Last updated: 13 August 2026
Space Access answers one question well: who can reach which Confluence space, and how do I fix it without clicking through every space one at a time? This page covers every screen, what each number means, and — at the end — what the app deliberately does not do.
In Confluence, open Apps → Space Access in the top navigation. The app opens on its own full-width page. There is nothing to configure first.
Reviewing and changing space permissions is an administrator's job in Confluence, so the app is for Confluence administrators. This is checked on the server, not by hiding a button, and the app always acts as you: if Confluence would refuse you something on your own, it refuses the app too. The app never borrows extra power.
The app reads every space you can see, then reads the permissions of each one, filling the table as it goes. A progress line says "Reading permissions — 312 of 2,000 spaces", and you can search and filter while it is still loading. There is no 500-space limit.
One row is one person, group or company-wide rule in one space:
| Column | What it means |
|---|---|
| Space | The space key and its name. |
| Who | The person, the group, "Everyone in the company", or an app account. |
| Type | Person, Group, Company-wide or App. |
| Access | The access level — see below. |
| Permissions | How many individual permission entries make up that access. It is the detail behind the label, useful when two people show the same level but one has more. |
Confluence is moving from loose permissions to space roles. The app speaks both languages and picks the right one automatically:
Filters work on what is already on screen, so they answer instantly — even mid-load.
Three kinds of row are hidden by default because they bury the answer, and the app always tells you how many it is hiding:
Export what I see builds a spreadsheet of exactly the rows currently shown — every column, with people and groups written out by name, not as ID codes. Copy the box into Excel, Google Sheets or Numbers. Because it exports what is shown, filtering first is the way to export one slice (for example, every space a leaver can still reach).
This is the part that saves the afternoon. Three steps, and nothing changes until the third.
Take access away from lists everyone and every group the app found, so you pick the leaver, the contractor, or the group that should no longer reach a set of spaces.
The app lists every space that person or group can currently reach, with their access level. Untick any you want to leave alone, then ask for the preview.
The preview is read fresh from Confluence, not from the table on your screen. If a colleague changed something five minutes ago, the preview reflects that, not what you loaded. It shows, space by space, what would change — and what the app will refuse to do:
Both rules run on the server, not only in the screen, and each refusal is shown in plain English next to the space it applies to.
The run always ends with three honest lists, never a single "something went wrong":
What was already changed stays changed. The app does not attempt a half-undo, which is how real damage gets done.
The last 200 bulk changes, newest first: when, who ran it, whose access was removed, which spaces changed, and what did not change and why.
This is the only thing the app ever stores, and it stores no names — only Atlassian account IDs, group IDs, space IDs and fixed reason codes. The names you read in the history are fetched live while the screen is drawn. Space names are excluded on purpose too: a personal space is named after its owner, so storing space names would have quietly stored people's names. See the Privacy Policy.
Anyone who can review space permissions on the site sees a Delete button on each record, and a Delete the whole history button underneath. Both ask for confirmation first, and both are immediate and final — there is no undo and no copy to restore from. Deleting a record does not put access back; it only removes the log line.
This is what answers an erasure request under GDPR or similar law: the history is the only thing the app stores, so deleting it is complete. People who cannot review permissions do not see these buttons, and the server refuses them anyway — otherwise the person who made a change could erase their own trace. See the Data Processing Agreement.
Only what it needs, and nothing that reads your content:
It does not ask for permission to read pages, blogs, comments or attachments — so it could not read them even if a future version tried. It has no external network access of any kind, and it never asks you for a password or an API token.
Said plainly, so nothing is a surprise after you buy:
Email support@saoirsesoftware.com — in English, on business days, with a reply aimed at within two business days. Telling us your Confluence plan and what the screen said gets you a useful answer faster.