Coverage of Team ’26 Europe in Amsterdam, October 6–8, 2026. Not to be confused with Team ’26 in Anaheim this May, which comes up later.
I got up stupidly early this morning. It was still pitch black, my wife was snoring, and even the cats were complaining about the hour. I got dressed anyway, went to my office, grabbed a glass of water (too early for coffee, breakfast, or meds), and started getting set up. I’d spent the past week planning for this morning so I wouldn’t miss any of it.
So what justifies all that? Team ’26 Europe is this week in Amsterdam, and the Founder Keynote started at 9:00 AM there, which is 3:00 AM Eastern. I’d have preferred to be in the room, obviously. That wasn’t in the cards this time, but it wasn’t going to stop me from being one of the first voices to weigh in.
It was worth the alarm, and not only for the announcements. Mike Cannon-Brookes (MCB) and his team got through all three sections of the keynote, with live demos that mostly behaved. Then, as Mike was wrapping up, the venue lost power. The feed cut out mid-sentence, on “a living nervous system that connects your a-“, and the last I heard, they were still working to get it back. Atlassian spent the morning promising calm and confidence as AI speeds everything up, and the building got the last word.
The thing I was listening for most was identity: who, or what, is doing the work in your Jira site. That question matters more than it sounds, because somewhere in almost every Jira site is a user nobody hired. It has no manager, no start date, and no exit interview on the calendar. It has the potential to touch more work items than most of your people, and if you filter a busy space’s history by its name you will likely find it in places you did not expect. Its name is Automation for Jira.
And let’s be clear here, Jira has had “non-human teammates” for as long as the concept of automation has been in the product. You can go back to API wrappers tied to an admin who left long ago and does who knows what, but everyone “in the know” swears it’s important and can’t be decommissioned. Or the integration based off a shared mailbox that is still the main way some departments interact with Jira. Or Marketplace apps that are as critical as Jira itself doing their own thing. Or Rovo agents, the newest additions. Anyone in your org can build these in Studio, and most sites likely already have a hoard of non-human actors that nobody has ever done a census on. Anyone who has administered Active Directory knows how that usually ends: a service account with far more rights than it needs, that nobody can explain and nobody will disable.
That’s the problem Atlassian brought on stage this morning, and they were blunt about where it’s heading. Taroon Mandhana put it plainly: “Too much of that agent work is getting buried inside people’s individual developer environments.” The headline answer was AMP, the Agentic Multiplayer Protocol: Atlassian’s name for how people and agents work together, on its platform and off it. Two of AMP’s three layers go straight at the service-account problem: knowing who is who, and keeping agents under control. Agents get their own dedicated accounts, version history separates what a person did from what an agent did, and Atlassian says its agent governance now reaches past its own walls. On paper, all of that sounds like something every admin can champion. It also isn’t a one-off. Read alongside what Atlassian said in May and shipped in July, this morning shows where the company is taking the platform: the governed place where everyone’s agents do their work, whoever built them, and where every one of them answers to someone.
What Atlassian Announced at Team ’26 Europe
MCB opened today by saying the questions he hears most from customers fall into three groups: which model to use, whether agents will replace people, and how to know what is going on when everything speeds up. Atlassian’s answers became the three words the keynote was built around: Context, Collaboration, and Confidence. AMP sits across all three, so it comes first.
The Headliner: AMP, the Agentic Multiplayer Protocol
MCB described AMP as “a collection of human-centric experiences, technologies, and patents that positively shape how people and agents can collaborate on and off the Atlassian platform.” It has three layers:
- Real-time and asynchronous collaboration. New UI patterns that show agents working live, what they have done, and when they need a human’s input.
- Identity and shared presence. In his words, “no matter what combination of agents and people are in a team, we make sure that you know who is who.” Agents get visible identity, attribution, and presence indicators across the products.
- Context and governance. “Our agent governance extends on and off the Atlassian platform with the right controls and scoped permissions,” so that people “are always able to initiate work, deal with exceptions and exercise their judgment.”
