In this page
Required access control settings
Required space permissions
Fix space permissions
Required content restrictions
Fix content restrictions
Use the Content Status Indicator or the Content List
Use Confluence built-in features
Archiving and content restrictions
How does access control work with the app?
The app is represented by an artificial user called "Better Content Archiving and Analytics for Confluence" on your Confluence site. We call it the "app user". The app user is automatically provisioned by Confluence when you install the app.
Access control works the same way for the app user as for any human user. See the Confluence Cloud documentation for general access control information, and for details of space permissions and content restrictions.
Required access control settings
In accordance with the previous, the app can work with a content (a page, for example) only if all these are satisfied:
- The app user has the required space permissions on the space that contains the content.
- Either there are no restrictions applied to the content, or there are and the app user is configured with the required content restrictions.
Required space permissions
In every space, except the excluded ones, the following space permissions must be granted to the app user.
| Permission | Why is it required? |
|---|---|
| View content | Required so the app can work with the space and the contents in it. |
| Edit content | Required so the app can write the content status and other app-specific information to pages. |
| Edit blogs | Required so the app can write the content status and other app-specific information to blogposts. |
| Manage access to individual content | Required so the app can keep the correct content restrictions in the page tree while archiving pages, and fix missing content restrictions on a content (when manually asked to). |
| Delete anyone's content |
Required so the app can delete pages using Delete type automations (logical removal). Also required so the app can purge pages using Purge type automations (permanent removal). |
| Delete blogs |
Required so the app can delete blogposts using Delete type automations (logical removal). Also required so the app can purge blogposts using Purge type automations (permanent removal). |
| Archive content | Required so the app can archive pages using Archive type automations. |
Notes:
- These permissions are usually present in the Manager role, see the Confluence Cloud documentation for the details of individual permissions in each role.
- The Free plan of Confluence Cloud Space does not allow modifying space permissions, but every user has every space permission in every space (a limitation introduced by Atlassian). Therefore, the app will "just work".
Fix space permissions
Fixing the required space permissions for multiple spaces can be time-consuming. The app provides convenience features to make it easier:
- The app space permissions screen to fix space permissions on multiple spaces (in bulk).
- The Content Status Indicator displays a Grant access button to fix space permissions on the enclosing space.
Required content restrictions
If there is a content restriction applied to a content, it must be configured so that the app user "can edit" the content.
"Can edit" is required because the app writes the content status and other app-specific information to so-called content properties. At the same time, the app never modifies the title, body and other "core" information. Therefore, it is safe to include the app user in content restrictions.
Fix content restrictions
Fixing the required content restrictions for multiple contents can be time-consuming. The app provides convenience features to make it easier:
- The app content restrictions screen to fix content restrictions in a whole space (in bulk).
- The Content Status Indicator displays a Grant access button to fix content restrictions.
Use the Content Status Indicator or the Content List
If you have permission to fix the problem, expand the Content Status Indicator popup, and it will display a Missing permissions or Cannot refresh message instead of the content status. Clicking it reveals more details, and if you have permission to fix the problem, also a Grant access button, which opens the App content permissions modal.
Alternatively, on the Content List, click the Cannot refresh message that appears in place of the content status. Clicking it opens the same App content permissions modal.
The App content permissions modal details the problem and displays a button to resolve it when possible. Clicking this button restores the app's access to the current page or blog post in one step.
It may update the following:
- Content restrictions on the current page or blog post.
- Content restrictions on parent pages, if they are inherited. (It grants access to both the app user and the current user.)
- Space permissions on the enclosing space, if they are missing. (It grants the space permissions to the app user.)
In any case, only the absolute minimum permission changes are applied.
Use Confluence built-in features
If the one-click fix is not available for some reason, follow these manual steps:
- Click the page title and open it in a new browser tab.
- Click the lock icon at the top.
- Select the user "Better Content Archiving and Analytics for Confluence" by typing the first letters.
- Select "Can edit".
- Click Add.
- Close the browser tab and return to the list.
Archiving and content restrictions
By default, archiving affects content restrictions. To help prevent unintended exposure of content, Better Content Archiving includes safeguards for handling restrictions. See this section for details.
Questions?
Ask us any time.