Please help us shape the "Runs on Atlassian" roadmap for 2026 and beyond

Hey @Nar_ChtN,

Wanted to jump into this with the perspectives of Customer Managed Egress and why we are not permitting Runs on Atlassian at this stage.

Customer Expectations - When we explored the customer desire to have increased control over how and where apps can egress data, we learnt two things:

  1. Larger enterprise or security-conscious customers want to increasingly be aware or have a say in how and where their data it utilised and CME provides an avenue to apply a principle of least privilege (i.e. where apps declare * today), or to better limit app access in ways which are still required for them to function.
  2. The perception of Runs on Atlassian was that the app does not egress any data at all. In fact, they preferred that we either had a different badge or no badge at all, rather than mixing these in with RoA.
  3. We are seeing CME being accepted as an acceptable pathway by some of our largest customers who previously preferred apps to be RoA. Even without the badge, this is supporting some partners in their sales and security conversations.

Flexible Implementation vs Abuse - CME has been developed in a way which enables apps to control egress is exposed and managed within their app. This was a conscious decision, as we understood that the use cases were diverse and having to defer to Connected Apps to manage egress would be a disruptive and sub-optimal customer experience. This came with a trade-off, which is that any incentive to adopt CME to attain a badge could be abused - an app could immediately ask for egress and not function without it.

While we understand that the overwhelming majority of partners want to and will do the right thing, the challenge emerges when one doesn’t. The customer perception of the badge and CME would be impacted and unfortunately, that impact flows on to every app which has implemented it with the correct intentions.

Diversity of badges - Atlassian is working on additional trust signals in the marketplace (such as A4A) which help level the perception playing field. Being able to present to customers that your app has a strong trust and security posture helps counter-set a reliance on RoA being the primary trust signal.