The demos made it concrete. Sherif Mansour, Atlassian’s Head of AI, recorded a Loom “for an agent,” pointing at parts of a web page and talking through changes. Loom turned the recording into a structured prompt with screenshots and acceptance criteria, and a Figma Make agent made the changes, including pulling icons from a Confluence page he had pointed at. In a second demo, a new Planner experience in the Teamwork Collection had a person, a teammate backstage, a Figma agent, and ChatGPT editing the same spec in real time, each with a presence indicator at the top of the page. Afterward the page showed which sections each person and agent had edited, and which agents had read the page as context and who had called them.

Atlassian put numbers on it: more than 11 million AMP interactions between teams and agents a month, and more than 15 million MCP tool calls a day.
One thing to be clear about. Despite the name, nothing on stage described AMP as a protocol in the sense MCP is, with a published spec other vendors implement. Atlassian presented it as a set of product experiences, the technology underneath them, and patents. I’d want to see what “protocol” means in practice before treating it as a standard.
Context: More of Your Business in the Teamwork Graph
The thesis underneath the Context announcements is the same one MCB laid out in Anaheim, when he called raw intelligence “a commodity.” In Amsterdam he put it as “models are the engine, but context is the fuel,” and added that a model that doesn’t know “why you made a decision back in 2022” can’t help you win in 2026. Tamar Yehoshua, Chief Product and AI Officer, said the Teamwork Graph has grown from 150 billion objects and relationships six months ago to more than 250 billion.
There were, of course, a few other details to share:
- Code context, now generally available. The Teamwork Graph indexes source code down to functions, symbols, and classes across Bitbucket and GitHub, both cloud and Data Center, with GitLab promised for next month. Code results show up in search across Jira and Confluence, through MCP and the CLI, and in a new dedicated Code Search app. If your repositories are already connected to Jira, turning it on is “a single click in the Admin Hub.” The promise of this one is exciting, so much so that since Team ’26 Anaheim, I’ve migrated my personal on-prem GitLab to GitHub to be able to take advantage of it. (Naturally, GitLab support is coming next month.)
- Data context. Live metadata from 20+ structured sources, including Databricks, Snowflake, Tableau, and BigQuery, becomes a Teamwork Graph context type. In the demo, someone @-mentioned Rovo in a Confluence page and got a live chart built from warehouse data embedded in the page.
- Connectors. More than 20 new connectors in six months, including Zoom and Gong, and 65+ improvements to existing ones. Employees can now add a connector themselves from Rovo Chat or the CLI, and admins get controls for connectors in the admin app.
- Agents and agent sessions in the graph. Agents are now represented in the Teamwork Graph alongside people. Agent sessions are indexed as part of the communications context, and Atlassian distills each one into “a reusable session memory” so the next person or agent working in that area starts from what was learned.

Collaboration: Agents Inside the Loop
- Rovo Work. A new mode in Rovo for long, multi-step tasks. Each session gets its own computer in a secure cloud sandbox, so it keeps running after you close your laptop, and Atlassian said tasks can take “tens of minutes to tens of hours.” It proposes a plan, asks for input when it needs it, and inherits the permissions of the person who started it. My favorite comment from the livestream chat at this point was “Well, now we understand why they did the limits.”
- Artifacts. A new object type in the Teamwork Graph and a new Artifacts app. AI-generated pages, prototypes, calculators, and even Markdown files from any tool (Rovo, ChatGPT, a file dragged from your desktop) get a permissioned home, and they embed live in Confluence pages, whiteboards, and Jira work items. This definitely feels like a “What took you so long,” but I’m glad to see it.
- Record for Agent and the new Loom desktop app. Narrate and point at your screen, and Loom writes the prompt for an agent. Loom also gets AI Overlays, motion graphics generated from your recording. Sherif showed a live demo, including waving his hand to prove it wasn’t pre-recorded.
- Agent sessions in Jira. A coding agent session running in a developer’s terminal appears on its work item in real time. The board shows every agent running for the team, local or cloud, Rovo, Claude, Cursor, or Codex, with a filter for the ones waiting on a human. You can answer a cloud agent’s question from inside Jira, and drag an untracked session onto the board to create a filled-in work item with the session attached.
- Interactive PR reviews. Loom, Rovo, and the Teamwork Graph turn a pull request into a short video showing what changed, why (with a link to the design doc where the decision lives), and how it was tested. It works across source control systems and coding agents and is “coming very soon” to the Teamwork Collection. The promise of this is amazing, but the uncanny valley voice they used for the demo was a hard stop for me.
