Third in the series after three doors and the fourth door, A2A. This one is about the doors most of us think we have already locked.
What I thought the control was. Atlassian Administration, Rovo, Rovo MCP server, Domains tab: a list. Atlassian's supported AI partners are allowed by default, you can add your own domains, or you can turn the Atlassian list off and add nothing, which is what I did months ago: no partner domains, no own domains, MCP effectively closed. That control is real and it works (control Rovo MCP server settings).
What I found on the next tab. The Authentication tab has two switches, both off by default, and each one routes around the domain list:
- Allow API token authentication. Atlassian's words on the control page: "Tools that authenticate via API token do not use domain allowlists and are instead governed by your IP allowlist configuration and the scopes granted to their tokens or API keys." Once on, a client presenting a valid scoped token from any domain connects with that account's permissions.
- Allow enterprise managed authentication (Beta). The caption in the console says it plainly: "Access is controlled by an IdP, not the domains list." Authorisation moves to your identity provider; the domain list is no longer consulted.
Why you will be asked to open the first one. The v2 tool sets for Jira Service Management and Bitbucket are only available through API token authentication (authentication and authorization). The first team wanting an AI agent on JSM queues through MCP will ask for the token switch, and from then on the domain list covers the interactive tools and nothing else.
And the third tab decides what a client can do once inside. Permissions lists Read, Write, Search, Delete and Manage per toolset. On my org today, with nobody having touched it: Read 13 of 13 allowed, Write 13 of 13, Search 4 of 4, Delete 0 of 1, Manage 0 of 1, plus a banner telling me new toolsets arrived and were allowed automatically. So the default posture is: writes on everything, deletes and admin blocked, and each new toolset opens on arrival. That tab is where the real least-privilege decision lives, and I suspect most orgs have never opened it.
What still guards both doors, and what each costs:
- IP allowlists, per product, apply to token, OAuth and IdP clients alike. Two catches from the doc: most orgs do not run them because they break remote work, and some AI tools use their own outbound IPs, so a user on an allowed VPN can still be blocked unless the tool's ranges are added.
- Token scopes and tracking. A token client is bounded by its scopes, and org admins can view and revoke user API tokens. Detective, not preventive.
- A data security policy rule, "Prevent Atlassian Rovo MCP server access," exists in the policy controls, so MCP can be blocked by classification and policy scope. I have not confirmed which plans carry it; if you have, say so below.
- Monitoring. Atlassian publishes a page on monitoring Rovo MCP server activity. Read it before the switch, not after.
And it is metered. MCP calls that search or pull context draw from the shared Rovo credit pool, up to 10 credits a call for search and Teamwork Graph tools, with extra usage billing from 3 December (how Rovo credits work). A service account's token in a backend loop is a meter running with nobody looking at it.
Where I am today: Atlassian domains off, no domains added, both authentication switches off, so nothing connects. Delete and Manage blocked by default; Read, Write and Search wide open by default, which I am now going to trim before the first request to open a door arrives.
What mine looks like today (Atlassian Administration, Rovo, Rovo MCP server):
Domains tab: Atlassian supported domains off, no domains added.

Permissions tab: Read 13/13, Write 13/13, Search 4/4 allowed; Delete 0/1, Manage 0/1.

Authentication tab: API token off, enterprise managed authentication (Beta) off.

Three questions, and I will summarise the answers in a follow-up:
- Have you enabled API token or enterprise managed authentication for the MCP server, and what forced it: JSM tools, Bitbucket, a backend integration, or an IdP mandate?
- Have you opened the Permissions tab, and did the Write defaults surprise you?
- Who in your org watches the Rovo credit meter, and has anyone attributed a spike to an MCP client rather than a person?
Every control above was checked against the Atlassian pages linked, and against my own console, on 9 September 2026. If Atlassian closes the gap (domain enforcement for tokens, or a per-token domain binding), I will update this post rather than leave it standing.