Avaratak Blog
Trello Just Got an AI Front Door. The Lock Came With It.

Every organization has a tool that isn’t on the architecture diagram.
It didn’t arrive through procurement. Nobody wrote a governance policy for it. It showed up because one person needed a board for a launch, invited four colleagues, and it worked — so it stayed. Six years later it holds the launch checklist, the vendor shortlist, and a card titled ‘ask legal about this’ that nobody has moved since 2023.
For an enormous number of companies, that tool is Trello. More than 100 million people have signed up for it, and a healthy share of those signups happened without a single conversation with IT. That is not a criticism — it is precisely why Trello works. Frictionless adoption is a virtue in any tool that has it, and it is also, universally and across every vendor in the category, how software ends up living outside the governance model.
Which makes what Atlassian shipped this month more interesting than the headline suggests. Trello now speaks MCP.
What actually shipped
The Model Context Protocol is the shared standard that lets AI assistants talk to applications. Atlassian has now published an official Trello MCP server, which means Claude, ChatGPT, Gemini, Cursor, and any other MCP-capable client can read your Trello data, search across it, and act on it — creating and managing boards, lists, cards, and checklists by prompt rather than by clicking.
The practical shape of this is the part worth picturing. You spend twenty minutes with an AI assistant planning a product launch, or a conference booth, or a two-week trip through Italy. Previously the plan lived in a chat window and the work of transcribing it into a board was entirely yours — the momentum-killing tax on every good planning session. Now the plan can land in Trello directly, structured, while the thinking is still warm.
Setup is unglamorous in the best way. Trello MCP is listed for ChatGPT and Claude, there is a Cursor deeplink, and for anything else you add the server URL to your client’s MCP settings and run the connection flow. It works on every Trello plan, including Free. The server is open on GitHub, which is a nice signal about how Atlassian intends to develop it.
The part that made me sit up
Here is what I did not expect, and what almost every write-up of this launch is going to skip.
Trello MCP arrived already governed. Organizations managed through admin.atlassian.com can control it from Atlassian Administration — allowing or blocking which MCP server domains their people can reach, and setting what level of access is permitted when users connect, across read, write, and search. Critically, Trello MCP uses the same admin control framework as the Atlassian Rovo MCP server. There is no separate Trello-specific admin tooling to learn, no second console, no parallel policy to maintain.
Think about the sequencing there. The obvious way to ship this feature would have been to get it into users’ hands first and sort out enterprise controls in a later release, once someone complained. Instead the controls landed with the feature, inside the framework administrators already know. That is a meaningfully harder engineering decision and a meaningfully better one, and it deserves to be noticed rather than buried under the demo.
Restraint, in three places
The design discipline shows up elsewhere too, and each instance is the kind of thing you only appreciate at 2 a.m. six months from now.
No destructive deletes. Your assistant cannot permanently delete a board, list, card, label, comment, or attachment. It can archive cards and lists — recoverable, reversible — and that is the ceiling. Anything genuinely destructive still requires a human in the product. When an agent is acting on your behalf across hundreds of cards, the difference between archive and delete is the difference between an inconvenience and an incident.
Permission inheritance. An AI assistant cannot do anything in Trello that you could not do yourself. It operates inside your existing access, not above it. This is the same principle we admired when Bitbucket separated the right to deploy from the right to administer — capability widens, authority does not.
Explicit scope. Your assistant can only reach the workspace you specifically authorize on the consent screen, and access is revocable at any moment. Authentication runs on OAuth 2.0 rather than a long-lived token pasted into a config file somewhere.
The honest caveats
Three things to know before you plan around this.
Each connection currently supports one workspace. If you live across several, you will be choosing one for now; multi-workspace support is on the roadmap but is not here today. Second, every MCP call draws on your AI client’s message limits or token budget — the server is free, the conversation is not. Third, a small tier note: connecting a calendar to Planner works broadly, but creating focus time requires Trello Premium or Enterprise.
Worth knowing for the future: Atlassian has said Trello data may become available through the Rovo MCP server as well, for teams already running Trello alongside Jira and Confluence. Listing it separately for now simply makes it easier for dedicated Trello users to find it. If you have read our piece on closing the AI context gap, you can see where that convergence eventually leads.
The Avaratak Take
The feature is genuinely useful. The lesson underneath it is more useful still.
For years, the tools sitting outside the governance model were largely harmless because their blast radius was small. A board is a board. But the moment any tool becomes an AI endpoint, its blast radius changes character entirely — not because the tool got more powerful, but because something reasoning across it did. That is an industry-wide shift, and it is arriving faster than most access reviews are scheduled.
So here is the small piece of work I would actually do this quarter, and it has almost nothing to do with Trello specifically. Open Atlassian Administration and look at your MCP access controls with fresh eyes. Decide, deliberately, which server domains your organization permits and what access level you are comfortable granting — read, write, or search. Then go find out which Trello workspaces exist in your company at all, because the honest answer at most organizations is ‘more than we think.’ A workspace nobody knew about is not a new problem. A workspace nobody knew about with an AI assistant attached to it is.
Do that and this launch is a straightforward win: less transcription, faster capture, and the same permissions you already had. Skip it and you have not created a crisis — you have simply left a decision to be made by whoever connects first.
If you would like a second set of eyes on your MCP access controls, or an honest inventory of what is actually running in your Atlassian estate before you start pointing agents at it, that is exactly the conversation we enjoy at Avaratak. Come find us at avaratak.com. Bring the boards you forgot about; we will bring the good questions.
.webp)