Hi,
I'm working on a threat and risk assessment for work. The assessment focuses heavily on Rovo and Atlassian AI features, Rovo MCP Server and also 3P MCP connectors as well as marketplace apps.
The question I can't get a definitive answer to is this:
Can we enforce data security policies that map data classification levels to Rovo MCP Server permissions, restricting sensitive data from being surfaced by connected AI clients?
The closest concept is data security policies to restrict access by marketplace and custom apps, of which Rovo MCP Server is neither.
The Problem: Our current DLP (Data Loss Prevention) rules stop users from exporting sensitive content, but a security gap exists where this same data can still flow to third-party clients via the Rovo MCP Server.
The Challenge: Broadly blocking access at the space or app level is not feasible. The target data contains critical business context that varies in sensitivity item-by-item, making blanket restrictions impractical.
Is there any short term plans for features in this area? I've found the Atlassian Cloud roadmap has the line items:
- Connector data security, and
- Rovo chat security
Should I be hopeful these might be the features I'm looking for?