The connection between tools becomes a policy decision.
Cross App Access is an OAuth extension that lets an application request access to another on a user's behalf, with the identity provider evaluating the request against enterprise policy and issuing a token if it passes. Our work is replacing ad-hoc integration consent with policy the identity provider enforces.
Cross App Access replaces per-user consent prompts with a policy the identity provider evaluates. It is how an assistant reaching another application becomes something an administrator can see and control.
What it is
Cross App Access is an OAuth extension that lets an application request access to another on a user's behalf, with the identity provider evaluating the request against enterprise policy and issuing a token if it passes.
It is for organizations where assistants and tools are already connecting to each other through consent prompts that individual users clicked, and where nobody can produce a list of what is connected.
What it does
Policy instead of consent prompts
Access between applications is evaluated centrally rather than approved by whoever saw the dialog.
Administrators can see what connects
A list exists, which is the prerequisite for governing anything.
It is an open protocol
Adoption across vendors is what decides whether this becomes the norm or a single vendor's feature.
Where it fits
L1, identity and access, controlling behavior that shows up at L4. Tool-to-tool connections are the fastest growing category of unmanaged access. Moving them from user consent to enforced policy is what makes them reviewable at all.
What we do with it
Inventory what is already connected
Consent-based integrations accumulated over years are the first finding, and usually a surprising one.
Connection policy
What may connect to what, under whose authority, and what evidence is kept.
Wiring it to the estate
Connections into Atlassian resolved through the same policy as everything else.
Where it earns its place
An organization with assistants already in use
Teams connected tools themselves. The question is what those connections can reach, and it has no answer today.
A regulated estate facing a vendor review
An integration approved by a user in a dialog is difficult to defend as a control.
An estate consolidating shadow integrations
Replacing bespoke tokens with a policy-evaluated path removes credentials nobody owns.
Proof
Early adopters of the protocol at announcement, including Anthropic, Zoom, and Slack.
Okta newsroom, Cross App Access partner announcement, 2026.
AI Innovator Finalist, 2026
Atlassian Partner Awards, 2026