The access review is not the report. It is the record that it happened.
AccessLedgerresolves effective permissions across Jira Cloud and Confluence Cloud, runs the quarterly round where each manager signs off on their own scoped list, and keeps the result as a timestamped, tamper-evident record you can hand to a SOC 2 or ISO 27001 auditor.
An Atlassian Forge app. It runs inside your own Atlassian site, and it is billed per seat on the Atlassian invoice you already pay — no separate vendor, no separate checkout.
Three things that are true of this and not of the alternatives
One record across both products
The two access-review apps on the Atlassian Marketplace today each cover a single product — one is Jira-only, the other is Confluence-only, and the Confluence one reports without a sign-off step. An access review covers every system in scope, and Jira and Confluence are usually both in scope for the same company. Two records that do not join is two half-answers.
Confluence view and edit restrictions do not inherit the same way
A view restriction cascades to child pages. An edit restriction does not. So a page can look locked down while everyone who can open it can also rewrite it. Reading that off the admin screens one page at a time is where mistakes survive. AccessLedger resolves the whole chain and shows you the pages where the two disagree.
The evidence cannot be backfilled
A permission report can be regenerated any time you want one. A record of who reviewed what, and on what date, cannot be created after the fact. That is the artefact an auditor asks for, and it is the reason the record gets more valuable the longer you keep running rounds.
What it covers, and what it does not
In the first version
- Jira Cloud: user to group to project role to permission scheme to project, resolved to an effective answer.
- Confluence Cloud: space permissions and page restrictions, including where the view and edit cascade disagree.
- Certification rounds with delegated, scoped manager sign-off.
- A sealed, timestamped evidence record with CSV and PDF export.
Not in the first version
- Changing permissions. It reads; you remediate.
- Systems outside Jira and Confluence Cloud.
- Atlassian Data Center and Server.
- Identity-provider and single-sign-on integration.
Ready when the listing is
The app is not yet listed on the Atlassian Marketplace, so there is nothing to install today. We would rather say that plainly than point you at a page that does not exist.