Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To control an Atlassian Rovo agent, configure who can create and use it in Rovo Studio, choose whether it acts as the user or a separately managed agent account, and grant that identity only the app and content access it needs. For interactive agents, Atlassian documents a confirmation prompt before consequential tools that may change data across systems. An agent used in an automation may act without a person confirming each action, so automation needs its own safeguards. Atlassian MCP and third-party Agent2Agent (A2A) connections have separate organization-level controls.

First identify how the agent will run

“AI agent” can refer to several different Atlassian control surfaces. Set the rules for the one you actually use; one setting does not govern every kind of agent connection.

  • Interactive Rovo agent: A person uses the agent directly. Configure agent creation, visibility, identity, content access, and available tools in Rovo Studio.
  • Rovo agent in an automation: A flow runs the agent as part of a process. Do not assume a person will confirm each action; set a separate review step or restrict what the agent can do.
  • Atlassian MCP server: An external MCP client connects through the Atlassian MCP server. Review its Read, Write, and Search permissions in Atlassian Administration.
  • Third-party A2A connection: An external agent connects through Agent2Agent. This has an organization-wide enablement control and requires user authorization.

Control who can create, edit, and use agents

Restrict agent creation

A Studio admin can open Rovo Studio > Settings and choose who may create agents. Creation is set to All users by default. The admin can instead select Selected groups and add up to 10 user groups, or select No users to restrict creation to the admin group.

Atlassian lists this Studio setting for Cloud Standard, Premium, and Enterprise, and says it is not available in Government Cloud. Confirm availability and labels in your tenant, since plan entitlements and settings can change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assign editors and managers

Agent owners manage collaborators in the agent’s Users and permissions settings. Editors can edit the agent. Managers can edit it, add other editors, and delete it. These roles govern agent administration; they do not by themselves grant the agent broader app or content access.

Restrict who can use an agent

Agent visibility is open to everyone by default. To limit it, turn off Open to all users in the agent’s user-permissions settings and add permitted people individually, assigning editor or manager roles as needed. Atlassian’s current documentation says visibility restrictions cannot be assigned to groups or teams, so individual access must be managed person by person.

Choose the identity whose permissions the agent uses

In the agent’s Access and identity settings, select User’s account or Agent’s account. The choice determines which permissions apply and how the agent’s work is attributed.

Identity choice Permissions used How work is attributed Documented fit
User’s account The interacting user’s permissions. In an automation, this can mean the account of the person who created the flow. Work appears under that user. Interactive or personal assistance. In automation, review the creator’s access carefully, especially if it includes restricted spaces.
Agent’s account A separately managed account whose access can be administered by the organization, app, space, or content administrators. Work appears under the agent. Automation that should use a dedicated identity rather than rely on a user’s credentials.

Neither identity should be treated as a way to bypass access controls. Grant the chosen account the necessary organization- and app-level access, then separately provide access to the relevant spaces, pages, or other content. Atlassian’s identity guidance recommends the agent’s own account for automation wherever possible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Limit tools and distinguish confirmation from approval

Add only the tools needed for the agent’s task. Instructions can tell an agent what it should or should not do, but the tools configured for it determine which actions are available.

For interactive Rovo agents, Atlassian documents a confirmation request before consequential tools that may mutate data across systems. That is a built-in confirmation behavior for the described interactive context; it is not evidence of a single, administrator-configurable approval matrix covering every action and every agent.

Use confirmation for that interactive prompt. Use approval for a human review step your organization deliberately places in a workflow. If an action must wait for a person, configure that review in the surrounding process rather than assuming the agent’s interactive confirmation will appear in an automation.

Set separate safeguards for automations

In an automation, there is no user interacting with the agent to review and approve each action. Atlassian says administrators and users can prevent agents from acting in automations. If agent actions are blocked, write tools fail; the flow can still use the agent’s text response through {{agentResponse}} in a subsequent action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a flow that needs to act, choose the agent’s own account where possible, keep its access narrow, and limit write capability to the steps that genuinely require it. Where appropriate, use the read-only setting in the automation’s Use agent step. If the task requires human sign-off, add a distinct review step to the workflow before the consequential action.

Review Atlassian MCP permissions separately

For the Atlassian MCP server, an organization admin can open Atlassian Administration > Rovo > Rovo MCP server > Permissions. Review the Read, Write, and Search controls. Use Edit details to configure settings per app, and decide whether those permissions should automatically apply to future app additions.

Atlassian says MCP permissions take precedence over Connected Apps or individual Marketplace app settings for MCP access. These controls apply to the MCP server and should not be confused with the tools configured for a Rovo agent.

Enable A2A only after organizational review

Agent2Agent is disabled by default. An organization admin enables it at Atlassian Administration > Rovo > Agent2Agent by turning on Allow A2A. Atlassian’s admin documentation, last updated August 7, 2026, describes this as an organization-wide control: it cannot be scoped per Atlassian app.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Enabling A2A does not grant an external agent unrestricted app access. The user’s existing permissions and app-level Rovo access still apply, and the third-party agent must obtain valid OAuth 2.1 user authorization. Complete the organization’s security and compliance review before enabling the connection.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Include connected apps and AI activation in the review

Before connecting an external source, review its permissions. Atlassian says admin-managed connectors are not enabled by default and that existing user access controls extend to connected apps. Organization admins can also manage activation of Rovo AI-powered features by app. Atlassian notes that some non-AI Rovo features are part of the platform and cannot be disabled.

Permission setup checklist

  • Identify whether the agent is interactive, part of an automation, using MCP, or connecting through A2A.
  • Limit agent creation in Rovo Studio and assign only the editors and managers who need to administer it.
  • Restrict visibility if the agent should not be available to everyone; add permitted people individually.
  • Choose the correct identity and grant it only the app and content permissions required for the task.
  • Give the agent only the tools it needs, with particular care around write capability.
  • For automations, decide whether to block agent actions, use read-only mode, or add an explicit human review step.
  • Review MCP permissions, A2A authorization, connected-app access, and AI feature activation in their own admin controls.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.