Back to Explore
NewsVibeFix 编辑部Updated Oct 8, 2026

Atlassian Launches AMP: AI-Written Code Can No Longer Hide

On October 7, Atlassian launched the Agentic Multiplayer Protocol (AMP): AI agents get an "identity," and codebases precisely record what humans wrote versus what agents did, across Claude, Codex, Figma, and Rovo. Bundled with the Teamwork Graph code index, the Rovo Work long-task mode, and EU-only inference. As vibe coding enters the enterprise, "who wrote the code" turns from vanity into compliance and cost.

Two developers collaborating around a screen displaying code

When code no longer knows who wrote it

Picture a scene every engineering manager knows in 2026: Monday morning code review, a 300-line diff where 200 lines came from Claude Code, 50 were pasted from ChatGPT, 30 autocompleted by Copilot, 20 typed by hand. CI green, tests passing. Now answer: who actually wrote these 300 lines? If there's a production incident, who does the postmortem? When measuring productivity, whose output is this?

On October 7, Atlassian offered its answer: the Agentic Multiplayer Protocol (AMP). The company calls it the "foundation for how humans and agents collaborate across the Atlassian platform" — agents join multiplayer work with an identity, scoped authority, shared context, tasks, and reviewable results. In plain terms: the AI agent is no longer an anonymous "ghostwriter" hiding behind someone's account, but a first-class citizen of the collaboration space, with an identity, permission boundaries, and a behavior record.

What's inside AMP: three pieces

First: Teamwork Graph. The technical base of AMP: it indexes source code down to functions, symbols, and classes, letting developers search across Bitbucket and GitHub without cloning repos. More importantly, the attribution — version history shows precisely what a human wrote versus what an agent did, across Claude, Codex, Figma, and Rovo. Atlassian's head of AI products Jamil Valliani put it bluntly in an interview: "For most enterprises, this is what is holding them back from further adopting AI" — the lack of meaningful visibility into code origin.

Second: Rovo Work. A new mode in Rovo Chat for complex, multi-step tasks: under human supervision and approval, it executes across Jira, Confluence, and connected tools, and can run for hours in a secure sandbox until it completes the approved goal. This answers the "agents can only do 5-minute tasks" complaint head-on — long-running agents don't need stronger models so much as a supervisable long-runtime environment.

Third: EU AI Inference. A geographic feature: LLM processing restricted exclusively to EU-hosted models. For European enterprises bound by GDPR and data sovereignty, this is a ticket for admission, not a nice-to-have.

Atlassian says those capabilities are available immediately. A batch of non-human identity (NHI) controls — governing what AI can see and restricting what access agent accounts get — is labeled "soon." Anyone experienced can tell: the "soon" pile may hold more value than what's already shipped.

Analyst cold water: the hardest part is the middle

The most informative part of this launch isn't what Atlassian said — it's the cold water analysts poured, every word worth a vibe coder's attention.

IDC research manager Adam Resnick: "The real value goes beyond knowing who typed a given line. Enterprises want visibility into where humans and agents exercised judgment on consequential decisions, such as which data store to adopt or how to handle authentication. The most useful provenance shows whether meaningful human review took place, rather than simply recording that someone clicked approve." His prescription is risk-based review: a small, well-scoped agent change may warrant lighter review than a human-written change to a payments system — origin is one input, alongside autonomy, consequence, and evidence of human oversight.

Aikido Security's enterprise CISO Mike Wilkes attacked from engineering reality: "Git can tell you who committed a change, but that is increasingly different from who, or what, actually wrote the code. A developer might accept Copilot suggestions, paste code from ChatGPT, delegate a task to Claude Code, or have an autonomous agent create a pull request. By the time that code reaches the repository, much of that provenance has been flattened into a human identity and a commit." Then he did the CIO's math: reliable attribution lets CIOs finally measure agentic development instead of counting AI licenses and token burn — comparing human vs. agent-assisted changes on cycle time, review effort, rework, defects, rollbacks, ultimately "cost per accepted change." He said: "An organization might discover that agents produce 40% of its changes, but only 10% of its engineering value, or exactly the opposite. That turns AI attribution from an interesting version control feature into a telemetry layer for understanding whether millions of dollars of enterprise AI investment are actually impacting real SDLC productivity."

Acceligence CEO Justin Greis offered the pragmatist's view: "If I want to know whether AI is making a developer more effective, I probably do not need to inspect every line of code for AI provenance. I can look at cycle time, defect rates, rework, throughput, security findings, and ultimately the quality and economics of what that developer produces before and after adopting the tool."

The sharpest cut came from Frank Dickson, principal analyst at Dickson Research: "The labeling alone is thin as a differentiator. The identity control plane beneath it is where the real value may sit. Atlassian labels that piece 'soon.'" He also seized on one phrase: "Atlassian says it traces every change back to the agent and 'the person who set it up.' The person who set up an agent is not always the person who approved its work. They may sit on different teams. The person who approves an agent's work owns it. Version history should make that ownership visible, not blur it." His example stings: an agent running on someone's credentials gets recorded as that person; a developer accepting an AI suggestion signs it as their own work; a human rewriting three lines of agent code creates a change belonging to both. "Attribution is easy at the edges; [but] it is hard in the middle, where most of the work now happens."

