Atlassian has extended its shadow IT prevention features to Bitbucket Cloud, enabling workspace admins to require approval before users can create new workspaces. This control aims to reduce data exposure risks caused by unmanaged software use within organizations.

  • Workspace creation requests require admin approval under new Bitbucket controls.
  • Feature available now in Bitbucket Premium with beta status.
  • Admins manage requests via Atlassian Admin security settings.

What happened

When users attempt to create a new workspace, they must submit product requests detailing intended usage. Admins then have the option to approve, reject, or mark requests under review through Atlassian Admin’s security tab. Approved requests result in workspace setup completion and notification to the user, while denied requests send rejection notifications.

Why it matters

Shadow IT presents risks such as data leaks, unmanaged costs, and disjointed compliance efforts. By empowering Bitbucket workspace admins to control workspace creation, Atlassian addresses these challenges in organizations using Bitbucket for source code management and collaboration.

The ability to centralize control over product instance creation reduces unintended exposure of sensitive code and resources. This also helps IT teams enforce governance policies more effectively by integrating Bitbucket workspace management into the broader Atlassian Admin console alignment with unified user and access management.

What to watch next

Currently, this shadow IT control feature is in beta for Bitbucket Premium subscribers since Bitbucket Cloud does not yet have a formal Enterprise plan. Atlassian indicates that eligibility and availability could evolve and that they will keep customers updated on changes.

Additionally, there is a continued focus on unified user management across Atlassian tools, which aids admins in managing users and permissions from a single pane. Future updates will likely further integrate Bitbucket with these centralized admin functionalities and may expand shadow IT protections or adjust request workflows based on enterprise feedback.

Source assisted: This briefing began from a discovered source item from Atlassian Blog. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings