Overview

The Confluence integration automates access reviews: it builds a roster of every user on your Confluence site, along with the groups they belong to and whether they hold administrative access. LowerPlane only ever reads data from Confluence — it never creates or modifies pages, spaces, users, or configuration.
This integration reads users and groups only. It does not read page content, spaces, or site settings.

Prerequisites

You need admin access to your Confluence site to authorize the OAuth connection. The consent screen asks you to choose which site to grant.

How to Connect

1

Start the connection

Go to Settings > Integrations in LowerPlane, find Confluence, and click Connect.
2

Authorize access

You are redirected to Atlassian. On the consent screen, select your site (e.g. yourcompany.atlassian.net) and approve the following access:View (read:confluence-user, read:confluence-groups)
  • View user information — account IDs, display names, and email addresses.
  • Retrieve user groups and their membership.
LowerPlane also requests offline_access so it can refresh the connection without re-authorizing.
3

Add as a critical system

To include Confluence in access reviews, go to Personnel > Access Reviews, click Add Critical System, and select Confluence.

What LowerPlane Monitors

User Accounts

Every account on the site, with account type so bot and app accounts are separated from people.

Group Memberships

Which groups each user belongs to, used to derive their role.

Administrative Access

Users holding site or Confluence administrator rights, tracked separately from general access.

Offboarding Status

Accounts cross-referenced against your HR system to catch access that outlived employment.

Checks Automated

CheckWhat It Verifies
Confluence access should be removed for offboarded userNo account remains active for an employee terminated in your HR system
Confluence user should be identifiedEvery account traces back to a named individual rather than an anonymous or undocumented one
User access to critical Confluence system should be validAccess is current and approved for each active user

Frameworks Supported

FrameworkWhat It Proves
SOC 2Logical access is authorized, reviewed, and revoked on termination (CC6.1, CC6.2, CC6.3)
ISO 27001Access rights are provisioned, reviewed, and removed as employment changes (A.5.16, A.5.18)
PCI-DSSUser identification and access revocation are enforced (8.1.3, 7.1.4)
HIPAAWorkforce access is authorized and periodically reviewed (164.308(a)(4))

Limitations

MFA status is not available. Confluence’s API does not expose per-user two-factor status. That data lives in the Atlassian organization admin API, which is a separate connection.
Email visibility affects offboarding checks. Atlassian only returns a user’s email address when the site’s profile visibility settings permit it. Without an email, an account cannot be matched to an HR record, so offboarding cannot be verified for that user.