Hey everyone đź‘‹
We’ve made the Confluence roles system a lot more flexible. Fewer forced permissions dependencies, more room to build custom roles that match how your team actually works, and no more requirement to have a full Admin in every space. Already in the roles beta or using roles exclusively? These changes are rolling out to you now. Here's what's new and what's possible with these updates!
With the most recent permission splits that introduced more granularity and control into the custom roles system, this permission no longer "manages everything." To be more accurate, we’ve renamed it to Manage space features, automation. This covers space-level features, automation, and integrations.
Previously, the custom roles system had strict hierarchical permissions rules. For example, you couldn’t hold the Manage access to space permission without holding all content-level permissions. We’re removing the most strict dependencies, and only keeping those that are essential, like:
This allows for more flexible custom roles, like an Admin who can manage the space but isn't allowed to manage users or delete sensitive data.
| Note: For customers in the roles beta, which supports both roles and permissions for managing space access, anyone with the Manage space features, automation and Manage access to space permissions can still manage all access in the space. This means former legacy admins won't lose control during the transition from permissions-based access to roles. For new sites in roles only mode, the system switches to "grant what you have" logic: users can only grant permissions they themselves hold. Confluence product admins are exempt and can still grant or remove access with any role. |
You no longer need to grant full Admin rights to at least one user or group in every space. You can now create "Lite" Admin roles by stripping away sensitive permissions (like deleting or exporting) while still allowing them to manage the space.
Managing Analytics and Apps is now controlled by the Manage access to space permission (instead of "Manage everything"). This change groups these actions with other controls that manage access to your space.
Impact: The default Manager role now includes the ability to manage app and analytics access.
Everything above sets the stage for what's next: Role-based access GA, starting in July. These are the final foundational changes ahead of the GA release:
Thanks,
The Confluence Permissions team
Marie Casabonne
3 comments