1. Home
  2. Docs
  3. Classification levels CLO...
  4. Quick Start
  5. Configure - Level Permissions

Configure – Level Permissions

Configure which Confluence groups can access pages at each classification level.

Navigate to Confluence Settings → Classification Levels Management → Level Permissions tab

How it works: When you assign groups to a classification level, the app automatically applies Confluence page restrictions to all pages with that classification.

For each classification level, you can configure two types of access:

  1. Edit Groups – Can edit and modify pages
    • Full access to page content
    • Can change classification levels
    • Can edit page properties
  2. View Groups – Read-only access
    • Can view page content
    • Cannot edit or modify
    • Cannot change classification

Steps:

  1. Select a classification level from the dropdown
  2. In the Edit Groups field, type and select Confluence groups
  3. In the View Groups field, type and select Confluence groups
  4. Click Save to apply the permissions
  5. The app will automatically update page restrictions for all pages with that classification level

Important Notes:

  • Groups must exist in Confluence before you can assign them
  • Changes apply immediately to all pages with that classification
  • Previous manual restrictions on pages may be overridden
  • Users need to be members of the specified groups to access classified pages

Best Practice:

  • Create dedicated groups for each classification level (e.g., secret-edit, secret-view)
  • Use descriptive group names that clearly indicate their purpose
  • Regularly audit group memberships to ensure appropriate access
  • Test permission changes with different user accounts

A new setting, “Apply page restrictions from classification levels”, is available in Classification Levels Management → Level Permissions.

  • On (default): classification levels control page restrictions. A level’s edit and view groups replace the page’s restrictions, and a level with no groups removes them, so a page’s classification always matches who can access it.
  • Off: classification only labels pages. Existing page restrictions are never changed.

Improved: consistent restrictions everywhere

Single pages, page trees, Save & Apply and large background jobs now all apply the same rule. Import Page Metadata applies restrictions only for levels that have groups, and never removes existing restrictions.

  • Classifying a page tree with a level that has no groups shows a warning with the number of pages affected.
  • Save & Apply on a level with no groups asks for confirmation and shows how many pages will lose their restrictions.

Improved: clearer results

  • If Confluence doesn’t allow a restriction change, the page is still classified and a warning explains why. Page restrictions require a paid Confluence plan.
  • Save & Apply now reports how many pages were updated and how many were not.