Product1 publisherNot yet confirmed elsewhere3 min readPublished
Atlassian's new protocol gives every AI agent an admin-assigned identity and scope
Atlassian's Agentic Multiplayer Protocol gives every AI agent an identity, with authority and scope set by administrators. Rovo Work can now run for hours and find its own tools, so that admin setting limits what happens between plan approval and final review.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Atlassian also launched Rovo Work, a Rovo Chat mode for long, multi-step tasks that a human reviews and approves.
- When Rovo Work meets a task it was not trained for, it tries to teach itself, as when it researched a reel format and got video synthesis tooling for a product manager.
- Rovo can generate custom skills for power users as a separately supported feature, though not every behavior it learns becomes a skill users can export.
- Rovo Code Search adds source code to the Teamwork Graph, Atlassian's context engine that maps relationships among people, code and documents.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision IT has to define each agent's authority and scope before teams start sending it work; the user who opts into Rovo Work is not the one who sets those limits.
- exposure An agent that fetches its own tooling for unfamiliar jobs can reach past what the requesting team pictured, and the admin's scope setting is the place that reach gets limited.
- contradiction Valliani calls a Rovo Work query permission to 'unleash itself fully' while the same report says agents cannot run rampant; which description holds depends on default scopes that were not described.
- precedent Each source Atlassian adds to the Teamwork Graph, source code first, becomes something agent scope reviews will be expected to cover.
A user picks Rovo Work over ordinary Rovo Chat when sending a query. Jamil Valliani, Atlassian's head of AI product [4], described what that choice hands over. "When you opt to send a query to Rovo Work, you're actually giving Rovo permission to go and actually unleash itself fully," he said [8].
The pitch Atlassian made at Team '26 Europe [1] is that agents should work like employees inside a fully governed system of work [2]. "This is a multiplayer game," Valliani told SiliconANGLE. "Humans and agents are working together in a very dynamic space, and there are lots of players." [4] Each agent gets an identity assigned by administration, with authority and scope, plus limits meant to keep it inside the platform [3]. An administrator sets those before any user types a request.
Teams count on the user for control: the user sets the objective, reviews the proposed plan, course-corrects and reviews the result [7]. But users hand Rovo a long task, and it can disappear for hours [7]. When the task is new to it, Rovo Work goes and finds what it needs, tooling included [11]. The human checkpoints sit at either end. For the hours in between, the limit is whatever scope the admin wrote [3].
That scope now covers more ground. With source code added to the Teamwork Graph [10], admins writing agent scope against the graph have repositories to account for as well as documents.
Atlassian says openly that it cannot predict what people will ask for. "We can't really imagine the creativity our customers are going to ask it to unleash," Valliani said. "We want customers to go and challenge it, and tell it what they really want." [13] SiliconANGLE's report says agents cannot run rampant [9]. Valliani gave the company's internal statement as "Headless software means brainless software," and its position is that autonomy is not useful without teamwork [5].
The report does not describe the screen where identity and scope are set, the default scope a new agent starts with, or pricing and availability.
Which agents need setup first depends on how long each one works between human checkpoints and what it can reach. On duration, it might give a single chat answer or run a Rovo Work task for hours [6]. On reach, it might use context already in the platform, or tools and skills it picks up on its own; Rovo can generate custom skills for power users [12]. For a short task on platform data, the user reading the answer is enough review. A long task on platform data depends on the scope matching the project. When a short task pulls in a new tool, the user who asked sees it in the output. In my view, the fourth box needs the most care: long tasks where the agent gets its own tooling. For those, identity, authority and scope should be written down before the first query, along with the name of the person who answers for the result.
What to watch
- The AMP admin console: what authority and scope a newly created agent identity gets by default, and whether it can be limited per project or space.
- Whether custom skills Rovo generates for power users need admin approval before other users can run them.
- Pricing and availability dates for Rovo Work and AMP, which the launch reporting did not include.