See who can really view and edit every page. Export it for your audit.
View restrictions cascade down the page tree. Edit restrictions do not. Restrict editing on a parent page and every child below it stays editable by your whole space — while looking locked in the tree.
This is documented Confluence behaviour, not a bug. CONFCLOUD-5095 has been open since 2006 with nearly a thousand votes. Fixing it now would silently change permissions on millions of existing pages, so it is unlikely ever to change.
Nobody catches it by clicking through pages, which is how access reviews are done today.
A page whose parent is locked, that is not. The one above, caught.
Restricted viewing with unrestricted editing: everyone who can see it can change it.
Restrictions naming deactivated accounts, or accounts no longer on the site.
They grant access to nobody, and they hide what was actually intended.
Sometimes deliberate. Worth knowing which.
Groups are resolved to the actual people, because "the legal group can edit this" is not something an auditor can sign off. The export is stamped with what it covers and when the permissions were read. Re-run it and it tells you what changed since last time.
Read scopes only. It cannot change a permission and we will not add that — "your app changed my restrictions" is a conversation we have chosen never to have. If you need bulk permission editing, this is not that product.
Runs on Atlassian. Compute and storage inside Atlassian's infrastructure, no external connections, verified by Atlassian's own eligibility check. Details in the privacy policy.
Free for up to 10 users. $1 per user per month above that.