- Atlassian MCP, rebuilt. A ground-up rebuild with many more tools, reach into almost every Atlassian app, support for custom Forge apps and Marketplace apps, and custom Rovo agents “soon.” Access is governed through Atlassian Guard, and Atlassian claims up to 25% fewer tokens. Token use was a massive complaint about the Atlassian MCP, so I’m happy to see it addressed.
- OpenAI partnership. You’ll soon be able to assign Jira work items directly to OpenAI’s Codex cloud agents.
- Rovo everywhere. A rebuilt native Rovo desktop app, a new Rovo mobile app, and Rovo chats you can schedule, pin, and share with permissions. I literally downloaded the Rovo mobile app right before the show today (I am not making this up). Guess I had a feeling it would show up.
Confidence: Governance, Visibility, and Cost
Taroon Mandhana, Head of Product Engineering, took this section, and said Atlassian has shipped more than 50 enterprise security features in the last few months.
- Non-human identities for agents. “Rovo or any other third-party agent on our platform, they get their own dedicated account. Now you can fully control what these agents can see and do.” This has been a massive complaint of mine: an agent scoped to your permissions also inherited any weaknesses in your permissions. The approach was defensible, but it left you exposed. Defining who can access agents, and where, is a win, though it also means a lot of new overhead for admins.
- Atlassian Guard. Real-time policies against data leaks, and automatic redaction of sensitive information across AI chats and connected tools.
- DX Agent Effectiveness. Scores agent sessions across the company on requirements, steering, and scope, plus a “model fit score” that flags work that could have run on a cheaper model. Personally, I find it fascinating, but telling you that you could have saved money in the past only helps you in the future.
- AI Capital Management. AI spend against budget and priorities, broken down by model provider, department, team, and Focus area, with human and token capital side by side. It is in open beta for all Strategy Collection customers.
- Service Collection. Rovo-assisted root cause analysis in the incident command center, cross-referenced to code; change risk assessment before releases; and onboarding that tracks tasks assigned to people and agents.
- EU AI inference. Atlassian is “officially starting to roll out” inference inside the EU, so “your prompts, your model inference, and the results, they all remain 100% within European borders,” on frontier models from OpenAI, Anthropic, and Google.
Atlassian’s own Team ’26 Europe write-up is on the Atlassian blog.
One timing note before going further. Dedicated agent accounts were announced from the stage in the present tense, but nobody gave a date, a plan tier, or a word about licensing, and the live inventory and org-wide suspend switch in Atlassian’s materials didn’t come up on stage at all. Atlassian’s platform post describes agent accounts as coming “soon.” Treat the identity piece as announced, not available.
What Your Users Will Notice First
Most of your users will never see an agent account. What they will see is agents showing up in the places they already work, which is AMP’s whole pitch.
The biggest visible change is attribution and presence. In the Planner demo, an agent’s cursor appeared on the page next to the humans’, and afterward the page could say which section ChatGPT wrote and which one Dave wrote. That answers the first question every team asks after an agent touches their work, which is “who did this?” It is also the feature your auditors will like most, because “a person approved what an agent produced” is a provable statement once the history separates the two.

Rovo Work changes how people delegate. Tamar Yehoshua’s demo turned a long expense policy into an interactive quiz: one spoken request, a plan to approve, a question answered from her phone, and a finished artifact. Today a Rovo Chat answer is one exchange. Work mode is a plan the user approves and then a job that may run for hours. The approval step is where the human earns their keep. Users who approve plans without reading them will produce work items, pages, and changes faster than anyone downstream can check, so the training conversation is about reading the plan, not writing the prompt.
And something to keep an eye on: Rovo Work still “inherits all of your permissions,” and in the demo the task ran as Tamar, the person who started it. The flagship long-running agent acts as a human, under that human’s name, so a page edited by a Work task may look like a page edited by its owner. Until I see otherwise, I’d treat every Work task as something the person who launched it answers for.
Artifacts fix a small, constant annoyance. Every AI tool produces something (a plan, a mock-up, an HTML report) that ends up in a downloads folder or a chat window nobody can find again. A permissioned home that embeds live in Confluence is a real improvement. It is also a new content type your users will create in volume, and one with an “open” setting that makes an artifact searchable by everyone in the organization.
