# Send reports to Issue Tracking or Jira

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

## Issue Tracking

Choose an Issue Tracking project for the program, then use **Create issue** on an accepted report. The issue carries the reference, title, priority and target, and links back.

**The report body is not copied.** An issue is visible to every member of that project, and the report is a working exploit — so the details stay in Bug Bounty where the access fence is.
## Jira, both ways

Bug Bounty uses your workspace’s existing Atlassian connection — it never asks for a second one. Connect Jira once, and every feature that uses it is turned on.

On the program’s **Jira** page, choose the project, the issue type, and the status that closes a report. Then:

- Accepting a report creates the Jira issue. Reports that turn out to be duplicates or out of scope never reach your backlog.
- Comments replicate both ways. A Jira comment arrives as an internal note, because a developer’s note in a ticket is not addressed to the reporter.
- Moving the Jira issue to your chosen status closes the report and emails the reporter — which is the point. Resolving the ticket should not leave somebody waiting on a manual step.

Priority is sent as a label such as `bb-p2` rather than Jira’s priority field, because a priority scheme belongs to a project and its names are whatever you chose.
## The Jira webhook

Add the webhook URL shown on that page to Jira, subscribed to *Issue updated* and *Comment created*. Treat the URL as a secret: Jira does not sign plain webhooks, so the address is what authenticates the delivery.

---

## Related Articles

- [Put the program on your own domain](https://help.totalctrl.app/en-US/articles/bugbounty-custom-domain-1)
- [Scope groups and reward tables](https://help.totalctrl.app/en-US/articles/bugbounty-scope-and-rewards-1)
- [Getting started with Bug Bounty](https://help.totalctrl.app/en-US/articles/bugbounty-getting-started-1)
- [Response times and the disclosure window](https://help.totalctrl.app/en-US/articles/bugbounty-sla-1)
- [Who can work a program](https://help.totalctrl.app/en-US/articles/bugbounty-access-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)