User guide

Troubleshooting and FAQ

Answers to the problems people most often run into, for Compliance Admins, owners, approvers and employees. Each answer explains why it happens and what to do about it.

  • Everyone

Setup and access

People see “hasn’t been set up yet”

Until a Compliance Admin finishes setup, everyone who isn’t an admin sees Compliance in a Box hasn’t been set up yet. Setup is finished once the compliance space exists and its pages have been generated. Admins see the Setup checklist in Settings instead, which lists what is still missing: the employee groups, the Compliance Admins group and the company profile come first, then the compliance space, then the pages. See Getting started.

Confluence asks me to “Allow access”

This is a one-time Confluence prompt. Every person is asked to grant the app access the first time they open it, before the page can show. Click Allow access. It doesn’t change your role: what you can see and do still depends on your role in the compliance program.

“You’re not part of this site’s compliance program”

You have no role in the app: you aren’t in an employee group or the Compliance Admins group, you don’t own or approve anything, and you have no policy to acknowledge. If you think you should be included, contact your company’s security contact (shown below the message when one is set), or ask a Compliance Admin to add your group under Settings → Access. Auditors don’t need a role: they read the compliance space and the Evidence & Reports pages in Confluence.

“Finishing installation…” doesn’t go away

Right after the app is installed or upgraded, it prepares its storage. While it does, the app shows Finishing installation… and refreshes by itself. This normally takes a moment. If it lasts much longer, reload the page, and if it still doesn’t clear, contact support.

A tab is missing

Tabs depend on your role. Employees see My Tasks and Policies. Owners and approvers also see Activities. Only Compliance Admins see Dashboard, Acknowledgements, Audit Log and Settings. Owners see the acknowledgement percentage of their own policies, but not who has or hasn’t acknowledged. Roles are checked every time you use the app, so a group change takes effect straight away.

Confluence didn’t let the app create the space

Some sites don’t allow apps to create spaces. The app then shows Confluence didn’t let the app create a space. A Confluence admin can create a new, blank space instead (no pages or blog posts), give Compliance in a Box the space admin permission there, and enter its key in Settings → Compliance space. The app checks that it can see the space, that it is the space admin, and that the space is empty apart from its home page. If you see That space key is taken, choose a different key.

Pages and permissions

Someone can’t edit a policy or evidence page

This is intended. Pages the app manages are locked so only their owner and the Compliance Admins can edit them. An activity’s owner can edit the activity page and its evidence pages. To let someone else edit, a Compliance Admin changes the owner in Settings → Owners & approvers. The page lock and the new owner’s space access follow the change.

If an owner still can’t edit their own page, open Settings → Permissions. A warning titled Space roles set by hand block some owners means that person already has a space role, given by hand, that doesn’t allow editing. The app doesn’t change roles it didn’t give. Raise their role in the space settings, or remove it so the app can grant access.

Someone can’t open a policy page they need to read

The app gives view access to the compliance space to the employee groups chosen in Settings → Access. People outside those groups, for example members of a policy’s specific audience group or an approver who isn’t an employee, may not be able to view the space. Add their group to the employee groups, or give them view access to the space in Confluence.

A managed page was trashed, archived or restored

The app notices when a policy or evidence page is moved to the trash, archived or deleted. A policy shows Page in trash in the Policies tab, and any submission waiting for approval is cancelled. A trashed page can’t be submitted, approved or acknowledged. Restore it from the space’s trash (or unarchive it) and the flag clears; then submit it again if needed. If a change was missed, the daily check picks it up within a day.

Important: the app never recreates a managed page that was trashed or deleted, so restore pages from the space’s trash rather than purging them. If a managed page was permanently deleted, contact support.

If an activity page is in the trash, the app can’t create that activity’s evidence pages under it until you restore it.

Page restrictions or space permissions were changed by hand

A daily check compares the space and its managed pages with who should have access, re-applies any page lock that was removed or changed, and restores space access the app gave that went missing. Each repair is recorded in the audit log. To repair straight away, click Re-apply permissions in Settings → Permissions.

The app only removes access it gave itself. Access a Confluence admin gave by hand, such as auditor guests or other apps, is left alone. If Confluence doesn’t let the app set space permissions on your site, Settings → Permissions shows Apply these space permissions in Confluence with the list to apply yourself; the daily check reports anything still missing.

“The app is no longer a space admin”

Someone removed the app’s admin permission from the compliance space, so it can’t manage its pages. Give Compliance in a Box the space admin permission again in the space’s settings.

Pages aren’t locked on Confluence Free

Confluence Free doesn’t support page restrictions. The app still works, but anyone who can edit the space can edit every policy, and the Evidence & Reports pages and personal task pages are visible to everyone who can view the space. Settings warns about this. To lock pages, upgrade to Confluence Standard or above.

Policies and approvals

An approval disappeared after an edit

Approvals are bound to the exact page version that was submitted. If the page is edited before every approver has approved, the submission is cancelled, usually within seconds, so nobody approves text they haven’t seen. The policy’s page in the app shows The last submission was cancelled with the reason. Any published edit counts, however small. Trashing the page or withdrawing the submission cancels it too. Submit the new version for approval.

