Resora

Security

Jira stays the source of record

Resora is a planning layer on Jira Cloud. It reads your work data, shows it as workload and timelines, and writes back only the planning changes you make on purpose.

What Resora stores

Resora caches the Jira issue fields needed for planning: key, summary, project, assignee, status, dates, estimates, story points, sprint, and logged time. It also stores the people, teams, PTO, and allocations you create in Resora. Issue attachments, comments, and descriptions are not synced.

What Resora writes to Jira

Writes happen only when someone changes something in Resora: assignee, due date, status, mapped start date, original estimate, and work logs. Resora never bulk-edits your Jira without an explicit action, and every write goes through the same permissions the connected account has in Jira.

Connections and scopes

The workspace sync uses your organization's Jira connection, managed by your admin. Individuals can optionally connect their own Atlassian account via OAuth to load extra assigned work on Me. The personal connection requests three scopes: read:jira-work, read:jira-user, and offline_access — read-only access to work and profile data. All tokens are stored encrypted at rest and can be revoked at any time from Resora or from your Atlassian account settings.

Sign-in

Resora accounts use email and password, or Google sign-in where enabled. Passwords are hashed; sessions are signed with Auth.js.

Retention and deletion

Cached Jira data lives only as long as your connection does. Disconnecting Jira stops all syncing; deleting your workspace removes cached issues, people, allocations, and tokens. Because Jira remains your system of record, leaving Resora never puts your data at risk.

Questions

Security questions or disclosure reports: contact your Resora administrator or the team through your account.