Atlassian Team '26 Europe announcements: AMP, MCP Server and Rovo Work, explained
Gabriela Perdum
Author
7 min readOctober 8, 2026
Key takeaways
Of the 11 announcements on our status board, only the Atlassian MCP Server carries a GA label, and its v2 has been GA since 8 September. Rovo Work has no status at all, and we couldn't find a doc page for the non-human identity inventory or for local EU AI inference.
On our test organization on 8 October, the Atlassian MCP Server's Permissions tab (Rovo MCP server in the admin menu) listed 36 toolsets, 19 of them tagged New. Every read, write and search toolset was allowed without review, and delete_jira and manage_jira were blocked.
To approve write toolsets yourself, change Write from Allow all toolsets to Allow some toolsets. Future ones then stop being allowed automatically, but all 15 you have now, the 8 tagged New included, stay allowed until you clear them.
On the same org, the Teamwork Graph CLI allowed all 32 of its permissions by default, including 7 that permanently delete data.
Extra usage billing for Rovo credits starts on 3 December 2026 at $0.01 a credit. Atlassian's doc says extra usage is on by default, but our test org's Rovo credits page still offered Enable extra usage on 8 October.
Code context stores indexed code in the United States, doesn't support data residency yet, and our admin page says it turns on for Rovo-connected Bitbucket workspaces by January 2027.
The Atlassian Team '26 Europe announcements came out on Wednesday 7 October, the day of the Founder Keynote in Amsterdam, and they fill 11 rows on our status board. Three of them get the most space here: AMP (the Agentic Multiplayer Protocol), the Atlassian MCP Server and Rovo Work, a new mode in Rovo Chat. The morning after, our test organization had no Rovo Work. Its MCP server page did list 19 toolsets tagged New, and every new read, write and search one was already allowed.
Atlassian's platform post says AMP is "live across the Atlassian platform today", and the features under it carry their own labels, from generally available to beta, early access and Soon. What reaches you as an admin is mostly settings and Rovo credits.
Sami Shaik hit the same default and posted about it two days before the keynote. He found "a new write toolset switched on because 'allow new write toolsets by default' was on" (Four switches govern external AI access to your data).
Most of the announcements are still coming, but the switches are already here. I'd spend this week on the switches.
Status words quoted from Atlassian's posts and docs, next to what our test organization showed on 8 October. Your org may differ.
Five things we found, mostly on our test org
Of the 11 items on our board, only the Atlassian MCP Server carries a GA label, and its v2 has been GA since 8 September.
Our MCP Permissions tab listed 36 toolsets, 19 tagged New. Every read, write and search one was allowed, new ones included, and Delete and Manage were blocked.
Next door, the Teamwork Graph CLI allowed all 32 of its permissions, the 7 delete ones included.
Rovo Work wasn't in any Rovo Chat menu on our test site on 8 October, with beta features switched on.
Code context turns itself on for Rovo-connected Bitbucket workspaces, and it keeps indexed code in the United States.
AMP: the Agentic Multiplayer Protocol
Atlassian calls AMP "the collection of human-centric experiences, technologies, and patterns that shape how humans and agents work together". In practice, agents show up next to people: the press release says they "now appear in real-time presence bars and cursors alongside human teammates on canvases and whiteboards". The AMP page also describes registering an agent once and choosing where it shows up, on a Jira board, a Confluence page or in Rovo Chat, but gives no date for it. Mike Cannon-Brookes's founder update says "AMP begins rollout today", and no Atlassian page we read gives it a plan tier. You won't find a setting called AMP.
What you'll actually configure is identity. The press release says agents can "Run as User" or use dedicated service accounts. The closest settings that exist today are Rovo Studio's "User's account" and "Agent's account", though Atlassian doesn't say they're the same thing. For automation, its doc suggests the Agent's account "to minimize security risks". I compared Rovo agent permissions with the approval step in our own app, CogniRunner, in an earlier post.
Atlassian MCP Server (the Rovo MCP server): from dozens of tools to 200+
It's the only GA row on our board. Atlassian's MCP post says "Atlassian MCP is generally available now" with "220+ tools" (its platform post says 200+), and the press release says it uses up to 25% fewer tokens, "in internal benchmarking on Claude models". The changelog shows v2 reached GA on 8 September, so if you read the developer changelog, you've met it already. Your admin page still calls it the Rovo MCP server.
Go to Atlassian Administration, then Rovo, then Rovo MCP server, then Permissions. Ours said "New toolsets available". Read was 15 of 15 allowed, Write 15 of 15, Search 4 of 4. Eight write toolsets were tagged New, among them write_goals, write_projects and write_teams. We don't know when each tag appeared: Atlassian's changelog added most of these families in September. The permissions doc explains the rest: "New permissions won't require manual review by admins".