Editing a policy after it was approved doesn’t remove the approval. The policy shows Changes pending until the new version is approved, and employees keep acknowledging the approved version.

I can’t approve or reject

Check the message the app shows:

  • You aren’t an approver of this submission. Approvers are fixed when a version is submitted. If you were added as an approver afterwards, you aren’t asked for that submission; the owner can withdraw it and submit again.
  • The page was edited after it was submitted, so the submission has been cancelled. Ask the owner to resubmit. See An approval disappeared after an edit.
  • You were looking at a different version. Reload and check the submitted version. Reload, read the submitted version and decide again.
  • This submission isn’t waiting for approval any more. Reload to see what happened. It was decided, withdrawn or cancelled in the meantime.
  • Not available without a licence: see The app is read-only.

Rejecting needs a comment that says why.

I can’t submit a policy for approval

  • No approver assigned: a Compliance Admin assigns at least one approver in Settings → Owners & approvers.
  • Only the policy’s owner or a Compliance Admin can submit it. Ask the owner, or ask an admin to change the owner.
  • This policy is already awaiting approval. Only one submission can wait at a time: it has to be decided or withdrawn first.
  • Nothing changed since the approved version. Use “Mark as reviewed” instead. For an annual review with no changes, use Mark as reviewed.
  • The page changed since you opened it. Reload and try again.

Why is an approval marked as a self-approval?

The approver also owns or submitted the item. That is allowed, so a new site isn’t blocked when one admin owns and approves everything, but it is flagged in the audit log, on the dashboard and in the approval log, because auditors may ask for an independent approver. Assign a different approver in Settings → Owners & approvers.

Acknowledgements

A policy isn’t showing for someone to acknowledge

A person is asked to acknowledge a policy when all of these are true:

  • The policy requires acknowledgement and has an approved version. Nothing can be acknowledged before the first approval.
  • An acknowledgement campaign is open. One opens when the policy is first approved and after each approval marked as a material change. A non-material approval keeps the current campaign, and earlier acknowledgements still count.
  • The person is in the policy’s audience: All employees means the employee groups in Settings → Access; otherwise the specific groups set on the policy.
  • The policy hasn’t been retired.

A Compliance Admin can check the policy in the Acknowledgements tab, which lists everyone the current campaign asks and their state.

A new starter sees “Not yet required”

People who join a policy’s audience, such as new hires or someone moving team, are picked up by the daily run and asked to acknowledge, with a due date 30 days later. Until then the policy shows as Not yet required in their My Tasks, and they can already acknowledge it.

“A newer version of this policy was approved”

A new version was approved while you were reading. Acknowledgements always apply to the approved version, so reload, read the new version and acknowledge again. If the page has edits that aren’t approved yet, the app links you to the approved version; that is the one you are acknowledging.

Someone is shown as “Not required”

The Acknowledgements tab says why: Left the audience (they left the policy’s groups; if they come back while the campaign is current, they are asked again), Excused (an admin excused them, with a reason), Former user (their account was deactivated), Account closed or Policy retired. Acknowledgements already given are never removed.

Activities and evidence

An evidence page didn’t appear

The app creates each period’s evidence page in its daily run, a set number of days before the period is due (14 by default). Each period is due on its last day. When an activity starts, only the current period opens; earlier ones aren’t backfilled. Open the activity in the Activities tab: Next periods shows the day each page will appear, and a period whose page isn’t there yet reads Not created yet.

If the app couldn’t create a page, the activity shows Some evidence pages couldn’t be created with the reason:

  • Another page in the space already has the evidence page’s title. The app leaves that page alone. Rename or move the other page; the app tries again every day.
  • The activity’s page is in the trash or was deleted. Restore it from the trash.
  • Confluence refused to create the page. The app tries again every day.

New periods also stop opening while the app is unlicensed. A Compliance Admin can change the days of notice with Edit schedule; periods already opened keep their dates.

Evidence submissions follow the same rules as policies

Editing an evidence page while it waits for approval cancels the submission, just as for policies; see An approval disappeared after an edit. A period that is approved or skipped can’t be skipped again, and a skip can’t be undone.

Evidence & Reports pages

My edits to a report page were lost

The Policy Approval Log, Policy Acknowledgement Report, Activity Completion Report, Audit Log and Controls Matrix pages are generated from the app’s records. Edits made by hand are overwritten on the next refresh, and Settings counts them as hand edits overwritten. Keep notes for auditors on a separate page.

An auditor can’t see the report pages

Report pages are visible only to the Compliance Admins and, if set, the Auditors group. Choose the group in Settings → Access → Auditors group (optional). Its members can view the pages but not edit them.

A report page couldn’t be refreshed

The pages refresh daily, and an admin can click Refresh now in Settings → Evidence & Reports at any time. If pages fail, the section lists why. A report page in the trash isn’t recreated: restore it from the space’s trash. If another page has the same title, rename or move it.

