DocsSign inInstall Kastel
All connectors

Plug your AI into Confluence without a restricted page coming up alongside the rest of its space.

With Kastel

Once Confluence is connected, your Kastel reads the text of the pages and blog posts in your spaces. Read access is inherited from the space, except where a page carries read restrictions of its own, which then override the space's. A space readable without an account is assigned to no department, and nobody reads it until an administrator has decided.

A Confluence space almost never has a single audience

A company that lives in Confluence files its knowledge by space. There is one space per team, a documentation space open to everyone, a leadership space, often a space per major client. The model is clean on paper, and it deforms over the years.

What deforms first is the exceptions. A salary review page is dropped into the HR space, then restricted to three people. An incident write-up naming a client lives in the engineering space, restricted to the leads. Each of those pages is protected by a restriction set on it by hand, which its space's permissions do not reflect.

That is the difference a connector loses when it settles for asking who owns the space. It then brings the salary review page up alongside the onboarding procedures, and nothing in the result signals that the two do not have the same audience.

The order in which your Kastel decides who may read a page

The calculation runs page by page, on every pass, and it stops at the first signal that settles the matter.

  1. The read restriction carried by the page governs first

    When the page names people or groups allowed to read it, they are what governs, and the space's permissions no longer count, however much wider they are. Groups are expanded into real people, all the way to the last page of the list.

  2. Failing that, the space's read permissions take over

    A page carrying no restriction of its own inherits its space's audience. The people and groups allowed to read that space are expanded the same way, and the page is then filed under the department they share. A permission list is never read halfway. If a page of results announces more to come without giving the means to reach it, the Confluence page is left with no audience, because a list read halfway can hand a whole department a page whose real audience was narrower.

  3. A space open without an account yields no audience

    A space a visitor can read without signing in is the broadest share there is, and it says nothing about who inside your company is meant to read what it holds. Its pages therefore wait for an administrator to assign them. Plenty of engineering teams publish their documentation this way, and it is the case where waiting surprises people most.

  4. A page the key cannot query is picked up later

    Sometimes the access key is not allowed to read the restrictions of a very closed page. That page is neither assigned at random nor forgotten. It is set aside for this pass and picked up on the next one, because the cursor never moves past content that could not be processed.

The scope, space by space and page by page

The connector asks Confluence for two content types only. The rest is not filtered after reading, it is never requested.

What your Kastel reads in Confluence

  • The text of the pages in your spaces, headings and lists included
  • The text of space blog posts
  • A page's read restrictions, to work out who may read it
  • The space's read permissions, when the page carries none

What it never reads

  • A page's attachments
  • Comments left at the foot of a page
  • Macro output and content pulled in from another tool
  • Archived pages and pages in the trash

Restrictions and space permissions are read as access rules, never as content. They serve to decide who may read a page, and the names they contain do not appear in what the AI receives.

One line changed in a space's permissions moves hundreds of pages

This is what makes Confluence particular, and it justifies an expensive engineering choice. The unit of permission is the space, so an administrator who adds a group to a space's readers changes the audience of everything it holds at once. No page has moved, no version date has changed, and yet the audience of every one of them is different.

Filtering on recently modified pages would miss that event, which is precisely the one this connector has to catch. Every pass therefore lists the accessible content again and recomputes its scope. A page whose text has not moved costs almost nothing to review, and a page whose audience has moved changes department, the version filed under the old department being retired before the new one is written.

The same reasoning holds the other way round, which is the way that matters to an auditor. Removing a group from a space's readers removes access on the next pass, with nobody having to remember it. That is what it means to govern your knowledge rather than copy it once and for all.

What actually arrives from a page is its text

The connector flattens Confluence's storage format into readable text. Headings, paragraphs and lists are kept, the markup goes. Space blog posts are handled like pages, which matters more than it sounds, since that is often where decisions get announced.

That text is not the page as a browser renders it. A page whose real content is an issue table, an automatic contents list or a page included from elsewhere yields little text, and your Kastel keeps only the little that is written out in the clear. On a heavily tooled space, that is a limit better known before connecting than discovered after.

The transport is the same one the Jira connector uses, and no write method exists in it. Where the Notion connector has to do without permissions Notion does not expose, Confluence says a great deal, and the difficulty lies in working out which of its signals really governs a given page.

What the Confluence connector does not do

It writes nothing in Confluence. No page is created, edited, moved or archived, and the transport shared with Jira exposes reading only. It also uses two permission signals and no more, the restriction carried by the page and its space's read permissions. Write permissions, administration roles and a group's entitlements in another Atlassian product play no part in the calculation.

It does not reproduce a page built out of macros. The text is extracted from the storage format, not from the rendering. On a page whose substance is produced by a dynamic table or by included content, what comes in is thinner than what you see on screen, and a plugged-in AI will answer accordingly.

It does not clean up a page's text. What your team wrote comes in as written, including an address, an access link or a credential pasted into a panel. The connector decides who may read a page, it does not rewrite what the page holds. If your pages double as an unofficial vault, that is a subject to settle in Confluence before connecting anything.

It does not erase what disappears on your side. A page deleted, archived or unshared drops out of what the connector sees, and your Kastel marks it as gone at the source. Its already-absorbed content stays readable there by the people who already had access, until an administrator decides to erase it.

See what the free core holds before paying for anything.

Kastel's core is free forever in self-host, with all of its connectors, which is enough to connect a Confluence space and judge on your own pages. The pricing page says what the core holds and where the paid plans begin.

See pricing
Other connectors in detail
Jira
An issue restricted by a security level stays restricted.
Notion
No page visible without an explicit share, and text only.
Guru
The verification state travels with the card, access comes from the collection.

See the full connector catalogue