Confluence
Bring the policies and procedures you keep in Confluence Cloud into the JupiterOne graph as evidence for GRC and continuous controls monitoring — spaces, the pages in them with their status, version number and last-updated date, the labels that classify them, and the users who created and last updated each page. Scope ingestion to your policy spaces and policy labels, then query for policies that have not been updated in the last year, see who last changed each one, and alert on policies last edited by an account that is no longer active. The integration reads page metadata only: page bodies, comments, attachments and content property values are never retrieved.
- Installation
- Authorization
- Data Model
- Types
Installation
This integration connects to Confluence Cloud using the Confluence Cloud REST API v2 (https://<your-site>.atlassian.net/wiki/api/v2/...) and ingests spaces, pages, page labels, and the users who authored them. It is built for GRC and continuous controls monitoring use cases where your policies and procedures live in Confluence. The integration is managed by JupiterOne and runs in the JupiterOne cloud, so no collector is needed. Confluence Data Center and Server are not supported.
Prerequisites
- A Confluence Cloud site, for example
your-company.atlassian.net. - An Atlassian account that can read the spaces and pages you want to ingest, and an API token for that account.
- Access to JupiterOne with permission to configure integrations.
Configuration in Confluence
The integration authenticates with Basic authentication: the Atlassian account email and an API token, sent as Authorization: Basic <base64(email:api_token)>. Every request is read-only.
Choose the account
The API token can see exactly what its Atlassian account can see. Pages and spaces the account cannot view are not returned by the API and are not ingested. We recommend a dedicated account that has:
- Access to the Confluence site (the Can use global permission).
- View permission on every space you want to ingest.
- Permission to view user profiles, which the Confluence Users data source needs.
The integration never writes to Confluence, so the account does not need edit or admin permissions.
Create the API token
- Sign in to id.atlassian.com/manage-profile/security/api-tokens as the account above.
- Select Create API token, give it a name, and choose an expiration date.
- Select Create, then copy the token. Store it somewhere safe; you will paste it into JupiterOne.
Create a regular API token, not an API token with scopes. Atlassian requires scoped tokens to call the API through api.atlassian.com, while this integration calls your site host directly.
Atlassian API tokens expire. New tokens default to one year, and one year is the longest you can choose. Note the expiration date: when the token expires, the integration stops ingesting until you add a new token to the instance.
Configuration in JupiterOne
To install the Confluence integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Confluence. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the Confluence account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
The Authentication fields below.
Authentication fields
| Field | Required | Description |
|---|---|---|
| Site Host | Yes | Your Confluence Cloud site host, for example your-company.atlassian.net. A full URL such as https://your-company.atlassian.net/wiki is also accepted and is reduced to the host. |
| Account Email | Yes | The email address of the Atlassian account that owns the API token. |
| API Token | Yes | The API token created above. |
When you save the instance, JupiterOne checks the credentials by requesting one space from the site.
Filters
All filters are optional. Leave them empty to ingest everything the account can read.
| Field | Default | Description |
|---|---|---|
| Space Keys | Empty (all spaces the account can read) | Ingest only these spaces, by space key. Applies to both spaces and pages. If none of the keys match a space, no pages are ingested. |
| Policy Labels | Empty (all pages) | Ingest only pages that carry at least one of these labels. Labels are matched case-insensitively. |
| Page Statuses | Current and Archived | Which page statuses to ingest. Options are Current and Archived. |
| Fetch Content Properties | Off | Also record the keys of each page's custom content properties in the page's contentProperties property. |
Click Create once all values are provided to finalize the integration.
Narrowing ingestion to your policies
A Confluence site usually holds much more than policies. Use Space Keys and Policy Labels together to ingest only your policy documents. For example, set Space Keys to the space where your policies live and Policy Labels to the label your team puts on approved policies, such as policy.
Each filter has a different cost:
- Space Keys is applied by the Confluence API, so it costs no extra requests and reduces the number of pages read.
- Policy Labels cannot be applied by the API. The integration lists every page in scope and makes one extra request per page to read its labels before deciding whether to keep it. Combine it with Space Keys on a large site so fewer pages have to be checked.
Policy Labels works on its own and does not need the Confluence Page Labels data source. That data source is what creates confluence_label entities in the graph.
