Identity and access management is the foundation of a secure cloud environment. As organizations adopt more cloud applications, external collaboration, automation, and AI-powered capabilities, identity decisions increasingly determine who can access information, what they can do, and how quickly access can be removed when circumstances change.
To help customers navigate this landscape, Atlassian has published a new white paper, IAM reference architecture for Atlassian Cloud.
Read the IAM reference architecture in the Atlassian Trust Portal
The paper presents a layered, defense-in-depth approach to governing identity and access across Atlassian Cloud. It is intended for enterprise security architects, IT administrators, and teams responsible for designing secure cloud operating models.
1. Establish identity
The first layer establishes trusted identities and organizational boundaries through capabilities such as:
Identity provider integration
Domain verification
SCIM-based user and group provisioning
Centralized identity lifecycle management
These controls help organizations ensure that access begins with a known identity and that changes in the authoritative identity system can be reflected across the cloud environment.
2. Strengthen authentication and external-user controls
Strong authentication is essential, but enterprise IAM also needs to account for external users and collaborators.
This layer includes:
Single sign-on
Multifactor authentication
External-user policies
Guest and collaboration controls
Together, these capabilities help organizations apply consistent authentication and collaboration policies while supporting the way modern teams actually work.
3. Govern organization and application access
Authentication confirms who a user is. Authorization determines what that user can access.
The third layer focuses on organization-level and application-level controls, including:
Administrative roles
Product access
Group-based authorization
Project, space, and site permissions
Separation of duties
A mature IAM program should make these decisions understandable, reviewable, and aligned with the organization’s operating model.
4. Govern non-human identities
Modern enterprise environments include more than human users. Service accounts, Marketplace integrations, automation, and AI agents may all access organizational data or perform actions.
The reference architecture therefore treats non-human identities as a first-class IAM concern. Organizations should understand:
Which services and agents have access
What permissions they require
Who owns them
How credentials are managed
How access is reviewed and revoked
Which actions require additional controls or human approval
This is especially important as organizations adopt Rovo agents and other AI-enabled workflows.
5. Make access observable
The final layer is visibility. Organizations need to be able to understand how identity and access controls are operating over time.
This includes:
Administrative audit logging
Access and configuration changes
Integration with security information and event management systems
Investigation workflows
Evidence for security and compliance reviews
Observability helps security teams detect unexpected changes, investigate incidents, validate controls, and demonstrate how the environment is governed.
A practical readiness checklist
The paper closes with a Cloud IAM readiness checklist to help organizations assess their current posture.
The checklist can support conversations such as:
Do we have a clear authoritative source for user identity?
Are provisioning and deprovisioning automated?
Are external users governed consistently?
Are administrative privileges limited and reviewed?
Do we know which service accounts, integrations, and agents can access our data?
Can we revoke access promptly?
Do our audit logs provide enough evidence for investigation?
Are our IAM controls aligned with our regulatory and customer requirements?
These questions are useful whether an organization is beginning its cloud IAM program or reviewing an established deployment.
IAM is an operating model, not a single setting
Enterprise IAM is not solved by enabling SSO alone. It is a connected operating model spanning identity providers, authentication, authorization, non-human identities, administrative processes, and security operations.
The IAM reference architecture provides a way to evaluate those layers together and identify where additional policy, process, or technical controls may be needed.
Read the full paper in the Atlassian Trust Portal, and use the readiness checklist to identify the next steps for your organization.
Alan Ross
0 comments