Engineers get the most immediately: Code Search, agent sessions on the board, and PR reviews that come with a recorded walkthrough. Atlassian said 77% of its own pull requests last month were entirely agent-generated, which is the problem the PR videos are aimed at. Loom users get Record for Agent, which may be the easiest of all of these to adopt, because “show it once and let the agent do it” matches how people already explain things.
The grounding point for users is the same one I made in July: nearly all of this depends on Rovo being enabled, and availability will roll out by plan and region rather than all at once. Check what your site has before you promise a team anything.
Context Is Now an Admin Deliverable
Atlassian’s whole pitch today rests on context. In AI, that word has a specific meaning: Anthropic defines it as “the set of tokens included when sampling from a large-language model.” In plain terms, it’s everything the model gets to see before it answers, and Atlassian’s bet is that the Teamwork Graph decides what goes in. We’ve been managing that material for years, even if we never called it context. Every page, issue work item, commit, PR, and ticket is a record of how work got done at a point in time. Every agent in this week’s announcements is only as good as the graph it reads, and the graph is only as good as the spaces, permissions, and content we govern. Now think about how most of your spaces are set up.
I said in May, after Team ’26 in Anaheim, that the Teamwork Graph is a context claim, and “whatever AI inherits from you, it inherits it as a whole.” Team ’26 Europe makes that inheritance bigger in two ways.
The first is reach. Code and structured data are now in the graph, and turning code context on is a single click in the Admin Hub. Rovo has always followed a simple rule: it can only show a user what that user is already allowed to see. That rule is reassuring until you remember what it implies. Rovo’s reach is identical to your permission sprawl, and every over-broad grant you never cleaned up is a retrieval path. Repositories down to the symbol and warehouse metadata add two more permission models to that sprawl, each from a system your Atlassian admins may not own. Nobody on stage explained how code results map to repository permissions, so ask before you click. Users can now add connectors themselves, too, from chat or the CLI, so check the new admin controls before someone connects a source you’d rather keep out of the graph.
The second is volume. Artifacts live in the graph. Agent sessions are now indexed and distilled into session memory that the next person or agent builds on, which MCB called “the definition of compounding context.” The graph is designed to compound, which is the point, and stale or wrong content compounds along with the good. An abandoned Confluence space with three conflicting runbooks was an annoyance when humans had to find it. When an agent finds it, it will cite the wrong one with complete confidence, and now its session memory may carry that mistake into the next run.
Put reach and volume together and the heading on this section stops being a figure of speech. Atlassian brings the models and the graph. What goes into the graph, who can pull it back out, and whether any of it is still true are decisions admins already make every week, usually without anyone calling it AI work. Anthropic has a name for that job too: context engineering. Every permission review, every archived space, and every outdated runbook you finally delete is now context engineering for every agent in your company. That’s the deliverable.
Somebody Has to Budget for the Hours-Long Task
It should come as no surprise that the thing the keynote said least about is the thing everyone has had the most questions about for the past month: cost. So let’s talk through those questions now, before they show up as line items in January.
Rovo credits begin billing on December 3, as I covered in the usage-based pricing post. Atlassian says a Rovo Work task can run for “tens of hours” in its own cloud sandbox. Nothing on stage explained how a long-running Work task draws credits, whether per task, per step, or by time, or whether admins can cap a single task. If you are an admin, that is the first question to put to your Atlassian account team.
To Atlassian’s credit, they are also shipping the measurement side, and they showed it on themselves. Taroon Mandhana said Atlassian ran 3,200 agent runs producing documentation last month, and for 59% of them a much cheaper model would have done. That is the kind of finding DX’s model fit score is built to surface. AI Capital Management adds the finance view: AI spend by provider, model, department, and initiative, next to the cost of the people. That pairing is what finance will ask platform teams for: what are we spending on AI, on what, and is it working? The catch is that AI Capital Management is an open beta inside the Strategy Collection, so check whether your organization owns it before you plan around it.
Residency Is Progress. Sovereignty Is a Different Question.
