Reporter-Based Routing in Jira: Send Security Tickets to a Different AI Reviewer

6 min read
Share:

The pattern

Big-company Jira instances usually have a security backlog that lives alongside the regular feature backlog. Tickets reported by security@yourcompany.com (or labelled security, or filed under a Security project) need a different review than a normal feature ticket — paranoid threat-model thinking, OWASP awareness, residual-risk notes.

In most setups today, this routing is done in someone's head: the team lead reads the reporter, mentally tags the ticket, and assigns it to the security-minded engineer. That's a human bottleneck and it doesn't scale.

Agentopias by CynetIQ Integration Rules make the routing declarative: the same rule engine that handles Jira reporters also handles Azure DevOps area paths, Sentry tags, and New Relic entity GUIDs.

What we'll build

  • Pull all open issues from a Jira project into agentopia.
  • Auto-tag any issue reported by anyone in the security team with security_review.
  • Auto-route those tickets to the security_developer AI reviewer agent (OWASP-aware).
  • Auto-set priority to critical so they jump the queue.

Step 1 — Connect Jira

  • Go to Agentopias by CynetIQ → Integrations → Jira.
  • Paste your Atlassian email + API token + site URL.
  • Pick the project to sync. Use a JQL filter like:
  • ``

    resolution = Unresolved AND project = "BACK" ORDER BY priority DESC

    `

  • Map the Jira project to your target repo (GitHub or Azure DevOps).
  • Step 2 — Define the security developer agent

  • Go to /dashboard/agents → New Agent.
  • Name it security_developer (the slug Agentopias by CynetIQ uses for OWASP-aware reviews).
  • Toggle is_reviewer on.
  • Pick a model. We use GPT-5-pro for security reviews — quality > cost.
  • The system prompt is pre-populated from security_dev_system_prompt in Prompt Studio. Customize if needed.
  • Save.
  • Step 3 — Create the Integration Rule

  • Go to /dashboard/integrations/rules.
  • Click New Rule → Provider = Jira.
  • Match clause:
  • - Field: reporter.emailAddress

    - Operator: in

    - Value: security@yourcompany.com, security-team@yourcompany.com

  • Action clause:
  • - Tag: security_review

    - Preferred agent role: security_developer

    - Priority: critical

    - (Optional) Target repo: override the default mapping.

    You can also match on labels (labels contains "security") or issue type (issuetype = "Vulnerability") — same engine.

    Step 4 — Verify

    The next time a Jira ticket lands in Agentopias by CynetIQ from the security team, it will:

    • Carry the security_review tag.
    • Stamp Preferred Agent Role: security_developer` in the description metadata.
    • Have priority bumped to critical.
    • When you click 🔎 Review on the task, the security_developer agent is preselected.

    Why this is better than a JQL filter + manual triage

    JQL filters tell you which tickets are security-related. Integration Rules tell Agentopias by CynetIQ what to do with them. The same rule applies to:

    • Imported Sentry issues (match on environment, project, error type).
    • Azure DevOps work items (match on Created By, Area Path, Tag).
    • New Relic auto-imports (match on entity GUID, error class).
    One rule engine across every source.

    Related reading

    Share:

    Agentic AI'ı denemek ister misiniz?

    Ücretsiz başlayın ve Agentopias by CynetIQ'nın 3D agentlarının geliştirme iş akışınızı yönetmesine izin verin.