The Confluence GRC question
GRC stands for governance, risk and compliance: the policies you set, the risks you track and the controls you prove to an auditor. When a small company starts on SOC 2, it soon has to decide where all of that lives. If your team already writes everything in Confluence, the question becomes "Confluence GRC or a separate GRC tool?"
There are three common answers:
- Plain Confluence plus spreadsheets. Policies are pages, and approvals, acknowledgements and the control calendar are tracked by hand.
- Confluence with a compliance app. The program still lives in a Confluence space, and an app adds the workflow and records that plain pages lack.
- A standalone GRC or compliance automation platform. A separate product, usually with its own policy library, employee portal and integrations into your cloud and HR systems.
None of these is right for everyone. Here is how they compare, and who each one fits.
What the auditor actually tests
A SOC 2 report is an attestation by a licensed CPA firm against the Trust Services Criteria. The auditor tests your controls, not your tooling. Whatever you choose, you need to show:
- Policies that management reviewed and approved, with a record of who approved which text, and when.
- Employees who read and accepted the policies that apply to them.
- Recurring controls (access reviews, risk assessments, scan reviews, tabletop exercises) performed on schedule, with evidence for each period.
- Technical controls that actually operate: MFA enforced, logging on, backups running, changes reviewed.
- An answer to "who can change this?" for your policies and evidence.
For a Type 2 report, this has to hold across the observation period (commonly 3 to 12 months; your auditor sets yours). Any of the three setups can produce this evidence. The difference is the manual effort, and how easily you can hand it over when asked. The SOC 2 readiness checklist lists what to prepare.
Option 1: plain Confluence plus spreadsheets
This is where most small teams start, and it is a reasonable way to do SOC 2 without a GRC tool. Policies are pages in a dedicated space. A spreadsheet or a locked log page records approvals. A form or another spreadsheet collects acknowledgements. A calendar reminds owners when the quarterly access review is due.
What Confluence gives you out of the box is useful:
- Version history. Confluence creates a new version each time a page is published, and you can compare and restore versions.
- Permissions. On Standard and above you control space permissions and can restrict individual pages. Confluence Free has no page restrictions, so anyone who can edit the space can edit every policy.
- Page approvals, on some plans. Confluence Premium and Enterprise include a built-in approval feature for pages. If you rely on it, check what it records and what happens when the page is edited after sign-off, because that is what an auditor will ask about.
- Exports. Pages can be exported to PDF or Word when an auditor wants files.
Where it strains is the bookkeeping. Every approval, acknowledgement and control period is a manual record that has to stay in step with page versions and the employee list, and nothing flags a missed quarterly review. That works for a few people and policies, and gets fragile as the team grows or the program changes hands. How to run a SOC 2 compliance program in Confluence covers this setup in detail, including how to structure the space and close each gap by hand.
Option 2: Confluence with a compliance app
The second option keeps the program where your team already works and adds the missing records with an app installed in your Confluence site. The policies are still ordinary pages written in the Confluence editor. The app adds what the spreadsheets were doing: approvals tied to a page version, employee acknowledgements, a schedule for recurring controls, reminders, and reports an auditor can read.
This suits teams whose program is mostly documents and people: write the policy, get it approved and acknowledged, run the quarterly review, file the evidence. Employees don't learn a new system, and the evidence sits next to the policies it supports. Technical evidence (cloud configuration, MFA reports, scan results) is exported from the source systems and attached to the right evidence page, as in option 1.
Option 3: a standalone GRC or compliance automation platform
A standalone platform is a separate product built around compliance. The category varies, but these platforms commonly offer:
- Integrations that collect technical evidence. Connections to cloud providers, identity providers, HR systems and code repositories that check configuration and pull evidence automatically, often continuously.
- Their own place for policies. A policy editor or library, an employee portal for acknowledgements, and often training and onboarding tasks.
- Broader framework libraries. Several frameworks mapped to shared controls, so evidence collected once can count toward more than one.
- Extras around the audit. Vendor risk workflows, risk registers, trust pages and workspaces for auditors, depending on the product.
The trade-offs are typical of the category too. It is another subscription and another system to administer, and employees get another portal to learn. Your policies and evidence live in the vendor's environment, and the integrations need read access to your cloud accounts and HR data. Automation also reduces the manual work without removing it: someone still writes the policies, runs the reviews and fixes what the checks find.
