I am testing a Rovo Agent intended to perform user account reviews and user recertification against our Atlassian Organization.
My objective is to build an automated User Recertification Agent that:
* Retrieves all users from the Atlassian Organization or from specific groups (such as "jira-servicedesk-users").
* Retrieves all ACTIVE human users.
* Excludes system, application, bot, service, and automation accounts.
* Reviews user activity.
* Identifies inactive users based on a configurable threshold (currently 180 days).
* Produces a recertification report for access reviews and license optimization.
I am an Organization Admin, and my expectation is that the agent should be able to retrieve all managed users and group members from the Atlassian Directory.
However, the agent appears to be limited to approximately 50 returned users and cannot perform pagination, I tried to give the agent a rest API that fetchs the group members but The agent repeatedly responds with messages similar to:
"The available tools do not provide the functionality to specify startAt, maxResults, or check for isLast for pagination."
and
"The jira_atlassian_user_search_by_query tool returned a maximum of 50 users and does not support pagination."
Questions:
1. Is Rovo currently capable of calling Atlassian Administration REST APIs such as:
GET /admin/v1/orgs/{orgId}/directory/users
or
GET /admin/v1/orgs/{orgId}/directory/groups/{groupId}/members
2. If I am an Organization Admin, should Rovo inherit my admin permissions when executing agent actions?
3. Does the built-in jira_atlassian_user_search_by_query tool have a hard limit of 50 results?
4. Does this tool expose any pagination mechanism (startAt, cursor, nextPageToken, offset, etc.) that Rovo can use?
5. Is there currently any supported method for a Rovo Agent to retrieve the complete membership of a large Atlassian group?
6. If built-in Rovo tools cannot perform this operation, is the recommended approach to create a Forge Action or custom Action that calls the Atlassian Admin APIs directly?
7. Are there any documented limitations preventing Rovo Agents from accessing Atlassian Administration APIs even when the user executing the agent is an Organization Admin?
8. Is there a supported way for a Rovo Agent to retrieve Last Seen / Last Active information for all users in the organization so that inactive accounts (e.g., users inactive for 180+ days) can be identified automatically?
9. Is user recertification and access review considered a supported use case for Rovo Agents, and if so, what is the recommended architecture?
Agent Prompt Used:
You are an Atlassian Jira Service Management Account Review Agent.
TARGET DATASET
Retrieve users who are members of the group "jira-servicedesk-users".
Requirements:
* Retrieve all group members.
* Use pagination until all pages are processed.
* Never analyze only the first page.
* Include only ACTIVE human users.
* Exclude System, App, Bot, Service, and Automation accounts.
* Report total members found.
* Report total ACTIVE members.
* Provide Display Name, Email Address, Account Status, Last Seen, and Status.
* Report excluded accounts and reasons for exclusion.
* Never generate a report from a partial dataset.
Expected Behavior:
The agent should retrieve the complete membership of the group and all available pages before generating a report. For user recertification purposes, the agent should also be able to identify users that have not accessed Atlassian products for 180 days or more.
Observed Behavior:
The agent only retrieves approximately 50 users and reports that pagination is unavailable through the tools exposed to the agent.
Could you please clarify whether this is an expected product limitation, a permissions issue, or whether additional configuration is required?
Thank you.