Security and data: Restriction Manager for Confluence
Last updated: 2026-09-30
In short
- Runs entirely on Atlassian Forge. No servers of ours, no calls outside Atlassian (the app declares no external network access).
- Eligible for Atlassian's "Runs on Atlassian" program, checked with Atlassian's eligibility tool on the release build.
- Never reads page content. Stores only settings, an activity log, job progress and audit results, with Atlassian account IDs as the only personal data.
- Only space admins can change settings, run bulk actions or see audit results, checked with each person's own Confluence permissions.
How the app changes restrictions
The app writes page restrictions as its own app account, because page events have no user attached. Before any change a person asks for (saving settings, bulk actions, audit fixes), the app first asks Confluence, as that person, whether they administer the space. If not, nothing happens.
Confluence only accepts a restriction change if the account making it keeps access, so the app adds its own account to the restrictions it sets. It appears in restriction lists as the app. It can't sign in, and only the app's own code acts through it.
Inheritance only ever adds restrictions: a parent page with no edit restrictions never removes restrictions from the pages below it, and view restrictions are never changed.
Confluence lets everyone on a page's edit list view that page, even when the page's own view restrictions leave them out. So before the app adds editors to a page that has view restrictions of its own, it asks Confluence whether each new editor can already view the page, and leaves out anyone who can't. The app never reveals a page to someone who couldn't see it before. The activity log records who was left out.
A page with a view list of its own but no edit list is view-only: nobody can edit it. The app treats such pages as the strictest setting and never adds editors to them. When asked to remove edit restrictions from a page with its own view list, it lets that page's viewers edit it, rather than making it view-only.
Confluence only lets an app change the restrictions of pages it may edit. When a space admin
applies restrictions to existing pages or fixes pages from the audit, the app acts as that admin
(Atlassian's offline user impersonation, declared for the write:confluence-content scope only) to
add itself to the edit restrictions of pages someone restricted without it. That is the only thing
it does as the admin, it can only succeed where the admin may edit the page, and the activity log
records each page. Pages neither can edit, and view-only pages, are left as they are and counted.
Automatic inheritance never acts as a person.
Data inventory
| Data | Why | Retention |
|---|---|---|
| Space settings (rule, mode, who saved it) | The space's inheritance rule | Until changed or uninstalled |
| Activity log (page ID and title, reason, who could edit before and after) | Lets space admins see what the app changed | 90 days |
| Job records (progress, errors, who started or cancelled) | Progress of bulk actions and audits | 30 days |
| Audit results (restricted pages, who can view and edit) | The audit screen | Until the next audit, or uninstall |
All of it is in Atlassian's Forge hosted storage for the customer's site, encrypted and hosted by Atlassian. It follows your site's data residency: Atlassian keeps Forge-hosted data in the same location as your Confluence data and moves it if your site moves (Forge data residency).
Personal data
Account IDs are the only personal data stored. The app reports them to Atlassian weekly through the Forge personal data reporting API, and erases any account Atlassian reports as closed.
Logs
Diagnostic logs contain page IDs, space keys, timings and outcomes only: no names, account IDs or page content. Atlassian shares production logs with us by default, and site admins can switch that off.
Permissions (scopes) the app asks for
| Scope | Used for |
|---|---|
read:page:confluence, read:hierarchical-content:confluence |
Reading a page's parent and the content below it |
read:folder:confluence, read:whiteboard:confluence, read:database:confluence |
Reading the parent of folders, whiteboards and databases, which inherit like pages |
read:space:confluence, read:confluence-space.summary |
Finding the space a screen or event belongs to, and its top-level pages |
read:confluence-content.all, read:confluence-content.summary |
Reading page restrictions (Confluence's restrictions API) |
write:confluence-content (with user impersonation) |
Changing page restrictions; as the admin who asked, adding the app to pages restricted without it |
read:confluence-content.permission |
Checking that new editors can already view a page |
read:confluence-groups |
Showing group names |
read:confluence-user |
Finding the app's own account ID |
storage:app |
Storing settings, the activity log and audit results |
report:personal-data |
Weekly personal data reporting |
Reporting a security problem
Email security@keywardlabs.com. We confirm receipt within 2 business days, keep you informed while we investigate, and credit you if you wish. Please give us reasonable time to fix a problem before disclosing it.
If something goes wrong
If we learn of a security incident affecting customer data, we will notify affected customers without undue delay, and within 72 hours of confirming it, with what happened and what to do.