I’ve been vocal for years about what Atlassian’s cloud direction means for regulated customers. Until now, European customers could keep their data in the EU, but the LLM processing crossed the Atlantic because the frontier models were hosted in the US. EU AI inference, which Atlassian started rolling out this week, keeps prompts, inference, and results inside Europe on the same frontier models. That removes one of the hardest objections European compliance teams have raised about Rovo. Atlassian’s materials also list Isolated Cloud across 11 regions, Customer-Managed Keys, and alignment with the EU AI Act and ISO 42001 for Rovo, which give compliance teams something to evaluate instead of a promise.
It also lands in the middle of a much bigger argument in Europe. A growing list of European governments are moving off US software altogether, and Microsoft is usually the first target. The German state of Schleswig-Holstein has moved its email off Microsoft and replaced SharePoint with Nextcloud. Denmark’s Agency for Digital Government and the International Criminal Court are moving to open-source suites. France plans to move 2.5 million civil servants off Teams and Zoom and onto its own video platform by 2027, with the minister behind it saying the government can’t risk sensitive data being “exposed to non-European actors.”
That’s a different question from the one EU inference answers. Residency is about where the data sits. Sovereignty is about whose laws can reach it. Last year, Microsoft France’s director of public and legal affairs told a French Senate inquiry, under oath, that he could not guarantee French data would never be handed to the US government under the CLOUD Act. Atlassian has been a US-domiciled company since 2022, and the three model providers behind EU inference (OpenAI, Anthropic, and Google) are American as well. Keeping the processing inside Europe is real progress for compliance teams, but it doesn’t change who the vendors answer to, and buyers asking the sovereignty question will notice. Those buyers also have one fewer exit than they used to: as I wrote when Atlassian announced the end of Data Center, the self-hosted option goes away in March 2029.
Most of my readers are in the US, so the follow-up is about American regulated industries. In July, agent features were not supported in HIPAA or FedRAMP environments. Nothing in the keynote changed that.
The Strategy Behind the Announcements
Step back from Team ’26 Europe and the individual features matter less than the direction they point. Atlassian has now told the same story at both of this year’s Team conferences and in a major launch between them, and the things I’ve written about along the way point the same way.
In May, at Team ’26 in Anaheim, the thesis went on stage. MCB called intelligence a commodity and context the differentiator, Atlassian described Jira as “your AI control plane across both agents and human workflows,” and the Atlassian MCP server was pitched as the way any AI tool could reach the Teamwork Graph. The same keynote talked about agent accounts with their own identity and scoped permissions, and about Guard blocking sensitive content before it reaches a model.
In July, the AI-native SDLC launch put that into Jira. You could assign work to Claude, Cursor, or GitHub Copilot directly, not only to Atlassian’s own coding agent, and DX started tracking AI spend across tools. I wrote then that Jira was turning from a work tracker into a platform for orchestrating and overseeing agents.
This week, Atlassian gave that direction a name. AMP is how the company now describes people and agents working together “on and off the Atlassian platform,” and MCB said the quiet part plainly: “bring your Cursor, your ChatGPT, your Claude, or any other agent harness. We love and use them all.” The platform got more open: a rebuilt MCP server, Artifacts accepting output from any AI tool, a Jira board that shows Claude, Cursor, and Codex sessions next to Rovo’s, and a partnership that lets you assign work items to OpenAI’s agents. It also got more controlled: dedicated accounts for “Rovo or any other third-party agent,” attribution that separates people from agents, Guard redaction across connected tools, and spend reporting broken out by model provider.
The line I keep coming back to came after the agent-sessions demo: “For 20 years, Jira’s been a picture of the work that the team had planned. Now, it becomes a system of record for all the work that’s actually happening in real time.” A system of record for work done by agents from several vendors is not something you build if you plan to win on your own agent.

Atlassian Has Run This Play Before
The clearest precedent is the Marketplace. In June I wrote about Connect’s end of support and what moving to Forge means: apps run inside Atlassian’s infrastructure, under Atlassian’s security model, and the ones that stay on Connect slowly fall behind the platform. Most Marketplace apps run on Forge now. That migration is why MCP support for Forge and Marketplace apps matters. An agent reaching your apps through the Atlassian MCP server is reaching code that already lives inside the governed platform. Atlassian made the point itself in Amsterdam: the new Artifacts app, with its UI, Teamwork Graph access, search, Smart Links, and MCP tools, was built as a single native Forge app. Atlassian brought the app ecosystem inside its walls first, and it is now doing the same for agents.
