Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

A practical IAM reference architecture for Atlassian Cloud

Identity and access management is the foundation of a secure cloud environment. As organizations adopt more cloud applications, external collaboration, automation, and AI-powered capabilities, identity decisions increasingly determine who can access information, what they can do, and how quickly access can be removed when circumstances change.

To help customers navigate this landscape, Atlassian has published a new white paper, IAM reference architecture for Atlassian Cloud.

Read the IAM reference architecture in the Atlassian Trust Portal

The paper presents a layered, defense-in-depth approach to governing identity and access across Atlassian Cloud. It is intended for enterprise security architects, IT administrators, and teams responsible for designing secure cloud operating models.

Five layers of cloud IAM
The reference architecture organizes IAM into five connected layers.

1. Establish identity
The first layer establishes trusted identities and organizational boundaries through capabilities such as:

Identity provider integration

Domain verification

SCIM-based user and group provisioning

Centralized identity lifecycle management

These controls help organizations ensure that access begins with a known identity and that changes in the authoritative identity system can be reflected across the cloud environment.

2. Strengthen authentication and external-user controls
Strong authentication is essential, but enterprise IAM also needs to account for external users and collaborators.

This layer includes:

Single sign-on

Multifactor authentication

External-user policies

Guest and collaboration controls

Together, these capabilities help organizations apply consistent authentication and collaboration policies while supporting the way modern teams actually work.

3. Govern organization and application access
Authentication confirms who a user is. Authorization determines what that user can access.

The third layer focuses on organization-level and application-level controls, including:

Administrative roles

Product access

Group-based authorization

Project, space, and site permissions

Separation of duties

A mature IAM program should make these decisions understandable, reviewable, and aligned with the organization’s operating model.

4. Govern non-human identities
Modern enterprise environments include more than human users. Service accounts, Marketplace integrations, automation, and AI agents may all access organizational data or perform actions.

The reference architecture therefore treats non-human identities as a first-class IAM concern. Organizations should understand:

Which services and agents have access

What permissions they require

Who owns them

How credentials are managed

How access is reviewed and revoked

Which actions require additional controls or human approval

This is especially important as organizations adopt Rovo agents and other AI-enabled workflows.

5. Make access observable
The final layer is visibility. Organizations need to be able to understand how identity and access controls are operating over time.

This includes:

Administrative audit logging

Access and configuration changes

Integration with security information and event management systems

Investigation workflows

Evidence for security and compliance reviews

Observability helps security teams detect unexpected changes, investigate incidents, validate controls, and demonstrate how the environment is governed.

A practical readiness checklist
The paper closes with a Cloud IAM readiness checklist to help organizations assess their current posture.

The checklist can support conversations such as:

Do we have a clear authoritative source for user identity?

Are provisioning and deprovisioning automated?

Are external users governed consistently?

Are administrative privileges limited and reviewed?

Do we know which service accounts, integrations, and agents can access our data?

Can we revoke access promptly?

Do our audit logs provide enough evidence for investigation?

Are our IAM controls aligned with our regulatory and customer requirements?

These questions are useful whether an organization is beginning its cloud IAM program or reviewing an established deployment.

IAM is an operating model, not a single setting
Enterprise IAM is not solved by enabling SSO alone. It is a connected operating model spanning identity providers, authentication, authorization, non-human identities, administrative processes, and security operations.

The IAM reference architecture provides a way to evaluate those layers together and identify where additional policy, process, or technical controls may be needed.

Read the full paper in the Atlassian Trust Portal, and use the readiness checklist to identify the next steps for your organization.

0 comments

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events