Before you start
Who can install the app
A Confluence site admin installs Compliance in a Box from the Atlassian Marketplace, like any other Confluence Cloud app. The app runs on Atlassian: its data stays in your Atlassian site and nothing is sent anywhere else.
Confluence site admins are always Compliance Admins in the app, so whoever installs it can set it up straight away and can never be locked out.
Pricing
The app is free for up to 10 users, with every feature included. Above 10 users it is billed per user by Atlassian, through the Marketplace, alongside your Confluence subscription. The pricing section on our home page and the Marketplace listing have the details.
The one-time access prompt
The first time each person opens Compliance in a Box, Atlassian asks them to grant the app access on their behalf, with an Allow access button. They need to accept it once before the app's view appears. It is worth telling your employees to expect this prompt when you announce the program.
What to decide first
Setup asks for a few choices. Agree them with the right people before you begin, because every settings change is recorded in the app's audit log.
| Setting | What it means |
|---|---|
| Compliance Admins group | The Confluence group whose members run the program: they configure the app, assign owners and approvers, and see everyone's status. Required before the space can be created. |
| Employee groups | One or more Confluence groups whose members are employees and must read and acknowledge policies. |
| Auditors group (optional) | A group that can view, but not edit, the generated evidence and report pages. |
| Company name | Used in the policy templates, the space name and the space home page. |
| Security contact | A person or a shared mailbox (such as a security@ address) named in the policies. |
| Effective date (optional) | The date shown on the policies. If you leave it empty, the day the pages are created is used. |
| Fiscal year start | The month your fiscal year starts. Annual activities and reports follow it. |
| Space name and key | The name and key of the Confluence space the app creates for the program. |
| Trust Services Categories | Which SOC 2 categories are in scope. Security is always included; you can add the others now or later. |
Note: The app picks from your existing Confluence groups and never creates or edits groups. If you want a dedicated group for Compliance Admins or auditors, create it in Atlassian administration first.
Open the app
Open Compliance in a Box from the Apps menu in Confluence. Right after installation you may briefly see Finishing installation… while the app prepares itself; the page refreshes on its own when it is ready.
What people see depends on their role and on whether setup is finished:
- Compliance Admins land on the Settings tab until setup is complete, and on the Dashboard after that.
- Everyone else sees Compliance in a Box hasn’t been set up yet until setup is complete, along with the security contact (or a suggestion to ask the Confluence administrator if no contact is set).
- After setup, people who aren't an employee, owner, approver or admin see You’re not part of this site’s compliance program.
The setup checklist
The top of the Settings tab shows a Setup checklist. Each step shows To do or Done:
- Choose the employee groups
- Choose the Compliance Admins group
- Fill in the company profile
- Create the compliance space
- Generate the policy and activity pages
The first three can be done in any order. The space can only be created once they are done, and the checklist lists whatever is still missing. Setup is complete, and the app opens up to everyone else, once every step is done.
Each section of Settings has its own save button and saves independently. If another admin saved the same section while you were editing, your save is refused with Changed by someone else: reload, check their change, and try again.
Choose the groups
The Access section holds the three group settings.
- Under Compliance Admins group, pick the group whose members will run the program, then select Save admin group.
- Under Employee groups, pick one or more groups. Before you save for the first time, the app pre-selects your site's Confluence users group when it can identify it. Check that this is right, then select Save employee groups. Nothing is stored until you save.
- Optionally, pick an Auditors group (optional) and select Save auditors group. Leave it empty to keep the report pages visible to Compliance Admins only. See Evidence, reports and audits for what auditors can see.
Tip: You don't need to put Confluence site admins in the Compliance Admins group: they are always Compliance Admins. The group is still required, because the app uses it for the space and page permissions.
Fill in the company profile
- In Company profile, enter the Company name.
- Under Security contact, choose A person and search for them, or A shared mailbox and enter its address, or leave it as Not set yet. Use a shared mailbox rather than a personal address.
- Optionally, set the Effective date (optional) shown on the policies.
- Choose the month in Fiscal year starts in.
- Select Save company profile.
Important: Get the company profile right before you generate the pages. The company name, security contact and effective date are written into each page when it is created, and the fiscal year start sets each activity's schedule. The app never rewrites pages afterwards, so later changes don't reach pages that already exist; you would edit those pages, or an activity's schedule, by hand.
Create the compliance space
The app keeps your whole program in one dedicated Confluence space: every policy, activity and evidence page lives there. There is exactly one compliance space per site, and it holds every framework. The Compliance space section offers two ways to get it. The app never takes over an existing space that already has content.
Let the app create the space (recommended)
- Check the Space name. It defaults to your company name followed by "Compliance".
- Check the Space key. It defaults to
COMPLIANCE. A key uses only letters and digits, starts with a letter, and appears in the space's address. When you leave the field, the app checks the key and tells you whether it is available. - Select Create space.
The app creates the space already locked down: the app and your Compliance Admins group are space admins, and your employee groups can view the space and comment where your site offers a commenter role (otherwise they can view it).
Hand over an empty space instead
Use this if your site doesn't let apps create spaces, or if you prefer to create the space yourself. If Confluence refuses to let the app create the space, the section switches to this option automatically and says Confluence didn’t let the app create a space. To choose it up front, select I’ll create the space myself.
- In Confluence, create a new, blank space. Don't add any pages or blog posts.
- In the space's settings, open the permissions and give the Compliance in a Box app the space admin permission.
- Back in the app, enter the space key and select Verify and use this space.
The app checks that it can see the space, that it is a space admin there, and that the space is empty apart from its home page. If a check fails, it tells you what to fix, for example The space isn’t empty with the number of pages it found, or The app isn’t a space admin. An archived space has to be restored first. Once the checks pass, the app takes the space over and applies its own permissions, exactly as if it had created the space. To go back to the first option, select Let the app create the space instead.
