User guide

Compliance in a Box user guide

Everything you need to run, take part in or audit a compliance program with Compliance in a Box. Start here for the big picture, then jump to the chapter for your role.

  • Everyone

What the app does

Compliance in a Box runs your company's compliance program inside Confluence Cloud. SOC 2 is the framework available today. The app creates one dedicated compliance space on your site and fills it with a ready-made page tree: policies, recurring activities, a controls matrix and an Evidence & Reports section. You write and edit everything with the normal Confluence editor; the app handles the workflow around it.

  • Policies with version-bound approvals. An owner submits a policy, and every assigned approver approves that exact page version. If the page is edited before the decision, the submission is cancelled, so nobody approves text they didn't review.
  • Employee acknowledgements. When a policy is approved for the first time, or after a material change, everyone in its audience is asked to read it and click to acknowledge the approved version.
  • Recurring activities. Controls such as access reviews and risk assessments run on a schedule. For each period the app opens a dated evidence page that the owner completes and submits for approval.
  • Dashboard and generated reports. Compliance Admins get a dashboard of overdue and upcoming work, and the app keeps approval, acknowledgement, activity and audit log reports up to date as ordinary Confluence pages your auditor can read.

The app runs on Atlassian: it has no external servers, and no data leaves Atlassian. People are recorded only by their Atlassian account; names are looked up when they are shown.

Note: the policy templates and control mappings are a starting point, not legal or audit advice. Review and tailor them, and have them reviewed by your auditor.

Roles

Your role decides what you see and can do. One person can hold several roles, and roles are checked every time you use the app, so a change to someone's groups takes effect on their next click.

RoleWhoWhat they do
Compliance Admin Members of the Compliance Admins group chosen in Settings, plus every Confluence site admin. Site admins are always Compliance Admins, so you can never be locked out of the app. Set up the app and the compliance space, choose groups, assign owners and approvers, change schedules, skip activity periods, excuse people from acknowledgements, see everyone's status and the full audit log, and refresh the generated reports.
Owner The person accountable for a policy or a recurring activity, assigned by a Compliance Admin. Edit the pages they own, submit a policy or an evidence page for approval, withdraw a pending submission, and see the acknowledgement percentage of their own policies.
Approver An executive, manager or reviewer assigned to a policy or activity. Approve or reject the submitted version. A rejection needs a comment and sends the item back to its owner.
Employee Members of the employee groups chosen in Settings, and anyone in a policy's specific audience groups. Read the policies and acknowledge the ones whose audience includes them.
Auditor (optional) An external auditor with access to your Confluence site. Auditors don't need a role in the app. Read the compliance space. Members of the optional Auditors group can also view, but not edit, the generated Evidence & Reports pages and the controls matrix.

Policies, activity pages and evidence pages are locked: only their owner and the Compliance Admins can edit them. The app keeps these Confluence page restrictions in step with who owns what.

Key concepts

Framework
A compliance standard, such as SOC 2. It defines which policies and activities you need and which controls they support.
Control
A requirement of the framework (for SOC 2, a Trust Services Criterion). The controls matrix shows which policies and activities cover each one.
Compliance space
The one Confluence space the app creates on your site. Every framework lives in it.
Managed page
A page the app created and tracks, such as a policy, an activity or an evidence page.
Policy
A managed page with an owner, approvers, an audience and a review date (yearly by default).
Policy version
A specific Confluence page version of a policy that was submitted for approval. The app records the version number and a fingerprint of its content.
Approval
An approver's decision, approve or reject, on a submitted policy version or evidence page. A version is approved once every assigned approver has approved it.
Material change
A change the owner marks as important enough that everyone must acknowledge the policy again.
Audience
Who must acknowledge a policy: All employees (the default) or specific Confluence groups.
Acknowledgement
A person's click-through confirmation that they have read a specific approved version of a policy.
Acknowledgement campaign
The round of acknowledgements opened when a policy version is approved for the first time or after a material change, with a due date.
Recurring activity
A control performed on a schedule (monthly, quarterly, semi-annual or annual), such as a user access review.
Period (occurrence)
One run of a recurring activity, for example "FY2027 Q2", with a due date on its last day, an evidence page and an approval.
Evidence page
The dated page the app creates for each period, where the owner records the work and attaches evidence before submitting it.
Audit log
An append-only record of every change in the program: submissions, decisions, acknowledgements, skips, settings changes and more. Entries can't be edited or deleted.

Where things live

The app

To open the app, choose Compliance in a Box from the Apps menu in Confluence. You can also click Open in Compliance in a Box in the status popup on any managed page. The app shows only the tabs your role needs:

TabWhat it's forWho sees it
DashboardOverdue work, reviews and activities coming up, acknowledgement completion and policy status at a glance.Compliance Admins
My TasksYour own to-do list: policies to acknowledge, approvals waiting for you, things you own, and your history.Everyone with a role
PoliciesEvery policy with its status, owner and approved version. Policies you must acknowledge are marked Required for you.Everyone with a role
ActivitiesEvery recurring activity with its schedule, current period and evidence pages.Owners, approvers and Compliance Admins
AcknowledgementsWho has acknowledged each policy, by policy and by person, with reminders.Compliance Admins
Audit LogEvery recorded change, newest first.Compliance Admins
SettingsSetup, groups, owners and approvers, reminders, permissions and reports.Compliance Admins

Compliance Admins land on the Dashboard (on Settings until setup is finished); everyone else lands on My Tasks. If you open the app without a role, you'll see "You're not part of this site's compliance program" and who to contact.

The status on managed pages

Policy, activity and evidence pages show a Compliance in a Box status item at the top of the page, next to the page details. Its label is personal: it says Your approval needed or Please acknowledge when you have something to do, and otherwise shows the status, for example Approved v4 · 2026-09-29, Changes pending approval, Awaiting approval or Draft. Click it to see the details and act on the page itself, for example Submit for approval, Approve, Reject or Acknowledge.

The compliance space

The space is the system of record your auditor reads. Its page tree looks like this:

  • <Company> Compliance Program (the space home)
    • Policies: one page per policy.
    • Recurring Activities: one page per activity, with an evidence page for each period underneath.
    • Controls Matrix — SOC 2: each control with the policies and activities that support it and their status.
    • Evidence & Reports: generated approval, acknowledgement, activity completion and audit log reports.
    • Compliance Tasks: private task pages used for reminders.

The controls matrix and the pages under Evidence & Reports are generated by the app. Don't edit them by hand: the next refresh overwrites your changes. See SOC 2 content reference for the full list of policies and activities.

Reminders in Confluence

Reminders use Confluence's own notifications; the app itself sends no email. Everyone with open compliance work gets a private page, "Compliance tasks for <your name>", under Compliance Tasks. Each reminder is a Confluence task assigned to you, so Confluence notifies you and lists it with your other Confluence tasks. Ticking the task does nothing: follow its link and acknowledge, submit or approve in the app or on the page. The task disappears once the work is done.

Find your way

Start here by role

All chapters