The money points the same way. In September, Atlassian put usage meters on Rovo credits, automation steps, and AI agent resolutions, all billing from December 3. Pricing by usage instead of by seat is how you charge for work that isn’t done by a person holding a license. Add AI Capital Management reporting spend by model provider, and you have a platform that expects to meter work from agents it didn’t build.
And two weeks ago, writing about what it would take to leave Atlassian, I landed on the platform as the thing you can’t replace: “one user directory, one permission model, and one admin console govern all of it.” AMP extends that sentence to agents.
What Atlassian Is Betting On
Put those together and the pattern is hard to read as a feature list. A company trying to win on its own agent would not give its competitors’ agents accounts on its platform, or build a cost report that assumes you’re paying several model providers at once. Atlassian is betting that most organizations will run many agents from many vendors, and that the scarce thing will be a single place where all of that work is recorded, attributed, governed, and paid for. Atlassian wants to be that place, and AMP is the name it chose for the attempt.

For admins, that moves our work toward the center of Atlassian’s pitch. If the product is the governed place where agents work, then the governance is part of the product, and the people who configure permissions, maintain the content, and decide who can build what are the ones delivering it. It fits what I wrote in July about the admin job market: cloud needs fewer people to keep it running. If that’s right, governing is a growing share of the admin work that’s left. Usage pricing rewards governance maturity, and orgs on either side of that gap will have very different experiences. That’s the argument I’m making on the main stage at Build IT Together in Dallas on October 28, in a talk called Governing AI in Atlassian: Is Your Environment Rovo-Ready? The short version: bad governance plus AI gives you fast, confident, well-formatted bad governance.
A strategy read is an inference, and I’ll hold this one loosely for two reasons. The dates have lagged: agent identity was on stage in May and is still “soon” in October. And the whole bet depends on customers running agents at scale. In June I wrote that Atlassian’s product strategy is built on AI adoption going well, while its own research showed that the people asked to adopt AI often get penalized for it. That tension hasn’t gone away. Watch the dates, and watch your own users, as closely as the direction.
Wrapping Up
Back to how this morning ended. MCB was cut off mid-sentence describing the Atlassian platform as “a living nervous system that connects your a-“, and the people in the room finished the thought without him. Atlassian Community Champion Susanna Babayan posted from the venue: “The electricity is out at Atlassian Team ’26 ⚡️❌ So obviously, this is the perfect opportunity to talk to more people 😂” She spent the outage meeting Marketplace teams and fellow Champions, and summed it up as “no electricity, more conversations, new people, cool apps, and free pins.”
MCB opened the keynote by saying the world runs on teams. Nobody planned the closing demo, but it made his point better than any of the others.
Team ’26 Europe gave the agent strategy a name. AMP promises agents an identity, a presence on the page, an attribution trail, and governance that reaches past Atlassian’s own products, and the graph underneath it now takes in code, data, and agent sessions. That’s worth celebrating. Put it next to Anaheim in May, the July launch, the Forge migration, and the new meters, and it reads as one strategy: Atlassian wants to be the platform where everyone’s agents work under one set of rules and one bill, which puts admin governance work at the center of what Atlassian is selling.
Here’s a twenty-minute way to get ahead of it. Open a spreadsheet with five columns: actor, what it can reach, who owns it, why it exists, and when someone last reviewed it. Start with your automation rules that run as Automation for Jira across multiple spaces, then the API tokens your org can see, then connected apps, then the Rovo agents built in Studio, which anyone in your org can create unless you’ve restricted it. The “why” column will be the hardest one to fill in. That’s the point I made in August about documentation answering the wrong question: the config tells you what exists, and only you can say why it’s there. You won’t finish in twenty minutes. You will have a first count, and when Atlassian’s agent accounts arrive, you’ll have something to check them against.
I’m curious how many non-human actors you find, and how many of them have an owner.
Until then, this is Rodney, asking: have you updated your Jira issues work items today?
Enjoyed this one? These posts are free and always will be — but if this saved you a headache or taught you something worth keeping, you can drop a tip in the Ko-fi jar. No paywall, no subscription, no catch. Just a thanks if the writing earned it.
→ Support The Jira Guy on Ko-fi
Discover more from The Jira Guy
Subscribe to get the latest posts sent to your email.