Reminders

People aren’t getting reminders

Reminders arrive as Confluence task notifications. Each person with open work gets a private Compliance tasks for … page under Compliance Tasks in the compliance space, and each reminder is a task assigned to them there. Check these in order:

  1. Send reminders is on in Settings → Reminders, and so is the switch for that kind of reminder.
  2. The person’s Confluence notification settings allow task notifications. Their tasks also appear in their Confluence Tasks list.
  3. The throttles: by default the app reminds about the same item at most once every 7 days, and sends at most 5 reminders per person per day, overdue items first. The rest follow on the next days.
  4. The person’s Atlassian account is active. Deactivated and closed accounts aren’t reminded.
  5. The app is licensed. Reminders stop while it is unlicensed.

Reminders go out with the daily run, not the moment something becomes due. Admins can send one at once with Remind on the Acknowledgements tab, at most once per person per policy per day.

Ticking a task doesn’t complete anything

That is expected. The tasks are reminders only, and people can’t tick them on their task page. Acknowledge, submit or approve in the app or from the panel on the page itself; the task then leaves the page.

Importing policies

An import was refused

  • The policy is waiting for approval. Nothing can be imported into a policy while a version waits for approval, because the import would cancel it. Let it be decided, or withdraw it, then import.
  • You can’t find the source page. Search only shows pages you can open yourself. Ask the page’s owner for access.
  • The page is too large. Pages over 900 KB can’t be imported. Split the page, or paste the text into the policy page by hand.
  • The import won’t start. Pages with attachments, images, mentions or macros that show other content need the I understand what won’t be copied box ticked first.
  • Another import is in progress. Wait for it to finish, or discard it if it was never started. Only one import runs at a time. An import that was never confirmed is discarded after 24 hours.
  • Not available without a licence: see The app is read-only.

Attachments and images aren’t copied: the owner re-attaches them. See Importing and custom policies.

Licensing

The app is read-only

A banner reading Compliance in a Box is unlicensed, or the message Not available without a licence, means the app’s license on your site isn’t active. Everyone can still view everything, admins can still refresh the Evidence & Reports pages, and background repairs keep running. Approving, rejecting, acknowledging, submitting, importing, changing settings and generating pages stop, as do new evidence pages and reminders. Your Confluence pages are unaffected.

A site admin renews the license through the Atlassian Marketplace. The app is free for up to 10 users. For billing and invoices, contact Atlassian or your Atlassian partner.

People and accounts

Something is owned by a former employee

When an account is deactivated or closed, nothing is reassigned automatically. The Dashboard shows Reassign: … belong to former users, and Settings → Owners & approvers flags each item with Former user: pick a new owner or Former user: replace this approver. Pick the new person there.

Approvers are fixed when a version is submitted, so a submission waiting on a former approver can’t finish. Change the approvers, then withdraw the submission and submit it again.

Why does someone appear as “Former user”?

Their Atlassian account was deactivated or closed. Their open acknowledgements are no longer required; a deactivated person who is reactivated is asked again with a new due date. When Atlassian reports an account closed, the app permanently removes the link to that person everywhere, including the audit log, as Atlassian requires. Counts and dates stay, and the report pages show “Former user” after their next refresh.

Uninstalling and data

What should I do before uninstalling?

Open Settings → Evidence & Reports and click Refresh now, so the report pages are up to date. Your policies, evidence pages and report pages stay in your Confluence space after you uninstall. The app’s own records (approvals, acknowledgements, the audit log) are deleted by Atlassian after a retention period. The app also tries a last refresh as it is uninstalled, but that is best effort.

I uninstalled by mistake

Reinstalling starts with empty records. Atlassian can reconnect the old data only on a support request made within 21 days of uninstalling, so contact us as soon as possible.

Error messages

These are the titles of the general error messages the app shows, and what to do about each.

MessageWhat it means and what to do
You don’t have accessYour role doesn’t allow this. Ask a Compliance Admin.
Not available without a licenceThe app is read-only. See The app is read-only.
Finishing installation…The app is getting ready after an install or upgrade. Try again in a moment.
Changed by someone elseSomeone saved a change while you were editing, so yours wasn’t saved. Reload, check the latest values and try again.
The page changedThe Confluence page has a newer version than the one you were looking at. Reload and check it.
Finish setup firstSomething has to be done first, such as creating the compliance space. The message says what.
Please check your inputA field needs fixing. The message says which.
Something went wrongAn unexpected error. Try again; if it keeps happening, tell your Compliance Admin or contact support.

Still stuck?

Email support@auralitesolutions.com. A person on our team sends a first response within 8 hours. To help us answer in one reply, include:

  • your Confluence site address (for example yourcompany.atlassian.net);
  • what you were doing, what you expected and what happened instead;
  • the exact error message, and roughly when it happened, with your time zone;
  • your role: Compliance Admin, owner, approver or employee.

Never send passwords or API tokens. We can’t see the data the app stores in your site, so we may ask you to look something up for us. More on the Support page.