Atlassian Adds AI Code Attribution With AMP, but Deeper Identity Controls Must Wait
The platform release connects code history, shared context and longer-running agent tasks. Analysts say identifying the author is not the same as proving meaningful human oversight.
Atlassian’s October 7, 2026, AMP launch combines code search and human-versus-agent version history with workflows that let agents work across its products. The records may help companies measure AI-assisted work, but they cannot by themselves establish who made key decisions or whether review was meaningful. Controls to inspect agents’ access and restrict their permissions are still planned, with no rollout date; for now, teams should treat attribution as one input to oversight, not proof of accountability.
01
Rovo Work can run cross-tool tasks for hours in a secure sandbox, with users reviewing plans and approving work.
02
Atlassian’s expanded Model Context Protocol server exposes 200 tools and handles about 15 million tool calls daily, according to the company.
03
Wilkes argues provenance could support comparisons of review effort, defects and rework, with cost per accepted change as a useful measure.
Atlassian is bringing AI agents into the same work records teams use to coordinate people. On October 7, 2026, it launched Agentic Multiplayer Protocol, or AMP, at Team ’26 Europe. The update ties shared tasks and context to contribution tracking, but analysts question whether code-origin labels can capture who made decisions and meaningfully reviewed the result.
An author label versus a decision record
Atlassian describes AMP as the foundation for collaboration between humans and agents across its platform. Its Teamwork Graph, a context layer connecting people, code and documents, now incorporates source code through Rovo Code Search. The company says it indexes individual functions, symbols and classes, allowing searches across Bitbucket and GitHub without downloading a repository.
The company also promises version history that distinguishes what people wrote from what agents did across Claude, Codex, Figma and Rovo. That addresses a problem Mike Wilkes, enterprise CISO at Aikido Security, described to InfoWorld: a repository can identify the person who committed a change while obscuring the tools that actually produced it.
IDC research manager Adam Resnick explained why the distinction is difficult. Git records an author and a committer; a locally run agent can leave the developer’s name on the record. Attribution in commit messages can be edited or lost, and developers routinely rewrite agent output. The resulting code is often a mixture, not cleanly human or AI.
The most useful provenance shows whether meaningful human review took place, rather than simply recording that someone clicked approve.
Adam Resnick, IDC research manager, speaking to InfoWorld
Wilkes also sees attribution as a way to judge AI spending, rather than merely count licenses and token consumption. Reliable records could let companies compare human and agent-assisted changes on completion time, review effort, rework, defects and rollbacks. His proposed bottom line is cost per accepted change—not simply how much code an agent produces.
Justin Greis, CEO of consulting firm Acceligence, questions whether that requires inspecting every line’s origin. He argues that companies can assess a developer’s effectiveness before and after AI adoption using delivery time, defects, rework, output, security findings and economics. That tests results without requiring a complete account of authorship.
Shared context, longer-running work
AMP’s coordinated release goes beyond tracking code. Rovo Work, a new mode in Rovo Chat, handles complex tasks across Jira, Confluence and connected tools. Atlassian says it can run for hours in a secure sandbox, an isolated execution environment, with people reviewing and approving the work. Users guide the objective, review the proposed plan and can correct its course.
Other parts of the announcement supply agents with instructions, business data and access to the shared workspace:
Loom captures spoken instructions and the on-screen objects a user points to, then formats those references into an agent prompt, according to Atlassian.
Data Context extends the company’s context layer to structured information in Databricks, Snowflake and Google BigQuery.
The expanded Model Context Protocol server gives external agents an interface to Atlassian’s platform. Atlassian says it exposes 200 tools and handles roughly 15 million tool calls daily.
The controls still to come
Atlassian says the announced capabilities are available immediately, but additional controls for non-human identities will arrive “soon.” Those planned controls examine what AI can see and restrict access granted to agent accounts. The company has not supplied a specific rollout date.
Frank Dickson, principal analyst at Dickson Research, sees greater potential in that identity-management layer than in labeling alone. He also challenges attribution to the person who set up an agent: that person may not be the person who approved its work. In his view, version history should make the approver’s ownership visible.
Resnick argues for review based on risk rather than a blanket rule for AI-generated code. A small agent change may need less scrutiny than a human-written change to a payments system. Origin is one factor; the consequences, degree of autonomy and evidence of human oversight also belong in the decision.
Editorial illustration for Atlassian Adds AI Code Attribution With AMP, but Deeper Identity Controls Must Wait.
Sources
siliconangle.comAtlassian lays groundwork for humans and AI agents to work side by side - SiliconANGLE
infoworld.comAtlassian launches AMP to tackle AI code visibility, attribution
Reader comments
Newest comments first. Replies stay oldest first.