Hi All,
While experimenting with a Rovo Agent, I scoped its knowledge to specific Jira projects and Confluence spaces by disabling "All Projects" and explicitly selecting only the sources I wanted the agent to use.
As an initial validation test, I asked the agent what projects it could access, and it correctly returned only the scoped projects.
That gave me some confidence, but before considering broader adoption, I'd like to better understand how others are validating data isolation and access boundaries in real-world deployments.
A few questions I'm exploring:
-
Are there audit logs, execution traces, or admin views that show which Jira projects or Confluence spaces were queried during agent execution?
-
If a new project is created later, does the agent remain limited to the originally scoped projects, or are there scenarios where additional content becomes discoverable?
-
For external connectors such as Google Drive or Slack, how are you validating the interaction between native source permissions and Rovo Agent scoping?
-
What negative testing approaches have you found effective? For example, intentionally prompting for content outside the approved scope to verify boundaries are being enforced.
-
For those already running Rovo Agents in production, what did your validation process look like before making agents available to end users?
My main objective is ensuring that the configured knowledge scope and underlying permissions behave exactly as expected before wider rollout.
Interested in hearing how platform teams are approaching this.