AccessLedger

The access review is not the report. It is the record that it happened.

AccessLedgerresolves effective permissions across Jira Cloud and Confluence Cloud, runs the quarterly round where each manager signs off on their own scoped list, and keeps the result as a timestamped, tamper-evident record you can hand to a SOC 2 or ISO 27001 auditor.

Not yet on the Atlassian MarketplaceSee an example record

An Atlassian Forge app. It runs inside your own Atlassian site, and it is billed per seat on the Atlassian invoice you already pay — no separate vendor, no separate checkout.

Three things that are true of this and not of the alternatives

One record across both products

The two access-review apps on the Atlassian Marketplace today each cover a single product — one is Jira-only, the other is Confluence-only, and the Confluence one reports without a sign-off step. An access review covers every system in scope, and Jira and Confluence are usually both in scope for the same company. Two records that do not join is two half-answers.

Confluence view and edit restrictions do not inherit the same way

A view restriction cascades to child pages. An edit restriction does not. So a page can look locked down while everyone who can open it can also rewrite it. Reading that off the admin screens one page at a time is where mistakes survive. AccessLedger resolves the whole chain and shows you the pages where the two disagree.

The evidence cannot be backfilled

A permission report can be regenerated any time you want one. A record of who reviewed what, and on what date, cannot be created after the fact. That is the artefact an auditor asks for, and it is the reason the record gets more valuable the longer you keep running rounds.

How a round runs

  1. Step 1

    Resolve

    AccessLedger reads Jira and Confluence permissions inside your own Atlassian site and resolves them to an effective answer — not the scheme, the outcome. Every grant carries the chain that produced it: the group, the role, the permission scheme, the space or page restriction.

  2. Step 2

    Delegate

    Open a round and each manager gets only their own scope. They approve, revoke, or record an exception with a written reason. You see who has finished and who has not, without chasing anyone by email.

  3. Step 3

    Seal

    When the round closes, the decisions, reviewers and timestamps are sealed into one record with a SHA-256 digest over its contents, and exported as CSV or PDF. Later rounds add to the history; they do not overwrite it.

The whole point is the last step. Read a complete closed round before you decide anything — it is exactly what the app produces.

What it covers, and what it does not

In the first version

  • Jira Cloud: user to group to project role to permission scheme to project, resolved to an effective answer.
  • Confluence Cloud: space permissions and page restrictions, including where the view and edit cascade disagree.
  • Certification rounds with delegated, scoped manager sign-off.
  • A sealed, timestamped evidence record with CSV and PDF export.

Not in the first version

  • Changing permissions. It reads; you remediate.
  • Systems outside Jira and Confluence Cloud.
  • Atlassian Data Center and Server.
  • Identity-provider and single-sign-on integration.

Questions

Does this make us SOC 2 or ISO 27001 compliant?
No. AccessLedger produces the user-access-review evidence those frameworks ask for. Compliance is determined by your auditor, across far more than access reviews. We are not auditors and nothing this app produces is an audit opinion.
Can it change permissions for us?
Not in the first version. It reads permissions and records decisions; removing access is something you do in Jira or Confluence, and the record notes what was removed and when.
Where does it run, and what leaves our Atlassian site?
It is an Atlassian Forge app, so it runs on Atlassian's own infrastructure inside your site. There is no server of ours in the path.
How is it billed?
Per seat through the Atlassian Marketplace, on the Atlassian invoice you already pay. There is no separate checkout here and this site takes no payment.
What if we want a refund?
Billing and refunds are handled by Atlassian under the Atlassian Marketplace terms that apply to your subscription, because Atlassian is the merchant of record. If the app fails to produce a record for a round you ran, write to us and we will work it through with you.
Do you have customers yet?
No. This is a new product and we would rather say so than imply otherwise. The sample record below is generated by the same pipeline a customer's round would use, on a fictional company.

Ready when the listing is

The app is not yet listed on the Atlassian Marketplace, so there is nothing to install today. We would rather say that plainly than point you at a page that does not exist.

Not yet on the Atlassian MarketplaceSee an example record