This chapter assumes setup is finished: the compliance space exists and the policy and activity pages are generated. If you haven't got that far, start with Getting started.
Settings reference
Open the app and choose the Settings tab. Only Compliance Admins see it. The sections appear in this order, and each one saves on its own with its own button.
How saving works
- Each setting is saved separately, so saving the company profile doesn't touch the groups, and the other way round.
- If another admin saved the same setting after you opened the page, your save is refused with Changed by someone else. Click Reload to load the latest values, then make your change again.
- Every saved change is recorded in the audit log as Setting changed, with who changed it and the old and new values. You can see these entries in the Audit Log tab.
Setup checklist
Shows each setup step as Done or To do: Choose the employee groups, Choose the Compliance Admins group, Fill in the company profile, Create the compliance space and Generate the policy and activity pages. Once everything is done you can ignore it.
Access
| Field | What it does |
|---|---|
| Compliance Admins group | Members are Compliance Admins. The group becomes the compliance space's admin and can edit every managed page. Confluence site admins are Compliance Admins whether or not they are in it. Save with Save admin group. |
| Employee groups | One or more groups whose members are employees: they can view the compliance space and must acknowledge policies whose audience is All employees. Save with Save employee groups. |
| Auditors group (optional) | Members can view, but not edit, the generated Evidence & Reports pages and the controls matrix. Leave it empty to keep those pages visible to Compliance Admins only. Save with Save auditors group. |
When you change a group, the app re-applies the space permissions and page restrictions in the background (see Roles and permissions). Changes to the employee groups also reach open acknowledgement campaigns at the next daily check: people who joined are asked to acknowledge, and people who left stop being asked. Acknowledgements already given are kept. See Policy acknowledgements.
Note: the Auditors group only controls who can see the generated report pages. The app doesn't give auditors access to the compliance space itself: give them (or the Auditors group) view access in the space's settings in Confluence, for example as guests.
Company profile
| Field | What it does |
|---|---|
| Company name | Used in the policy and activity templates and the space home page. |
| Security contact | Choose A person (pick someone), A shared mailbox (enter an address such as a security team mailbox, not a personal address) or Not set yet. The contact is named in the generated policies and shown to people who open the app without a role, or before setup is finished. |
| Effective date (optional) | The date shown on the policies. If empty, the day the pages are created is used. |
| Fiscal year starts in | The month your fiscal year starts. New activities are scheduled from the start of your fiscal year, and period labels follow it (for example "FY2027 Q2"). |
Save with Save company profile.
Important: the company name, security contact and effective date are written into pages when the pages are generated. Changing them later doesn't rewrite existing pages, because the app never edits a policy or evidence page after creating it (that would break version-bound approvals). Edit the pages themselves if needed. Likewise, changing the fiscal year doesn't move the schedules of existing activities; change those per activity (see Recurring activities).
Compliance space
Once the space exists, this section shows it as Ready, with a link, its key, and whether it was Created by the app or Handed over to the app by an admin. It also warns you about problems with the space's access:
- The app is no longer a space admin: someone removed the app's admin permission from the space. Give Compliance in a Box the space admin permission again in the space's settings, or the app can't manage its pages.
- The space uses your site's default permissions: Confluence didn't accept the app's own permissions when the space was created. Review the space's permissions in Confluence.
- Confluence Free: page restrictions aren't available, so managed pages can't be locked.
Creating or handing over the space is covered in Getting started.
Frameworks & pages
Shows the framework (SOC 2) with a checkbox per Trust Services Category and how many of its pages are set up. Security is always included.
- Add a category: tick it and click Generate again. Categories can be added later, but not removed.
- Restore missing pages: Generate again is always safe. It only creates pages that are missing and never changes existing ones. If a managed page is in the space's trash, the result tells you; restore it from the trash rather than generating a new one.
- Framework updates: when a newer version of the framework's content is available, it appears here. See Framework content updates.
- Import existing policies (optional) opens the import wizard; see Importing and custom policies.
Permissions
Shows how the app manages access to the compliance space (explained in Roles and permissions):
- Last applied and Last daily check: when permissions were last applied, why (for example after an owner change or daily check), and what changed.
- Owners & approvers: opens the page for assigning owners and approvers (see Change owners and approvers).
- Re-apply permissions: re-applies every space permission and page restriction now, in the background. Click Reload a minute later to see the result.
Warnings appear here when pages can't be locked (Confluence Free), when you must apply space permissions by hand, when a hand-set space role stops an owner from editing their pages, or when some changes failed (the daily check tries again).
