The Dashboard
The Dashboard tab shows the health of the whole compliance program on one page. Only Compliance Admins see it, and it is where they land when they open Compliance in a Box. Everyone else lands on My Tasks.
The Dashboard is read only. Each figure and list links to the tab where you can act on it, such as a policy, an activity or the Acknowledgements tab.
How current the figures are
The figures are calculated when you open the Dashboard, and the heading says which day they reflect: Program health as of a date in UTC. Select Refresh to recalculate them without leaving the page. The storage estimate is the exception: it is measured once a day.
If one figure can't be loaded, the rest of the page still appears, with a Some figures couldn’t be loaded message. Select Refresh to try again.
Before setup is finished, the Dashboard shows Provision the compliance space to see your dashboard and a Go to Settings button. See Getting started.
Summary figures
| Figure | What it counts |
|---|---|
| Overdue | Everything past its date, with a breakdown: activity periods past their due date, policy reviews past their review date, and acknowledgements past their due date (one per person per policy). |
| Reviews due in 30 days | Policies whose yearly review is due within the next 30 days. The line below shows how many policies you have in total. |
| Activities | Activity periods still to be submitted that are due in the next 30 days (due soon), periods submitted and awaiting approval, and periods approved in the last 90 days (completed in 90 days). |
| Policies acknowledged | Across every policy's current acknowledgement campaign, the share of required acknowledgements that are done, shown as a percentage with a progress bar and as "acknowledged of required". It shows a dash when no acknowledgements are required yet. |
Charts and lists
- Policies by status
- A pie chart of your policies by status: Approved, Changes pending, Pending approval and Draft. Retired policies are not included.
- Acknowledged (%) per policy
- A bar for each policy with a current acknowledgement campaign. The Who hasn’t acknowledged (Acknowledgements tab) button takes you to the per-person view. See Policy acknowledgements.
- Upcoming
- Dates in the next 60 days, soonest first: activity due dates (Activity due), policy review dates (Policy review), and the next acknowledgement due date of each campaign with how many people still have to acknowledge (Acknowledgements due). Select an item to open it.
- Evidence & Reports status
- When the generated Evidence & Reports pages were last refreshed, and how many pages couldn't be refreshed, if any. The Evidence & Reports settings button takes you to the controls in Settings. See Evidence, reports and audits.
- Storage
- An estimate of how much of the app's data storage on your site is in use (Storage: ≈ … MiB of … MiB), with a progress bar and the date it was last measured. It turns into a warning as usage gets close to the limit. The app never deletes audit data to save space, so contact support if you approach the limit. Until the first daily measurement, it says the estimate will appear after the next daily maintenance run.
Dashboard warnings
Warnings appear at the top of the Dashboard only when something needs a Compliance Admin's decision.
Items that belong to former users
The app checks every day whether the people taking part still have active Atlassian accounts. When an account is deactivated or closed, that person's open acknowledgements are no longer required, but anything they own or approve is not reassigned automatically. The Dashboard shows a Reassign: … warning listing owned items, approver assignments and pending approvals that belong to former users, with a link to each item.
- Select Owners & approvers in the warning (or go to Settings > Owners & approvers).
- Pick a new owner or approver for each listed item, and save.
- For a listed pending approval: the approvers of a submission are fixed when it is submitted, so it can't finish. After changing the approvers, withdraw the submission and submit it again. See Policies and approvals and Recurring activities.
The warning disappears once nothing is held by a former user.
Approved without an independent approver
The app lets owners approve their own work, but flags it. This warning counts policies whose current approved version, and activity periods approved in the last 12 months, were approved only by their owner or the person who submitted them. Auditors may ask for an independent review, so either add another approver and resubmit, or be ready to explain why. The affected policies are listed with links.
Reports visible to the whole space
On Confluence Free, which has no page restrictions, the Dashboard warns that the generated reports are visible to everyone who can view the compliance space. See Evidence, reports and audits.
My Tasks
My Tasks lists everything that is waiting for you, and only you: nobody can see another person's My Tasks. Everyone with a part in the program sees it, whether they are an employee, an owner, an approver or a Compliance Admin. If nothing needs you, it says You’re all caught up.
My Tasks doesn't do the work itself. Each button opens the policy or activity page where the action happens. Select Refresh to update the list after you've finished something.
Policies to acknowledge
Policies whose audience includes you and whose approved version you haven't acknowledged yet.
- Approved version links to the exact page version you are asked to read (Read version …).
- Due shows the due date, Overdue once it has passed, or Not yet required. "Not yet required" means you're in the policy's audience but haven't been added to its current acknowledgement campaign yet, for example because you joined recently. You can acknowledge it anyway.
- Acknowledge opens the policy, where you confirm you've read it.
A policy leaves this list once you've acknowledged it, or if a Compliance Admin excuses you. See Policy acknowledgements.
Approvals waiting for you
Submissions where you are one of the approvers and haven't decided yet. Each row shows the item and its kind (Policy, Policy review or Evidence), the Submitted version (a link to that exact page version), and who submitted it. Evidence that is past its due date is marked Overdue. If you own the item or submitted it yourself, it is marked Yours: flagged as self-approval.
Review opens the policy or activity, where you approve or reject. An approval leaves your list once you've decided, or when the submission is withdrawn or cancelled (for example because the page was edited after it was submitted). See Policies and approvals.
Things you own
Shown if you own policies or recurring activities.
- Your policies that need you, with the Next step: Submit for approval (a draft, or changes since the approved version), resubmit after a rejection, or review it when the yearly review is due within 30 days or overdue. For a review where nothing changed, use Mark as reviewed on the policy. The table also shows the next review date and the acknowledged percentage. A policy leaves the list once it is submitted and approved and its review is not due.
- Your activity periods that aren't finished: open, rejected, overdue, or submitted and waiting for approvers. Each shows its due date, the next step and a link to its Evidence page. A period leaves the list once it is approved or skipped. See Recurring activities.
- Acknowledgement of your policies: the percentage of people who have acknowledged the current approved version of each policy you own. Owners see percentages only, never who has or hasn't acknowledged.
My history
At the bottom of My Tasks, My history lists your own acknowledgements, submissions, approvals and other decisions, newest first, from the app's audit log. Select Load more to see older entries.
How reminders work
Compliance in a Box doesn't send email and uses no external service. Reminders are ordinary Confluence tasks, so they arrive through Confluence's own notifications, and nothing leaves Atlassian.
Your Compliance tasks page
When you first get a reminder, the app creates a private page for you in the compliance space, called Compliance tasks for followed by your name. It sits under a page called Compliance Tasks. Only you and the Compliance Admins can see it.
Each reminded item appears on your page as a Confluence task assigned to you, with a link to the policy or evidence page, its due date, and an "overdue" label when it is late. For example:
- Read and acknowledge the Access Control Policy
- Review and approve or reject: a policy or evidence submission
- Collect the evidence and submit: an activity period
- Review a policy (annual review due)
Because the task is assigned to you, Confluence notifies you that you've been assigned a task, and the task also appears in your Confluence task list. Whether that notification reaches you in Confluence, by email or both depends on your own Confluence notification settings.
To remind you again later, the app issues the same item as a new task, which notifies you again. Other changes to the page, such as an item being added or marked overdue, don't send a notification.
Important: ticking a task as complete does nothing in Compliance in a Box. Acknowledge, submit and approve in the app: from My Tasks, or from the Compliance in a Box item at the top of the linked policy or evidence page.
How tasks leave your page
A task is removed from your page once the item is done: the policy is acknowledged, the submission is decided, the evidence is submitted, or the item is skipped or excused. The page is updated once a day, so a finished item can stay on it until the next daily update. My Tasks is always current.
Your page only shows items you've been reminded about. If you have other open items that haven't had a reminder yet, the page says how many and points you to My Tasks, which lists everything.
The page is generated by the app, and any edits to it are overwritten.
Note: Confluence Free has no page restrictions, so on Free plans the Compliance tasks pages are visible to everyone who can view the compliance space. Settings shows this warning to Compliance Admins.
When reminders are sent
The app checks for due reminders once a day. Reminders follow a fixed schedule for each kind of item:
| Kind | Who is reminded | When |
|---|---|---|
| Policies to acknowledge | Each person who still has to acknowledge | When the acknowledgement opens, 3 days before it is due, then once a week after the due date (up to 4 times) |
| Approvals waiting | Each approver who hasn't decided | 2 days after the submission, then once a week (up to 8 times) |
| Activity periods opened (evidence to collect) | The activity owner | When the period's evidence page opens |
| Activity evidence due soon or overdue | The activity owner | 3 days before the due date, then once a week after it (up to 6 times) |
| Policy reviews due | The policy owner | 30 days before the review date, on the review date, then every 2 weeks after it (up to 6 times) |
Some limits keep reminders from piling up:
- One reminder per item at a time. A person gets at most one reminder about the same item within the number of days set in Reminder settings (7 by default). A scheduled step that falls sooner waits until that time has passed. Reminders sent by an admin with Remind count too.
