Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

📣 Beta: Simplify space access in Confluence with roles

Hello Confluence community đź‘‹

Say goodbye to cognitive overload with the current granular permissions table in Confluence! We’re excited to announce that starting next week, we will begin the opt-in beta rollout of one of our top-requested features: Managing space access with roles.

 

before-after-roles.png

 

Confluence’s roles are preset configurations of permissions that can be assigned to users, groups, guests, and user classes. They give you confidence in what each user can do and make managing space access in Confluence more consistent, predictable, and scalable.

 

 

Starting on Monday, June 16, and rolling out to all Confluence Cloud Standard, Premium, and Enterprise sites over the next two weeks, product admins will see the option to opt their Confluence site into the role-based access control beta in the New features section of Confluence administration.

 

Simply select a role

Within the Users table, the 14 individual permissions checkboxes to assign access to each user, group, guest, app, or user class will be replaced with a role selector. Out of the box, you’ll have access to 4 default roles: Admin, Manager, Collaborator, and Viewer. Custom roles will be listed underneath them.

roles.png

View each role’s individual permissions

From the Users table, you can easily audit all permissions associated with a role and, if necessary, make changes either by selecting a new role or adding/removing permissions for that individual.

If a user or group has permissions that don’t map to any role, they will have their access listed as “Custom access” in the role selector. This means that they have no role selected and instead only have individual permissions assigned (a.k.a., the old access model). Simply choose a role from the selector to give them permissions and enjoy the clarity and consistency of a role-based system.

role-permissions.png

 

Create custom roles

Custom roles let you tailor access to fit your organization’s unique needs beyond what Confluence’s 4 default roles support. Confluence admins can define the exact permissions, name, and description for up to 10 custom roles, making it easy to match internal workflows and ensure the right people have the right access. Learn more about creating and managing custom roles.

Create custom role.gif

 

New permissions offer added control

To create the Manager role (and, overall, additional levels of control), we split some permissions into smaller pieces. This doesn’t change anyone’s access; it simply offers more granular options for fine-tuning.

For example, anyone holding the Admin permission before landing in the roles beta experience will still hold all of the permissions split off from the original Admin permission after landing in the roles experience. The difference is that you can now choose to give them individual pieces of the original Admin permission without giving them permissions to manage everything in the space. 

permissions-splits.png


Note
:
People with the Manager role can’t assign or revoke the following individual permissions or assign roles that include them:

  • Manage everything in the space

  • Export space

  • Archive space

  • Delete space

  • Allow and manage anonymous access

 

Manage access at scale with user classes

Assign roles to different classes of users, like All Confluence users or All Confluence admins, to grant general access to spaces, regardless of group membership. Learn more about user classes.

user-classes.png

 

Manage it all from a single table

Instead of three separate tables to manage permissions for users, groups, and guests, you now have a complete view of access from a single, easily searchable Users table.

users-table.png

 

Audit all sources of access for a user in a space

Having trouble identifying all the different ways a user can access your space? You’ll now see all sources of access when you search the individual user in a space’s Users table.

A user’s ultimate access is the combination of permissions from all of these sources. Learn more about the additive permissions concept in Confluence.

audit-access.png

 

Assign roles in bulk

Easily add users, groups, and user classes to all spaces with a particular role (or remove access from all spaces) in a single flow.

bulk.png

 

Share your feedback

As your organization explores and uses roles, we’d love to know what you think about it! Let us know what you love about using roles, any challenges or gaps you encounter, and suggestions for how we can make roles even better. Your feedback is invaluable as we continue to improve and prepare for our next release.

rbac-feedback.png

 

What to know before turning on roles

Once turned on for your Confluence site, roles can’t be turned off, so make sure you’re ready. If in doubt, try it out in a safe environment first.

Roles beta works best for:

  • New customers
  • Customers with smaller or simpler organizational structures
  • Confluence instances with permissions configurations that easily covered by the beta's role offering (4 default roles + 10 custom roles)

Consider testing it out first in a safe, non-production instance if:

  • Your organization is large or complex
  • Your instance has a lot of spaces
  • You want to assign custom roles to guests (not supported yet)
  • You’re currently migrating or plan to migrate soon

Once the beta is enabled for your Confluence site:

  • The UI will shift from a granular permissions table to a role selector. You’ll notice the new, split-off permissions available, but no one will have any different access than they had before. Whatever they had before, they’ll have the same after.
  • Each user’s access level in the role selector will be represented as “Custom access” and can easily be updated to a role from there.
  • We recommend that your first step be choosing roles in default access for new spaces. This make sure your new spaces start on roles and don't have to be converted to roles in the future!

