Question about development method and marketplace policies

Hi,

I’m planning to build and publish apps on your marketplace, and before I invest in development I’d like to check that my working method doesn’t conflict with your policies.

I work solo. I design the app architecture, decide how it is structured, review and test the code, and I’m responsible for maintaining it long term. I use an AI coding assistant to write a significant part of the code itself, in the way many developers now use AI-assisted tooling in their editor.

My questions:

  1. Does your marketplace have a policy on AI-assisted or AI-generated code? I wasn’t able to find one in the public documentation.

  2. If there is one, where is the line drawn? I would expect a difference between an app generated end to end from a prompt and submitted as-is, and an app that I architect, review, test and maintain myself with AI assistance.

  3. Is there anything specific the review team looks at in this area - code ownership, test coverage, technical documentation, or the developer’s ability to explain and maintain the codebase?

I’d much rather find this out now than after the app is built. Thank you for your time.

Welcome to the Atlassian Developer Community @AlexK1,

I am not a lawyer and this is not legal advice. Below is simply reference to public documentation.

No policy for or against. It would be very difficult for us to implement a prevention policy for AI-assisted/generated code because many Marketplace vendors already use coding agents. And, so does Atlassian. That horse has left the barn.

No, Atlassian does not distinguish.

Yes and no. Yes, there is a review team for Marketplace. No, they don’t examine code ownership or your codebase, even for open-source apps. Most Marketplace apps are proprietary.

There are some important policies that apply, AI or not:

Above are not necessarily exhaustive of policies that apply. I’m just not aware of any that include AI coding.

Thank you, Ian - that’s a clear answer and it helps a lot. The part about the review team not looking at the codebase is exactly what I couldn’t find in the docs. And pointing me to the Shared Responsibility Model and the Partner Agreement made the picture clearer: what matters is what the app does once it’s running, not how it got written.
Two more questions, if you have time.

  1. Partner Verification. The docs mention identity and business verification, and new apps don’t get approved until it’s done. Does that need a registered company, or can an individual or sole proprietor pass it? And is there a list anywhere of which countries are supported, both for verification and for payouts?

2. Something I’d rather just ask directly. I’m a solo developer, not a company. Reading the Security Enforcement Policy - 10 days to fix a Critical finding, a P1 ticket within 24 hours of learning about an incident, a written incident response process, an update at least every 18 months - it reads like it assumes a team with someone always on call.
So can one person realistically be a Marketplace partner? Are there any doing it now and staying in good standing? If the honest answer is that this needs more than one person, I’d rather know that before I build than after I list.
Thanks again for the time on the first set.

@AlexK1,

There might be country-to-country nuances that (in my not-a-lawyer understanding) would require registration. I do know that there have been and are sole-proprietor Marketplace vendors. To the best of my understanding, the verifications are typical “know-your-partner” kinds of checks that make sure addresses, phone numbers, emails, and domains are real so that are doing due-diligence to prevent fraud. In public presentations, we have made appeals to attract the solo-developer as Marketplace partner. Again, I’m not a lawyer, so I can’t say if our policy makes that possible for all jurisdictions.

Yes, there are solo Marketplace developers here in this community even. If anything, I’d think the AI questions you ask above help mitigate the tight timelines. While I think the “survivors” prove it is possible, I’m aware from many historical posts that it isn’t easy.

To interpret some of the prior discussions, I think our Marketplace partners have struggled with keeping pace with our switch from Connect to Forge, an evolving trust posture (including but not exclusively security), and delivering new and valuable features. Starting now, you won’t face that first problem, but the pace of trust evolution is still very rapid, with new Atlassian offerings like Government & Isolated Cloud. If the LLM labs are to be trusted, AI might require a faster pace of security remediation (not that I see anything specific in our roadmap about that).

Hopefully, your questions get some answers from some of the members who have “been there done that”. Although I know many partners through my efforts here and in-real-life, I’m broad but not deep on what it’s like to be a Marketplace partner.