Security
How Group Watch for Confluence keeps your site safe.
Runs on Atlassian
The app is built on Forge, Atlassian's app platform. It runs inside Atlassian's cloud, has no servers of its own, and sends no data outside Atlassian.
Least access
The app asks Confluence only for what it needs: read groups and their members, check who can view a page, read the page tree, read edit counts for the email estimate, and add or remove watches. It never edits page content and never changes permissions. (Confluence has no watch-only permission, so the app holds the general “write content” permission that adding watches needs.)
Who can change rules
- Only Confluence admins can open the admin page, unless they let space admins manage rules for their own spaces.
- A rule's preview counts every member of the chosen groups and every child page under the chosen page, including pages the person previewing can't open. It shows counts only, never names or titles.
- The app checks who is asking on every request, using Atlassian's own sign-in. It never trusts a user id sent from the page.
- Every rule change, sync now, undo, pause and clean-up is written to the activity log with who did it and when.
Safe by design
- The app keeps an exact record of the watches it made, and only ever removes those. It never removes a watch someone set up themselves (one known limit: see the FAQ).
- People only get watches for pages they can already see. The app never grants access.
- Preview, big-rule guard, a size cap, pause and undo stop mistakes from spreading.
- Logs record ids and counts, never names or email addresses.
Data
Stored only in Atlassian's Forge storage and deleted on uninstall. See Privacy.
Report a security issue
Email hello@goldstandardweb.com with "Security" in the subject. We treat security reports as critical and reply within 24 hours.