Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Announcement: A new phase of role-based access in Confluence is here

Roles are coming to Confluence, and the next phase is here

If you’ve been following along over the past few years, you know that Confluence is on a mission to make managing user access exponentially easier. In March, we launched a new way to share in Confluence, and since June, Confluence roles have been available in Beta.

image-20251106-120227.png

 

Today, we’re announcing the next phase of our Confluence roles rollout, which has 3 parts:

  1. Tools to plan your roles rollout
  2. A roles-only access experience for new Confluence sites
  3. Changes to Cloud data migrations experiences to ensure backward compatibility across access modes

 

1. Tools to plan your roles rollout

To help you plan for Confluence roles, we’re introducing two new resources for Confluence admins — Roles Central and permissions data exports.

Roles Central

Roles Central is a one-stop shop for your transition — all the tools and everything you need to know to assign roles to users across your whole site. 

roles-central.png

Export permissions data

Before you can start assigning roles, you’ll likely need a plan. To create that plan, you’ll need a clear picture of how permissions are being used across your site. Enter permissions data exports.

First, you can get a complete view of all the combinations of individual permissions currently used on your site, ordered by most commonly used. Second, you can export the full access lists of each space on your site.

Together, these 2 exports will help you:

  1. Understand how your current permissions map to Confluence’s default roles
  2. Plan what custom roles you’ll need to create

export-permissions-data.png

*Note: All Confluence admins, whether your organization is enrolled in the roles beta or not, will have access to these resources directly in Confluence settings.

 

2. Roles only experience for new Confluence sites

To simplify the space access administration experience for new customers, we’ve made it so that when you create a new Confluence site (in a new or existing Atlassian org), it will use roles, and only roles, for managing space access.

This means that everything from site defaults to space access, Company hub access to Automations that set and update space access, will all do so using roles. There won’t be an option to assign any access with individual permissions, without a role.

space-defaults.png

company-hub-roles.png


3. Backward compatibility support for Cloud data migrations

To ensure all permissions data is safely transferred when running cloud data migrations, the destination Confluence Cloud instance’s space access mode will always land in “roles transition” mode, also known as roles beta. 

Learn more about each migration flow and if it’s impacted by these roles changes.

 

The future: all customers will get roles

We can’t wait for the roles beta to come to an end and for every customer to have roles, and we’re hard at work building some exciting features to help with your transition.

For now, we recommend familiarizing yourself with the resources in Roles Central where you can get an up-to-date picture of your site’s permissions data, see how your site and spaces are set up, and plan for the types of roles you’ll need.

 

Thanks!

The Confluence Permissions team

6 comments

Ajay _view26_
Community Champion
November 17, 2025

Thanks @Marie Casabonne  for the headsup! 

Quick Query -  With Confluence moving to a roles-based access model, what is the expected impact on Marketplace apps—especially those that read space permissions, validate user access, or perform actions on behalf of users? Do we anticipate changes in permission-related APIs, app-user behavior, or how apps should interpret effective permissions when the underlying model shifts from granular permissions to roles?

Like # people like this
Will Stampley
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 18, 2025

Hey @Ajay _view26_ - there's three good questions in there.

With respect to impact on apps that currently change space permissions, we've already made a couple changelog entries for our marketplace partners to expose APIs they need to switch over to roles (and to write apps that tolerate the variety of role modes that exist across our customers today).

With respect to apps that read space permissions directly today, ideally they would consider moving over to role-based reads as well, though we haven't decided if we're going to remove the permission read APIs yet.

Authorization itself, especially for apps that perform actions on behalf of a user, shouldn't be impacted at all. The only tangential thing to consider in here that the RBAC changes also come with fine-grained space permissions that didn't used to exist - so whether a user can take an action or not might be controlled by a slightly different permission than it used to be controlled by (create vs. edit, manage users vs. administer space, etc.).

Like # people like this
Raimo
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 24, 2025

Hi @Marie Casabonne

Given that the Custom Roles are limited to 10, how are Marketplace Apps that manage Space permissions now supposed to define access to Spaces? If there are already 10 Custom roles in place and the installed app would like to define a new custom set of permissions which does not match any of the previous ones - what will happen or how to resolve this?

Rune Rasmussen
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
November 25, 2025

Two questions:

1. Do we know why there is a limit on how many custom roles we can create?
If you have a large user base and/or many different types of users/teams, I can easily envision a situation where 10 custom roles wouldn't be enough.

2. Is there any plan to bring in Permission Schemes?
Schemes work so well in Jira and they just make managing permissions a million times easier.

Christopher Kraft
December 4, 2025

Hi @Marie Casabonne 

When will the enterprise customers be moved into the roles transition phase? Is there a timeline? We need to plan the changeover with our admins and reserve the necessary capacity.

Thank you!

Like C_ Dicker likes this
Marie Casabonne
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 5, 2025

Hi @Christopher Kraft - We're looking to get the GA release onto our public roadmap in the next few months for all customers to follow the release date. A few important things to note about the GA release:

  • When roles is released, no access will change - all users, groups, etc. will still have the same access, represented as "custom access" in the roles system.
  • Roles will be available to start using, and you'll have tooling to transition your site from custom access to roles.
  • We'll be releasing enablement resources to make sure you and other admins have the support you need.

Eventually, we do plan to deprecate permission-based access / custom access. This deadline will be communicated with our GA release. 

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events