- A daily limit per person. Each person gets at most a set number of scheduled reminders a day (5 by default). Overdue items go first; the rest follow on the next days.
- No catching up. Someone who joins partway through gets only the reminder that is due now, not the ones they missed.
- Active accounts only. People whose Atlassian account is deactivated or closed are not reminded.
Every reminder is recorded in the app's Audit Log as Reminder sent. Reminders stop while the app's license is inactive; finished items still leave people's task pages.
Remind people now
Compliance Admins can send an extra reminder about a policy acknowledgement at any time, from the Acknowledgements tab. Manual reminders are available for acknowledgements only.
Remind everyone who hasn't acknowledged a policy
- Open the Acknowledgements tab, on the By policy view.
- On the policy's row, select Remind (…). The number is how many people are outstanding.
- Confirm with Remind …. The result says how many reminders were sent, and how many people were skipped and why. For a large group, the reminders are sent in the background.
Remind one person
- On the By policy view, select the policy to see everyone in its campaign.
- Select Remind on the person's row. The Last reminded column shows when each person was last reminded about this policy.
Each person gets at most one manual reminder per policy per day (UTC); anyone already reminded today is skipped. People whose account isn't active are skipped as well. The Remind buttons are unavailable when reminders are switched off in Settings or the license is inactive. See Policy acknowledgements for the rest of this tab.
Weekly compliance summary
Once a week the app writes a Weekly compliance summary page under Evidence & Reports in the compliance space. Only the Compliance Admins and, if you've set one up, the Auditors group can see it. It shows:
- Overdue activity periods, acknowledgements and policy reviews
- Acknowledgement completion for each policy, with how many people are outstanding
- Policy versions and activity evidence waiting for approval
- What is due in the next 30 days
The page also holds a task for each member of the Compliance Admins group (up to 20), "Review this week's compliance summary", so each admin gets a Confluence notification every week. The page is replaced each week; the app's audit log keeps the history.
The summary is written on the weekday chosen in Reminder settings (Monday by default, in UTC), and never more than once a week. If a week's summary is missed, it is written on a later day.
Reminder settings
Compliance Admins configure reminders in Settings, in the Reminders section. Reminders are switched on by default, so a new installation starts reminding people as soon as there is work to remind them about.
| Setting | What it does | Default |
|---|---|---|
| Send reminders | Switches all reminders on or off, including the weekly summary and the Remind buttons. | On |
| Remind people about: | A switch for each kind of reminder: Policies to acknowledge, Approvals waiting, Activity periods opened (evidence to collect), Activity evidence due soon or overdue and Policy reviews due. | All on |
| Days between reminders about the same item | The least number of days between two reminders to one person about one item (1 to 30). | 7 |
| Reminders per person per day | The most scheduled reminders one person gets in a day (1 to 20). Overdue items go first. | 5 |
| Weekly compliance summary for the Compliance Admins | Switches the weekly summary on or off, and sets the weekday (UTC) it is written. | On, Monday |
Select Save reminder settings to apply your changes. There is no per-person opt-out: everyone with open work is reminded while their kind of reminder is switched on.
If reminders don't arrive
Work through these checks:
- Is there anything to remind about? Open My Tasks. If the item is there, check the schedule: for example, approvers are first reminded 2 days after a submission, and a person gets at most one reminder about an item every 7 days by default.
- Look for your Compliance tasks page. In the compliance space, open Compliance Tasks and then your own page. If the task is there, the reminder was issued and the problem is with notifications.
- Check your Confluence notification settings. Make sure Confluence is allowed to notify you about tasks assigned to you, in the app and by email if you want email.
- Ask a Compliance Admin to check the settings. In Settings > Reminders, Send reminders and the switch for that kind of reminder must be on.
- Check the license. Reminders stop while the app's license is inactive.
Compliance Admins can confirm that a reminder was sent in the Audit Log tab, where each one appears as Reminder sent. More help is in Troubleshooting and FAQ.