5 Questions in the Atlassian Universe with Martin Runge

Maria ReisingerMaria Reisinger·2026-09-10·6 min read
JiraAtlassianGovernanceComplianceNIS2Jira Administration

About Martin

Martin Runge · Head of Atlassian Practice, XALT · Erlangen, Germany

Martin leads the Atlassian practice at XALT and brings over 17 years of consulting experience, including training and infrastructure consulting since 2004. He is an Atlassian Certified Administration Expert, Community Champion, and served as Subject Matter Expert and Peer Reviewer for Atlassian's certification program. With his biweekly newsletter "My Atlassian Pulse" he keeps over 1,100 readers up to date on the ecosystem.

Areas of expertise: Atlassian Consulting · Jira & Jira Service Management · ITSM & ITIL · Cloud Governance & Security · Agile Delivery & SAFe · Atlassian Certifications

martin-log-quote.png

1. What do customers actually need from a consultant today that they didn't need five years ago?

Certifications prove product knowledge, and what changed is that product knowledge alone is no longer the differentiator. Five years ago, the requests were technical: configure this project, run this migration. Today customers ask what they get at the next step of their journey, so the work sits much closer to business consulting. They want someone who understands the whole process and the whole chain of tools, not one product. We used to buy performance with hardware, another node or a bigger database, and we bought security with patch cycles and firewall rules. Atlassian now owns the infrastructure layer of both, which does not reduce our responsibility, it concentrates it. Speed comes from a disciplined data model instead of ten years of unused custom fields. Security comes from permissions granted by intent instead of by default. That is what a consultant is for today.

2. What compliance or audit requirement surprises customers most about their own Jira setup?

Backup, and specifically their own share of it. Most customers assume Cloud means Atlassian has it covered, and they usually only find out otherwise because we raise it. Atlassian runs platform-level backups for disaster recovery, and the products give you self-service recovery for simple mistakes through trash and version history. Everything between those two is the customer's. Atlassian Backup and Restore closes part of the gap as an optional add-on, but retention periods, backup frequency and granular restores still need a deliberate decision, especially for deleted projects, attachments and Marketplace app data. The moment it really lands is when someone asks how to get one single project back into a live site.

3. Where is the biggest gap between what regulated teams need and what the platform offers out of the box?

Jira has the features, they just have to be combined into one governed setup, and that does not happen overnight or by trial and error. Data residency is close to a one-time decision. Most of the rest is not. Custom security policies, IP allowlisting and permission design need permanent attention, and so do the certifications themselves, because ISO 27001 and SOC 2 come with recurring audits rather than a one-time sign-off. The real gap is the effort to keep all of that in sync while more teams and more processes move into Jira and while rules like NIS2 raise the bar. Where the Atlassian platform genuinely stops is at the regulated edge: electronic signatures for 21 CFR Part 11, a captured reason for change at field level, and separation of duties that actually holds. That is also what I bring back to the product side, because today it needs Marketplace apps or custom work, and these processes rarely stay inside the Atlassian stack anyway.

4. How well can a typical Jira instance answer "who changed this, when, and why"?

Jira is built for speed and flexibility, which is close to the opposite of what an auditor wants. Who and when are logged well, and higher Jira plans together with Atlassian Guard widen the coverage considerably. The catch is retention. The site audit log can be set to 1, 3 or 6 months, the organization audit log keeps events for 180 days and that cannot be changed, and automation logs only 90 days. So anything an auditor asks about beyond roughly six months has to have been exported before they asked. Two things weaken the answer further. Changes made by automation rules or connected apps show up as the rule or the app, not the person behind it, so who quietly degrades in exactly the automated environments regulated customers are building. And why is the hardest part? Because without mandatory comments and approval gates, a log proves that a change happened, not that it was authorized.

martin-retention.png

5. If you could change one thing about governance in Jira tomorrow, what would it be?

I would move teams from reactive compliance to automated guardrails. Standard baseline permission schemes instead of per-project improvisation, centralized identity policies through Atlassian Guard, and admin rights granted by exception rather than held by default. Separation of duties should be structural, so nobody approves their own change or merges their own pull request. And a baseline is only worth something if you notice when it drifts, so whatever you standardize needs a regular check to make sure it is still what you standardized.

Five lessons from Martin Runge

  1. Product knowledge is no longer the differentiator. Consulting today means understanding the whole process and the whole chain of tools, not one product.

  2. Your backup is more yours than you think. Everything between platform disaster recovery and the trash bin is the customer's responsibility.

  3. The clocks run out before the audit starts. Organization audit logs keep 180 days, automation logs 90. Evidence has to be exported before anyone asks.

  4. A log is not an authorization. Without mandatory comments and approval gates, logs prove that changes happened, not that they were allowed to.

  5. A baseline is only worth what your drift check makes of it. Whatever you standardize needs a regular check that it is still what you standardized.

Thank You

Our sincere thanks to Martin Runge for taking the time to share his expertise with this level of depth and precision.

The retention numbers, the quiet erosion of "who" in automated environments, and the distinction between a logged change and an authorized one: these are insights that will change how many readers look at their own Jira instance.

We truly appreciate your time and your openness.

About this series

5 Questions in the Atlassian Universe is an interview series by MetaFrazo featuring experienced practitioners from across the Atlassian ecosystem.

Each conversation explores practical lessons, real challenges and proven approaches to managing Atlassian products at scale.

Because the best ideas don't come from tools alone. They come from the people who use them every day.

About MetaFrazo

MetaFrazo helps organizations understand what is changing, what matters and where operational risks are emerging inside Jira.

By transforming Jira metadata into operational intelligence, teams gain the visibility needed to improve governance, reduce configuration drift and make better decisions without exporting sensitive business data.

www.metafrazo.cloud · Available on the Atlassian Marketplace

See you in the next edition of 5 Questions in the Atlassian Universe.

Copy

Rate this post

5.0 · 1 vote