Option to prevent direct user assignments from space owner assignment and page-sharing flows (group-only access enforcement)

XMLWordPrintable

    • 1

      Summary

      Confluence currently creates a direct user assignment when:

      1. A user is assigned as a space owner (even if they already have access through a group), and
      1. The page-sharing flow grants space access to a user who does not currently have access.

      We are requesting a native setting that prevents these flows from creating direct user assignments, so that all space access is routed exclusively through groups.

       

      Problem Statement

      Organisations that manage access through an Identity Management (IDM) system rely on group membership as the single source of truth for user access. When Confluence creates direct user assignments outside of these groups, those assignments fall outside the IDM lifecycle — meaning they are not automatically revoked when an employee changes role or leaves a team. This creates residual access that requires manual cleanup and introduces an access-governance and data-safety risk (relevant for GDPR-regulated environments).

      Periodic bulk cleanup via Confluence Administration → Permissions → Bulk space access reduces the exposure window but does not eliminate the underlying risk, as assignments can accumulate between cleanup cycles.


      Requested Behaviour

      1. Space ownership without direct user assignment — If a user is assigned as space owner and already has the required access through a group, no additional direct user entry should be created. Optionally: restrict space owner assignment to users who already hold the required permissions via a group.
      1. No direct user assignment through page sharing — When the page-sharing flow would grant space access to a user who does not have it, the flow should not create a direct user entry. Instead, the action should either be blocked (requiring access to be granted through a group first) or routed through an admin-controlled group-assignment approval process.

      Proposed Configuration

      A site-level or space-level toggle such as:

      "Enforce group-only access — prevent direct user assignments from space ownership and page-sharing flows"

      This would allow organisations with IDM-driven access governance to opt in without affecting customers who rely on the current behaviour.

              Assignee:
              Unassigned
              Reporter:
              Tanya -
              Votes:
              2 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: