Dome Systems

Atlassian MCP server and Dome

Let agents file the work. Decide what they can rewrite.

Jira and Confluence sit behind one Atlassian Rovo MCP server. Connect it to Dome once and each call runs as the person the agent acts for, with rules that read its tool and its site.

EngineersAgentsDomeAtlassianCallersEngineersAgentsjira-triagerAgentsspec-checkerAgentsincident-scribeGatewayseng-gatewayJiraacme.atlassian.netConfluenceRead onlyModel poolAny providerRulesGuardsAuditsaudit-trail
jira-triager→atlassian/searchJiraIssuesUsingJql· as m.reyesAllowed

How Dome helps

Dome provides a tool gateway and authorization for Atlassian

One site, by its cloudId

Every Atlassian tool call names a site. Rules refuse any site but yours.

Their login, their permissions

Each engineer authorizes Atlassian from the first call. The agent inherits their Jira and Confluence permissions, and nothing more.

Jira writes, Confluence reads

Rules name the tool. An agent can file and edit work items while every Confluence page stays read-only.

Get started

Atlassian behind the Gateway in three steps

Add the tools=all endpoint, sync the catalog as yourself, then apply the site rules. Dome registers an OAuth client with Atlassian for you.

  1. 01

    Add the Atlassian MCP server

    The tools=all endpoint lists every tool by name, so rules can name them. Credentials are per user, through OAuth.

    $ dome tools add --name atlassian \
    --url "https://mcp.atlassian.com/v2/mcp?tools=all" \
    --auth-method oauth --credential-type per-user \
    --oauth-authorize-url https://auth.atlassian.com/authorize \
    --oauth-token-url https://auth.atlassian.com/oauth/token \
    --oauth-registration-url https://auth.atlassian.com/VCeDsk8ZHncYF1g234fKtc4lNipbBhu3/dcr/register \
    --oauth-default-scope offline_access \
    --oauth-default-scope read:jira:agent-interface \
    --oauth-default-scope write:jira:agent-interface \
    --oauth-default-scope search:jira:agent-interface \
    --oauth-default-scope read:confluence:agent-interface \
    --oauth-default-scope search:confluence:agent-interface \
    --gateway eng-gateway
  2. 02

    Sync the catalog

    The sync lists tools with your own Atlassian sign-in. Without it, agents see “tool not available in this gateway”.

    $ dome tools catalog sync atlassian
  3. 03

    Apply the rules

    Start with one agent. Simulate a call against another cloudId and check it's refused before you deploy.

    $ dome rules apply atlassian-args.cedar \
    --agent incident-scribe --name atlassian-per-site

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Atlassian itself, see Atlassian's documentation.

Rules

Your site, and Jira only for writes

The permit admits the agent. The forbids turn away any cloudId but your site's, and any Confluence create or update.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "atlassian" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "atlassian" &&
resource has arguments && resource.arguments has cloudId &&
resource.arguments.cloudId != "7f6c3e2a-1d4b-4c8e-9a0f-2b5d8e1c4a9f"
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "atlassian" &&
["createConfluenceContent", "updateConfluenceContent"].contains(resource.tool_name)
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Site

agent incident-scribe · acting as m.reyes
atlassian/createJiraIssue(cloudId: "7f6c3e2a-1d4b-4c8e-9a0f-2b5d8e1c4a9f")
  1. Agentincident-scribe is registered and active
  2. Callerm.reyes verified through Okta
  3. RuleCalls to the acme site are allowed
DecisionAllowed

Example agents

Three agents on Jira and Confluence

From our template library. Each one reads broadly and writes narrowly.

jira-triager

Triage new work items

Reads each new work item and the ones like it, then sets its labels and assignee.

  • atlassian/searchJiraIssuesUsingJql
  • atlassian/getJiraIssue
  • atlassian/editJiraIssue

spec-checker

Check tickets against specs

Reads the Confluence spec behind a work item and comments where the two disagree.

  • atlassian/getConfluenceContent
  • atlassian/getJiraIssue
  • atlassian/addOrEditJiraIssueComment

incident-scribe

File incident follow-ups

Reads the runbook and the incident's comments, and files the follow-up work in Jira. The runbook stays with an engineer.

  • atlassian/getConfluenceContent
  • atlassian/listJiraIssueComments
  • atlassian/createJiraIssue

Agent workflow

Bringing it together

Connecting Atlassian to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

MCP server

Atlassian

This page

FAQ

Common questions

Does Dome work with the Atlassian Rovo MCP server?

Yes, by URL with OAuth. Dome registers its own client with Atlassian, and each engineer consents the first time an agent calls for them.

Why use the tools=all endpoint?

Atlassian's default endpoint shows a few tools and routes the rest through discover and execute. The flat list gives every tool its own name for rules to read.

Can an agent write to Jira but not Confluence?

Yes. Rules read the tool name, so Jira writes can be allowed while Confluence creates and updates are refused.

Whose Atlassian permissions does an agent use?

Those of the person it acts for. Dome keeps each person's Atlassian token and uses the one that matches their verified identity.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.