When the space is ready
The section then shows a Ready label, a link to the space and its key. It may also show a warning:
- The space uses your site’s default permissions: Confluence didn't accept the app's own permissions when it created the space, so review the space's permissions in Confluence.
- The app is no longer a space admin: someone removed the app's admin permission. Give it back, or the app can't manage its pages.
- Confluence Free: Confluence Free doesn't support page restrictions, so managed pages can't be locked. Confluence Standard or above is needed for locking.
Generate the policy and activity pages
Once the space is ready, the Frameworks & pages section lets you choose what to cover and generate the page tree. SOC 2 is the framework available today.
Choose the Trust Services Categories
Each category is a checkbox whose label says what it adds. In the current SOC 2 content:
| Category | What it adds |
|---|---|
| Security | Always included: 20 policies and 13 recurring activities |
| Availability | 2 more policies and 2 more activities |
| Confidentiality | Nothing extra: its policies are already among the Security pages |
| Processing Integrity | 1 more policy |
| Privacy | 1 more policy |
With every category selected you get 24 policies and 15 recurring activities. The SOC 2 content reference lists them all. Categories can be added later, but not removed.
Start and follow the generation
- Tick the categories you want.
- Select Generate pages.
- Watch the progress bar. It reads, for example, "Generating pages… 12 of 47 checked (12 created, 0 linked)" and updates itself while the work runs in the background.
When it finishes, you see Pages are up to date with a count of pages created, linked and already there. The section also shows how many pages are set up (for example "47 of 47 pages set up"), a link to Open the compliance space, and a button to Import existing policies (optional) if your company already has policies elsewhere. See Importing and custom policies.
If some pages couldn't be set up
If something got in the way, the section shows how many pages couldn't be set up and a table with each page, the reason and what to do. A common cause is another page in the space that already has the same title: rename that page. Then select Generate again.
Generating again is always safe. It only creates what is missing and never changes pages that already exist, so anything your team has edited stays as it is. If a page the app expects is already in the space, it is linked rather than created a second time. If a managed page was trashed, the summary says so: restore it from the space's trash.
What gets created
The space home page becomes your program's home page, titled with your company name followed by "Compliance Program". Under it, the app creates:
- Policies, with one page per policy, each filled in from a template with your company details.
- Recurring Activities, with one page per activity, such as User Access Review or Penetration Test.
- Controls Matrix — SOC 2, which maps the SOC 2 criteria to your policies and activities.
- Evidence & Reports, with the Policy Approval Log, the Policy Acknowledgement Report and the Activity Completion Report.
Over time the app adds more pages, such as a dated evidence page for each activity period, more report pages and private reminder pages for people with open tasks.
Every policy and activity starts with you, the admin who generated the pages, as its owner and its approver. Policies start as drafts: nothing is approved or sent to employees until an owner submits a version and it is approved.
What happens after setup
As soon as the pages exist, setup is complete. Admins now land on the Dashboard, and employees, owners and approvers see their own views of the app.
Managed pages are locked
Every page the app manages is locked: only its owner and the Compliance Admins can edit it. Section, report and matrix pages can be edited only by Compliance Admins and the app. When you change an owner, the lock follows. On Confluence Free, page locks aren't available, and the Permissions section warns about it.
Space permissions
The app keeps the space's permissions in line with each person's role in the program:
| Who | In the space | Can edit |
|---|---|---|
| Compliance Admins group | Space admin | Every managed page |
| Policy and activity owners | View, add and edit pages, while they own at least one item | Only the pages they own, including an activity's evidence pages |
| Employee groups | View and comment | Nothing |
| Approvers | Covered by the employee or admin access | Nothing, unless they are also an owner or admin |
| Auditors | Added by you in Confluence, typically as guests | Nothing |
The app only ever removes access it gave itself. Access you grant by hand, for example to auditors or other apps, is never touched. If your site doesn't let the app set space permissions, the Permissions section lists the access to apply by hand under Apply these space permissions in Confluence, and page locks still apply. The section also has a Re-apply permissions button. Administration covers permissions in more depth.
The daily check
Once a day the app runs a background check. Among other things, it opens activity periods and their evidence pages as they come due, re-applies page locks that someone removed by hand, refreshes the Evidence & Reports pages and sends reminders. You don't need to start or schedule anything.
Add categories later
You can widen your scope at any time:
- Go to Settings and find Frameworks & pages. Categories you already cover are ticked and can't be changed.
- Tick the categories you want to add.
- Select Generate again.
The app creates only the new pages. Existing pages, including everything your team has edited, stay as they are. Categories can't be removed once added. When a newer version of the SOC 2 content is available, the same section offers it; see Administration.
Next steps
With the pages in place, turn the templates into your program:
- Assign owners and approvers. In Settings, open Owners & approvers and give each policy and activity the right owner and one or more approvers. Until you do, you own and approve everything yourself. Approving your own work is allowed, but the Dashboard flags it as approved without an independent approver, and auditors may ask about it. See Administration.
- Review and edit the policy drafts. Owners edit their policy pages in the normal Confluence editor, then submit a version for approval. See Policies and approvals.
- Bring in policies you already have, if any. See Importing and custom policies.
- Plan acknowledgements. Once a policy version is approved, employees in the policy's audience are asked to acknowledge it, for the policies that require acknowledgement. See Policy acknowledgements.
- Check the activity schedules. See Recurring activities.
- Review the reminder settings. Reminders are on by default and arrive as Confluence tasks. Adjust them in the Reminders section of Settings. See Dashboard, tasks and reminders.