Documentation

Access Snapshot for Confluence · On Record Labs

Install the app, open Access Snapshot from the Confluence apps menu as an administrator, and click generate. There is nothing to configure and no per-space setup. The report runs with your access, so it covers exactly what you cover.

What the report contains

Access by space

For every space on the site: each group, user, access class and app that holds permissions there, with the operations each one holds and the stable account or group identifier beside the display name.

Where each person or group reaches

The same data inverted. Pick a group or a person and see every space and restricted page they can reach. This is the view an access review actually needs, and the one no native screen gives you.

The restricted-page count here counts pages, not permissions. Someone who can both view and edit one page counts as one.

Restricted pages

Every page carrying a read or edit restriction, with the origin of that restriction stated:

Origin Meaning
own The page carries its own restriction.
inherited The page has no restriction of its own, but an ancestor does — so in practice it is closed.
own and inherited Both apply. The stricter one wins, as Confluence decides.

Inheritance is why this column exists. Confluence's API returns empty restrictions for a page that is closed only because its parent is closed. A report that trusted that answer would list a closed page as open — a false negative, and the worst thing an access report can do. The app resolves the ancestors and says so.

Reading the coverage line

Every report and every export opens with one sentence: who generated it, when, and how many spaces were read out of how many exist. Below it sits the list of declared gaps.

The gaps are the point. A report that claims completeness it cannot prove is worse than useless in an audit, because it gives false confidence. This one tells you where its own edges are.

Declared gap What it means, and what to do
Spaces could not be read The account that generated the report has no access to them. Run it as a site administrator for full coverage.
Pages outside the search index Confluence search is index-backed and lags the database. The app counts your pages both ways and reports the difference. Recently created or changed pages are the likely ones. Wait and run again.
Collection time limit reached Atlassian ends a user-triggered operation after 25 seconds; the app stops before that and says what it did not reach. Affects very large sites.
Names not resolved An identifier could not be turned into a display name. The identifier is still shown — it is the identity that matters.
Application context The report was produced without a user context and cannot see restricted pages. Generate it from the button, as an administrator.

Exports

CSV downloads as three files — by space, by person or group, and restricted pages. Each one repeats the full provenance header, so a single file still defends itself when it is detached from the other two and attached to a process months later.

The files are UTF-8 with a byte-order mark and CRLF line endings, so Excel on Windows opens them correctly instead of mangling accented names.

PDF comes from your browser's print dialog and contains all three sections regardless of which tab is on screen.

Identity: names change, identifiers do not

Every row carries both the display name and the account or group identifier. Display names are mutable — people rename themselves, and we have watched the same account report two different names through two different API contexts on the same day. The identifier is what an auditor can rely on months later.

Email addresses are never read or displayed. An address is not a name, and putting one in a document that circulates through compliance is a privacy problem.

Language

The report follows the language configured in your Atlassian account. English and Brazilian Portuguese ship today; the whole document comes out in one language, screen and file alike.

Permissions the app requests

Eight read scopes on Confluence, plus the app's own storage. No write scope on Confluence, and no external network access at all — the app declares no outbound domains, which Atlassian verifies from the manifest rather than taking our word for it.

The app stores no page content, no page titles and no permission data. What persists is a handful of counts and one provenance sentence, so the screen can tell you when the last report was produced. Full detail in the privacy policy.

Limits worth knowing before you buy