Narrowing a filter later removes pages from JupiterOne. Pages that no longer match Space Keys, Policy Labels or Page Statuses on the next run are deleted from the graph.
Page statuses and drafts
By default the integration ingests current (published) and archived pages. Unpublished drafts cannot be ingested, because the Confluence pages API does not list them. A published page with unpublished edits is still ingested, with the status current.
Content properties
Fetch Content Properties makes one extra request per ingested page. Only the property keys are stored. Property values can hold arbitrary data, so they are never ingested.
Data Sources
Each data source can be enabled or disabled on its own. All data sources are disabled by default, so enable the ones you want to ingest. The confluence_account entity for the site is always created.
| Data Source | Description | Entities Created |
|---|---|---|
| Confluence Spaces | Spaces in the Confluence site, limited by Space Keys when set. | confluence_space |
| Confluence Pages | Pages in the Confluence site, limited by the filters above, with their status, version number, version message, created and last-updated dates, and (optionally) the keys of their content properties. | confluence_page |
| Confluence Page Labels | Labels on the ingested pages, used to tell policies from general wiki content. Makes one API request per ingested page. Requires Confluence Pages. | confluence_label |
| Confluence Users | Users referenced as creators, owners or last editors of the ingested pages, and creators of the ingested spaces. Requires Confluence Spaces and Confluence Pages. | confluence_user |
To ingest everything the integration supports, enable Confluence Spaces, Confluence Pages and Confluence Users, and add Confluence Page Labels if you want labels in the graph.
Confluence Users must be enabled together with Confluence Spaces and Confluence Pages. Users are not read from a directory: they are looked up from the creator, owner and last-editor account IDs on the ingested pages and spaces. If either Confluence Spaces or Confluence Pages is disabled, the Confluence Users data source does not run at all and no users are ingested.
Relationships are built only when every data source they need is enabled:
| Relationship | Requires |
|---|---|
confluence_account HAS confluence_space | Confluence Spaces |
confluence_space HAS confluence_page | Confluence Spaces and Confluence Pages |
confluence_page HAS confluence_page (parent page to child page) | Confluence Pages |
confluence_page HAS confluence_label | Confluence Pages and Confluence Page Labels |
confluence_account HAS confluence_user | Confluence Users (with Spaces and Pages) |
confluence_user CREATED confluence_page | Confluence Users (with Spaces and Pages) |
confluence_user UPDATED confluence_page (author of the current version) | Confluence Users (with Spaces and Pages) |
A parent-to-child page relationship is created only when the parent page was also ingested. With Policy Labels set, a policy whose parent page has no matching label has no parent relationship.
Each user is looked up in Confluence. The user's email is included only when the user's Atlassian profile privacy settings allow it.
Example queries
Policy pages that have not been updated in the last 12 months. On an instance where Space Keys and Policy Labels already limit ingestion to your policies:
FIND confluence_page WITH status = 'current' AND updatedOn < date.now - 12 months
With the Confluence Page Labels data source enabled, the same check for pages labeled policy, with a link to each page:
FIND confluence_page AS p
THAT HAS confluence_label AS l
WHERE l.name = 'policy' AND p.updatedOn < date.now - 12 months
RETURN p.displayName, p.updatedOn, p.webLink
What the integration does not collect
- Page body content, comments, attachments, and content property values.
- Unpublished drafts, blog posts, whiteboards, databases and folders. Only pages are ingested.
- Page and space permissions or restrictions.
- Policy acceptance or acknowledgment records. Confluence does not provide them, so evidence that employees have read and accepted a policy has to come from another system.
Rate limits
Confluence Cloud enforces rate limits. The integration paces its own requests and, when Confluence answers with 429 Too Many Requests, waits for the time given in the Retry-After header before retrying. Policy Labels, Fetch Content Properties and the Confluence Page Labels data source each add one request per page, so on large sites they make each run take longer.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Additional resources
- Manage API tokens for your Atlassian account — creating, expiring and revoking API tokens
- Basic auth for Confluence Cloud REST APIs — email and API token authentication
- Confluence Cloud REST API v2 — overview and pagination
- Pages API — page fields and supported statuses
- Spaces API
- Labels API
- Content properties API
- Users API
- Confluence Cloud rate limiting
OAuth Scopes
OAuth scopes that must be granted to the application or service principal.
