Skip to content
Agents and automation

One standard connection, and the same permission question.

The Model Context Protocol is an open standard for connecting assistants to tools and data. Our work is scoping what assistants can reach and governing the identity behind the connection.

The Model Context Protocol is how assistants reach systems of record. Standardizing the connection removed the integration problem and left the governance one untouched.

What it is

The Model Context Protocol is an open standard for connecting assistants to tools and data. Anthropic authored it and donated it to the Linux Foundation in December 2025, and it is now how most assistants reach a system of record, including Atlassian.

It is relevant to any organization whose teams are already connecting assistants to internal systems, which in practice means most of them, usually without a list of what is connected.

source build review deploy run scope check built inside the permission model, not beside it L1 L2 L3 L4

What it does

One protocol instead of many integrations

A single thing to govern rather than a bespoke connection per tool.

It inherits the connecting identity

Reach is decided by the account, not by the protocol, which is where the control belongs.

It is a foundation-governed standard

Vendor neutral, which is what makes it worth building a policy around rather than a workaround.

Where it fits

L4, agents and automation, entirely dependent on L1. The protocol carries no permissions of its own. It exposes exactly what the connecting identity may reach, which means the standard moved the hard part rather than solving it. The remaining question is which account an assistant connects as, and that is identity design.

Where it earns its place

An organization with assistants already connected

Teams connected things themselves. The first deliverable is an inventory, not a policy.

A regulated estate asked what assistants can see

The answer is a permission model, and it either exists or it is written during the audit.

An engineering group connecting a coding assistant

Read access to the right repositories and nothing else is a design problem, not a toggle.

Proof

97M+

Monthly SDK downloads, following the donation of the protocol to the Linux Foundation in December 2025.

Anthropic and the Linux Foundation, December 2025.

AI Innovator Finalist, 2026

AI Innovator Finalist, 2026

Atlassian Partner Awards, 2026

Questions we get

Is the protocol itself a risk?
No more than HTTP is. It carries no permissions. The risk is the identity you connect with, which is a decision you make.
How is this different from the Atlassian Remote MCP Server?
That is one implementation, exposing the Atlassian estate. This is the standard it speaks.
Where do we start?
An inventory of what teams have already connected. It is usually longer than expected and it makes the policy conversation concrete.

Find out what an agent would inherit.

Fixed scope. The assessment reads the three layers an agent lands on, identity, platform and governance, before anything is switched on. You get the findings, the ownership gaps, and the order to close them in.