Compliance Glossary for Confluence

How do I explain a finding to an auditor?

Use the finding record as the response spine. In Compliance Scanner, record status, owner, due date, severity, justification, and closure evidence. The app stores the page ID, term ID, actor, and decision time. Re-scan after remediation. Then generate an Audit Evidence Package so the auditor can correlate the resolution with page status and retained scan history.

Last verified against production v6 · 26 September 2026

At a glance

EvidenceRecorded dataAuditor useLimit
Scanner findingPage, term or candidate identifier, finding type, message, and contextExplain what the scanner foundSource page body text is not included in the evidence export
AcknowledgeStatus plus optional owner, due date, and severityShow that remediation has been acceptedAcknowledgement does not fix the page or term
JustifyHuman-entered Justification...Explain why the current usage is acceptedA non-empty justification is required
CloseHuman-entered Closure evidence...Record the evidence used to close the workClosure evidence is required; closing does not execute the remediation
Resolution savePage ID, term ID, canonical term name when available, status, actor, and timeIdentify who recorded the current disposition and whenThe same finding key stores the latest resolution state, not every resolution transition
Follow-up scanPage status, finding count, scan time, page version, and glossary revisionShow the terminology state observed after the responseA scan proves its recorded point in time only
Download Evidence Package CSVfinding_resolution, page_status, and scan_history rowsCorrelate records by page and term identifiersRows are separate; the app does not write an auditor narrative
Open Print-Ready PackagePage scan status and a Finding Resolutions tablePresent a readable evidence summaryThe printable resolution table omits page and term IDs; use CSV for identifier-level correlation

How it works

  1. Open Compliance Scanner and locate the page-level finding.
  2. Record Owner..., due date, and Severity.
  3. Select Acknowledge when the work is accepted.
  4. If the usage is an accepted exception, enter Justification... and select Justify.
  5. If the issue is remediated, enter Closure evidence... and select Close.
  6. Select Scan Space after the page or glossary change.
  7. Open Audit Evidence Export.
  8. Set Evidence scope, Period from, and Period to.
  9. Select Generate Evidence Package, then Download Evidence Package CSV.
  10. Correlate the finding_resolution row with page_status and scan_history by Page ID. Use Term ID for the governed term record.

Example

A scan flags “AE” as a non-preferred synonym on page p1. The QA lead records high severity and a due date, then selects Acknowledge. The page is updated to “Adverse Event.” The lead enters the approved change record under Closure evidence... and selects Close. A follow-up scan records the current page version. The CSV contains the resolution, actor, time, page ID, term ID, and separate scan evidence.

What this does not mean

A resolution is a human-recorded disposition. It does not edit Confluence content, approve a term, or certify compliance. The stored record reflects the latest resolution state for that finding key. Scan history is separate evidence. Correlate it by page and time. Keep the exported CSV when page and term identifiers are required; the print-ready package is a summary.

Related questions

Next step

Record one complete disposition, run the follow-up scan, and export the scoped CSV before the auditor review.

View on Atlassian Marketplace
Verification basis: production v6 code, tests, manifest, and operations guidance. Verified 26 September 2026.