 

Learn more about roles

 

We are committed to making managing space access in Confluence with roles the best it can be, and are eager for you to join this beta and help us improve the experience for all Confluence users.

 

- Marie & the Confluence Permissions team

13 comments

Brita Moorus
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 14, 2025

This is a fantastic update - huge thanks to the Confluence team for delivering one of the most requested features! 🙌

The role-based access model looks like a big win for clarity, scalability, and governance. I especially appreciate the ability to audit access more easily and assign roles in bulk - those will be game-changers for larger teams. The ability to define up to 10 custom roles is also a great balance between flexibility and control.

Looking forward to testing this out in a staging instance next week. Keep up the great work!

Like • Josh likes this
Tami Dubi
Contributor
June 14, 2025

Hi,
Thanks for the information. 
1. Will everyone be able to see the users through the users' sidebar?
2. Will you enable regular contributors to create templates, in addition to Admins?

Thanks,
Tami

Tomislav Tobijas
Community Champion
June 15, 2025

I can just say we've been in EAP for a while now in our main instance and it was an instant win once we switched from the old experience to using permission roles. đź’Ş

Also, some of our clients asked about this and I'm glad we can now tell them this is in beta 🙂

Like • # people like this
__ Jimi Wikman
Community Champion
June 15, 2025

AMAZING!! 
I love it!!

Like • Josh likes this
Marie Casabonne
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 23, 2025

Thanks for all the positive feedback so far, folks! 

@Tami Dubi - the Users table will only be viewable to users who are able to manage access in the space. In terms of our default roles, that means on users with the Admin or Manager role will see the "Users" table in space settings. 

Creating templates in the space is still tied to the admin-level permission in the space, now called 
Manage everything in space

Shahriman Mohammad June 23, 2025

Hi @Marie Casabonne 

May i know if this implementation have any impact on the existing confluence cloud rest api for space permission ?

We had submit registration to participate on the EAP, but until now we did't get any response and could't test this before it go to Beta.

 

Thanks,

Shahriman

Martin James
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 25, 2025

I've enabled the beta on our sandbox. Looks very interesting but still a little disappointing that app permissions continue to blend in with user permissions. All it does it creates a lot of noise and gets in the way when you need to manage user access.

Would be good if we could have a separate filter for app permissions:

app perm.png

 

 

Marie Casabonne
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 25, 2025

Hi @Shahriman Mohammad - there are new APIs for new roles experience. Both the old & new apis will continue to work alongside each other for now. The new APIs can be found in our developer change log here.

 

@Martin James - appreciate your feedback around app users. I'll work with the team to see how we can improve the experience, and look into adding a filter for apps. 

Like • Martin James likes this
Michiel SCHUIJER
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 26, 2025

Very welcome change, something I have asked for and wanted for a long time! I agree with @Martin James that App permissions would be good to separate, though. 

And I'm still wondering if Atlassian Teams could be leveraged into the role access, to allow for better self-serve.

Looking forward to using this!

Marie Casabonne
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 27, 2025

@Martin James - confirmed we have it in plans to add a filter for Apps (like users, groups, etc.)! 

@Michiel SCHUIJER - using Teams for managing space access is in the works! It's on our roadmap and the team is actively building it out now :) stay tuned for more detailed announcements and timelines in the next few months

Like • Michiel SCHUIJER likes this
Tami Dubi
Contributor
June 29, 2025

@Marie Casabonne 
Hi Marie,
By Team, do you mean the Team that Rovo uses, or is there a difference?
I am asking because I found out that the team Rovo uses has employees who are unsubscribed in the system (have left the company) and are still listed as active. 

Martin James
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
June 30, 2025

@Marie Casabonne - Perfect, thank you

Josh
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 4, 2025

Echoing the comments of everyone else on this thread - the RBAC approach is a welcome improvement.

Looking forward to seeing this roll out as GA.

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events