-
Type:
Suggestion
-
Resolution: Unresolved
-
Component/s: Permissions - Space
-
None
-
1
In Confluence Cloud's role-based access model, administrators can use System Operations to automatically assign a role (e.g., Admin) to Authorized Apps whenever a new space is created.
However, this is an "all-or-nothing" setting. There is currently no granular way to prevent specific 3rd party apps from being included in this automatic assignment. If the "Authorized Apps" operation is active, every installed app is granted the designated role in the new space by default.
Enhance the System Operations > Authorized Apps configuration to allow:
- Selective Inclusion/Exclusion: A multi-select list or "blacklist" where admins can choose specific apps to exclude from the automatic role assignment.
- App-Specific Roles: The ability to assign different default roles to different apps (e.g., App A gets 'Viewer', App B gets 'Admin', App C gets 'None') during the space creation trigger.
Workaround:
- Set the "Authorized Apps" system operation to "Don't assign a role" and manually add required apps to each space.
- Use Marketplace App Access Controls to block specific apps from accessing content, though the app will still hold the role in the space UI.