
In Confluence, access authorizations can be implemented in future using a role-based method(RBAC = role-based access control). This makes it possible to set up a consistent and detailed authorization structure more intuitively.

How does this work with the existing authorizations?
Here is an overview of the existing authorizations:

Here are the new authorizations using the default role "Admin" as an example:

Overview compared to the previous authorizations
|
Previous authorization |
Role-based authorization |
|
|
All |
View content |
|
|
All |
Delete own content |
|
|
Pages, whiteboards, databases, and Smart Links |
Create content |
|
|
Pages, whiteboards, databases, and Smart Links |
Archive any content in the space |
|
|
Pages, whiteboards, databases, and Smart Links |
Delete anyone's content |
|
|
Blogs |
Create blogs |
|
|
Blogs |
Delete blogs |
|
|
Comments |
Comment on content |
|
|
Comments |
Delete anyone's comments |
|
|
Attachments |
Add attachments |
|
|
Attachments |
Delete attachments |
|
|
Restrictions |
Manage user access to content |
|
|
Space |
Export space |
|
|
Space |
Manage everything in space |
In order to define permissions more granularly and consistently, Atlassian has introduced the following additional permissions:
- Manage user access to space
- Allow and manage public links
- Manage guest access to space
- Allow anonymous access
- Delete space
- Archive space
- Edit content
- Edit blogs
- Export individual content items
Default roles
The following four default roles are created automatically with different authorizations and cannot be edited:
- Admin
- Manager
- Collaborator
- Viewer

User-specific roles
You can define up to ten user-specific roles:

Activation (still in beta)
RBAC in Confluence is not yet generally available. It can only be activated by activating the beta function "New Features".

But be careful: Once activated, this function can no longer be deactivated!
Before activating it, it is therefore essential to plan which roles with which authorizations are required and to which users or groups they should be assigned.
If you have any questions or would like to find out more, please do not hesitate to contact me.