Confluence vs a GRC tool: side by side
How the three setups typically compare. Products differ, so read the third column as a description of the category, not of any one tool.
| Plain Confluence plus spreadsheets | Confluence with a compliance app | Standalone GRC platform | |
|---|---|---|---|
| Where policies live | Confluence pages | Confluence pages, managed by the app | The platform's own editor or library, sometimes linked to your wiki |
| Approvals and acknowledgements | Manual logs, forms or spreadsheets (or built-in page approvals on some plans) | Recorded by the app against a page version | Built-in workflows and an employee portal |
| Recurring controls | A calendar and manual evidence pages | Scheduled by the app, with evidence pages and reminders | Built-in tasks and schedules |
| Technical evidence collection | Manual exports and screenshots | Manual exports, attached to the right evidence page | Often automated through integrations |
| Auditor access | Space access or exported files | Space access, generated reports or exported files | Often a dedicated auditor workspace |
| Data location | Your Confluence site | Your Confluence site (depends on the app; check where it stores data) | The vendor's environment |
| Learning curve | Familiar tools, but high manual discipline | Low for employees, moderate for admins | A new system for everyone |
| Best fit | Very small teams, early preparation | Small to mid-sized teams already on Confluence, one or two frameworks | Larger or cloud-heavy companies, several frameworks, continuous monitoring needs |
Do I need a compliance automation platform?
Plain Confluence is probably enough if
- You are a handful of people preparing for a first audit, and one person runs the program closely.
- You have a small number of policies and recurring controls, and you are disciplined about keeping logs.
- You are on a paid Confluence plan, so you can restrict who edits policies.
A compliance app inside Confluence fits if
- Your team already writes its documentation in Confluence and you don't want a second system for policies.
- The painful part is the bookkeeping: approvals, acknowledgements, missed quarterly reviews and assembling evidence per period.
- You want evidence and records to stay in your own Atlassian site.
- Your technical evidence is manageable by hand, for example a few cloud accounts and an identity provider you can export from.
A standalone platform is the better fit if
- You run many cloud accounts and services, and collecting configuration evidence by hand would take real time every month.
- You need several frameworks at once (for example SOC 2 alongside others) and want evidence mapped across them.
- You want continuous monitoring with alerts when a technical control drifts, not just periodic reviews.
- You have the budget and someone to administer another system.
Tip: Ask your auditor what evidence format they prefer before you choose. Many firms work with evidence from any of these setups, and their answer may make the decision simpler.
You can combine approaches
These options are not exclusive. Common combinations:
- Confluence for policies and recurring controls, other tools for technical evidence. Your cloud provider's own reports, your identity provider's MFA report and your scanner's output are exported each period and attached to the matching evidence page. See SOC 2 evidence collection for how to organize that library.
- A platform for technical monitoring, Confluence for the documents. Some teams keep a platform for automated checks while policies and procedures stay in Confluence, where people actually read them.
- Start in Confluence, move later. Clear approval and acknowledgement records, each tied to a policy version, carry over if you outgrow it.
The one rule: decide which system is the record of truth for each kind of evidence. Two acknowledgement lists that disagree cause more trouble in an audit than either tool alone.
Option 2 in practice: Compliance in a Box
Compliance in a Box is a Confluence Cloud app that takes the second approach. It turns one Confluence space into your SOC 2 program. You keep writing policy text in the normal Confluence editor; the app handles the workflow, the state and the evidence around it.
- A ready-made program in your space. Setup creates a dedicated compliance space with policy templates and recurring activities mapped to the Trust Services Criteria: 24 policies and 15 activities with every category selected. Existing policies can be imported.
- Version-bound approvals. Owners submit a policy and every assigned approver approves that exact page version. The app records the version and a fingerprint of its content, and an edit before the decision cancels the submission.
- One-click acknowledgements. When a policy is approved for the first time or after a material change, its audience (all employees or specific groups) is asked to acknowledge the approved version, with a due date and completion tracking.
- Recurring activities with evidence pages. Access reviews, scan reviews, risk assessments and tabletop exercises run monthly, quarterly, semi-annually or annually, aligned to your fiscal year. Each period opens its own dated evidence page, which the owner completes and submits for approval.
- Dashboard, My Tasks and reminders. Compliance Admins see overdue work and acknowledgement completion; everyone else sees what is waiting on them. Reminders arrive as Confluence task notifications.
- Reports and a controls matrix. A Policy Approval Log, Policy Acknowledgement Report, Activity Completion Report, Audit Log pages and a controls matrix are generated as Confluence pages and refreshed daily. An optional Auditors group can view them; see Set up the Auditors group.
The app runs on Atlassian with no external services, so no data leaves Atlassian, and people are stored only as Atlassian account IDs. App data follows your Confluence site's data residency location, and your policies and evidence are ordinary pages in your space. It is free for up to 10 users with every feature included. To see what setup involves, read Getting started.
Note: The policy templates and control mappings are a starting point, not legal or audit advice. Tailor them to your company and have them reviewed by your auditor.
FAQ
Do I need a GRC tool to get a SOC 2 report?
No. Auditors test whether your controls are designed and operating, not which software you used. What you need is complete, consistent evidence, and the right tool is the one that makes that easiest for your team.
Can Confluence be our GRC system?
For the governance and compliance side (policies, approvals, acknowledgements, recurring reviews and their evidence), yes, either with careful manual records or with an app that adds them. Automated collection of technical evidence from your cloud systems is where standalone platforms are strongest.
Which Confluence plan do we need?
A paid plan (Standard or above) is a good baseline, because Confluence Free can't restrict who edits a page. Some features, such as built-in page approvals, depend on your plan.