Hi Atlassian Community,
We're currently using Atlassian with Claude Enterprise, and we'd like to restrict Rovo MCP server access so that only connections from our company's Claude organization are allowed — not personal Claude accounts.
The concern is straightforward: if an employee connects their personal Claude account (claude.ai) to our company's Atlassian via MCP, they could access all Confluence and Jira data from outside the organization, which is a significant security risk.
Since both personal and enterprise Claude accounts share the same domain (claude.ai), domain-based filtering doesn't help here.
Our question:
Is there currently any way to restrict MCP connections based on the Claude organization (e.g., Enterprise org), rather than just the domain?
If this isn't currently supported, we'd like to request this as a feature — specifically, the ability to allowlist specific Claude organizations or tenants at the Rovo MCP Server level.
This would be especially valuable for organizations that want to enable MCP for productivity while preventing unauthorized data access through personal AI accounts.
Thanks in advance for any guidance or feedback.
Hello @김지호_정보보호사무국_
Your concern is very very Very Very.....valid, but Atlassian’s Rovo MCP Server currently lacks tenant-level controls. Because personal and enterprise Claude share the same domains, domain allowlisting cannot distinguish between them.
For now, you must rely on broader security layers: disabling API-token auth, minimizing write permissions, using IP allowlisting, and checking if Claude Enterprise can restrict integrations on its side. To achieve true tenant-specific filtering, I recommend raising a feature request with Atlassian or look if there's already one.
Best,
Arkadiusz 🤠☀️
Thanks for the answer.
If I pay for Atlassian Guard, would that resolve the issue? I'd like to know whether it's still not possible even then.
Please let me know if you have any information on this.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Guard can "Tighten" your Security but The underlying limitation Stays, MCP controls filter by domain, which cannot differentiate between a personal Claude account and your corporate Claude Enterprise organization. For an official production security decision, I recommend confirming this with your Atlassian account contact, but you will ultimately still need that tenant-level feature request.
Best,
Arkadiusz🤠
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.