Evidence & Reports
Lists the generated report pages and the controls matrix, with when each last changed, and when they were last refreshed. They refresh daily; Refresh now refreshes them immediately. It also holds the Before uninstalling warning (see Uninstalling). For what each report contains, see Evidence, reports and audits.
Reminders
Turns reminders on or off (Send reminders), per kind of reminder, and sets the limits: Days between reminders about the same item (1 to 30) and Reminders per person per day (1 to 20). It also controls the Weekly compliance summary for the Compliance Admins and the weekday it's written (UTC). Save with Save reminder settings. Reminders are explained in Dashboard, tasks and reminders.
Roles and permissions
Roles are worked out every time someone uses the app, from their Confluence groups and from what they own or approve. A change to someone's groups takes effect on their next click.
Who has which role
- Compliance Admin
- Members of the Compliance Admins group, plus every Confluence site admin. Site admins are always Compliance Admins, so your organization can't lock itself out of the app.
- Employee
- Members of any of the Employee groups. People in a policy's specific audience groups are also asked to acknowledge that policy.
- Owner
- The person assigned to a policy or a recurring activity. New items start with the admin who generated the pages as owner and approver.
- Approver
- One to ten people assigned per policy or activity.
- Auditor
- Doesn't need a role in the app. You give auditors access to the space in Confluence; the optional Auditors group lets them view the generated reports.
What the app sets in Confluence
The app keeps Confluence's own permissions in step with these roles, so Confluence enforces who can edit what:
| Who | Compliance space access | Can edit |
|---|---|---|
| Compliance Admins group | Space admin | Every managed page |
| Owners (each person) | View, add and edit pages, comment, while they own at least one policy or activity | Only the pages they own: the policy page, or the activity page and its evidence pages |
| Employee groups | View and comment | No managed pages |
| Approvers | Covered by the employee or admin access | No managed pages, unless they are also an owner or admin |
| Auditors | Whatever you give them in Confluence | No managed pages |
Every managed page is locked with a Confluence edit restriction: its owner, the Compliance Admins group and the app. Section pages, the controls matrix and the report pages are locked to the Compliance Admins group and the app. Owners need space-level edit access to work on their pages, and the locks stop them editing anything they don't own.
The report pages and the controls matrix are also view-restricted to the Compliance Admins group, the Auditors group (if set) and the app. Each person's private reminder task page is visible only to that person, the Compliance Admins group and the app.
Note: approvers must be able to see the compliance space. If an approver isn't a Compliance Admin, an employee or an owner, the space's permissions don't let them read what they must approve, and the Owners & approvers page flags them with Can't see the space. Give them view access in Confluence, or pick someone else.
How the app keeps permissions in step
The app re-applies permissions automatically after pages are generated, after an owner changes, after a group setting changes, when new evidence or report pages are created, and once a day. You can also click Re-apply permissions in Settings. Changes are recorded in the audit log.
- Edit restrictions on managed pages are put back. If someone removes a page's lock, or adds an extra editor to it, the next run restores the lock to the owner, the Compliance Admins group and the app. To let someone edit a page, make them its owner or a Compliance Admin instead.
- View restrictions you add to policy, activity or evidence pages are left alone. The app only manages who can view the report pages, the controls matrix and the reminder task pages.
- Space access the app didn't give is never touched. The app keeps track of the space permissions it granted and only ever changes or removes those. Access you gave by hand, for example to auditors or other apps, stays. When someone stops owning anything, the app removes the edit access it gave them.
- Hand-set roles win. If an owner already has a space role you set by hand that doesn't let them edit, the app doesn't overwrite it. Settings shows Space roles set by hand block some owners; raise their role in the space's settings, or remove it so the app can grant access.
When the app can't set space permissions
On some sites Confluence doesn't let the app set space permissions itself, for example a site that doesn't use space roles yet. Settings then shows Apply these space permissions in Confluence with the list of people and groups and the access each needs, marked in place or missing. Apply them in the space's settings. The daily check reports anything missing but doesn't fix it. Page locks still apply.
On Confluence Free
Confluence Free doesn't support page restrictions, so the app can't lock managed pages: anyone who can edit the space can edit every policy. The report pages and reminder task pages are also visible to everyone who can view the space. Settings and the dashboard warn about this. Upgrade to Confluence Standard or above to lock pages.
Change owners and approvers
Owners and approvers for every policy and activity are managed on one page:
- In Settings, under Permissions, click Owners & approvers.
- Find the policy or activity in the table and click Edit.
