Content Audit
The Content Audit scans every current Confluence page for keywords you configure, identifies stale content, records page ownership and access restrictions, and catalogs attachments. It reports risk findings and page inventory without storing any page content or attachment binaries.
What it audits
The Content Audit performs three coordinated analyses in a single run:
- Risk Findings — pages matched against your configured sensitive-content keywords (credentials, personal data, financial terms, or custom categories).
- Page Inventory — complete page metadata including creation and update dates, current ownership status, stale-content flags, and access restrictions.
- Attachment Inventory — file counts, types, sizes, and creation metadata per page (no file binaries are stored).
How it works
The audit reads each page's body, performs keyword matching against the stripped text, records metadata, then discards the body. Nothing from the page body, snippets, or attachment binaries are written to persistent storage. Results contain page title, space, matched keywords, match counts, and governance metadata only.
Configuring keywords
Keywords are managed site-wide in Configuration → General Settings under Risk keyword categories. The active keyword configuration is read from Config at audit start time and snapshotted into the run record, so changes to Config after a run do not alter that run's keyword snapshot.
Keywords are matched case-insensitively as substrings against stripped page text. A single page can produce multiple finding rows — one per matched keyword.
Built-in preset categories
Three preset categories are provided as defaults:
| Category | Keywords |
|---|---|
| Credentials | password, api key, secret, token, credential, passphrase, private key |
| Personal Data | email, phone, address, date of birth, social security, passport, national id |
| Financial | credit card, bank account, routing number, iban, swift, cvv |
When you first run a Content Audit and no custom keyword configuration has been saved, the effective keyword union is built from these three preset categories.
Snippet capture
Snippet capture (a ~160-character text window around each first keyword match) is configured site-wide in Configuration → General Settings. When enabled, snippets are held temporarily during the scan and delivered to the browser session for the current results view — they are never written to storage. If you load this run later from Audit Library, snippets are not available.
Configuring scope and stale-content threshold
- Audit scope — run against all current spaces or enter specific space keys to scope the scan. Only current (non-archived) spaces and pages are scanned.
- Stale content threshold — configured in Configuration → General Settings. A page is flagged as stale if its last update is older than this threshold (default: 365 days) as of the scan start time.
Running a Content Audit
- Navigate to Audit 360 for Confluence in Confluence Settings.
- Select Content Audit from the top navigation.
- Click Run New Audit.
- The configuration screen shows your current keyword categories and snippet setting (both sourced from Configuration).
- Choose the audit scope: all spaces or selected space keys.
- Click Start Audit to begin the scan.
- The audit runs in the background. Progress is shown by phase and percentage.
- When complete, results load automatically and display in three subtabs.
Reading the results
All results display in three subtabs: Audit Overview, Page Inventory, and Risk Findings.
Audit Overview tab
Summary cards show key metrics from the scan:
| Card | Meaning |
|---|---|
| Pages scanned | Total pages crawled across all included spaces. |
| Risk findings | Total page–keyword match pairs found. One finding per matched keyword per page. |
| Keywords matched | Number of distinct keywords that produced at least one finding. |
| Spaces with findings | Number of spaces containing at least one page with a keyword match. |
| Stale pages | Pages not updated since the configured stale threshold (default: 365 days). Review Page Inventory for details. |
| Pages with owner | Pages with an assigned owner out of the total scanned. |
| Review-worthy owners | Pages whose owner is deactivated, unverifiable, or unlicensed — account statuses the app detected as potentially problematic. Use the "Review-worthy owners only" filter in Page Inventory to see them. If this card shows "Not checked," the ownership verification was skipped (usually due to time limits on very large audits). |
| Total attachments | Total attachment files found across all scanned pages. |
| Pages with attachments | Number of pages that have at least one attachment. |
| Attachment storage | Total size of all attachments across scanned pages. |
The Execution details section shows the audit timestamp, who ran it, which keywords were used, audit scope, and whether snippets were captured.
If there are any warnings (e.g., scan stopped due to time limit, snippets truncated, ownership checks incomplete) they appear in the Coverage notes section.