Our test org, 8 October. Look for the purple New tags. With Allow all toolsets selected, each one was allowed without a separate approval.
Read toolsets arriving on their own worry me less, since every action respects the user's existing permissions. Still, the new ones on ours included read_loom and read_talent, which reach Loom meeting recordings and Talent headcount metrics, so look through yours. Write is different, and I'd want to see each one first. That takes two steps. While Write says Allow all toolsets, its switches are greyed out. Change it to Allow some toolsets and you can set each one yourself, and Allow new write toolsets turns off with it. All 15 stay allowed until you clear them.
Delete and Manage were 0 of 1 on our org, with their allow-new switches off. Good, because delete_jira can "permanently delete issues, comments, and attachments".
Delete and Manage stay blocked, and new delete toolsets don't arrive on their own. Check that yours say the same.
Domain allowlists and the MCP control in data security policies only apply to OAuth connections. An AI tool using an API token skips the domain list, and so does one connected through enterprise managed authentication, which is in beta. Both were off on our org, so check yours.
Atlassian also adds tools inside toolsets: on 30 September, getJiraScreen and updateJiraScreen went into manage_jira, available to users who had already approved it. And on 1 March 2027, anything still on v1 starts using the v2 tools automatically. Every tool call lands in the audit log on all tiers (monitor MCP activity).
Illustration, generated locally with FLUX. On our org, read and write toolsets walked straight past and delete_jira waited at the rope. Somebody on your team gets to be the bouncer.
The Teamwork Graph CLI sits two items below the MCP server in the Rovo menu, and it surprised me more. On our org, "Allow all permissions by default" was on. View was 13 of 13, and Write and manage was 12 of 12. Delete was 7 of 7.
Our test org, 8 October. Delete 7 of 7 allowed, and new permissions allowed automatically.
Rovo Work: announced, but not in Rovo Chat on our site yet
The platform post says Work "handles complex, multi-step tasks", that "A task can run for hours", and that it runs "in a secure sandbox your admins govern". Atlassian gives it no status, and we couldn't find a doc page. On our test site, with beta features switched on for the org, the reasoning menu offered Let Rovo decide, Quick answers, Think deeper and Deep Research. The + menu had skills, files, links, mentions and formatting. No Work.
Our test site, 8 October. Four reasoning options, and Work isn't one of them yet.
Keep an eye on cost. The licensing FAQ lists "Work mode in Rovo Chat" under premium AI interactions with variable pricing. Extra usage billing for Rovo credits starts on 3 December 2026 at a list price of $0.01 a credit, and Atlassian's doc says extra usage "is enabled by default" (How Rovo credits work). On our test org it wasn't on yet: the Rovo credits page offered Enable extra usage. I want to try Work. I just can't tell you yet what one long task costs.
Agent accounts and a non-human identity inventory: Soon
The platform post says "Soon" for "agent accounts and non-human identity inventory": one place to see every agent, app and service account, and switch any of them off. Today our Directory has Users, Groups, Teams, Managed accounts, Service accounts and Domains. Rovo agents sit under Rovo, then Agents. The inventory isn't there yet.
Illustration, generated locally with FLUX. Atlassian says agent accounts and an identity inventory are coming Soon. This is one desk of several. Until the inventory arrives, agents, apps and service accounts each get their badge in a different place.
Local EU AI inference: rolling out, with no setting we could find
Atlassian says it restricts "LLM processing exclusively to models hosted within the EU", and the founder update says it's "rolling out". We couldn't find a doc page. Our Data residency page has no inference setting either. Data residency pins where data is stored. This one is about where the model runs, so I'd ask your account team before telling your DPO you're covered.
Code context: open beta, code kept in the US
There are three names here: "Rovo Code Search" in the platform post, "Code Search app" in the press release, and code context in the docs. Atlassian doesn't say they're the same. I won't guess. Code context is "gradually rolling out ... through open beta" on Standard, Premium and Enterprise. Indexed code is "stored and processed in the United States", and data residency isn't supported (set up code context). For a paid Bitbucket workspace connected to a Jira site with Rovo, "Atlassian will automatically enable Code context". Our admin page puts it as "by January 2027".
The Artifacts app: in beta, private by default
AI-made plans and HTML views get permanent links you can embed in Confluence or Jira. The doc says "Atlassian Artifacts is in beta. It's available to all paid plans." New artifacts are private. A deleted one "can't be restored", so plan for that.