- Pick the Owner and one to ten Approvers, then click Save.
When the owner changes, the page lock and the owner's space access move to the new owner in the background. The Needs attention column flags items with No approver, approvers who can't see the space, and former users.
Approvers are fixed when something is submitted. A new list of approvers applies to the next submission, not to one already waiting for approval. For the details of submitting and approving, see Policies and approvals and Recurring activities.
When people leave
The app notices when an Atlassian account is deactivated or closed. Nothing a former user owns or approves is reassigned automatically: that's your decision.
Deactivated accounts
The app checks account status daily. When someone's account is deactivated:
- Their open acknowledgements stop being required. They show as Former user in the acknowledgement views and drop out of counts, reminders and reports. Acknowledgements they already gave stay as evidence.
- If the account is reactivated, their acknowledgements for current policies come back with a new due date.
Closed accounts
The app reports the account IDs it stores to Atlassian at least once every seven days, as Atlassian requires. When Atlassian reports an account as closed, the app erases the person:
- Their open acknowledgements are waived.
- Their account ID is replaced by a random placeholder everywhere the app stores it, including the audit log. Counts and timelines stay intact, but the person can no longer be identified. The app shows Former user instead of their name, and the generated report pages drop the name at their next refresh.
- If they were the security contact in the company profile, the contact is cleared. Choose a new one in Settings.
- Their page locks and the space access the app gave them are removed, and their reminder task page is emptied and moved to the space's trash.
Reassign their work
When a former user (deactivated or closed) still owns or approves something, the Dashboard shows a Reassign: … belong to former users warning, and the Owners & approvers page flags each affected row with Former user: pick a new owner or Former user: replace this approver.
- On Owners & approvers, pick a new owner or replace the approver for each flagged item.
- For any submission already waiting for that former approver: the approvers were fixed when it was submitted, so it can't finish. After changing the approvers, withdraw the submission and submit it again. The owner or a Compliance Admin can do this.
Framework content updates
A new release of the app can add framework content, such as new policies, activities or control mappings. Your site keeps the framework version it has until a Compliance Admin applies the update, so nothing changes without your say.
- Open Settings and go to Frameworks & pages. When an update is available it shows, for example, SOC 2 update available (version 1 → 2).
- Read the summary of each version, the table of Pages the update adds, and any new criteria for the controls matrix.
- Click Apply update. The new pages are generated like any other page generation.
Updates are add-only. Existing pages, including anything your team edited, are never changed or removed, and improved template text only reaches pages created after the update. Applying an update is recorded in the audit log. New pages start with the admin who applied the update as owner and approver; reassign them on Owners & approvers.
Licensing
Compliance in a Box is free for up to 10 users, with every feature. Above that, subscriptions are bought and billed through the Atlassian Marketplace. See Billing and licenses on the support page.
If the license is inactive
If your site's license lapses, the app becomes read-only. Every page of the app shows the banner Compliance in a Box is unlicensed, and anything that changes compliance records is refused with Not available without a licence.
| Still works | Stops |
|---|---|
|
|
Everything works again as soon as the license is active.
Data and privacy
- Runs on Atlassian. The app runs entirely on Atlassian's infrastructure. It calls no external services, so no data leaves Atlassian. Auralite Solutions has no access to the data it stores.
- Account IDs only. People are stored as Atlassian account IDs. Names and email addresses are never stored; names are looked up live when shown. The only exception is a shared security mailbox you enter in the company profile.
- Your content stays in Confluence. Policies, evidence pages and generated reports are ordinary pages in your compliance space. The app stores its workflow records (versions, approvals, acknowledgements, activity periods, settings and the audit log) alongside your site.
- Data residency. App data follows the data residency location of your Confluence site.
- Retention. App data is kept while the app is installed. The audit log is append-only and never pruned: it is compliance evidence. The only change ever made to it is erasing closed accounts.
For the full details, see the Privacy Policy.
Uninstalling
Before you uninstall, open Settings, go to Evidence & Reports, click Refresh now and wait for it to finish, so your report pages are up to date. The app also tries a last refresh during uninstall, but that is best effort only.
| What stays | What goes |
|---|---|
| The compliance space and every page in it: policies, activity and evidence pages, the controls matrix and the Evidence & Reports pages, as of their last refresh. | The app's own records (approvals, acknowledgements, the audit log and settings), which Atlassian deletes after its retention period. |
Reinstalling starts with empty records. If you uninstalled by mistake, contact support@auralitesolutions.com within 21 days: Atlassian can reconnect the old data only on a support request made in that time.