Skip to main content

What it’s for

Tracking findings as Jira issues and writing them up in Confluence. A workflow step files one issue per confirmed finding and skips duplicates; a chat agent checks whether a finding is already tracked, comments on the issue with what it learned, or drafts a review page in the space your team reads. One Atlassian connection covers both products. The bot account’s product access decides which of the two agents can actually reach.

Before you connect

  1. Create the bot Atlassian account. See the bot account.
  2. Give it product access to both Jira and Confluence on the site agents should use, and add it to the projects and spaces they should work in.
  3. Sign your browser into the bot account, then follow the connect flow. During authorization, Atlassian asks you to choose a site — pick the one from step 2.
Atlassian fixes what the connection can reach at the moment you approve it. The bot account must already have Confluence access on the site before you authorize — if you grant Confluence later, agents’ Confluence tools fail with “no authorized Atlassian clouds” until an admin disconnects and reconnects.
Atlassian labels Amplify Console an unreviewed integration on the consent screen. That’s expected for an app shared by link rather than listed in the Marketplace. The authorization screen asks for: read and write Jira work items, read Jira users, manage Jira configuration, and read, search, and write Confluence pages and spaces. The Jira configuration scope is required by Atlassian for the issue-creation tools; a bot account without Jira admin rights still authorizes normally, and admin-only operations simply aren’t available to it.

What agents can do

Jira

Agents are instructed to create issues only for findings you asked to track, never in bulk, and to check a project’s issue types before filing. Status changes go through the transition tools, not through Jira_UpdateIssue.

Confluence

What agents can’t do

  • Delete issues, pages, or comments, or remove labels from an issue (labels are removed by updating the issue’s label list)
  • Attach files to issues
  • Create or manage sprints or boards
  • Comment on Confluence pages, or rename them
  • Reach a site other than the one chosen at authorization, or a project or space the bot account can’t see

Example

A filing step that runs once per finding:
See using integration tools in an agent for why group-by: [id] is there.

Revoking fully

Disconnecting in Console deletes Amplify’s stored authorization. To remove Atlassian’s side of the grant too, sign in as the bot account at id.atlassian.com → Connected apps and revoke Amplify Console.