Execution happens outside the perimeter
Most agent platforms run the work in a vendor cloud. For a regulated organization, that turns an engineering decision into a security review, and the review often arrives after the budget is committed.
Fleet is a harness: the pattern and the underlying architecture for running agent work inside an organization's own environment. Work is queued, executed, reviewed by a person, and merged, and nothing crosses the account boundary to do it.
Most agent platforms run the work in a vendor cloud. For a regulated organization, that turns an engineering decision into a security review, and the review often arrives after the budget is committed.
A single impressive run is not a system. No durable state, no approval trail, no retry policy, no escalation path when work stalls overnight. Nothing that survives an audit.
Queue, sandbox, approval gate, source control integration, escalation. Every agentic build starts by reconstructing the same scaffolding, so the opening months of a program go to plumbing rather than the work it was funded for. Built once as a harness, that foundation carries into every engagement that follows, turning a cost repeated on each project into a repeatable revenue base across clients.
Fleet is where agent work runs when it cannot leave the environment. It is not a place to track work. It is a place to do it.
A packaged product is bought, configured within its own model, and used as shipped. A harness is different. It is an architecture that other things are built on, and a pattern that repeats across builds rather than a system delivered once. Fleet has an interface, but the interface is the smallest part of it. The value is in the layer below.
The harness needs three things from its host: container compute, a governed model endpoint, and enterprise identity. Any environment that provides them can run it. Snowflake is where Fleet is built and running now. Other governed environments are a port of the same pattern, not a new architecture.
A person describes the work. An agent picks it up, reads the codebase, plans the change, writes and tests it, and opens the result for review. Nothing merges without a human approval.
Work described in plain language, with priority and scope.
An agent clones the repository and branches.
Implement, run the tests, commit.
A person reads the diff. Approve, or reject with feedback.
Approved work merges and deploys.
Full autonomy is not the objective. Every change carries a named human who approved it, and every rejection is recorded with its reason. That trail is what makes agentic delivery defensible in a regulated environment.
Fleet exposes a Model Context Protocol server, so an agent outside Fleet can create work, launch it, and read the result. Fleet sits underneath the tools an organization already runs rather than replacing them.
Three things are different once the harness is running.
Initiatives held up by data residency, egress, or model provider review proceed, because execution never leaves the account. The security question is answered by the architecture rather than negotiated case by case.
Every merged change carries a named approver, and every rejection is recorded with its reason. Agentic delivery stops being something to defend in review and becomes something with a trail behind it.
Well specified work executes in parallel and continuously. Delivery capacity stops being set by how many engineers are available on a given week.
Jira, from Atlassian, is the most widely deployed system of record for engineering work: tickets, priorities, assignees, sprints, reporting. Most organizations already run it, and Fleet does not replace it.
Jira now executes work as well as tracking it. Atlassian's Rovo Dev turns a work item into an execution surface, planning a change, updating code, running tests, and opening a merge ready pull request in an Atlassian managed cloud sandbox. Agents are assignable in the same way a person is. That capability went broad in May 2026.
The difference is not the feature. On features this converges, and quickly. The difference is where execution happens, what it sits next to, and how it is paid for.
| Axis | Work management platform | Fleet |
|---|---|---|
| Where code executes | Vendor managed cloud sandbox | The organization's own account, no egress |
| What the agents sit next to | Work artifacts and connected applications | The data estate, model layer, and governance |
| Customization | Configured within the product's model | The code is ours, so the harness bends to the customer |
| Cost shape | Per seat plus metered AI credits | Compute and tokens, against a build cost |
| Time to first value | Already deployed and in use | Requires an engagement to stand up |
| Reach beyond engineering | Service management, finance, marketing | Engineering and data work |
| Ecosystem | Mature marketplace and connector estate | Model Context Protocol, platform native |
| Scale behind the roadmap | A public software company | Hakkoda and IBM |
Jira is the incumbent for good reasons. It is already deployed, it reaches well beyond engineering, and its connector ecosystem is mature. Fleet does not compete on any of those and is not intended to. It competes on the one axis a regulated organization cannot compromise on, which is where the work is allowed to run.
Jira remains the system of record. Work is defined, prioritized, and reported there, and none of that moves.
Work that can run in a vendor cloud stays there. Work touching regulated data, production pipelines, or anything that cannot cross the boundary routes to Fleet.
The Model Context Protocol interface is the join. An agent on the tracker side can create work in Fleet, launch it, and read the result back.
The conditions that make Fleet the right answer are specific, and so are the ones that rule it out.
Fleet is early. Its components are not.
Fleet is not licensed and there is no seat price.
The engagement deploys the harness into the customer's environment and hands over agents already configured for their stack, their coding standards, and their review policy. Pre-configured agent roles are the difference between a framework and something that does useful work in week one. A first workload runs through it before handover, with a runbook.
The harness is the accelerator. The customer specific build on top of it is the work.
The qualifying condition is narrow and easy to test: an artificial intelligence initiative that has already stalled because the work could not leave the account.
Fleet detail comes from the build itself. Everything referenced about Atlassian is public and dated below.