Prevent Atlassian Rovo MCP server access
The Atlassian Rovo MCP server control lets you choose whether AI agents and assistants can read your organization's Jira and Confluence data through the Atlassian Model Context Protocol (MCP). Use this control in a data security policy to allow or block AI access to content your organization wants to protect.
Data security policies (DSPs) are enforced only for OAuth authentication methods, not API token authentication methods.
Who can do this?
Role:Organization admin
Atlassian Cloud: Atlassian Guard Standard. Classification-level overrides require Atlassian Guard Premium.
Atlassian Government Cloud:Available
Understanding the Atlassian Rovo MCP server control
The Atlassian Rovo MCP server lets AI agents read Jira work items and Confluence pages on a user's behalf. This control lets you allow or block that access at an organization, site, container, or classification level.
The control works alongside your existing user permissions, not instead of them. Blocking MCP access doesn't change what users can do directly in Jira or Confluence. It only prevents covered content from being read through the Atlassian Rovo MCP server.
Changing this control can affect AI agents and workflows that rely on reading content through MCP. Agents that expect certain content to be available may no longer return complete results.
How do I use this control?
admin.atlassian.com に移動します。複数の組織がある場合は、対象の組織を選択します。
Select Security > Data protection > Data security policies.
Select the Atlassian Rovo MCP server control, then select Create draft.
Set the organization-wide default by selecting Allowed or Blocked.
To apply finer-grained rules, select Add override and configure at a:
Atlassian app level
Space level
Classification level (requires Atlassian Guard Premium)
Then select Save overrides.
Review your configured policies, then select Activate.
Once activated, the control takes effect within a short time as the policy propagates.
私のユーザーはどのような体験をするでしょうか?
The information below describes what happens when you apply this control. If you add overrides, test the results to confirm the level of access you expect. Configure an override for a control
When the control is set to Blocked
Jira
AI agents can't read Jira work items covered by this control through MCP.
Covered work items aren't returned in searches, including JQL searches run by an AI agent through MCP.
If an agent requests a specific covered work item, it isn't returned. The agent receives a "does not exist or you don't have permission" response.
The block applies even when the underlying user has permission to view the work item directly in Jira.
Confluence
AI agents can't read Confluence pages, spaces, or classified content covered by this control through MCP.
Even when blocked, MCP servers may still be able to:
get and list global templates in Confluence
create a space
get the current user's personal space
list Confluence spaces
watch or unwatch Confluence labels
When the control is set to Allowed
The user's existing permissions control what the AI agent can access. Agents can read the same Jira and Confluence content the user can access, subject to their permissions.
What this control doesn't affect
Users viewing or working with content directly in the Jira or Confluence UI.
Access through custom MCP servers. This control covers the Atlassian Rovo MCP server only.
REST APIs used by first-party Atlassian product features.
Other data security policy controls, such as data export, attachment download, public links, and Marketplace and custom app access. Those controls are governed separately.
Existing user permissions. Blocking MCP access doesn't remove or change what users can do in Jira or Confluence.
この内容はお役に立ちましたか?