Manage app access in Confluence spaces 

When you install a marketplace or private app in Confluence, there are two ways the app gains access to spaces automatically, depending on the scopes the app has.

How apps get space-level access across Confluence

Access level

How space access is granted

As an individual app user

Connect and Forge apps that hold write scope are granted the default Admin role automatically* in all new Confluence spaces created after the app is installed.

This can be updated later by users who can manage access in the space.

Through the default Confluence users group

Connect apps that don’t hold write scope and Forge apps that don’t hold write || delete scopes are not directly granted individual access to Confluence spaces automatically.

On most sites, these apps inherit their access from the default Confluence user group, which they are automatically added to.

*For sites not using Confluence’s role-based access, all space permissions except export space, delete own content, manage access to individual content, and archive content are granted to apps that hold write scopes (connect apps) and write || delete scopes (Forge apps) automatically.

Confluence admins can configure what role, default or custom, is granted to Connect and Forge apps when they’re added to a site during space creation in System operations. They can also choose that no role be granted automatically to apps that are added to the site. For more broad-scale controls, you can block Marketplace and custom app access with Data security policies.

Still need help?

The Atlassian Community is here for you.