The Operational Risk Mitigation Agent takes a Jira risk entry and converts it end-to-end into a structured problem record. It reads the risk, queries Lansweeper for the full blast radius of the linked CVE — every active asset exposed, not just the one named on the ticket — and cross-references NVD, CISA KEV and Mitre to confirm severity, exploit status and patch availability. It then assigns a priority, drafts specific remediation steps, and — with the user’s confirmation — creates the problem record in Jira and links it back to the original risk.
The agent works inside a live chat, so the analyst can ask for a broader CVE scope assessment or explore a systemic pattern before the record is created.

Lansweeper MCP
https://mcp.lansweeper.com/mcp
LLM
Claude 3.5+ — via Rovo (Atlassian’s agent platform runs on Claude models) and via the standalone Claude skill build
Atlassian Rovo, designed to work with any ITSM tool connected via MCP (Jira Service Management, ServiceNow, Freshservice)
Lansweeper plan
Starter, Pro, Enterprise
Claude skill — core blast-radius, CVE lookup and prioritisation logic
standard instruction – site confirmation, query catalogue, active-asset filtering
This agent is available on two platforms: Atlassian Rovo and Claude. Steps 1 to 3 are the same shape everywhere; the platform-specific detail is called out where the steps diverge. Follow the column for your platform.
Step 1 — Download
Download the agent package from the location in section 6 below, or ask your Lansweeper contact for the current build.
Step 2 — Open your agent platform
Step 3 — Load the instructions
Step 4 — Connect Lansweeper
Authenticate the Lansweeper MCP connection (EU or US endpoint, as required) and confirm you can see your site list. Both platforms need this step; only the connection method in each platform’s settings differs.
Step 5 — Connect your ITSM tool
Connect the Jira MCP. Confirm the agent can read a test risk entry and create a linked ticket before using it live.
Step 6 — Confirm web search access
This agent looks up CVE intelligence on NVD, CISA KEV and Mitre. Confirm your platform allows the agent to browse these sites — without it, the agent falls back to Lansweeper data alone and flags the external lookup as unsuccessful.
Step 7 — First-run configuration (Claude skill only)
The Claude skill asks for six values on first use: your ITSM platform name, what your organisation calls risk entries and problem records, which project or queue to create new records in, which link type to use between a risk and its problem record, and which connected MCP to use for your ITSM tool. The Rovo version has these values built into the instructions, so this step does not apply to it.
Step 8 — Run a test conversion
Give the agent a test risk entry referencing a real CVE and ask it to produce a problem record draft. Confirm it queries the full blast radius across all active assets — not just the one named on the ticket — checks external CVE intelligence, explains its priority decision, and waits for your confirmation before creating anything in Jira.