Diagnostic TeardownATLASSIAN

Confluence Access Is Three Different Questions, Not One Permission Switch

Author
Alex Florian
Published
Updated
Reading time
4 min

“Can you open this page up for me?” may be a request from someone who cannot enter Confluence, someone who cannot reach a space, or someone who can read the page but cannot edit it. The wording is similar because the person wants the same thing: to finish their work.

The repair depends on which experience they mean. Giving someone broader access before locating the failure can remove a legitimate restriction along with the complaint.

Confluence organizes content into spaces and pages. Entry to the application, permissions within a space, and restrictions on content answer different questions. The intended action matters too: reading a page is not the same permission as editing or administering it. [1][2][3]

Start with what already works

A building is a useful mental picture. Getting through the front door doesn't give you access to every room, and entering a room doesn't authorize every activity inside it. For Confluence, the equivalent first step is to establish how far the affected account gets.

What the colleague can doA more specific question to investigate
Sign in, but not enter ConfluenceDoes this account have the required application access under the site's setup?
Enter Confluence, but not reach the intended spaceWhat space-level access reaches this account?
Open the space, but not one pageWhat content restrictions or relevant parent visibility affect this page?
Read the page, but not edit itWhich controls allow editing for this account and content?

These are starting points, not guaranteed diagnoses. The permissions and restrictions active in the actual environment still determine the answer.

Consider a hypothetical colleague who can use the space normally but cannot read one decision page. I would start by establishing whether that page is meant for them. A restriction may be functioning exactly as intended. The administrator can explain the effective controls; the content owner can confirm the intended audience.

Sometimes the answer is help without wider disclosure

Suppose the page contains a sensitive decision, but the colleague only needs to know which application they should use afterward. Granting access to the entire discussion may be unnecessary. An appropriate summary or a separate instruction could let them continue while keeping the decision's supporting material restricted.

That is a different outcome from simply refusing to help. It takes the person's need seriously without assuming that the page is the only way to satisfy it.

When access should be granted, a maintained group or role can make the relationship easier to understand than repeated unexplained exceptions. Its name is not enough, however: the membership may confer access elsewhere. The change needs to fit the legitimate task rather than merely make the current link open. [1][2]

If most content in a collaborative space requires its own exception, the space's normal audience may no longer match the work being stored there. Another page restriction can be valid while the wider arrangement still deserves reconsideration. That is a design question, not proof that all restrictions should disappear.

Repeat the colleague's route after the change

An administrator's successful preview doesn't demonstrate that the affected colleague can follow the same direct link, navigation path, or search result. Use the account and action that produced the complaint as the comparison.

For sensitive content, also check a person or action that should remain excluded. Both results matter: the intended reader gains access, and unrelated readers do not. Several simultaneous broad grants make it difficult to tell which change was necessary or how much extra access was introduced.

The person asking for help doesn't need a lecture on every administrative layer. A good resolution can be brief: the missing permission was identified and appropriately changed, or the needed information was supplied through an authorized route. Either leaves them able to work without turning a request for one answer into permission to read everything around it.