Skip to content
Security & Trust

Atlassian says AMP tags AI code; IDC analyst says proof of review matters more

Atlassian says AMP shows what an agent wrote. An IDC analyst says buyers also need to know who checked it.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Atlassian says AMP tags AI code; IDC analyst says proof of review matters more
In brief
  • Atlassian says its new AMP can show which code a human wrote and which an agent wrote. Its agent identity controls are promised 'soon'.
  • An IDC analyst says origin alone is a weak signal. Evidence that a person genuinely reviewed consequential changes is more useful than a record of who typed.
  • Leaders should ask where attribution is stored today, whether agents have revocable identities, and what proof of review they keep.

A customer, an auditor or your own board can fairly ask a plain question about your software. Who wrote this part, a person or an agent? Atlassian says lack of that answer holds many enterprises back from using AI more widely. It says it now has a tool that helps.

What Atlassian announced

On October 7, at its Team '26 Europe conference, Atlassian introduced the Agentic Multiplayer Protocol, or AMP. The company calls it the foundation for how people and agents work together on its platform. Under AMP, an agent has an assigned identity and scoped authority. It shares context with the team, and its results can be reviewed by people.

Atlassian says AMP is live now. Its Teamwork Graph, which links work, people and code, can now index source files at the level of single functions and classes. Engineers can search that code across Bitbucket and GitHub without copying a repository to their machine.

InfoWorld reports a further claim. Atlassian says the graph keeps a version history that marks each change as human or agent. It lists Claude, Codex, Figma and Rovo as covered. Jamil Valliani, Atlassian's head of AI products, told InfoWorld that missing visibility into code origin is what holds many enterprises back.

10 million+
Human-agent collaborations a month on Atlassian's platform
Source: Atlassian, Team '26 Europe announcement (October 7, 2026)

Why the record is hard to keep

The difficulty sits in tools developers already use. Adam Resnick, a research manager at IDC, told InfoWorld how Git works. It records an author and a committer. If a developer runs an agent on a laptop, the record names the developer.

Any note about the agent usually sits in the commit message. Resnick said developers can switch that off, edit it, or lose it when history is rewritten. Vendors follow different conventions. People also rework what agents produce, so one file can hold both kinds of work. Many organisations run several agents at once.

Resnick called the separation of AI and human work "one of the hardest problems in AI software engineering intelligence." Git was built to track changes, and the tools that wrap it were not built to certify authorship.

A receipt is not an audit

Here the story turns. Knowing who typed a line is like holding a receipt. It shows a purchase happened. It does not show anyone inspected the goods.

Resnick makes a similar point. He said the useful record shows whether a person really reviewed the work, not just that someone pressed approve. Think of a signed contract. The signature names the signer. It says nothing about whether the page was read.

He argues this lets organisations match review effort to risk, instead of one blanket rule for AI code. A narrow, well-scoped agent fix may need less scrutiny than a person's edit to payment code. In his words, origin is one input. Others are how autonomous the agent was, how consequential the change is, and evidence of human oversight.

What is still unproven

Some of Atlassian's features address review. Agent sessions in Jira link local and cloud agent runs back to work items. Rovo Work asks a person to review and approve multi-step tasks. Those tasks can run for hours in a sandbox that admins govern.

The sources do not say whether those records capture the quality of a review or only the fact that one happened. InfoWorld reports that analysts and consultants welcomed more visibility. They also said it is unclear whether Atlassian's offering will give enough useful context. That remains the open question.

Agent identity is also unfinished. Atlassian says controls over what AI can see, an inventory of non-human identities and one-switch access revocation will arrive "soon."

Atlassian also says it rebuilt its MCP, the connector that lets outside agents work inside its tools. Atlassian describes its Rovo MCP as giving coding agents scoped access. The tool count grew from dozens to 200+. That count is growing while some identity controls are still promised for later. The sources do not say the two are linked, but buyers should weigh them together.

200+
Tools in Atlassian's rebuilt MCP, up from dozens
Source: Atlassian, Team '26 Europe announcement (October 7, 2026)

Questions to put to your team

First, where does AI attribution live in your repositories today? If it sits in commit messages, assume it can be edited or lost.

Second, does each agent have its own identity that you can list and revoke? Or does it borrow a developer's credentials?

Third, what proof of human review do you keep for changes to authentication, payments and data storage? An approve click is thin evidence.

Fourth, how many agents run in your teams, and does your tooling cover all of them? Atlassian names four in its attribution claim.

Origin tells you who held the pen. Risk depends on who read the page.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Atlassian.

Share this insight