Show OAuth Scopes (3)
read:page:confluenceread:space:confluenceread:user:confluence
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (5)
https://your-domain.atlassian.net/wiki/api/v2/pageshttps://your-domain.atlassian.net/wiki/api/v2/pages/{id}/labelshttps://your-domain.atlassian.net/wiki/api/v2/pages/{page-id}/propertieshttps://your-domain.atlassian.net/wiki/api/v2/spaceshttps://your-domain.atlassian.net/wiki/api/v2/users-bulk
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (5)
- https://developer.atlassian.com/cloud/confluence/rest/v2/api-group-content-properties/#api-pages-page-id-properties-get
- https://developer.atlassian.com/cloud/confluence/rest/v2/api-group-label/#api-pages-id-labels-get
- https://developer.atlassian.com/cloud/confluence/rest/v2/api-group-page/#api-pages-get
- https://developer.atlassian.com/cloud/confluence/rest/v2/api-group-space/#api-spaces-get
- https://developer.atlassian.com/cloud/confluence/rest/v2/api-group-user/#api-users-bulk-post
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (2)
| Step | OAuth Scopes | Endpoints |
|---|---|---|
| Fetch Labels | read:page:confluence | https://your-domain.atlassian.net/wiki/api/v2/pages/{id}/labels |
| Fetch Users | read:user:confluence | https://your-domain.atlassian.net/wiki/api/v2/users-bulk |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Account | confluence_account | Account |
| Label | confluence_label | Record |
| Page | confluence_page | Document |
| Space | confluence_space | Project |
| User | confluence_user | User |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
confluence_account | HAS | confluence_space |
confluence_account | HAS | confluence_user |
confluence_page | HAS | confluence_label |
confluence_page | HAS | confluence_page |
confluence_space | HAS | confluence_page |
confluence_user | CREATED | confluence_page |
confluence_user | UPDATED | confluence_page |
Confluence Account
confluence_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
siteHost * | string | The Confluence Cloud site host this account represents, e.g. your-company.atlassian.net. |
Confluence Label
confluence_label inherits from Record
| Property | Type | Description | Specifications |
|---|---|---|---|
labelId * | string | The Confluence label id (Label.id). | |
prefix | string | null | The label prefix (Label.prefix), e.g. "global" or "my". |
Confluence Page
confluence_page inherits from Document
| Property | Type | Description | Specifications |
|---|---|---|---|
authorId | string | null | Account id of the page creator (PageBulk.authorId); source of the CREATED relationship. | |
contentProperties | array | null | Keys of the custom content properties on this page, collected when the fetchContentProperties toggle is on. Only keys are stored; property values may contain sensitive customer data and are never ingested. | |
labels | array | null | Names of the labels attached to this page, collected by the labels step. Empty when the page has no labels; null when labels were not fetched. | |
ownerId | string | null | Account id of the current page owner (PageBulk.ownerId). | |
parentId | string | null | Id of the parent content for the page hierarchy (PageBulk.parentId); null for a top-level page. | |
parentType | string | null | Type of the parent content (PageBulk.parentType): page, whiteboard, database, embed or folder. | |
spaceId | string | null | Id of the space containing this page (PageBulk.spaceId). | |
versionAuthorId | string | null | Account id of the author of the current version (PageBulk.version.authorId); source of the UPDATED relationship. | |
versionMessage | string | null | The change message on the current version (PageBulk.version.message). | |
versionMinorEdit | boolean | null | Whether the current version was flagged a minor edit (PageBulk.version.minorEdit). | |
versionNumber | number | null | The current version number of the page (PageBulk.version.number); the review-cycle counter. |
Confluence Space
confluence_space inherits from Project
| Property | Type | Description | Specifications |
|---|---|---|---|
authorId | string | null | Account id of the space creator (SpaceBulk.authorId). | |
homepageId | string | null | Id of the space homepage (SpaceBulk.homepageId). | |
spaceType | string | null | The space type (SpaceBulk.type): global, collaboration, knowledge_base, personal, system, onboarding or xflow_sample_space. |
Confluence User
confluence_user inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
accountStatus | string | null | The account status (User.accountStatus), e.g. "active". | |
accountType | string | null | The account type (User.accountType): atlassian, app, customer or unknown. | |
isExternalCollaborator | boolean | null | Whether the user is an external collaborator (User.isExternalCollaborator). |