# Send reports to Issue Tracking or Jira

**Updated:** 2026-10-04

## Issue Tracking

Choose an Issue Tracking project for the program, then use **Create issue** on an accepted report. The issue carries the reference, title, priority and target, and links back.

**The report body is not copied.** An issue is visible to every member of that project, and the report is a working exploit — so the details stay in Bug Bounty where the access fence is.
## Jira, both ways

Bug Bounty uses your workspace’s existing Atlassian connection — it never asks for a second one. Connect Jira once, and every feature that uses it is turned on.

On the program’s **Jira** page, choose the project, the issue type, and the status that closes a report. Then:

- Accepting a report creates the Jira issue. Reports that turn out to be duplicates or out of scope never reach your backlog.
- Comments replicate both ways. A Jira comment arrives as an internal note, because a developer’s note in a ticket is not addressed to the reporter.
- Moving the Jira issue to your chosen status closes the report and emails the reporter — which is the point. Resolving the ticket should not leave somebody waiting on a manual step.

Priority is sent as a label such as `bb-p2` rather than Jira’s priority field, because a priority scheme belongs to a project and its names are whatever you chose.
## The Jira webhook

Add the webhook URL shown on that page to Jira, subscribed to *Issue updated* and *Comment created*. Treat the URL as a secret: Jira does not sign plain webhooks, so the address is what authenticates the delivery.


---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)