Configuration
The Configuration page is where Confluence administrators set governance policies that apply across all audit runs. Instead of configuring audit parameters on every run, you set them once, and all subsequent scans automatically respect your site's policies.
Configuration has two tabs: General Settings (where you set thresholds and keywords) and Trash Management (where you restore or permanently delete trashed audit runs).
General Settings
Governance Thresholds
Set the age limits that determine what the app flags as stale.
| Setting | What it does | Default |
|---|---|---|
| Content age threshold | Pages not updated within this many days appear as stale in Content Audit. | 365 days |
| Space inactivity threshold | Spaces with no page updates in this many days are flagged as inactive. | 365 days |
| Trash retention | Deleted audit runs are permanently removed after this many days. | 60 days |
Each threshold accepts values between 30 and 3,650 days.
Risk Vocabulary
The Content Audit scan uses keyword categories to identify content at risk. The app comes with three built-in categories: Credentials, Personal Data, and Financial. You can customize these or create your own.
In the Risk Vocabulary section, you can:
- Add a category — Click "+ Add category" to create a new category. Enter a name and add keywords.
- Rename a category — Click the category name or the menu (⋯) and select "Rename category". Press Enter or click elsewhere to save the new name.
- Delete a category — Click the menu (⋯) and select "Delete category".
- Add keywords — Type a keyword in the input field and press Enter. Keywords are automatically normalized (lowercase and trimmed). Each category requires at least one keyword.
- Remove a keyword — Click the × on a keyword chip to remove it.
Every category must have a name and at least one keyword. At least one keyword must exist across all categories combined.
Scan Options
- Show matched text in results — When on, Content Risk results include the surrounding sentence for each keyword match. When off, results show only the keyword and location.
All changes to General Settings remain unsaved until you click the "Save configuration" button. Click "Reset to defaults" to discard your changes and restore all values to their defaults.
If any field has been changed since the last save, it displays a subtle background highlight. This visual cue shows you which fields have unsaved changes.
Trash Management
The Trash Management tab shows all audit runs you've sent to trash. You can:
- View trashed runs — The table displays the run name, audit type, the date it was trashed, who trashed it, and how many days remain before permanent deletion.
- Restore a run — Click the Restore icon (↶) to move a run back to the Audit Library. The run immediately returns to your Audit Library and no longer appears in Trash.
- Delete permanently — Click the Delete icon (🗑) to permanently remove a run and all its data. A confirmation dialog appears; confirm to delete immediately without waiting for automatic purge.
The retention period (set in Governance Thresholds) determines when trashed runs are automatically deleted. When a run reaches its deletion date, the "Deletes in" column shows "Due for deletion" and the app permanently removes it on the next daily maintenance run.
You can search for a specific run by name, and filter the table by audit type (Spaces Audit, Content Audit, or Permission Audit).
Access and permissions
Only Confluence site administrators can view or edit Configuration. If you don't have administrator permissions, the Configuration tab does not appear in the app.
How configuration affects audits
Configuration settings apply prospectively — to all audit runs you create after saving changes. Existing audit results are never recalculated when you adjust a threshold.
This design keeps your audit history stable and comparable over time. If you change the content age threshold from 365 days to 180 days, a page that was flagged as stale in a previous run remains stale in that run's results. Only the next Content Audit scan uses the new 180-day threshold.
The same applies to Risk Vocabulary and snippet inclusion: changes affect only future scans, not the keywords or snippets displayed in previous audit runs.
Configuration history
The Configuration page shows who last updated the settings and when. Display names are shown when available; if a user has been deactivated or their profile cannot be resolved, the account ID is displayed instead.
Configuration changes are logged but not displayed as a full history. Each save overwrites the previous value.