Hi Atlassian Community,
We're currently using Atlassian with Claude Enterprise, and we'd like to restrict Rovo MCP server access so that only connections from our company's Claude organization are allowed — not personal Claude accounts.
The concern is straightforward: if an employee connects their personal Claude account (claude.ai) to our company's Atlassian via MCP, they could access all Confluence and Jira data from outside the organization, which is a significant security risk.
Since both personal and enterprise Claude accounts share the same domain (claude.ai), domain-based filtering doesn't help here.
Our question:
Is there currently any way to restrict MCP connections based on the Claude organization (e.g., Enterprise org), rather than just the domain?
If this isn't currently supported, we'd like to request this as a feature — specifically, the ability to allowlist specific Claude organizations or tenants at the Rovo MCP Server level.
This would be especially valuable for organizations that want to enable MCP for productivity while preventing unauthorized data access through personal AI accounts.
Thanks in advance for any guidance or feedback.