Compliance Glossary for Confluence

Which content is included in Confluence audit evidence?

Audit scope is the evidence boundary you declare and then validate against recorded coverage. In Audit Scope Register, name included and excluded spaces, pages, repositories, and paths. Add Glossary revision, Last scan timestamp, and Scope notes. Then compare the declaration with Space Pages Status and baseline coverage. Declared fields do not enforce page, repository, or path filtering.

Last verified against production v6 · 26 September 2026

At a glance

InputApp actionOutputLimit
Included and excluded spaces, pages, repositories, and pathsSaves the declared boundaryAudit Scope Register attached to evidence exportsThese fields are metadata; they do not enforce filtering
Glossary revision, Last scan timestamp, and Scope notesSaves context with the declared boundaryScope context in CSV and print-ready evidenceThese are administrator-entered values, not automatic proof
All spaces or one selected Confluence space, plus Period from and Period toFilters stored scan and resolution evidenceA scoped evidence packageThe server also applies an evidence record cap
Current page list and stored scan resultsCompares pages with available scan evidencePassed, Needs attention, Stale, or Not checked in Space Pages StatusMissing or old evidence remains visible; it is not counted as current coverage
Selected Governed spaces for a freezePins the server-owned scan snapshot and measures captured evidenceBaseline scope and a Baseline evidence reportCoverage can remain incomplete and must be reviewed

How it works

  1. Open Audit Evidence Export.
  2. Complete Audit Scope Register. Record declared inclusions and exclusions.
  3. Add Glossary revision, Last scan timestamp, and Scope notes.
  4. Select Save Scope Register.
  5. Choose All spaces or one space. Set Period from and Period to when needed.
  6. Select Generate Evidence Package.
  7. Compare the export with Space Pages Status and the Baseline evidence report. Investigate gaps before presenting the package as complete.

Example

A review covers the OPS and QA spaces but excludes ARCHIVE. The register declares those spaces, the relevant policy pages, one repository, and approved paths. The export is generated for OPS and the review period. Space Pages Status shows one page as Not checked. The declared boundary is clear, but coverage is incomplete until that page has current scan evidence or a documented exclusion.

What this does not mean

The Audit Scope Register records intent. It does not fetch every declared page, repository, or path. It does not prove that every item was scanned, captured, or frozen. Export filters are limited to the selected Confluence space, evidence period, and server record cap. Baseline scope is separate and uses the selected Governed spaces.

Related questions

Next step

Define the boundary in Audit Scope Register. Then confirm that scan and baseline evidence cover every included item.

View on Atlassian Marketplace
Verification basis: production v6 code, tests, manifest, and operations guidance. Verified 26 September 2026.