Skip to main content
Connect Jira Service Management Operations to let CloudThinker agents triage alerts, see who is on call, and run the alert lifecycle during an incident. JSM Operations authenticates with an Atlassian API token tied to one account.

Prerequisites

  • A Jira Service Management site with Operations enabled. Operations ships on the Premium and Enterprise plans only.
  • An Atlassian account that can open Operations on that site.
  • An Atlassian API token from id.atlassian.com.
  • A CloudThinker workspace on the Business or Enterprise plan.
This is a separate connection from Atlassian. Atlassian covers Jira issues and Confluence over Rovo; Operations is a different product with a different credential, so connect both if you want tickets and alerts.

Setup

1

Create an Atlassian API token

Go to id.atlassian.com → Security → API tokens and click Create API token:
  • Label: cloudthinker
  • Click Create
Copy the token immediately — Atlassian will not show it again.
2

Confirm Operations is reachable

Open your site and check that Operations appears in the JSM sidebar for the account you just created the token under. A site without Operations, or an account that cannot open it, fails the connection test.
3

Add the connection in CloudThinker

Navigate to Connections → Jira Service Management and enter:
  • Site URL: your Atlassian site, such as https://acme.atlassian.net
  • Account email: the account the token belongs to
  • API token: the token you just created
Click Connect. CloudThinker resolves the site, calls Operations once to confirm access, and shows a Connected status.
An API token carries the full permissions of its account. Create it under a dedicated account scoped to the teams CloudThinker needs, not a site admin.

Connection details


Required permissions

Minimum (read-only)

An account with Responder access to the relevant teams provides:
  • List alerts and read their timelines
  • View who is on call now and upcoming rotations
  • View schedules and escalation routing
Add team admin on the teams you want agents to act on:
  • All read permissions
  • Acknowledge, assign, and add responders
  • Add notes, close, and escalate
Follow least privilege: start with a Responder-level account for read-only triage, and grant team admin only on the teams where agents should write.

Agent capabilities

Once connected, agents work alerts within the token account’s team access. Incident sync runs as a Deep Response Engine outcome. When a responder acknowledges the alert in JSM, the matching incident moves to Acknowledged — a responder owns it, and analysis has not started.
Closing and escalating always ask for your approval, even in Auto mode. Acknowledge, assign, add responder, and add note run under the incident’s standing approval.

Verify the connection

Example prompts


Troubleshooting

Authentication worked, so the token is good. Either the site’s JSM plan does not include Operations, or the account cannot open it. Confirm Operations appears in the JSM sidebar for that account, then reconnect.
The token is wrong, revoked, or paired with the wrong email. The email must be the account that created the token. Create a new token at id.atlassian.com and update the connection.
CloudThinker resolves your site before calling Operations. Enter the site origin, such as https://acme.atlassian.net — a custom domain that does not front an Atlassian site fails here.
The token account is not on the relevant teams. JSM scopes alerts by team, so add the account to every team whose alerts agents should see.
Incident sync needs the JSM outcome enabled for the incident. Open the incident’s connections panel and confirm Sync provider incident is on.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Dedicated account — issue the token from an account created for CloudThinker, so revoking it never locks out a person.
  • Team scoping — an API token inherits everything its account can reach; keep that account on only the teams you want agents to touch.

Atlassian Connection

Jira issues and Confluence knowledge

PagerDuty Connection

On-call management and escalation