I opened Data security policy this morning and there is a row I did not create: Atlassian MCP server, default configuration Allowed, applies to Jira and Confluence, overrides 0, updated by Atlassian (first screenshot below). It arrived on 29 September (Rovo MCP changelog) as a data security policy control that governs how external AI tools read and write Jira and Confluence data, with overrides by app, space and classification level. It is the right control to have. It is also the fourth switch for external AI access that has landed in my org since early September, and every one of them arrived with a default somebody else chose.
Here are the four, as they stand on a Standard-tier org today:
- Data security policy → Atlassian MCP server. Allowed by default, no overrides. If you classify content, this is where you can keep a classification level away from MCP clients entirely. Until you touch it, nothing is excluded.
- Rovo MCP server → Permissions. The write toolsets. Two weeks ago I posted that a new write toolset had switched itself on in my org because "allow new write toolsets by default" was on. Still on unless you turned it off.
- Rovo MCP server → Authentication. Two toggles, both off on my org: Allow API token authentication (non-interactive access for agents and pipelines) and Allow enterprise managed authentication, marked Beta, which hands MCP authorization to your identity provider instead of the domains list (second screenshot below). These are the two I would want a change ticket for before anyone flips them.
- Forge rovo:mcp module, in Preview since 1 October (developer changelog). A Forge app can now expose its own tools to external AI clients; the admin control during Preview is a single switch per app that exposes every tool the app declares. This one is not in the admin console yet unless you have such an app installed; it will be.
Three questions, because the answers will tell us more than the docs do:
- Did the MCP server row appear in your Data security policy, and had anyone on your side reviewed it before you read this? I am especially interested in orgs with classification levels in use: did you add an override, and for which level?
- Is enterprise managed authentication showing as Beta on your org too, and has anyone wired it to Okta or Entra yet? A thread this week suggests the Okta path works with the right values and the Entra path is not yet validated; a second data point would help.
- Who owns these four switches in your organisation? On most orgs I have seen, the Rovo MCP page is owned by whoever set up Rovo, the Data security policy by security, and Forge apps by the app owners. Four switches, three owners, one data flow.
I will fold what comes back into a longer write-up next week. No vendor pitches please; this one is about the admin console.