Introducing Leen's Bi-Directional ITSM Integrations
.png)
Create tickets, pull complete ticket history, and track every update across Jira and ServiceNow, all through a single API.
Security work doesn't end when an issue is found. It ends when the ticket closes.
Today, we're excited to announce that Leen now supports bi-directional ITSM integrations. Your product can create and update tickets in your customers' Jira and ServiceNow environments through the same unified API you already use to read their security data. Combined with full support for historical ticket data and continuous syncing of ticket updates, Leen now covers the entire lifecycle of a ticket: open it, track it, and confirm the work actually got done.
Why bi-directionality matters
For most security platforms, the moment of truth isn't detection, it's remediation. And remediation lives in ITSM tools. Vulnerabilities become Jira tickets. Access reviews become ServiceNow tasks. If your platform can only read security data, your customers have to leave your product to get work done, and you lose visibility the moment they do.
Until now, teams solved this by building write integrations themselves, one vendor at a time: OAuth flows, custom fields, rate limits, and APIs that change without notice. That's exactly the kind of undifferentiated engineering work Leen exists to eliminate.
With bi-directional ITSM support, you integrate once and get the full loop out of the box.
What you can do now
1. Create tickets via the passthrough API
You can now create tickets programmatically, one at a time or in bulk, with both synchronous and asynchronous options for high-volume workflows. Updates work the same way, so your platform can reprioritize, reassign, or close tickets as things change.
To make ticket creation feel native inside your product, we also expose passthrough endpoints that return live data directly from the vendor: projects, issue types, assignable users, and ticket search using vendor-native query syntax like JQL. You can build a ticket-creation flow in your app that mirrors exactly what your customer sees in their own ITSM tool, without maintaining any of the plumbing behind it.

Vendor-native IDs pass straight through, so you can reference the exact project, issue type, or assignee your customer expects, with no lossy translation in between. The API respects each vendor's model, too. ServiceNow tickets route automatically to the right table based on their type, Incident or Problem, and ServiceNow-specific fields like work notes and resolution notes are supported natively. For high-volume workflows, the synchronous bulk endpoint returns per-ticket results in a single call, so there's no job polling and no guesswork about what succeeded. You can also attach your own tracking identifier to every ticket you create, which makes closed-loop reporting trivial: tag the ticket when you open it, retrieve it by that identifier later.
2. Pull data on historical tickets
Leen ingests your customers' full ticket history, along with the objects that give tickets meaning: projects, comments, attachments, users, and groups. That means you're not just pulling ticket titles and statuses. You get the discussion threads, the files, and the people involved, with enough context to power reporting, analytics, or an in-product ticket view.
Like every category Leen supports, ITSM data is normalized into one consistent model. Statuses and priorities map to a standardized set of values across vendors, so a ticket in progress in Jira and its ServiceNow equivalent look the same to your application. Flexible filters for status, priority, type, project, assignee, and tags let you pull exactly the slice you need, whether that's every open critical ticket in one project or a full backfill for reporting.
3. Pull data on ticket updates
Tickets are living objects. They get reassigned, reprioritized, commented on, and eventually closed. Leen keeps you current with incremental syncs and updatedSince filters for on-demand pulls, plus webhook support for Jira that pushes changes to you the moment they happen.

This is what closes the loop: your platform can open a ticket from a critical finding on Monday and know the moment it's resolved on Thursday, without polling vendor APIs or asking your customers for screenshots.
What this unlocks
Bi-directional ITSM support turns Leen from a source of security data into the connective tissue for entire remediation workflows:
- Exposure and vulnerability management platforms can route prioritized findings into the tools where engineering teams actually work, then automatically verify closure when the ticket resolves.
- Automated GRC platforms can turn remediation into evidence. Every control gap gets a ticket, and every closed ticket becomes a timestamped audit trail for frameworks like SOC 2 and ISO 27001.
- SOC automation and MDR platforms can file incidents directly into customer workflows and track them to resolution, keeping response metrics accurate without manual updates.
- Cyber insurance and risk platforms can measure what actually matters: how fast tickets get closed. Remediation velocity and SLA adherence are far stronger signals of security maturity than a point-in-time snapshot.
Getting started
Bi-directional ITSM support is live today for both Jira and ServiceNow.
Current Leen customers can enable ITSM connections from their dashboard in just a few clicks. For endpoint details, request schemas, and webhook configuration, head to our documentation.
Not building on Leen yet? Join teams like Drata, Thoropass, Scytale, Opus Security, and Cowbell Cyber that use Leen to scale their integrations. Schedule a demo to see how bi-directional ITSM fits into your product.
.png)
.png)
.png)