Compliance Glossary for Confluence

What audit evidence does the app produce?

Compliance Glossary produces four evidence layers. Version History records governed term decisions. Compliance Scanner records page status, findings, resolutions, and scan history. Terminology Baseline freezes term and scanned-page state for comparison. Enterprise evidence workspace adds hashes, verification, trace links, conformance, and portable archives. These records support an audit; they do not perform one or certify compliance.

Last verified against production v6 · 26 September 2026

At a glance

Evidence layerRecords producedPrimary useLimit
Term governanceCurrent term, status, version, actor, time, reason, and available communication evidenceReconstruct terminology decisions in Version HistoryOnly data recorded through the workflow is available
Page scanningLatest page status, findings, approved usage, page version, scan time, and glossary revisionShow the terminology state observed on a Confluence pageA scan is point-in-time evidence, not permanent page cleanliness
Finding responseStatus, owner, due date, severity, justification, closure evidence, actor, and timeExplain remediation or an accepted exceptionThe latest resolution state is retained for each finding key
Audit Evidence PackageTerm history, page status, retained scan snapshots, and finding resolutionsExport scoped operational evidence as CSV or a print-ready packageSource page body text is not included
Terminology BaselineFrozen glossary term states and scanned page states for selected spacesCompare changed terms, changed pages, usage, and new findingsThis Confluence baseline stores page versions, not content hashes or trace links
Baseline impactFrozen and current indexed term usage by pageIdentify observed pages affected by a term changeResults are bounded and can be marked truncated
Enterprise freezeFrozen meanings, artifact revisions, usage observations, findings, trace links, counts, coverage, and hash rootsDeposit a verifiable evidence packageCoverage depends on the records captured by each source adapter
Run verificationManifest count and root-hash checks, artifact checks, usage states, and trace endpoint statesSeparate conformant, incomplete, and nonconformant evidenceVerification checks recorded evidence; it does not validate legal conclusions
Trace graphApproved or imported links between evidence nodesFollow evidence forward or backwardCandidate links are not governed trace evidence
Export archiveOrdered, content-addressed parts and a root manifestMove a frozen package between controlled environmentsExport is a queued job and is complete only after final verification

How it works

  1. Define the audit question and evidence period.
  2. For current operational records, open Audit Evidence Export.
  3. Set Evidence scope, Period from, and Period to.
  4. Select Generate Evidence Package. Download the CSV or open the print-ready package.
  5. For a comparison point, open Terminology Baseline.
  6. Enter Reason for this baseline, select Spaces included, and select Create baseline.
  7. Review Baseline evidence report and Changed since baseline.
  8. For hashed integrity or cross-artifact trace evidence, open Enterprise evidence workspace.
  9. Resolve Coverage blockers, then select Run verification.
  10. Use Trace graph for evidence paths. Select Export archive for a portable frozen package.

Example

A release review needs decision, adoption, and integrity evidence. The team exports the approved term's Version History and the affected pages' scan records. A Terminology Baseline shows which term and page versions changed after the release point. The enterprise baseline verifies stored hashes and trace endpoints. Its archive packages the frozen evidence for controlled handoff.

What this does not mean

The app records terminology governance and related evidence. It does not run an audit, interpret a regulation, certify compliance, approve a release, or replace an electronic signature. Operational exports are not immutable signing systems. The standard Confluence baseline has explicit hash and trace limits. Enterprise conclusions remain limited by captured sources, coverage blockers, and unresolved checks.

Related questions

Next step

Choose the smallest evidence layer that answers the audit question, verify its coverage, and export the scoped records.

View on Atlassian Marketplace
Verification basis: production v6 code, tests, manifest, and operations guidance. Verified 26 September 2026.