A while back, someone in this community asked a question that stuck with me: their team hosts company policies in Confluence, and to stay ISO 27001 compliant, policies need version control and a clear approval trail. Inside Confluence, they said, that lifecycle stays intact. The moment someone exports or prints a page, though, it becomes an "uncontrolled copy," and they wanted a watermark that only showed up on exports, never on the live page, so anyone holding a PDF would know it might already be outdated.
It's a great question, and Confluence does earn the "controlled collaboration" part: every edit is timestamped, and history shows who changed what and when. Approvals are still taking shape, Confluence just opened a native Approvals workflow in beta (Premium/Enterprise, page by page), which is a real step forward, but until then, and outside those tiers, "approved" usually means a team built that step themselves. Either way, export is where the real gap shows up. The moment a page becomes a PDF, it's a frozen snapshot with no idea Confluence has moved on without it, and nobody holding that file can tell if it's still current, unless the page itself says so. That's what "compliant export" really means: making sure the document can explain itself once it's outside Confluence.
Watermarking fixes that, and it's usually the first thing people reach for: stamp the export with something like "uncontrolled copy if printed" plus the version or export date, and the file flags its own shelf life.
Worth clearing up first: Confluence itself now has a watermarking feature (Enterprise Edition), and it does something different from what most people picture in a compliance conversation.
Confluence's built-in watermark applies to images. Admins can overlay a logo or a viewer's user ID across images wherever they appear, mainly to discourage someone from lifting a diagram or screenshot and passing it off as their own. Useful for protecting visual IP, but it won't stamp "Draft" or "Confidential" across a full PDF.
For labeling at a file level, you're looking at something like Scroll PDF Exporter, where the watermark is a text label (Draft, Internal Only, Uncontrolled Copy) running across the entire document, every page, not tucked in a corner.
Before dynamic watermarking, a common workaround was a customizable background instead of a watermark, a label rendered onto the page during export without touching the live Confluence page. It works, but it's static: it tells a reader "this is a draft," not who exported it or when.
That's where a dynamic watermark helps. Pulling from the same placeholders used elsewhere in your templates, it can carry the exporter's user ID or name and the exact date and time of export, not just the document type. Instead of "Confidential," you get "Confidential, exported by jdoe on 2026-07-19, 14:32." 😉 If that copy turns up somewhere it shouldn't, you're not guessing who took it. Here's how to style a watermark and add placeholders like these.
If that feels like too much sitting across the page, those same details can live in a header or footer instead, letting the watermark stay a simple "Confidential" or "Internal Only."
Even so, with enough patience, any of this can be edited or cropped out. A watermark, dynamic or not, tells you who exported the file and when. It doesn't stop that file from being forwarded or screenshotted. So, a watermark is more of a “do not trespass” sign rather than a gate.
A few other Scroll Documentation Platform features round this out, worth knowing even if watermarking is your starting point:
Adjustable metadata. Title, author, subject, and keyword fields get baked into the PDF itself, not just visible in Confluence. Whoever builds the template decides how much control the exporter gets: locked for governance, or left open per export. Same choice applies to the watermark and other export settings.
PDF/A-3 and PDF/UA compliance. PDF/A-3 locks in long-term archival integrity, embedding fonts and removing external dependencies so the document renders identically years from now. PDF/UA adds the tagged structure screen readers rely on. For teams under WCAG or Section 508, skipping this is its own compliance gap.
The approval step. Confluence's new Approvals, mentioned above, covers this well if you're on Premium or Enterprise, but it's built for one page at a time. If you need sign-off to span an entire page tree, or you're not on those tiers, Scroll Content Manager's Draft / In Review / Approved workflow closes that gap. Once you save a version as a snapshot, it can be locked in place, permanently, even as the live page keeps evolving around it. Pair this with Scroll PDF Exporter's Version Name and Document ID placeholders, and that snapshot's identity gets stamped right onto the exported PDF, so what you export later traces back to a specific, unchangeable moment in time.
Who's allowed to export at all. Disclaimer: on Confluence Cloud, this isn't something you can restrict yet with Scroll PDF Exporter. Anyone with view access can export the content. Prevention is the piece none of the other controls on this list cover, and it's on our roadmap for Scroll PDF Exporter. If restricting who can export is a real blocker for your team today, we'd genuinely like to hear about it.
Stacked with a dynamic watermark, these start to look like an actual export policy instead of a single label.
A reasonable starting point for teams handling anything sensitive or regulated:
Add a watermark template for draft, internal, and uncontrolled-copy states, dynamic if you can, so it names who exported the file.
Decide upfront whether the watermark and metadata should be locked or customizable at export time.
Enable PDF/A-3 and PDF/UA compliance if archiving and accessibility are part of your compliance picture.
Keep the underlying pages properly versioned and reviewed, so the export is trustworthy in the first place.
Watermarking is often the first thing people reach for; it's visible, quick, and solves a real problem. Just worth remembering it's one layer, not the whole picture. If you want to see it done well, our Template Library has a few examples worth borrowing from.
Curious how this is playing out for others here: are you relying on watermarks alone, or has your process become a stack of smaller controls?
Cheers, Ericka (K15t)
If you want a hand setting any of this up, reach out to us anytime at help@k15t.com.