Compliance Glossary for Confluence

What should security teams review?

Security teams should review Forge permissions, Confluence read scopes, storage, GitHub egress, data types, retention, roles, licensing, upload limits, and failure handling. They should also confirm product boundaries. These include no certification, legal WORM storage, release approval, or signature execution.

Last verified against production v6 · 26 September 2026

At a glance

InputActionOutputLimit
Current Forge manifestReview modules, scopes, and egressDeployed permission modelRecheck after every manifest change
Evidence data modelReview SQL, Object Store, and legacy KVS useStorage and retention understandingRegional behavior follows current Atlassian services
GitHub connectorReview repository binding, paths, credentials, and egressApproved external access modelCurrent visible workflow is report-only terminology checking
Uploaded evidenceReview type, size, hash, parser, and retention controlsFile-ingestion risk modelSuccessful parsing is not content approval
Administrative rolesReview term-manager and license gatesAccess-control evidenceOrganizational authority remains external

How it works

  1. Review the current production manifest.
  2. Map each data type to its storage path and retention state.
  3. Review GitHub egress and repository restrictions.
  4. Validate administrator roles and inactive-license behavior.
  5. Review file upload limits and failure states.
  6. Record accepted risks and required controls outside the app.

Example

A procurement reviewer confirms that Confluence access is read-only, enterprise evidence uses Forge storage, and GitHub API egress is declared. The reviewer also records that the app is not eligible for a no-egress designation in this configuration and does not provide WORM storage.

What this does not mean

This page is a review checklist, not a security certification. Customers must assess the current deployed version, Atlassian platform terms, their configuration, and their own risk requirements.

Related questions

Next step

Review the current manifest and data flow before approving production use.

View on Atlassian Marketplace
Verification basis: production v6 code, tests, manifest, and operations guidance. Verified 26 September 2026.