In this page

How does access control work with the app?

The app is represented by an artificial user called "Better Content Archiving and Analytics for Confluence" on your Confluence site. We call it the "app user". The app user is automatically provisioned by Confluence when you install the app.

Access control works the same way for the app user as for any human user. See the Confluence Cloud documentation for general access control information, and for details of space permissions and content restrictions.

Required access control settings

In accordance with the previous, the app can work with a content (a page, for example) only if all these are satisfied:

  1. The app user has the required space permissions on the space that contains the content.
  2. Either there are no restrictions applied to the content, or there are and the app user is configured with the required content restrictions.

Required space permissions

In every space, except the excluded ones, the following space permissions must be granted to the app user.

Permission Why is it required?
View content Required so the app can work with the space and the contents in it.
Edit content Required so the app can write the content status and other app-specific information to pages.
Edit blogs Required so the app can write the content status and other app-specific information to blogposts.
Manage access to individual content Required so the app can keep the correct content restrictions in the page tree while archiving pages, and fix missing content restrictions on a content (when manually asked to).
Delete anyone's content Required so the app can delete pages using Delete type automations (logical removal).
Also required so the app can purge pages using Purge type automations (permanent removal).
Delete blogs Required so the app can delete blogposts using Delete type automations (logical removal).
Also required so the app can purge blogposts using Purge type automations (permanent removal).
Archive content Required so the app can archive pages using Archive type automations.

Notes:

  • These permissions are usually present in the Manager role, see the Confluence Cloud documentation for the details of individual permissions in each role.
  • The Free plan of Confluence Cloud Space does not allow modifying space permissions, but every user has every space permission in every space (a limitation introduced by Atlassian). Therefore, the app will "just work".
Fix missing space permissions

Fixing the required space permissions for multiple spaces can be time-consuming. The app provides convenience features to make it easier:

Required content restrictions

If there is a content restriction applied to a content, it must be configured so that the app user "can edit" the content.

"Can edit" is required because the app writes the content status and other app-specific information to so-called content properties. At the same time, the app never modifies the title, body and other "core" information. Therefore, it is safe to include the app user in content restrictions.

Fix missing content restrictions

Fixing the required content restrictions for multiple contents can be time-consuming. The app provides convenience features to make it easier:

Fix with the Content Status Indicator or Content List

To fix a missing permission, you must have permission to manage permissions. You can start it from two locations:

  1. Content Status Indicator: Click the Missing permissions pseudo-status, then click the Grant access button.
  2. Content List: Click the Cannot refresh pseudo-status, then click the Grant content access button.

Either way, the App content permissions dialog explains what's missing for the app to access the content:

Clicking the Grant access button will fix what is missing, by potentially updating the following:

  • Content restrictions on the current page or blog post.
  • Content restrictions on ancestor pages, if they are inherited. (It grants access to both the app user and the current user.)
  • Space permissions on the enclosing space. (It grants the space permissions to the app user.)

In any case, only the absolute minimum changes are applied.

Fix with Confluence built-in features

Alternatively, you can follow these manual steps:

  1. Click the page title and open it in a new browser tab.
  2. Click the lock icon at the top.
  3. Select the user "Better Content Archiving and Analytics for Confluence" by typing the first letters.
  4. Select "Can edit".
  5. Click Add.
  6. Close the browser tab and return to the list.

Questions?

Ask us any time.