Two weeks ago this community mapped three doors AI agents use to enter Jira: workflows, automation, and assignment. That thread collected governance patterns I still quote. But while we were watching those doors, a fourth one opened, and it is not for agents entering your org.
It is for agents talking to each other.
This is shipping, not roadmap. In Atlassian Administration, the Rovo MCP server page now carries an A2A tab (Beta) with a single Allow A2A toggle, off by default: enable it and, per the product's own words, "external agents can discover Rovo's capabilities and collaborate on tasks across Atlassian apps." Rovo publishes a public AgentCard for exactly this discovery. Gemini Enterprise can already connect to Rovo through a Google Cloud Marketplace listing. And the door swings both ways: a Forge module in EAP lets remote agents (GitHub Copilot, Cursor, Box AI) live inside Jira as assignable, mentionable colleagues, speaking the same A2A protocol. Atlassian is a founding partner of that protocol. This is a direction, not an experiment.
Now, credit where due: the documentation answers the first governance question well. An A2A connection acts with the authorizing user's own permissions, Rovo cannot do anything that user cannot, and org AI policies still apply. Good. But the three-doors thread taught me that "technically bounded" and "governable" are different things, and here is where I stop knowing the answers:
- A user's permissions, exercised at machine speed by a chain of agents, are not the same risk as that user clicking. When Gemini asks Rovo which asks a Forge-connected agent, every hop is "authorized", and the blast radius is still nothing your review processes have ever seen. Is per-user permission scoping enough, or does agent delegation need its own ceiling?
- What does audit mean for a delegation chain? "Who did this" now has answers like: your PM's Gemini asked Rovo. What does your compliance team write in that finding?
- Would you turn Allow A2A on today? If not, what is the concrete thing that would change your answer: scoped capabilities, chain-level logging, an approval step per connection, something else?
- And underneath it all: when agents discover and delegate to each other, is the unit you govern still the agent, or is it the conversation?
My toggle stays off while I think. Where is yours, and more importantly, why?