Start my assessment

Manufacturing and defence: operational sovereignty, export control and continuity.

In manufacturing and defence, the question is not only where the data is hosted. It is to understand how the organisation can keep working, collaborating and deciding when access to a supplier, a technology or certain data is restricted.

Atlassian Platinum Solution Partner since 2008 · French consultancy · Paris and Lyon

Technician inspecting an aircraft engine in an aerospace assembly hall
The dominant constraintOperational sovereignty and NIS 2

Three defining requirements shape this field.

01
Operational sovereignty

Sovereignty is not just about where data is located. It includes the ability to operate the systems, recover the information, change supplier, sustain operations and keep the skills needed to act without excessive dependence.

02
Export control and control over access

In an international environment, not all information can be accessible to every employee, partner or subcontractor. Export control, confidentiality and nationality rules can require fine-grained partitioning, access restrictions and precise traceability of exchanges.

03
Continuity and traceability

Incident, change, access, approval and archiving processes have to stay understandable and auditable. The evidence has to be produced at the moment of the action, not reconstructed afterwards.

A developer at a monitoring screen, seen from the corridor

The Atlassian Data Center exit has a timetable.

The official Atlassian timetable sets three deadlines for the Data Center products concerned.

30 March 2026End of Data Center sales to new customers.
30 March 2028Last possible purchase or extension for existing customers.
28 March 2029Effective end of life, switch to read-only, at 23:59 PST.

An industrial environment kept on premise for good reasons therefore has a decision to work through, with time on its side. We scope that decision in the assessment Controlled Data Center Exit, in 6 to 10 weeks: the sequence is set out on Atlassian Cloud migration.

What we put in place

RequirementWhat it means in practiceWhat BleuLemon puts in place
Operational sovereigntyContinuing to operate without depending on a single supplierReversibility architecture, export of data and configurations, documentation, alternative hosting, tested exit scenarios.
Export controlRestricting access according to the applicable rulesSeparate scopes, dedicated groups and permissions, access workflows, logging, partitioned test environments.
Sensitive dataPreventing uncontrolled circulationClassification, anonymisation or masking for testing, sharing rules, periodic review of permissions.
TraceabilityBeing able to reconstruct a decision or an actionTimestamped workflows, approvals, a usable history, archiving of closed projects outside the active instance.
Supplier continuityPreparing a real exit, not a theoretical oneRecovery tests, retention of usable formats, contractual and operational documentation of reversibility.

The real test of sovereignty is not going in with a supplier. It is the ability to leave without losing control of your operations.

Archiving has its own page: Jira archiving before migration, with Aquarius, our extraction solution that can be consulted outside Jira.

Our references in this industry.

Safran is among BleuLemon's references. The scope of the engagement remains covered by a confidentiality agreement: we present the arrangement and the indicators in a meeting, never beyond what the client has authorised.

BleuLemon, a French consultancy (Paris, Lyon) and Atlassian Platinum Solution Partner since 2008.

Frequently asked questions

A question that finds no answer here is dealt with in a thirty-minute conversation, about your actual context rather than a general case.

Talk to an expert
What does "operational sovereignty" actually mean?

The ability to keep working if a supplier becomes unavailable, if an offer changes or if a legal or commercial constraint limits its use. That requires recoverable data, documented configurations, in-house skills and a realistic exit path.

How do you take export control into account?

By translating the applicable rules into permissions, scopes, access workflows and logging. The setup depends on the client's context: countries, data, programmes, subcontractors and categories of authorised people.

Do you necessarily have to stay on premise?

No. The point is not to favour one architecture on principle, but to choose a target that fits the requirements for confidentiality, continuity, access and reversibility.

How do you prove the traceability of a change?

Each change can involve a requester, an impact assessment, approvals, an execution window and an outcome. The history stays available and can be archived in a usable format for closed projects.

Going further: IT service management (ITSM / ESM)·Atlassian Cloud migration·Aquarius·The Assessment