CFR Dashboard for Jira — Getting started

CFR Dashboard shows your team's Change Failure Rate (CFR) and Mean Time to Restore (MTTR) inside Jira. It reads the commits of your Git repository and finds revert commits — so you get the numbers without any CI/CD setup, incident-management tooling, or issue-linking discipline.

Setup takes about 5 minutes. You need to be an admin of the Jira project and to create one read-only token in your Git provider.

Requirements

How the numbers are calculated

Step 1 — Create a read-only token in your Git provider

Create a token that can only read the repository. It is used by the app to list commits (messages, dates and SHAs). The app never downloads source code.

Provider What to create Required permission
GitHub Fine-grained personal access token, limited to the one repository Contents: Read-only
GitLab Fine-grained personal access token (or a classic token) Commit: Read and Project: Read (classic token: the read_repository scope)
Bitbucket Cloud Repository access token Read-only access
Azure Repos Personal access token Code: Read

GitLab note: without Project: Read the app cannot read the project metadata and you get a 403 insufficient_granular_scope error when saving.

Give the token the shortest expiry you are comfortable with — you only need to paste it again when it expires.

Step 2 — Configure the project in Jira

  1. Open the project → Project settings → Apps → CFR Dashboard (in Jira versions that call projects spaces: Space settings → Apps → CFR Dashboard).
  2. Select the Git provider and fill in the repository fields:
    • GitHub / GitLab / Bitbucket: owner (workspace / namespace) and repository name;
    • Azure Repos: organization, project and repository.
  3. Set the analysis window (days, default 90) and paste the token.
  4. Click Save. The app checks that the repository is reachable with your token before saving.

The token is stored per project in Forge's encrypted secret storage. It is never displayed again — if you leave the token field empty on a later save, the saved token stays in effect.

Step 3 — Open the dashboard

Open the CFR Dashboard tab in the project navigation (next to Summary, List and Board). The first load fetches the commits and calculates the metrics; results are cached for 15 minutes (saving the settings refreshes them). Everyone who can view the project can open the dashboard — they do not need access to the repository, because the app uses the project's token.

Who can do what (checked by the app on every request, as the signed-in user):

Action Required Jira permission
Open the dashboard, the issue panel and generate the CSV Browse projects in that project
Change the settings, use Sync now Administer projects in that project (the Sync now button is hidden for everyone else)

Optional: issue panel

The CFR Dashboard — revert history panel shows the reverts that belong to the current issue.

The panel is hidden by default. This is how Jira treats every app panel. On each issue, click the gear icon below the issue title ("View app actions") and choose CFR Dashboard — revert history from the menu.

The issue is identified by the issue key in the commit message (for example KAN-12: fix rounding). A revert whose message contains no issue key is counted in the dashboard but does not appear in any issue panel.

Optional: export events

In the Event export block of the dashboard every commit becomes a deploy event, and every revert an additional revert event that references the reverted commit — ready to be combined with your other business metrics.

Sending events to your own data warehouse

In Project settings (or Space settings) → Apps → CFR Dashboard → Destination system you can push the events to your own account:

Destination Authentication Notes
Google BigQuery Service account JSON key with the BigQuery Data Editor role The Google Cloud project needs a billing account linked, otherwise streaming inserts are rejected (403)
Amazon S3 JSON {"accessKeyId": "...", "secretAccessKey": "..."} Each sync writes one timestamped .jsonl object. A narrow IAM policy is enough: s3:ListBucket on the bucket and s3:PutObject on its objects. Regions: us-east-1, us-east-2, us-west-1, us-west-2, eu-west-1, eu-central-1, ap-southeast-1, ap-southeast-2

The destination is always your own account; events go there directly from the app. Sync can be manual (the Sync now button) or automatic (hourly, daily or weekly). If a period holds more commits than one run can read, the sync continues on the next runs until the whole period is sent — no events are lost.

Limits

Troubleshooting

Symptom Cause and fix
Saving fails with "repository unreachable" Check the owner/organization/repository spelling and that the token has the permission listed in Step 1 and has not expired
GitLab: 403 insufficient_granular_scope Add Project: Read to the token
MTTR shows N/A No revert could be paired with its original commit — the message must contain the This reverts commit <sha> line
The issue panel does not show up Enable it per issue with the gear icon (see Optional: issue panel)
The dashboard shows no reverts Only commits inside the analysis window are read; extend the window, or check that your reverts follow Git's standard message format
BigQuery sync returns 403 Link a billing account to the Google Cloud project
Numbers look outdated Results are cached for 15 minutes; saving the settings refreshes them
"You do not have permission to do this in this project" The action needs the Administer projects permission (settings, Sync now) or Browse projects (dashboard, CSV) in the project you are looking at
Saving fails with a message about characters that are not allowed The repository owner, name, bucket or dataset contains characters the provider does not allow — check the spelling

Data handling

The app reads commit messages, dates and SHAs from your Git provider and, only if you select context fields, the values of those Jira fields for the issues named in commit messages. Tokens and destination credentials are stored in Forge's encrypted secret storage. Nothing is sent anywhere except to your Git provider's API and — if you configure one — your own destination system. See the Privacy Policy.

Support

support@cfrdashboard.app — please include your Jira site name, the project key and what you see on the dashboard (never send tokens).