This depends entirely on your org's security policies and governance when it comes to AI use.
You should probably start here:
https://www.atlassian.com/software/rovo/guides/admin-guide/introduction
https://support.atlassian.com/rovo/resources/
If you're not sure - its probably reasonable to enable it strictly for "Rovo Chat" - with no web searching - limited to only Atlassian Resources - Blocking Studio access so no one can run off and make agents.
Rovo mandate is to run on any users permissions and only scoped to those permissions.
Once you have figured out your limits and where you want to go - you can adjust from there.
In my personal opinion? Rovo's the one AI in the bunch that won't break the wall like others - but at the same time - it's on the user to be responsible with it.
That means you don't feed it anything sensitive - you don't grab random prompts off the net - you verify everything you do with it.
Yes Rovo will read/study/learn from your Org's content - which varies from org to org.
Rovo is an assistant - not a solution.
There's also an ACH Certification pertaining to Rovo that is free - and will prime you on all things Rovo.
https://community.atlassian.com/learning/path/get-the-most-out-of-rovo
https://community.atlassian.com/learning/certifications/rovo-fundamentals
Also be sure to be aware of your Rovo Allowance on Credits.
Happy hunting!
I would check with security, compliance/legal, or AI governance within your organisation for policy, risk, and acceptable-use on this. Great chance AI use in Atlassian is not the first tool you're enabling AI.
Rovo respects user permissions, but it makes over-shared content far easier to find. A project open by mistake used to be protected by obscurity, with Rovo, a single prompt can surface in seconds what took ticket-by-ticket digging before.
Before enabling it, audit your permission schemes (look for "Any logged-in user" or broad groups on Browse Projects). Do the same for Confluence spaces and any connected.
To be clear:
If a space is left open - that's not a Rovo problem - that's a Jira-Admin/Confluence-Admin problem.
It doesn't change the situation if you found it manually vs Rovo finding it.
A number of very foolish "Experts" (air quotes) keep ranting about Rovo being exploitable when they have very little understanding on how it works in the first place.
There are two key points here:
Check your permission schemes - treat this as you would any user accessing things they shouldn't.
Rovo is an accelerant - not the ignitinter when it comes to these risks.
If its a concern - this is a good time to do a site wide Audit on your access controls.
Because as I/we have said - Rovo is scoped to the users permissions - always.
It looks like you're new here. Sign in or register to get started.