected organization and product scope before adding data.
- Use least-privilege provider credentials and rotate them on the provider's schedule.
- Do not store secrets, raw customer data, or unnecessary personal data in evidence or questionnaires.
- Review public Trust Center content before every publication.
Read the Privacy Notice, Terms of Service, and Data Processing Addendum.
Uninstall and deletion
Disconnect provider credentials before uninstalling when practical. Uninstall Audit Otter through Atlassian administration, then contact privacy@auditotter.com for deletion confirmation or a data-rights request.
Troubleshooting
Fix the smallest failing dependency first
- Connection validation fails
- Check the provider URL, credential, required permissions, and network availability. Replace a credential that may have been exposed.
- Collection fails
- Read the displayed dependency error, correct the provider or permission issue, then retry.
- Evidence is stale or not run
- Run the relevant collection and confirm that the resulting test completed with usable data.
- A page is empty
- Check the selected organization, compliance product scope, framework, filters, and permissions.
- Access is denied
- Ask a site administrator to confirm your Audit Otter role and your access to the exact Jira or Confluence resource.
Get support
Send us the error, not your secrets
Use the Audit Otter support portal. Include the page, action, visible error, provider name, and approximate time. Do not include credentials, tokens, sensitive evidence, or unnecessary personal data.
Report security issues to security@auditotter.com.