← Treekeep
DocumentationPrivacyEULASupport

Treekeep documentation

Treekeep: Edit Restriction Inheritance for Confluence, by Great Work LLC.

What it does

Confluence passes view restrictions down a page tree but not edit restrictions. Treekeep adds:

  1. Inheritance rules: every page below a top page carries that page's edit restrictions, including pages created, moved or copied there later.
  2. Bulk changes: add, remove or replace people and groups, remove all restrictions, or make pages match their parent, across a page tree or a CQL search, for edit or view restrictions. Always previewed first, and undoable.
  3. Report: pages whose restrictions differ from their parent page.

Where to find it

  • On any page: ••• (More actions) > Restrictions (Treekeep). Tabs: Inheritance, Bulk change, Compare with parent, My changes.
  • Space settings > Treekeep (space admins): Inheritance rules, Bulk change (page tree or CQL in this space), Report, History and undo.
  • Confluence admin settings > Treekeep (site admins): the same for the whole site.

Inheritance

  1. Open the top page, ••• > Restrictions (Treekeep) > Inheritance.
  2. Choose Match (pages below get exactly this page's editors) or Add (pages below get this page's editors and keep their own extra ones).
  3. Keep "Keep the creator of a new page as one of its editors" on if people who create pages in this tree should be able to keep editing them.
  4. Preview: every page below, its editors now and after. Nothing is written yet.
  5. Apply and turn on inheritance.

From then on:

  • A new page, a page moved into the tree, or a copy gets the top page's edit restrictions within seconds. A moved page's own children follow shortly after.
  • When the top page's edit restrictions change, the tree follows (about 20 seconds later).
  • Stop inheriting here (and below) on a page opts that branch out; Inherit again brings it back. A page further down can have its own rule; the nearest rule wins.
  • Pause, Resume, Re-sync now, Switch mode, Turn off are on the top page's Inheritance tab and in Space settings > Treekeep > Inheritance rules. Turning a rule off leaves every page's restrictions as they are.

Pages Treekeep can't see (a view restriction that leaves Treekeep out) are not changed. To include a view-restricted tree, add "Treekeep: Edit Restriction Inheritance" to the view restriction of the top restricted page.

Bulk changes

  1. Pick Edit restrictions or View restrictions.
  2. Pick what to do: add, remove, replace, make each page match its parent, or remove all.
  3. Pick people (type a name) and groups (search by name).
  4. Pick which pages: from a page, this page and everything below, only the pages below, or only this page. From Space settings or admin settings, a page tree or a CQL query, for example label = "finance" or title ~ "policy" and ancestor = 12345. Treekeep adds type = page (and the space, in Space settings).
  5. Preview, check the list (filter by status or by a person or group), then Apply.

CQL tip: Confluence returns no results (not an error) for space keys or labels that don't exist, so a preview with 0 pages means the query matched nothing.

Report

Lists pages whose edit (or view) restrictions differ from their parent page. Run it for a page tree or a whole space. "Also list restricted pages that match their parent" turns it into a list of every restricted page; use Mentions person or group to see where someone is named. Preview: make these match their parent prepares a bulk change for every differing page.

Undo and history

Every change (bulk, inheritance, automatic) is recorded for 180 days with each page's restrictions before and after. Undo this change puts the earlier restrictions back on every page Treekeep changed, except pages someone changed since (listed as "Left alone"). Undo works even if the subscription has lapsed.

Safety rails

  • Treekeep never removes your own access: if a change would, you are kept as an editor (shown in the preview). You can switch this off for bulk changes.
  • It never leaves a page with no editor who is a person. A list with only apps or empty groups is blocked and the page is left as it is.
  • It never removes the last view entry from a page (which would expose it) unless you chose "Remove all restrictions".
  • Groups are matched by id, so a renamed group keeps working and a deleted group is dropped.
  • From a page, it only changes pages you can edit, like Confluence's own Restrictions dialog.

Why Treekeep is listed as an editor

Confluence requires the app making a restriction change to be listed in that restriction. So "Treekeep: Edit Restriction Inheritance" appears in edit lists it writes. It is an app account: nobody can sign in as it, it never counts as a person for the safety rails, and Treekeep hides it in its own screens. It also keeps Treekeep able to keep inheritance current.

Permissions

WhereWhoWhich pages a change can touch
Page menuPeople who can edit the pagePages they can edit
Space settingsSpace adminsPages in the space they can view
Confluence admin settingsSite adminsPages they can view

Data

Treekeep runs on Atlassian's Forge platform and sends nothing outside Atlassian. It stores rules and change records (page ids, titles, account and group ids). See the privacy policy: https://greatwork.company/apps/treekeep/privacy

Support

Support portal on the Marketplace listing. hello@greatwork.company.