Features
Automatic Assessment
Risk assessment runs automatically on ticket creation
Smart Warnings
High-risk tickets are flagged immediately with clear warnings
Team Visibility
Risk scores visible to entire team in ticket metadata
Workflow Integration
Block or require approval for critical-risk tickets
How It Works
When a developer creates a Jira ticket, Orcho automatically:1
Ticket created
Developer creates a new Jira ticket with title and description
2
Orcho analyzes
The Orcho app intercepts the creation event and calls the
assess_risk API with the ticket content3
Risk assessment returned
Orcho evaluates the ticket for:
- Data sensitivity
- Input clarity
- Potential blast radius
- Security concerns
4
Risk displayed
Risk score and level are added as custom fields on the ticket:
- Risk Score: 0.72
- Risk Level: HIGH
- Recommendations: Review required before implementation
5
Team notified
For high-risk tickets (≥ 0.6), stakeholders are automatically notified
Installation
1
Install Orcho for Jira
Visit the Atlassian Marketplace and search for “Orcho Risk Assessment”
Or have your Jira admin install from the Apps section
2
Contact for API key
Email [email protected] to request an API key for your organization
3
Configure the app
In Jira, go to:
- Settings → Apps → Manage Apps
- Find “Orcho Risk Assessment”
- Click “Configure”
- Enter your API key
- Save configuration
4
Enable for projects
Choose which Jira projects should have automatic risk assessment:
- Settings → Apps → Orcho Configuration
- Select projects to enable
- Configure risk thresholds (optional)
- Save changes
5
Test the integration
Create a test ticket with a high-risk description:Verify that the risk assessment appears on the ticket
Risk Assessment Fields
Orcho adds the following custom fields to your Jira tickets:Overall risk score from 0.0 (minimal risk) to 1.0 (critical risk)Example:
0.72Risk level category: minimal, low, medium, high, or criticalExample:
HIGHBreakdown of individual risk factor scoresExample:
Actionable recommendations for mitigating riskExample:
- Add WHERE clause to limit scope
- Require security team approval
- Create backup before deletion
Timestamp when risk assessment was performedExample:
2026-01-08T14:30:00ZExample Risk Assessment
High-Risk Ticket
Low-Risk Ticket
Workflow Automation
Automatic Approvals
Configure Jira workflows to require approvals based on risk:- High Risk (≥ 0.6)
- Critical Risk (≥ 0.8)
- Low Risk (< 0.4)
Require approval from:
- Security team lead
- Engineering manager
- Product owner
- Ticket created → Risk assessed
- If risk ≥ 0.6 → Status changes to “Security Review”
- Security team notified automatically
- Requires approval before moving to “In Progress”
Configuration Options
Risk Thresholds
Customize thresholds for your organization:Risk score that triggers warnings and notificationsDefault:
0.6 (high risk)Risk score that blocks ticket from moving to developmentDefault:
0.8 (critical risk)Risk score below which tickets are auto-approvedDefault:
0.4 (medium risk)Notification Settings
Send notifications for high-risk tickets (≥ 0.6)
Send notifications for critical-risk tickets (≥ 0.8)
Where to send notifications: email, slack, jira-commentDefault:
["email", "jira-comment"]Who receives notifications for each risk levelExample:
JQL Queries
Use Jira Query Language to find tickets by risk level:Find High-Risk Tickets
Find Tickets Needing Review
Find Safe-to-Implement Tickets
Find Tickets by Risk Factor
Dashboards & Reports
Risk Distribution Dashboard
Create a dashboard showing:- Total tickets by risk level (pie chart)
- Risk score distribution (histogram)
- Average risk score trend over time (line chart)
- High-risk tickets by assignee (bar chart)
Security Review Board
Track tickets requiring security review:- Pending security reviews
- Average time in security review
- Approval vs rejection rate
- Most common high-risk patterns
Troubleshooting
Risk assessment not appearing
Risk assessment not appearing
Check app installation:
- Go to Settings → Apps → Manage Apps
- Verify “Orcho Risk Assessment” is installed
- Check that app is enabled
- Settings → Apps → Orcho Configuration
- Ensure API key is entered correctly
- Test connection with “Test API Key” button
- Verify risk assessment is enabled for this project
- Check that user has permission to view custom fields
API key errors
API key errors
Invalid API Key:
- Contact [email protected] to verify key
- Check for extra spaces or special characters
- Try regenerating the key
- Contact [email protected] to check quota
- Upgrade plan if needed for higher volume
- Verify Jira can reach app.orcho.ai
- Check firewall/proxy settings
- Contact IT to whitelist Orcho API
Incorrect risk scores
Incorrect risk scores
Update ticket for reassessment:
- Edit ticket title or description
- Save changes
- Risk will be reassessed automatically
- Click “More” (•••) on ticket
- Select “Reassess Risk” from Orcho menu
- New assessment will replace old one
- Settings → Apps → Orcho Configuration
- Customize thresholds for your needs
- Save and test with sample tickets
Notifications not working
Notifications not working
Check notification settings:
- Settings → Apps → Orcho Configuration
- Verify notification channels are enabled
- Check recipient email addresses
- Create a test high-risk ticket
- Check spam folders
- Verify Slack webhook is configured correctly
- Ensure recipients have access to project
- Check Jira notification scheme settings
Best Practices
1
Start with monitoring mode
Enable for 1-2 projects initially to tune thresholds before org-wide rollout
2
Train your team
Educate developers on:
- How risk assessment works
- What different risk levels mean
- How to write safer ticket descriptions
3
Review blocked tickets
Hold weekly reviews of blocked tickets to:
- Understand common high-risk patterns
- Adjust thresholds if needed
- Improve ticket writing practices
4
Integrate with existing workflows
Don’t create parallel workflows - integrate risk assessment into existing approval processes
5
Monitor and iterate
Track metrics:
- False positive rate (safe tickets marked high-risk)
- False negative rate (risky tickets marked low-risk)
- Time spent in security review
- Developer feedback
Advanced Features
Custom Risk Weights
Adjust risk factor weights based on your organization’s priorities:Jira Automation Rules
Create automation rules triggered by risk assessment: Example: Auto-assign high-risk ticketsIntegration with Other Tools
Slack Notifications
Connect Orcho risk assessments to Slack:- Install Jira for Slack
- Configure webhook in Orcho settings
- Get notifications in #security-alerts channel
- Include risk score and direct link to ticket
Confluence Documentation
Automatically create security review docs:- High-risk ticket created
- Orcho creates Confluence page with risk details
- Security team adds review notes
- Link back to Jira ticket
Support
Need help with the Jira integration?Install App
Find us on Atlassian Marketplace
Get API Key
Contact us for an API key
API Documentation
Review the REST API docs
Email Support
Contact support team
Next Steps
1
Install the Jira app
Search for “Orcho” in Atlassian Marketplace
2
Get your API key
Contact [email protected]
3
Configure risk thresholds
Set thresholds that match your security policy
4
Enable for pilot project
Start with one project to tune settings
5
Train your team
Help developers understand risk assessment
6
Roll out organization-wide
Expand to all projects once validated