Hi Atlassian Community!
I am David Cross, the Chief Information Security Officer at Atlassian. A rising theme I see in security leader roundtable discussions is the imperative to establish modern governance and hygiene before scaling adoption of AI agents in organization workflows. As autonomous systems take multi-step actions at machine speed, traditional perimeter and access models must evolve to ensure data remains secure without hindering team productivity.
Organizations adopting and scaling Rovo Agents can trust that Atlassian applies rigorous defense-in-depth security across the underlying platform, while providing customer security teams with the controls needed to govern their own environments.
This guide outlines practical steps to establish strong AI security hygiene. We cover both our baseline platform protections and the Atlassian Guard controls you can implement today to manage agent permissions, connected data, and threat detection.
1.0 How Atlassian secures Rovo:
Rovo is designed and deployed under Atlassian's Responsible Technology Principles. We use trusted commercial models from OpenAI, Anthropic and Google, as well as open-weight models that run entirely on Atlassian controlled and secured AWS infrastructure. Atlassian does not permit third-party hosted LLM providers to use customer data to train or improve their models, and those providers operate under zero data retention arrangements. These commitments are incorporated into Atlassian’s AI Terms.
Rovo runs on Atlassian Cloud and inherits its platform controls, including tenant isolation and encryption with TLS 1.2 or higher in transit and AES-256 at rest, as set out in the Technical and Organizational Security Measures incorporated into the Data Processing Addendum. The ‘Rovo Security and Trust White Paper’ describes these controls in depth and is available to customers on the Trust Portal, with a preview in our Trust and Security community post.
If you are new to the Trust portal, you may be guided through a quick, one-time access flow (one-time code, and possibly an NDA for your organization). To learn more about the Atlassian Customer Trust Portal, visit
https://customertrust.atlassian.com/
.
Rovo’s security program is regularly assessed against standards such as SOC 2 Type II and ISO 27001, and our AI management system is ISO 42001 certified. Atlassian is at the forefront of EU AI Act compliance, monitoring developments and implementing required measures as new provisions take effects.
The shared responsibility model for security in Atlassian Cloud extends directly to agentic workflows. To support this, Atlassian provides the security controls and implementation guidance you need to secure your specific agent use cases. Here is an overview of those controls.
2.0 What you can do to secure Rovo Agents:
The controls we use to secure Rovo agents are available to you now. Here is where to start:
2.1 Audit user access first.
An agent can only act upon content the invoking user can already reach, so an over-broad permission becomes easier to exploit. Review user access in Jira and Confluence and in every connected source, then narrow each agent below the user's ceiling with scoped knowledge sources.
2.2 Restrict who can build and run agents.
Uncontrolled creation produces sprawl and agents that no one owns or reviews. In Rovo Studio settings, limit creation to selected groups or to admins only, have owners restrict visibility with named editors and managers, and keep an inventory with an owner and a purpose for every production agent.
2.3 Scope connectors and integrations.
Each connected source expands the information available to Rovo, subject to the invoking user’s permissions in that source, so enable only the connectors and capabilities required for each agent’s use case. A practical checklist that organization admins should evaluate includes:
2.4 Classify data and set policies over what AI may touch.
A Rovo agent acts with the invoking user’s permissions and the capabilities of its configured tools, so organizations should limit access at both the identity and content layers.
With Atlassian Guard Premium, you can detect sensitive data in Jira and Confluence and apply data classification levels based on configurable detection rules. Data security policies can then restrict supported actions and integrations for covered content. For example, you can block access through the Atlassian MCP server at the organization, app, space, or classification level. Guard Premium also supports the investigation and redaction of sensitive information detected in Jira and Confluence content.
2.5 Separate experimentation from production.
Test Rovo Agents in an isolated sandbox environment first before deployment into production. Agent owners should initially configure agents with read and search tools only first, then narrowly scoped write tools may be introduced where required, subject to the invoking user’s permissions, confirmation for consequential interactive actions, audit logging and documented disablement procedures. Organization administrators can separately block write access through the Atlassian MCP server.
2.6 Evaluate, debug and verify agents regularly.
In Rovo Studio, run agent performance evaluations across response accuracy and resolution rate before launch and after and every material change. Agent owners can debug and conduct conversation reviews live to trace how an agent’s response was produced and correct the instructions or sources behind it. Agents proven to be accurate and safe should be marked as verified, so they can be easily distinguished by users in your organization.
2.7 Monitor and log agent activity.
Coordinated agent behavior only shows up when events are correlated. Rovo agent lifecycle events, Rovo chat starts and connector changes are surfaced in audit logs. Atlassian Guard Premium or Cloud Enterprise Customers can stream audit logs to their external SIEM, to enable analysis of anomalous activity against your enterprise detection rules. The Rovo Insights dashboard also shows agent runs, active agents and usage trends, and should be reviewed on a regular cadence as agent count grows.
3.0 Concluding Thoughts: A Shared Responsibility
Securing an autonomous agent environment requires an active partnership between the platform provider and your security team:
- Atlassian governs the platform baseline. We enforce model safety boundaries, tenant isolation, zero data retention commitments, and runtime permission controls across Atlassian Cloud. To explore our underlying architecture in depth, review the Rovo Secure AI Architecture whitepaper on the Atlassian Trust Center, and follow upcoming security capabilities on the Cloud Roadmap.
- Your team governs the environment. Your administrators set agent creation policies, manage user permissions, approve connected enterprise data sources, and monitor organizational activity.
To support your rollout, Atlassian provides abundant enablement material which include support articles, the Rovo Atlassian Community Forum, and interactive learning courses, together helping your organization adopt Rovo Agents confidently at speed.