In this page

How does access control work with the app?

The app is represented by an artificial user called "Better Content Archiving and Analytics for Confluence" on your Confluence site. We call it the "app user". The app user is automatically provisioned by Confluence when you install the app.

Access control works the same way for the app user as for any human user. See the Confluence Cloud documentation for general access control information, and for details of space permissions and content restrictions.

Required access control settings

In accordance with the previous, the app can work with a content (a page, for example) only if all these are satisfied:

  1. The app user has the required space permissions on the space that contains the content.
  2. Either there are no restrictions applied to the content, or there are and the app user is configured with the required content restrictions.

Required space permissions

In every space, except the excluded ones, the following space permissions must be granted to the app user.

Permission Why is it required?
View content Required so the app can work with the space and the contents in it.
Edit content Required so the app can write the content status and other app-specific information to pages.
Edit blogs Required so the app can write the content status and other app-specific information to blogposts.
Manage access to individual content Required so the app can keep the correct content restrictions in the page tree while archiving pages, and fix missing content restrictions on a content (when manually asked to).
Delete anyone's content Required so the app can delete pages using Delete type automations (logical removal).
Also required so the app can purge pages using Purge type automations (permanent removal).
Delete blogs Required so the app can delete blogposts using Delete type automations (logical removal).
Also required so the app can purge blogposts using Purge type automations (permanent removal).
Archive content Required so the app can archive pages using Archive type automations.

Notes:

  • These permissions are usually present in the Manager role, see the Confluence Cloud documentation for the details of individual permissions in each role.
  • The Free plan of Confluence Cloud Space does not allow modifying space permissions, but every user has every space permission in every space (a limitation introduced by Atlassian). Therefore, the app will "just work".

Fix space permissions

Fixing the required space permissions for multiple spaces can be time-consuming. The app provides convenience features to make it easier:

Required content restrictions

If there is a content restriction applied to a content, it must be configured so that the app user "can edit" the content.

"Can edit" is required because the app writes the content status and other app-specific information to so-called content properties. At the same time, the app never modifies the title, body and other "core" information. Therefore, it is safe to include the app user in content restrictions.

Fix content restrictions

There are two ways to fix content restrictions on a single page or blog post.

Using the Content Status Indicator or the Content List

(It is the recommended way.)

If you have permission to fix the problem, expand the Content Status Indicator popup, and it will display a Missing permissions or Cannot refresh message instead of the content status. Clicking it reveals more details, and if you have permission to fix the problem, also a Grant access button, which opens the App content permissions modal.

Alternatively, on the Content List, click the Cannot refresh message that appears in place of the content status. Clicking it opens the same App content permissions modal.

The App content permissions modal details the problem and displays a button to resolve it when possible. Clicking this button restores the app's access to the current page or blog post in one step.

It may update the following:

  1. Content restrictions on the current page or blog post.
  2. Content restrictions on parent pages, if they are inherited. (It grants access to both the app user and the current user.)
  3. Space permissions on the enclosing space, if they are missing. (It grants the space permissions to the app user.)

In any case, only the absolute minimum permission changes are applied.

Using Confluence built-in features

If the one-click fix is not available for some reason, follow these manual steps:

  1. Click the page title and open it in a new browser tab.
  2. Click the lock icon at the top.
  3. Select the user "Better Content Archiving and Analytics for Confluence" by typing the first letters.
  4. Select "Can edit".
  5. Click Add.
  6. Close the browser tab and return to the list.
Working with a large number of restricted contents

If a space contains many restricted pages or blog posts, and you want to ensure the app can access all of them, go to the space and navigate to Space settingsContentRestricted to see the list.

For each restricted content, if the app user (named "Better Content Archiving and Analytics for Confluence") does not have "Edit" type permission, you can either:

(Fixing a large number of content restrictions can be tedious. The app may provide a convenience feature for this in the future, but right now this is not possible due to limitations in the Confluence Cloud REST API.)

Archiving and content restrictions

By default, archiving affects content restrictions. To help prevent unintended exposure of content, Better Content Archiving includes safeguards for handling restrictions. See this section for details.

Questions?

Ask us any time.