Hey everyone!
The rollout of Role-Based Access on Confluence has been a great step forward for managing user permissions more granularly — really loving it so far!
That said, it got me thinking about how to best handle app access on spaces, and I'd love to hear how others in the community are approaching this.
Specifically:
Are you using one of the standard roles provided by Atlassian for your apps, or did you find them too broad?
Did you create dedicated custom roles for apps — either a single generic one or several depending on the app's purpose?
Any feedback, tips, or real-world examples are welcome. Thanks in advance for sharing! 🙏
@Patrice Champet , good question, and it is the one the RBAC rollout leaves for admins to answer on their own, because app access is where the "role equals a bundle of permissions" model meets a user that is not a person.
What I have landed on: one custom role per app purpose, never a standard role, and never one role for all apps. The reasoning:
Two things to check before building any of this: custom roles need a plan that supports them (Premium or Enterprise), so on Standard the honest answer is the least-broad standard role plus space restrictions; and the fallback role you set for the site applies to apps too, so an app added to a space with no explicit assignment inherits whatever the fallback grants. That second one is the thing I would verify first on any site: open a space's People list, find the app users, and see which role they actually hold today. In the estates I have looked at, the answer was rarely the one the admin expected.
I would be interested in what the app vendors themselves say when you ask which permissions their app needs at minimum; the good ones answer with a list, and the list is the role.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.