Page Inventory tab
A sortable, filterable table of every page scanned. By default, pages are sorted by last updated date (most stale first).
Columns:
| Header | Content |
|---|---|
| Space | Space key and name |
| Page | Page title (linked to Confluence) |
| Status | Current or Archived |
| Version | Page version number |
| Last updated | Relative time (e.g., "2 months ago") |
| Updated by | Account name of the last editor |
| Owner | Account name of the designated page owner (if assigned) |
| Owner status | Deactivated (owner's account is inactive), Unverified (owner account cannot be found), Unlicensed (account marked as unlicensed), or a lock icon (if direct page restrictions apply); active owners show a dash |
| Stale | Stale or Current based on the configured threshold |
| Attachments | Count of attachment files for this page; click the expand icon to view details |
Filters:
- Text search — search by page title or space key
- Status — filter by Current or Archived pages
- Space — filter by one or more spaces
- Stale only — show only stale pages
- Review-worthy owners only — show only pages whose owner is flagged as deactivated, unverifiable, or unlicensed
Attachment inspection:
Click the expand icon on any page row to open a modal with attachment details — filename, media type, file size, creation date, and who uploaded it. Attachment metadata is recorded during the scan; binaries are never stored.
Risk Findings tab
A sortable, filterable findings table with one row per page-keyword match, sorted by match count descending (highest risk first).
Columns:
| Header | Content |
|---|---|
| Space | Space key and name |
| Page | Page title (linked to Confluence) |
| Keyword | The matched keyword (highlighted as a label) |
| Matches | Number of occurrences of the keyword in the stripped page text |
| Last updated | Relative time since the page was last updated |
| Snippet | (current session only) Truncated ~160-character context around the first match; only visible if snippets were enabled at audit time |
Filters:
- Text search — search by space key, page title, or keyword
- Keyword — filter by one or more matched keywords
- Space — filter by one or more spaces
Snippet availability:
Snippets are only shown during the current audit session. If you load a previous run from Audit Library, the Snippet column is hidden and a coverage note explains that snippets are not available for historical runs (they were never persisted after the scan completed).
Owner-status enrichment
The Content Audit checks the status of each page owner (the designated page owner, not the last editor) and flags pages whose owner is no longer a valid, active user:
| Status | Meaning | Action |
|---|---|---|
| Deactivated | The owner's Confluence account is inactive. | Consider transferring the page to an active owner or archiving it. |
| Unverified | The owner's account could not be found or verified. | Investigate whether the account was deleted or the ownership record is stale. |
| Unlicensed | The owner's account is marked as unlicensed. | Consider whether an unlicensed owner should be managing active content. |
Active, licensed owners are not flagged. If the app was unable to check ownership status for this run (usually due to time limits on very large audits), the Review-worthy owners card shows "Not checked" and a coverage note explains this.
Audit Library
Every completed audit is saved automatically. Open Audit Library to:
- Reload a previous run and review all three tabs.
- Pin (star) an audit for easy access.
- Rename a run with a custom label.
- Move a run to trash, and permanently purge after 60 days.
When you load a historical run from Audit Library, keyword tags and audit metadata are displayed, but snippets are unavailable (they were never persisted beyond the scan session). The Risk Findings tab indicates this with a coverage note.
Coverage notes
When the audit completes, any relevant notices appear in the Coverage notes section on the Audit Overview tab:
- Snippets not captured — If snippets were excluded from this run via the Configuration setting.
- Snippet truncation warning — If the scan found too many keyword matches to deliver all snippets in a single session (capped at 100 entries); re-run a more focused scope to get full snippet coverage.
- Ownership checks incomplete — If the audit ran out of time before checking all page owners; ownership information is partial.
- Restriction checks capped — If the audit was checking for access restrictions on review-worthy pages but reached a limit; the flagged pages shown are the first 200 that were checked.
- Scan stopped early — If the audit hit the time limit before scanning all spaces; results shown are partial but saved automatically.
- Space listing failures — Named warnings for any spaces where the page listing failed partway through.