Burnwise

How it works

Security and data

Where Burnwise keeps your data, the Jira permissions it asks for, how access is checked, and what leaves Atlassian for email alerts.

Platform

Burnwise is built on Atlassian Forge (Forge functions and Forge SQL). Its data is stored in your Atlassian site’s Forge storage, with one database per installation.

Apart from email alerts, Burnwise sends no data outside Atlassian. When a person turns email alerts on, each alert email is sent through Transactful’s email server. See Email alerts below.

Jira permissions (least privilege)

Scope Why
read:jira-work Read worklogs and issues, and search
read:jira-user Show display names, and find people
write:jira-work Create, edit and delete worklogs from the Burnwise timesheet, as the signed-in user

Who can see and change what

  • Every request loads the caller’s permissions on the server: a Jira administrator check (made as the user) and the Burnwise role (app administrator, finance administrator, project manager, team manager or employee). What the browser says about the user is never trusted for access.
  • Keep pay rates private stops individual rates from being worked out from totals. See How the numbers are calculated.
  • Worklogs written from the timesheet are written as the user, so Jira’s own “Work on issues” and “Edit/Delete own worklogs” permissions apply.

Input safety

  • Jira ids are checked to be numeric before they are used in JQL or REST paths, and REST paths are built with Forge’s route tag.
  • CSV exports neutralise spreadsheet formula injection.

Integrity

  • Forge SQL has no transactions, so every write is idempotent and safe to retry.
  • Background jobs tolerate at-least-once delivery, and an hourly check repairs missed events.

Audit log

Changes to rates, budgets, projects, settings, roles, billing state and timesheet approvals are logged with who made them, when, and the old and new value of each field. Finance administrators see it in Settings → Audit log.

Email alerts

Email alerts are optional and off until a person turns them on. When they are on, Burnwise sends that person’s email address, the project name and the alert text (for example the share of the budget spent, or the expected cost) to Transactful’s email server, Broadcast. Broadcast sends the email through Amazon SES in the us-west-2 region (United States).

Individual people’s rates are never included in an alert email. Each person can turn email alerts off at any time. The privacy policy has the details.

Questions

Email [email protected] for security questions.

Not answered here? Email [email protected] with your Jira site address (your-company.atlassian.net). We usually reply within one business day.