Why attribution is hard: Git's "author" field is failing

To grasp AMP's value, first understand what it replaces. Git's author/committer fields are failing systemically in the agent era, for three reasons:

First, local agents impersonate developers. You run Claude Code locally; it commits; the author is you. The commit message may carry a "Co-authored-by: Claude" line — but that's a textual convention: deletable, editable, lost on rebase. Attribution by text convention is taxation by honor system.

Second, human-machine co-edits can't be split. The agent generates 100 lines; you change 5 — whose are those 5? Git's line-level blame only tells you "who last touched this line," never "whose idea this line was." Atlassian's approach records at the change level, not the line level: a change initiated by an agent keeps its lineage even after human edits.

Third, identity explosion with parallel agents. One developer runs Claude Code, Codex, and Rovo simultaneously — all committing as them. Without an agent identity layer, you can't even answer "which agent introduced this bug," let alone "which agent has the best ROI." AMP's "agent identity" solves exactly this: agents stop being human shadows and become independently-identified actors.

See these three layers and the analysts' line clicks into place — "labeling is thin, the identity control plane is thick." Labels are for humans to read; the identity control plane is for machines to decide on: permissions, audit, billing all hang off identity. Whoever makes this identity facility the default first, owns the developer-platform entrance for the next decade.

Why vibe coders should care about an "enterprise" launch

AMP looks enterprise-y, but the inflection it marks concerns every indie developer: vibe coding is moving from "personal toy" to "organizational productivity," and "who wrote the code" is turning from vanity into compliance and cost.

On compliance: when your vibe project starts serving enterprise customers, their security questionnaire will eventually ask: "What share of your code is AI-generated? What's the review process?" Today you answer verbally; tomorrow you may need tooling to prove it. Once attribution infrastructure like AMP spreads, "AI code without provenance" flips from the default state into the exception that needs explaining.

On cost: Wilkes's "cost per accepted change" deserves a slow read from everyone who codes with AI. When you run 5 agents in parallel, how do you know which one creates value and which burns tokens on rework? Today it's vibes; tomorrow it's telemetry. Indie developers can start the lightweight version now — standardized commit trailers for agent work (e.g. Co-authored-by: claude-code), tagging tasks per agent to track rework rates. Build the habit first; the tooling follows.

Then there's the career angle: once "AI involvement" becomes measurable, "can direct AI" turns from mystique into provable skill. HackerRank already made "AI fluency" a hiring metric (we covered it yesterday); attribution facilities like AMP will make "what a candidate shipped with AI, and at what quality" checkable. Leaving clean "human-machine collaboration records" in your public projects today is credit for your future self.

Our take: attribution isn't about blame — it's about pricing

Many people's first reaction: is attribution about blaming the AI when things break? Quite the opposite. Attribution's real purpose is pricing — pricing AI investment, pricing human judgment, pricing risk. Without attribution, enterprise AI spend is an unaccountable blur: licenses bought, tokens burned, productivity gains all "felt." Resnick is right: risk-tiered review, cost attributed per change — that's what makes a CIO keep paying.

The action list for vibe coders is concrete. First, standardize your agent commit messages starting today — note which agent did what; it's zero-cost attribution hygiene. Second, keep evidence of "where the human made the key call" — one line in the PR description like "human-reviewed the auth boundary conditions" carries more long-term value than a hundred lines of AI-generated comments. Third, if you're building for businesses, put "AI code provenance traceable" in your security whitepaper — it will differentiate you from competitors.

Whether Atlassian's AMP becomes the standard is still open — until the "soon" identity control plane lands, it's more manifesto than infrastructure. But the direction is irreversible: when the people writing code change from "one person" to "one person plus N agents," infrastructure recording "who did what" becomes as inevitable as Git recording "who committed what" once was. Those who adapt early take the first-mover seat under the new rules.

Sources

Browse projectsPublish your project

Related articles

Data visualization charts of a global developer survey with code elements
News
Stack Overflow 2026 Survey: AI Adoption Plateaus, Trust Turns Conditional

Stack Overflow published its 16th annual developer survey on October 6: 30,000+ respondents across 169 countries. 66% use coding assistants, 26.2% already run automated agent workflows; but trust has shifted — nearly half only trust AI when they can verify its work, and just 6.6% would entrust it with important decisions; 30% say workplace AI use is left to individual discretion. The official snapshot of vibe coding penetration in 2026.

Industry TrendsAI CodingLearning & Career
Concept illustration of a robot holding a digital ID card with a shield verification badge, symbolizing AI agent identity
News
AI Agents Get Their Own 'Sign in with Google': AgentMail Launches AgentID

AgentMail launched AgentID on October 6: agents log in to third-party apps using their own email as an OpenID Connect identity. The verification-code step disappears, one authorization lasts 180 days. Identity may be the real watershed between agent toys and agent production.

AI CodingProduct LaunchAuthentication & Access