Who can really see this Confluence page?
If you can't answer that in ten seconds, your Confluence permissions need an audit. Updated July 2026.
The short version: Confluence access is spread across space permissions, groups, system-wide grants, space roles and page restrictions — and they interact in ways nobody can hold in their head. There is no native screen that answers "who can really see this, and who can change it?" Access Lens reads all of them and gives you one clear table, riskiest first, plus the page locks — including inherited ones — that the UI never warns you about.
Why "who has access?" is so hard to answer in Confluence
- Access hides in five places. Space permissions, group memberships, system-wide grants ("all licensed users"), space roles on newer RBAC sites, and per-page restrictions — each a different screen, none of them combined.
- Inherited restrictions are invisible. A page silently inherits view/edit restrictions from its parent. Nothing in the UI tells you, so audits become archaeology.
- Broad access looks harmless. "Everyone with a license can edit" is one click away and easy to miss — until it's on the page with the salary bands.
What Access Lens shows you
| Question | Native Confluence | Access Lens |
|---|---|---|
| Who can see this space, in one view? | Spread across 4–5 screens | One table: every person, group & system grant, riskiest first |
| Is access dangerously broad? | You have to notice it yourself | "All licensed users can edit" is flagged automatically |
| Which pages are restricted — including inherited? | No inherited-restriction view | Every page scanned for its own and inherited locks, with names |
| New role-based (RBAC) sites | Partial | Reads classic permissions and space role assignments |
| Audit evidence for SOC 2 / ISO / GDPR | Manual screenshots | One-click CSV export of the full access list |
| Where your data goes | — | Nowhere — Runs on Atlassian, zero egress, nothing stored |
| Price | — | Free ≤10 users · $4.50/user/month |
Built for access reviews and audits
SOC 2, ISO 27001 and GDPR all expect you to review who has access to what on a regular basis. When an auditor asks "who can see the space with the board minutes?", Access Lens answers it in one table and exports the evidence as a dated CSV — instead of an afternoon of clicking through permission screens and hoping you didn't miss an inherited restriction.
Access Lens — Permissions Audit for Confluence
Launching on the Atlassian Marketplace. Free for teams up to 10 users.
Read the documentation →Questions? [email protected]