Atlassian Insights: a phased rollout
Structured data from your lakes and warehouses becomes Teamwork Graph context. The Insights post promises "a phased rollout starting after Team '26 Europe" for all paid Cloud customers. If your org uses Atlassian Analytics today, it's been renamed Insights, and your org admin chooses between the existing experience and Rovo Insights.
Agent Sessions and Interactive PR Reviews: closed EAP
Agent sessions link local and cloud agent runs back to work items. If you use Rovo agents, the Jira coding agent or a cloud coding agent like Claude, Cursor or GitHub Copilot, Jira can already link their sessions to work items (Use the Agents dashboard). Local sessions from IDEs and terminals are the new part, and Atlassian's SDLC post says "Agent Sessions and Interactive PR Reviews in Loom are in closed EAP". Record for Agent, where a quick screen-and-voice recording becomes a brief an agent can turn into Jira work items, is in open beta.
Atlassian Guard Premium: scanning you can use now
The platform post lists full-site historical scanning, scanning of content and attachments, and guardrails across Rovo Chat. If you have Guard Premium, both scans are documented already, one since April and the other since 2 September. The MCP control in data security policies was announced in the changelog on 29 September and needs Guard Standard (our earlier explainer).
New connectors: Zoom, Gong, Microsoft Entra ID and Google Identity
Atlassian names these among the additions to its 80+ connectors, which its docs call Teamwork Graph connectors. Zoom has a setup doc. If you're after Gong, Entra ID or Google Identity, we couldn't find a doc under those names yet. The nearest Google one is Connect Google Workspace Directory to Teamwork Graph, published 6 October, and Atlassian doesn't say it's the same thing.
Also announced: an OpenAI partnership, Flexera in Assets and more
Atlassian posted an OpenAI partnership on 6 October. On 7 October came a Flexera agreement bringing its Technopedia data into Jira Service Management and Assets. Three smaller items that aren't on our board carry a GA label: Workforce Management and AI Change Risk Assessment workflows in Jira Service Management, per the Service Collection post, and the DX AI Measurement solution, per the SDLC post. Atlassian also profiled its Forward Deployed Engineer programme, which started as a pilot late last year and is open to a select group of enterprise Cloud customers using Rovo.
For Forge builders, the MCP post says developers "can build custom MCP tools with Forge". The rovo:mcp module does that. It has been in Preview since 14 August. On 1 October the changelog moved one more part into Preview: connecting its tools to external AI clients like Claude Desktop, Codex and Cursor. The module reference still labels that part EAP. The SDLC post says Cognition's Devin, Factory and Warp "are all available on the Atlassian Marketplace today, with OpenAI Codex coming soon".
What I'd do this week
Open Rovo, then Rovo MCP server, then Permissions, then Write. Change Allow all toolsets to Allow some toolsets, clear any toolset you don't want, starting with the ones tagged New, and save. That also turns off Allow new write toolsets.
Keep Delete and Manage blocked unless someone asks with a reason. On the Authentication tab, make sure Allow API token authentication and Allow enterprise managed authentication are off unless something needs them.
Open Rovo, then Teamwork Graph CLI. If nobody needs it to delete, turn off "Allow all permissions by default", clear Delete, and choose Save and revoke sessions.
Open Insights, then Platform usage, then Rovo credits, before 3 December. If you see Update extra usage limit, set one. If Get more usage offers Enable extra usage, it isn't on for your org yet, so look again in December.
If you have a paid Bitbucket workspace connected to a Jira site with Rovo, open Rovo, then Code context. There's no switch to keep it off: the page only offers Request indexing. If your code mustn't be stored in the US, ask your account team now whether you can opt out, or be ready to disable it the day it turns on, which deletes the stored index.
What we're watching next
The Closing Keynote is scheduled for Thursday 8 October at 15:00 CEST, and Atlassian's on-demand library says recordings start on 12 October. Part 3 asked where Rovo agents land in Jira Service Management. The Service Collection post puts its AI agents in Slack, Teams and Claude through "service and operations context where you work", which is in closed EAP, and Atlassian's MCP post still lists Jira Service Management workflows as "coming soon". One update we've made to our hub: Atlassian's keynote session page now lists four speakers, not the five it listed on 5 October, and has it ending at 10:30. Its agenda still says 10:15. When Rovo Work or the identity inventory shows up on our org, it'll get its own write-up.
Atlassian Partner Accelerate at Team '26 Europe: Forge, revenue share and who we met
Atlassian Partner Accelerate, the partner-only day before Team '26 Europe, was for us a day of meeting solution partners and other Forge app builders. Here is what was on the screens about Forge and Teamwork Graph, the Marketplace revenue share that applies from 1 October 2026, the partner tiers, how we shared LeanZero by QR code, and a little of Amsterdam.