Overview
The Confluence integration automates access reviews: it builds a roster of every user on your Confluence site, along with the groups they belong to and whether they hold administrative access. LowerPlane only ever reads data from Confluence — it never creates or modifies pages, spaces, users, or configuration.This integration reads users and groups only. It does not read page content, spaces, or site settings.
Prerequisites
How to Connect
Start the connection
Go to Settings > Integrations in LowerPlane, find Confluence, and click Connect.
Authorize access
You are redirected to Atlassian. On the consent screen, select your site (e.g.
yourcompany.atlassian.net) and approve the following access:View (read:confluence-user, read:confluence-groups)- View user information — account IDs, display names, and email addresses.
- Retrieve user groups and their membership.
offline_access so it can refresh the connection without re-authorizing.What LowerPlane Monitors
User Accounts
Every account on the site, with account type so bot and app accounts are separated from people.
Group Memberships
Which groups each user belongs to, used to derive their role.
Administrative Access
Users holding site or Confluence administrator rights, tracked separately from general access.
Offboarding Status
Accounts cross-referenced against your HR system to catch access that outlived employment.
Checks Automated
| Check | What It Verifies |
|---|---|
| Confluence access should be removed for offboarded user | No account remains active for an employee terminated in your HR system |
| Confluence user should be identified | Every account traces back to a named individual rather than an anonymous or undocumented one |
| User access to critical Confluence system should be valid | Access is current and approved for each active user |
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Logical access is authorized, reviewed, and revoked on termination (CC6.1, CC6.2, CC6.3) |
| ISO 27001 | Access rights are provisioned, reviewed, and removed as employment changes (A.5.16, A.5.18) |
| PCI-DSS | User identification and access revocation are enforced (8.1.3, 7.1.4) |
| HIPAA | Workforce access is authorized and periodically reviewed (164.308(a)(4)) |
Limitations
MFA status is not available. Confluence’s API does not expose per-user two-factor status. That data lives in the Atlassian organization admin API, which is a separate connection.
Email visibility affects offboarding checks. Atlassian only returns a user’s email address when the site’s profile visibility settings permit it. Without an email, an account cannot be matched to an HR record, so offboarding cannot be verified for that user.