Skip to content
Regulit
Use case

Applicant data off the open work item

One override in the HR space sends every attachment to review before anyone else opens it. Every other space keeps the site wide rule exactly as it was.

One override, one space

Recorded in a live Jira Cloud site. 3 minutes, no sound.
Where it goes wrong

The file is readable the second it is attached.

Three gaps, and none of them is solved by asking people to be careful.

The space is wider than the shortlist

Permissions on an HR space cover more people than the ones handling the case. An attachment is open to all of them from the first second.

Nobody reads every upload

Spotting the scan of a passport in an application means opening each file. That work has no owner, so it does not happen.

The cleanup is the incident

Removing it afterwards means retracting, re-permissioning and explaining. By then the file has been on the work item for weeks.

The override

One space, one different rule.

The site wide rule stays as it is. The HR space sets the types it receives to Needs approval, and from then on nothing stays on a work item unread.

  • Set once. Pick the space, pick the file type, choose Needs approval and tick Override global configuration.
  • Nothing else moves. A space without an override keeps following the global category. The override is stored on the space, not on the site.
  • It starts at the next upload. The rule applies from the moment you save it. Attachments already on work items are not touched.

Setting the override takes a few minutes

The file type settings, with a category set per type
One category per type, overridden for a single space.
What happens to the file

It waits in your own cloud storage.

A file in Needs approval is taken off the work item and kept in the storage you connected, in your own cloud account, until someone decides.

  • Off the work item right after the upload. The attachment is removed and a comment on the work item names the file and the rule that held it.
  • A space admin decides. Approve puts the file back on the work item. Reject deletes the stored copy.
  • Nothing waits forever. A file nobody decides on is deleted after the review window, 10 days by default. You set it in the storage configuration.
The approval queue listing removed attachments
The queue, one row per held file.
Before the decision

Approve restores the original. A redacted copy is a new file.

Regulit holds, restores or deletes a file. It never edits one. If an application carries something that should not have been sent, the honest path has three steps, and each of them is recorded.

  • Reject the original

    Rejecting deletes the stored copy. Nothing goes back onto the work item, and the decision stays in the log.

  • Attach the cleaned version

    Whoever handles the case uploads the redacted copy like any other file. It follows the same rule as the first one.

  • Read the row afterwards

    The log names the file, the space, the rule and the person who decided, with a timestamp.

Without storage

Without connected storage nothing can be held. Needs approval is then handled like Blocked: the file is removed, and the comment says so. Connect storage before you switch the rule on.

The Regulit log, one row per change

Questions about sensitive uploads

Can HR run a stricter rule than the rest of the site?

Yes. Set the file types in the HR space and tick Override global configuration. Every other space keeps the global rule.

Who can approve a held file?

Space admins of the HR space, and service desk agents if you allow it. A Jira admin also needs Administer spaces there.

Where does a held file sit while it waits?

In your own Amazon S3, Google Cloud Storage or Azure Blob Storage. Regulit keeps no copy.

Can Regulit redact a file?

No. It holds, restores or deletes a file. It never edits one.

What happens if nobody decides?

The file is deleted after the review window, 10 days by default. You set it in the storage configuration.

Read on

Two pages carry the rest.

This page argues the case for holding uploads in one space. What the app does with a held file, and what it takes to switch it on, each have a page of their own.

Start with the HR space.

With storage connected, set one file type to Needs approval in a test space and upload a file. It leaves the work item and appears in the approval queue.