Manage Agent2Agent connections

Who can do this?
Role:Organization admin
Atlassian Cloud: Free, Atlassian Guard Standard, Atlassian Guard Premium, Enterprise
Atlassian Government Cloud:Not available

The Agent-to-Agent (A2A) Rovo integration allows third-party AI agents, such as Google Gemini, to call Rovo for organization-approved AI tasks.

Key behaviors:

  • You can disable or re-enable A2A connections at any time.

  • Rovo uses your existing organization settings. See Manage Rovo access

  • Rovo only acts within an authenticated user’s existing permissions in connected systems.

  • Users must complete OAuth 2.1 authorization before their third-party AI agent can call Rovo on their behalf. See Set up Agent2Agent connections

Before you begin

As an organization admin, you already have access to Atlassian Administration and Rovo settings. Before getting started with A2A connections, make sure that:

  • your organization has Rovo enabled for some Atlassian apps. See Manage Rovo access

  • your security and compliance teams have approved using A2A third-party AI agents with Rovo.

Enable A2A connections

A2A connection functionality is disabled by default. You can check its status, enable it, or disable it from your Rovo settings.

To enable A2A connections:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Rovo, then Agent2Agent.

  3. Check that the toggle for Allow A2A is enabled. If it’s not, select the toggle to enable it.

You can return to this setting at any time to check or change its status.

How access is enforced

Rovo enforces multiple layers of control when a third-party AI agent calls Rovo:

  • Allow A2A, in Atlassian Administration. This is the organization-level control for A2A. When it is off, no third-party AI agent can send requests to Rovo. It applies to your whole organization. You cannot allow A2A for some Atlassian apps and block it for others.

  • Rovo access, in Atlassian Administration. This is an existing app-level control, not an A2A setting. It determines which apps, such as Jira and Confluence, have Rovo turned on. A2A does not bypass it, so existing Rovo access settings continue to apply to anything an agent asks Rovo to do. There is no single Rovo on or off switch, so an organization can have Rovo on for one app and off for another. Enterprise organizations may also be able to scope Rovo access to user groups.

  • User authorization. The agent must have a valid OAuth 2.1 grant from the user, and it always acts within that user's existing permissions. It cannot see or change anything the user could not see or change themselves.

Troubleshooting

Use the checks below if users report that a third-party AI agent cannot call Rovo.

  • Integration appears unavailable to all users:

    • Confirm that the Allow A2A setting is enabled in Atlassian Administration.

    • Verify that Rovo-enabled apps are turned on in your organization settings.

  • Specific user cannot use Rovo features:

    • Ask the user to complete or retry the OAuth 2.1 authorization flow when prompted by a third-party AI agent.

    • Check that the user has sufficient permissions in the underlying apps and data sources; Rovo will not exceed the user’s existing permissions.

  • Behavior differs between environments or groups:

    • Confirm that organization-level Rovo-enabled apps settings are consistent across the affected environments.

    • Verify that the Allow A2A setting is enabled in each environment.

Still need help?

The Atlassian Community is here for you.