Atlassian Rebuilds Its MCP Server: 220 Tools, Per-User Permissions and Audit Trails

After the AMP protocol, a rebuilt MCP server, and an OpenAI deal that explicitly does not make GPT-6 Astra Rovo's standard, the strategy looks clear: models are commodities, the work graph is the differentiator — but every key figure is…

Illustration: a panel of hundreds of tiny connectors with a few tokens plugged in, one token mid-connection trailing a thin thread that records the change.
Illustration
Gift article

Atlassian Rebuilds Its MCP Server: 220 Tools, Per-User Permissions and Audit Trails

After the AMP protocol, a rebuilt MCP server, and an OpenAI deal that explicitly does not make GPT-6 Astra Rovo's standard, the strategy looks clear: models are commodities, the work graph is the differentiator — but every key figure is the company's own, and the prompt injection risk remains.

What Was Announced in Amsterdam

At the Team '26 Europe conference in Amsterdam on 6–7 October 2026, Atlassian launched a package of announcements that together sketch the company's answer to the question of who will own the context that enterprise AI agents work from: AMP — The Agentic Multiplayer Protocol —, a completely rebuilt Atlassian MCP Server and expansions of the Teamwork Graph, according to the company's press release. The same week, an expanded OpenAI partnership was described by VentureBeat as a spend commitment: VentureBeat dates the OpenAI news to Monday 6 October, while AMP was announced at the conference on 7 October. The details of what was presented on stage versus what sat in the press release are unclear in the coverage.

According to the press release, AMP will let customers collaborate with agents in "richer and more visible ways". The announcements came the same week as the OpenAI commitment — a combination that looks contradictory at first glance but is in fact the whole point of the strategy.

How It Works

The technical core is the context graph and the protocol that governs agents' access to it.

Teamwork Graph. Atlassian says the graph now connects more than 250 billion objects and relationships across the company's products — and that it can now also read source code down to the function, symbol and class level. The latter is significant: it means, according to the company, that agents can reason about how the code relates to the tickets, documents and decisions it belongs with. The company further says that humans and agents now collaborate more than 10 million times a month, and that more than 120 enterprise features have been shipped over the past year — both figures should be read as the company's own numbers from the press release, not independently verified.

The MCP server. The rebuilt server exposes, according to VentureBeat's coverage, more than 220 tools against the Atlassian platform. The security architecture is detailed: authentication with OAuth 2.1 and PKCE, permissions enforced per user at query time, separate risk tiers for read, write and delete operations respectively, and confirmation on risky steps. Data leak prevention happens via Atlassian Guard. The adoption figures — almost 2 million monthly active users and more than 15 million daily tool calls, a fifteenfold increase in six months — are again Atlassian's own. So is the claim that the new version uses up to 25% fewer tokens for the same Jira and Confluence work, benchmarked internally on Claude models.

AMP's permission model. The press release describes AMP as enforcing strict permissions, so that agents can run as "Run as User" or via dedicated service accounts, with a full audit trail for every action. That is the answer to what VentureBeat calls the most tangled objection to pointing an autonomous agent at a system of record: that actions must be traceable to accountable identities.

Multi-Model as Principle, Not Exception

The most telling part of announcement week may be what was not announced: GPT-6 Astra will not be Rovo's standard model. Atlassian was, according to VentureBeat, explicit in correspondence with the editorial team that Rovo routes dynamically via an internal AI gateway across OpenAI and other providers, weighting capability, speed and cost per task. An OpenAI representative described, according to VentureBeat, the deal as "effectively a spend commitment" — that is, not an exclusive partnership. The contract terms have not been disclosed.

The company's basis for this stance was articulated by co-founder and CEO Mike Cannon-Brookes. At a press briefing, he said, according to Computer Weekly: "Most customers, well north of 75% of our customers, use multiple large-scale providers. They choose multiple foundation model providers, often with Microsoft in the mix, often with Google in the mix. Most large enterprises don't say: 'I'm going to choose A'." On stage, he tied it to a more general frame, quoted by TechRadar: "Models are the engine, but context is the fuel. No matter how capable a model becomes, if it doesn't reliably know why you made a decision back in 2022, it can't help you in 2026."

Sherif Mansour, head of AI at Atlassian, made the interoperability point explicit to Computer Weekly: "We're enabling other application vendors to be interoperable with the Atlassian platform, and for Atlassian's agents to be interoperable with their platforms through AMP. A big part of AMP is letting customers bring in the agents they want. It doesn't have to be ours."

The Positioning Against Competitors

According to TechTarget, Atlassian's executives — without naming competitors — argued against two alternative architectures: "headless" and "control tower" approaches, terms strongly associated with Salesforce and ServiceNow respectively. It is worth emphasising, as TechTarget does, that the names were not used; the association lies in the terminology.

In the same coverage, analyst Torsten Volk of Omdia offers the sharpest independent assessment: "Microsoft, ServiceNow, Salesforce and GitHub are running the same argument with their own graphs, so the differentiation for customers will boil down to which graph already holds the most of their work — and Atlassian's advantage there is Jira and Confluence, not the AI." It is a consistent observation: if the strategy is to sell context, the market position is determined by where the context already sits, and then the model choices matter less.

What Is Settled — and What Is Not

VentureBeat points to an honest dividing line in the company's own security story. The combination of per-user permissions, separated write tiers, confirmations on risky steps and DLP through Atlassian Guard amounts, according to the coverage, to a "reasonable mitigating strategy that should be stress-tested in a proof of concept". But it does not, in itself, solve the risk of prompt injection — a malicious instruction attempt planted in a ticket or a page to steer an agent with write access. That objection still stands.

For buyers of enterprise AI platforms, this means a concrete evaluation checklist: which graph already holds the organisation's work, how identity and auditing are enforced in the agent connections, and how well the MCP integration resists manipulation attempts in the content the agents read.

There is also reason for caution about what has been reported. Every key figure — 250+ billion objects, 15 million daily calls, 2 million monthly users, 25% token savings, 10 million human-agent collaborations — comes from Atlassian's own press release or internal benchmarking, not from independent verification. The details of the OpenAI deal have not been disclosed. And it remains unclear in the coverage exactly how much of the announcements was presented on stage in Amsterdam versus what sat in the press release itself.

But the strategic line is unambiguous across all the sources: Atlassian is betting that foundation models become interchangeable commodities, and that the context graph — not the model — becomes what the customer actually pays for.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.