Atlassian Corp. has enabled federal-grade audit trails for Australian public-sector workloads hosted in its Sydney cloud region, giving agencies a tamper-evident log of administrative actions across Jira, Confluence and Jira Service Management without forcing data to leave the country. The feature ships months after the company completed an Information Security Registered Assessors Program review at PROTECTED level and as departments map controls to the Australian Government Information Security Manual.

What the Sydney audit stream covers

According to documentation shared with existing government customers, the audit trail captures configuration changes, permission grants, authentication events, and exports from admin consoles, streaming events to customer-owned storage endpoints in ap-southeast-2. Logs are append-only from the tenant’s perspective: administrators can query and forward, but cannot edit entries in place—a requirement agencies cite when replacing on-premise tools that wrote to local syslog servers.

Atlassian distinguished the capability from standard product analytics. Analytics telemetry used for reliability remains segregated; audit events are generated specifically for security operations centres reviewing privileged access. Sydney-region pinning means the export path stays within Australian data-residency commitments Atlassian markets to Commonwealth buyers, though customers remain responsible for classifying data they store in tickets and pages.

How this fits IRAP PROTECTED

IRAP is not a certification but an assessor’s opinion that controls align with a given ISM release. Atlassian achieved PROTECTED for its cloud products in March 2025, covering Jira, Confluence and Jira Service Management. The company’s trust site notes ongoing addenda as the Australian Cyber Security Centre publishes ISM updates, maintained through a retainer with external assessors rather than a one-off report.

Agency security architects said immutable audit logs close a common gap in cloud adoption packs: proof that privileged actions inside collaboration tools can be monitored with the same rigour as identity providers. Several departments had been exporting weekly CSV snapshots; the new stream pushes near-real-time JSON events compatible with Microsoft Sentinel and Elastic stacks already approved for PROTECTED environments.

Who is adopting first

Early adopters include a state transport agency consolidating IT service management and a federal science portfolio that migrated project tracking off ageing data-centre hardware. Both had IRAP assessment reports in flight before enabling audit trails; their chief information security officers said the feature removed a blocker to decommissioning self-hosted Confluence clusters in Sydney.

Systems integrators on the Digital Transformation Agency marketplace list Atlassian expertise alongside IRAP advisory services, signalling demand from councils and universities that adopt ISM principles even when not formally PROTECTED. Atlassian’s government sales team is briefing state CISO forums in Melbourne and Brisbane this month, emphasising that audit trails do not by themselves satisfy records-management rules—agencies must still classify issues and pages appropriately.

Competitive and procurement context

Microsoft and Google have parallel government cloud offerings with audit logging; Atlassian’s pitch is depth inside agile delivery tools agencies already use for software and policy projects. Procurement panels increasingly ask for evidence of local region support and assessor addenda rather than generic SOC 2 letters alone.

Defence and intelligence agencies at higher classifications remain outside this product tier; Atlassian has not claimed SECRET hosting in Sydney. For the bulk of PROTECTED-adjacent workloads—human resources tickets, grant administration, public inquiry casework—the audit trail is pitched as the missing compliance layer that keeps ministerial offices comfortable approving cloud migration memos.

Implementation friction

Customers must configure log sinks and retention policies; Atlassian warns that high-volume tenants during migration can generate bursts that stress downstream SIEM ingestion. Identity federation through government single sign-on must map groups carefully so audit entries attribute actions to named individuals, not shared break-glass accounts—a recurring finding in internal readiness reviews.

Licensing includes audit trail entitlements in government SKUs announced this quarter; commercial enterprises in Sydney can enable the same feature for regulated industries such as banking, though Atlassian’s marketing emphasises public-sector references. Professional services partners quoted four- to six-week integration timelines for departments with mature SOC processes, longer where legacy VPN access still coexists with cloud admin roles.

What agencies watch next

The next ISM release will test Atlassian’s retainer model: if new controls require additional event types, assessors must issue addenda before buyers claim continued alignment. Parliamentary committees examining AI in government have also asked whether collaboration audit logs should capture prompts sent to embedded assistants; Atlassian has not extended trails to third-party AI plugins yet, leaving that question to customer policy.

For Sydney-based teams, the practical outcome is simpler: when an administrator exports a sensitive project space or changes global permissions at midnight, an evidence line lands in Australian storage within minutes. That is the bar federal CISOs set—and the reason Atlassian shipped audit trails in the region where it was founded before pushing the same controls to other geographies later this year.