PermPilot Documentation

PermPilot is an access and permission auditor for Confluence Cloud. In one click it shows who can view and edit every page across a space or your whole site, flags permission risks by severity, and exports an audit-ready CSV report.

Getting started

  1. Install PermPilot from the Atlassian Marketplace on your Confluence Cloud site.
  2. In Confluence, open Apps → PermPilot.
  3. Pick a space (or All spaces) and click Run audit.

The audit runs with your permissions, so it can evaluate the restricted pages you are entitled to see. Auditing is read-only and never changes anything. Changes only ever happen if you explicitly choose to fix a finding, described below.

Understanding the findings

  • Critical. A page is restricted for viewing but has no edit restriction. Anyone who can still view it can also edit it. Edit restrictions do not inherit down the page tree in Confluence, which is why this gap is common and invisible.
  • High. A guest or external account appears on a restricted page.
  • Medium. A restriction still names a deactivated user.
  • Low. A page is edit-locked but readable by all space members.
  • Locked. Both view and edit are restricted. This is the correctly secured state.

The report

Every restricted page is listed with its space, breadcrumb path, who can view, who can edit, and severity. Click any page to open it in Confluence and fix its restrictions. Export CSV produces a compliance report with a recommendation per page, suitable for SOC 2, ISO 27001, and internal security reviews.

Fixing findings

PermPilot can close two of the findings it reports. Both are optional, and neither runs unless you start it.

  • Match edit to view (Critical). Applies an edit restriction matching the page’s view audience, closing the inheritance gap above.
  • Remove deactivated users (Medium). Clears restriction entries naming accounts that no longer exist.

Before anything is written, PermPilot shows you the exact change it will make on every page and lets you export the current restrictions as a CSV, so you always have a record of the state you started from. It re-checks each page immediately before writing, skips any page where the finding no longer applies, and if one change in a page fails it reverses that page’s other changes rather than leaving it half-applied.

Two things it deliberately will not do. It refuses any change that would widen access rather than tighten it, so it will never remove the last remaining viewer from a restriction. And it leaves guest, external, and “readable by everyone” findings alone, because deciding who should have access is a judgement call rather than a mechanical fix.

All writes run with your own Confluence permissions, never the app’s. PermPilot cannot change anything you could not change yourself, and anything you lack rights to simply fails and is reported back to you.

Free vs paid

The free plan audits one space with full severity findings. A paid license unlocks auditing all spaces at once, the CSV compliance export, and fixing findings. Billing and trials are handled by Atlassian.

Data security

PermPilot is built on Atlassian Forge and runs entirely inside your Atlassian tenant. No page content or permission data ever leaves Atlassian. See our privacy policy.

Support

Email [email protected]. We reply within one business day.