PermPilot: Access & Permission Auditor for Confluence

PermPilot icon
Access & permission auditor for Confluence

See who can really read and edit every Confluence page.

Confluence tells you a page is restricted. It does not tell you that the people who can still see it can also rewrite it. PermPilot audits every page in one click, ranks what it finds by severity, and exports an audit-ready CSV.

Runs on Confluence CloudFree for one spaceRead-only, never changes a permissionData stays in your Atlassian tenant

Nobody knows who can read the private spaces.

Confluence permissions are set one page at a time, by whoever happened to be editing that day, over years. There is no single screen that answers the one question every security review asks: who can actually get to this, and who can change it.

Restrictions scattered across thousands of pages

Every page can carry its own view and edit rules. Checking them by hand means opening each page and reading a dialog. Nobody does that, so nobody knows.

Edit rights that quietly do not inherit

View restrictions cascade down the page tree. Edit restrictions do not. A locked-looking parent can sit above child pages that anyone in the space can rewrite.

Auditors want evidence, not screenshots

SOC 2 and ISO 27001 reviewers ask for a list: every restricted page, who can see it, who can edit it, and what you did about it. Assembling that by hand takes days.

Every finding, ranked by how much it should worry you.

PermPilot does not hand you a wall of undifferentiated data. It reads each page’s real permission state and sorts it into five levels, so you fix the dangerous ones first and ignore the ones that are already correct.

Critical

Restricted to view, wide open to edit

The page is view-restricted but carries no edit restriction, so everyone who can still open it can also rewrite it. This is the gap Confluence hides, because edit restrictions do not inherit down the tree the way view restrictions do.

High

A guest or external account on a restricted page

Someone outside your organisation is named on a page you deliberately locked down. Usually a leftover from a project that ended a year ago.

Medium

A deactivated user still named in the restriction

The account is gone but the grant remains. Harmless until the account is reactivated or the identity is recycled.

Low

Edit-locked but readable by the whole space

Often intentional, sometimes not. Worth a look when the space is large or the content is sensitive.

Locked

View and edit both restricted

The correctly secured state. Listed so you can prove it was checked, not so you have to act on it.

Three clicks from install to a finished audit.

No configuration, no service account, no data export. PermPilot runs inside Confluence with your own permissions, which is what lets it evaluate the restricted pages you are entitled to see.

1

Install from the Marketplace

PermPilot is built on Atlassian Forge and installs onto your Confluence Cloud site like any other app.

2

Pick a space, or all of them

Open Apps then PermPilot, choose a single space or your whole site, and click Run audit.

3

Fix, then export the proof

Every restricted page is listed with its space, breadcrumb path, viewers, editors and severity. Click through to fix it in Confluence, then export the CSV for your reviewer.

PermPilot is read-only. It reports on permissions and never changes them. Full setup notes live in the PermPilot documentation.

Start free on one space.

Audit a single space at no cost, with the full severity breakdown. Upgrade when you need the whole site and the compliance export. Billing and trials are handled by Atlassian.

Free

  • Audit one space
  • All five severity levels
  • Full viewer and editor lists
  • Click through to fix in Confluence

Paid

  • Audit every space at once
  • CSV compliance export
  • A recommendation per page
  • Built for SOC 2, ISO 27001 and internal reviews

Find out what your restricted pages are really exposing.

Install PermPilot on your Confluence Cloud site and run your first audit in about a minute. Nothing leaves your Atlassian tenant.

Get it on the Atlassian Marketplace