On 9 September I posted Your MCP domain allowlist has two doors it does not guard and ended it by saying I would trim the Permissions tab on my own org, where every Write toolset was allowed by default (13 of 13). I did not do it. This morning I opened the same tab, and here is what fifteen days of not doing it looks like.
Write: 14 of 14 allowed. The new one is write_capacity_planning, tagged New, described as "create and update capacity plans and allocations to help you adjust how work is planned." Atlassian's Rovo MCP changelog dates it to 24 September 2026, today, as a progressive rollout by tenant. It was allowed in my org before I knew it existed, because the switch Allow new write toolsets ("automatically allow new write toolsets when they are added to Atlassian MCP server") is on by default, and the Write dropdown reads Allow all toolsets.
Atlassian's changelog entry says it in its own words: "If your organization uses auto-enablement for toolset groups, these tools may not be immediately available to all users. Admins can manage access and enable these toolsets through the Atlassian MCP section in the Admin portal." Auto-enablement is the default, so for most orgs "may not be immediately available" reads as "already on."
It was not alone. Scrolling the Write list, six more carry the New tag: write_focus, write_goals, write_loom, write_projects, write_talent, write_teams. All allowed. All arrived since 9 September. Read went from 13 to 14 the same way. Screenshots below.
What this means in plain admin terms. Any AI client that has passed the door (OAuth over an allowed domain, or an API token if that switch is on) can now create and modify capacity plans, goals, focus areas, teams and team memberships in my organisation, through a server whose permission surface is growing by Atlassian's release calendar rather than by my decisions. None of that is a bug; the page tells you what it does. It is a default that turns "review new capabilities before enabling them" into "discover them after the fact," which is the opposite of how every other admin control in Atlassian Administration behaves.
What I did, ten minutes ago.
- Write dropdown: Allow all toolsets to Allow selected toolsets, keeping
write_jira, write_confluence and write_jsm (the three my own integrations use), blocking the rest including all seven New ones. - Allow new write toolsets: off. Same for Read and Search. From now on a new toolset arrives blocked and gets a decision.
- Delete and Manage stay at 0 of 1, as they were.
The MCP permissions page explains each category; what it does not do is tell you when the lists change, so put the tab on a monthly calendar reminder or you will be writing this post yourself in a month.
Three questions for the people who run orgs:
- Open your Write section now. What is the count, and how many rows carry the New tag? I am collecting real numbers for a follow-up, not hypotheticals.
- Has anyone found a way to be notified when a new toolset is added (audit log event, email, anything), or is opening the tab the only signal?
- For those on Standard, where the IP allowlist is not available and this tab is the whole perimeter (Anne Saunders made that point on the last post): did you know this default was on?
I will fold the answers into the follow-up alongside the starter #4 results.
Console screenshots taken 24 September 2026; changelog verified the same day.