Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Integrate Bitbucket

Prev Next

The Scrut - Bitbucket integration connects your Bitbucket workspace with Scrut to automate the collection of compliance evidence and support access reviews and asset tracking. In this guide, we explain how to connect your Bitbucket repositories with Scrut.

What this Integration Does in Scrut

  • Automated Tests: Runs automated compliance checks that continuously evaluate your Bitbucket configurations against applicable compliance frameworks.

  • Evidence Tasks: Scrut automatically collects pull request data and uploads it to the Evidence Task "Code Review Results" on the 15th and last day of each month.

  • User Access Data: Fetches user details, roles, and permissions from Bitbucket for Access Reviews.

  • Asset Management: Populates the Asset Management module in Scrut with discovered repositories and supports the collection of asset-related compliance evidence.

Prerequisites

  • An active Bitbucket account with workspace admin access

  • At least one workspace and repository configured in Bitbucket

Pro Tip!

Log into your Bitbucket account before starting the setup to avoid being redirected mid-flow during authentication.

Permissions and Access Requirements

For Bitbucket

Scrut requests read-only access to the following:

  • Account information

  • Repository issues

  • Workspace and project settings

  • Repositories contained within your workspace’s projects

  • Repository and pull request data

  • Team membership information

Why does Scrut require these permissions?

These permissions are essential for Scrut to collect the necessary evidence for your audits.

  • Account Information: This permission allows Scrut to read your basic account details and organizational information.

  • Repository Issues: Scrut requires read access to repository issues to monitor security-related tickets, track vulnerability remediation efforts, and compliance-related concerns.

  • Workspace and Project Settings: This permission enables Scrut to read your workspace's project configurations and repository settings, to understand your repository structure, access controls, and governance policies to ensure they align with compliance requirements.

  • Repository and Pull Request Data: Read access to repositories and their pull requests enables Scrut to monitor code changes, review processes, and development practices critical for security compliance.

  • Team Membership Information: This permission enables Scrut to read your team structure and access permissions, enabling a proper assessment of who has access to what repositories and ensuring that access controls meet compliance standards for your organization.

Scrut has read-only permissions and cannot modify or alter your code repos.

OAuth Security: Scrut uses the OAuth 2.0 protocol for secure authentication, which means:

  • Your Bitbucket username and password are never shared with or stored by Scrut

  • Authentication is handled directly by Bitbucket’s secure servers

  • Scrut only receives secure access tokens with limited, specific permissions

  • All data transmission is encrypted and follows industry security standards

For Scrut

  • Admin access to Scrut (or Contributor role with access to the Integration module)

Data Collected

  • Bitbucket workspace details

  • Team membership and user profiles

  • Bitbucket project metadata

  • Repository metadata

Sync Frequency

Data for Access Reviews, Automated Tests, and Asset Management syncs every 24 hours. You can also trigger a manual sync at any time by clicking Sync Now on the Bitbucket integration page.

For evidence collection, Scrut uses a separate schedule. After connecting Bitbucket, Scrut automatically collects pull request data and uploads it to the Evidence Task "Code Review Results" on the 15th and last day of each month.

Integration Setup

Step 1: Connect Bitbucket in Scrut

  1. Sign in to Scrut and click Integrations in the left navigation panel.

  2. Go to the Integrations Library tab.

  3. In the Categories section, scroll to Version Control.

  4. Locate the Bitbucket tile and click Integrate.

  5. On the Bitbucket integration page, click Connect in the top right corner.

Step 2: Authenticate and Configure Scope

  1. Scrut redirects you to the Bitbucket authentication page. If you are not already logged in, complete the Bitbucket login before proceeding.

  2. Review the permissions Scrut is requesting and click Grant Access.

  3. Watch for the Connected status indicator on the Bitbucket integration page in Scrut.

  4. Click Configure Scope in the top right corner of the Bitbucket integration page.

  5. Select the repositories from which you want Scrut to collect evidence.

  6. Click Save.

What Happens Next?

Initial data sync

Once the integration is connected and the scope is configured, Scrut begins collecting data from Bitbucket. You can monitor sync activity in the Audit Log tab on the Bitbucket integration page.

Review synced data

  • Navigate to Tests to view automated test results and flagged misconfigurations for Bitbucket. Use the Application filter to view tests only for Bitbucket.

  • Navigate to Compliance → Evidence Tasks to view the Code Review Results evidence task, where pull request evidence is uploaded on the 15th and the last day of each month.

  • Navigate to People → Access Reviews to create an access review and validate access data for your GitHub organization.

  • Navigate to Asset Management to view code repositories discovered through the integration.

Note: You can trigger an on-demand sync at any time by clicking Sync Now on the Bitbucket integration page.

Common Errors and Troubleshooting

Authentication failure

Possible solutions:

  • Confirm you are logged into the correct Bitbucket account before clicking Connect.

  • Disconnect the integration and repeat the setup flow.

  • Check that your Bitbucket account has workspace admin access.

Data not appearing in Scrut

Possible solutions:

  • Verify that the correct repositories are selected under Configure Scope.

  • Trigger a manual sync using the Sync Now button and check the Audit Log for errors.

  • Confirm that the integration status shows Connected on the Bitbucket integration page.

Users or repositories missing from Asset Management

Possible solutions:

  • Check that the missing repositories fall within the configured scope.

  • Confirm that the relevant Bitbucket users are active members of the workspace.

  • Allow up to 24 hours after a scope change for data to reflect.

FAQs


1: Can I select which repositories Scrut collects data from?

Yes. After connecting, click Configure Scope on the Bitbucket integration page to select specific repositories. You can update this selection at any time.

2: What happens if I update my Bitbucket credentials or access tokens?

If your Bitbucket credentials change, the integration may stop syncing. Disconnect and reconnect the integration to re-authenticate with the updated credentials.

Reach out to support@scrut.io or contact your CSM for further assistance.