Restriction Manager for Confluence: user guide
Confluence passes view restrictions down to the pages below, but not edit restrictions. Restriction Manager does: switch it on for a space, and pages created, moved or copied there get their parent's edit restrictions automatically. A restriction audit finds the pages that slipped through and fixes them in one click.
Before you start
- Who can use it. Only space admins can change the space's settings, run bulk actions and see audit results. Everyone else just notices that new pages get the right edit restrictions.
- The app appears in restriction lists. Confluence only accepts a restriction change if the account making it keeps access, so the app adds its own account ("Restriction Manager") to the restrictions it sets. It is not a person and cannot sign in.
Switch it on for a space
- Open Space settings → Integrations → Restriction Manager.
- Turn on Inherit edit restrictions in this space.
- Choose how child pages inherit:
- Copy: child pages get exactly the parent's edit restrictions.
- Add: child pages keep their own edit restrictions and also get the parent's.
- Optionally turn on When someone changes a page's edit restrictions, update the pages below it too, so pages keep following their parent after a change.
- Select Save.
To bring pages that already exist in line, select Apply to existing pages. It runs in the background and shows its progress; select Cancel to stop it.
What happens automatically
- A page, folder, whiteboard or database that is created, moved or copied under a restricted page gets that page's edit restrictions, usually within a minute.
- When you move a page that has pages below it, the pages below follow too, unless they have edit restrictions of their own.
- A new page keeps any edit restrictions its author set when creating it.
- Inheritance only ever adds restrictions: a parent with no edit restrictions never removes its children's.
Apply restrictions to one page tree
On any page, open ••• → Apps → Restriction Manager: apply to page tree. The dialog shows who can edit the page and offers:
- Copy these edit restrictions to all pages below, or
- Remove edit restrictions below, after which anyone who can view those pages can edit them. View restrictions are not changed.
Both run in the background, and the dialog shows progress and a Cancel button.
The restriction audit
Open Restriction audit in the space sidebar and select Scan now. The audit lists the pages where restrictions start or differ from the parent page, with who can view and edit each one. Pages that simply have their parent's edit restrictions are counted rather than listed, so the list stays short.
Each listed page is compared with its parent:
| Label | Meaning |
|---|---|
| Matches parent | Same edit restrictions as the parent page |
| Stricter than parent | Fewer people can edit it than its parent; usually intentional |
| Looser than parent | Anyone who can view it can edit it, while its parent is locked down: the risky case |
| Different from parent | Restricted, but to different people than its parent |
To fix a flagged page, select Match parent on its row; to fix every looser page at once, select Fix all looser pages. You confirm before anything changes. A fixed page gets its parent's edit restrictions, and so do pages below it that have none of their own. The list updates straight away.
"Nobody (view only)" means nobody can edit the page, and "Nobody (hidden)" means only the app can view it.
Activity log
Recent changes on the settings screen lists every change the app made in the last 90 days: when, which page, why, and who could edit it before and after.
Good to know
- The app never reveals a page. In Confluence, being on a page's edit list lets you view it. Before adding editors to a page with view restrictions of its own, the app checks each one can already view it and leaves out anyone who can't. The activity log says who was left out.
- View-only pages stay view-only. A page with a view list but no edit list can't be edited by anyone; the app never adds editors to it.
- Pages people restricted themselves. Confluence only lets an app change pages it may edit. When you apply restrictions or fix pages, the app adds itself to such pages as you, if you're allowed to edit them; otherwise it skips them and tells you how many.
- Pages hidden from the app. If a page's view restrictions leave out the app, Confluence hides that page and everything below it from the app. To cover such a tree, add Restriction Manager to the top page's view restrictions.
- Top-level folders. Folders directly under the space (beside its home page) aren't included in "Apply to existing pages" or the audit yet. Folders anywhere below a page are.
- Timing. Confluence tells apps about page changes in the background. The app usually reacts within a minute, occasionally a few minutes.
Uninstalling
Restrictions the app set stay on your pages as ordinary Confluence restrictions. The app's own data is deleted as described in the privacy policy.
Getting help
Email support@keywardlabs.com with your site address, the space and what you expected to happen.