Skip to content

Confluence Public Links: The Audit Nobody Told You To Run

Illustration of an office building above a city skyline with one window open and paper planes drifting out

If your Confluence site arrived on Cloud after October 2023, every space on it has been allowed to publish to the open internet since day one. Here is how to find what actually is published, and what you can genuinely enforce on your plan.

The short version

  • Sites created or migrated on or after 16 October 2023 have the global public links toggle on, and every space set to allow.
  • A public link ignores every view restriction you have set, including the parent page and the space.
  • Anyone who can edit a page can publish it. There is no approval step.
  • Public whiteboards are editable by visitors, not just readable.
  • One content item has one permanent link. Switch it off and back on, and the old URL works again.
  • The organisation wide block requires Atlassian Guard. On Confluence Standard you cannot stop a space admin re-allowing.

1. The default nobody in your company chose

Atlassian documents the exact cutoff on its How secure are public links? page:

“If your site was created before October 16, 2023, the global public links toggle will be off until you choose to turn it on. If your site was created on or after October 16, 2023 — including sites migrating to Confluence Cloud — the global public links toggle will be on.”

Source: Atlassian, How secure are public links?

The clause in the middle is the one that matters to anyone who left Data Center. A migration creates a Cloud site, and a Cloud site created after that date starts with the toggle on. The same page continues:

“Because all spaces will allow public links by default, this also means all spaces on your site will be allowing public links from the time you created the site.”

Be precise about what this does and does not mean

Atlassian is explicit: “Confluence allows public links by default but no public links will actually be on by default. People will have to manually turn them on, where allowed.” Nothing was published for you. The permission was granted for you, everywhere.

And the decision to use that permission was delegated to every person who can edit a page:

“On specific content items, users can turn on or off a public link as long as they can edit the content and as long as public links are allowed by an admin.”

There is no request, no approval queue, no ticket. That is the design of the feature, and it is perfectly reasonable as long as you know it is switched on.

Public links exist on Confluence’s paid plans only, and only for some content types: “Only Confluence pages, live docs, and whiteboards can have public links, not any other type of Confluence content (e.g., blogs, databases, etc.).”

2. What a public link actually overrides

This is the part that decides how seriously to take the rest. Atlassian gives it its own heading, “Public links override all restrictions”, and then says:

“Public links ignore restrictions on who can view content in Confluence. Normally, Confluence content obeys view restrictions inherited all of its higher-level containers — any parent content, the space, and the site itself. However, the public link will just work.”

In case that was not clear enough, the same page adds:

“Again, this means restricting a parent item won’t have any effect on who can view the public link of a child item.”

Read that against how teams actually secure content. You restrict the parent page, or you restrict the space, and you treat the children as covered. For a child page carrying a public link, they are not covered. The restriction and the link are independent, and the link wins.

3. Three things that surprise people

The link is permanent

Atlassian’s heading is “Content will only ever have one public link”, and the behaviour is:

“If you turn a public link off, anyone using it to try to access the content will get a message saying the content can’t be found. But if you later turn the public link back on, people who already have the public link will again be able to access the content because it’s the same link as before.”

Switching a link off is therefore not revocation in the way most people assume. It is a pause. Everyone who ever copied that URL is back in the moment it is switched on again, even years later.

Whiteboards are not read only

“Public whiteboards can be edited by visitors, not only viewed, and likewise ignore any restrictions to who can view or edit the content in Confluence.”

Read access is enough to spread a link

“A user who can view a content item but not edit can still copy a public link that’s already on and share it with anyone on the internet.”

4. What Atlassian actually says about search engines

Worth quoting exactly, rather than paraphrasing in either direction:

“Atlassian has taken all necessary steps within its capability to make sure search engines do not index our public links. This means that public links are not indexed by search engines, which means no one will be able to find the public link in a Google search. They need the actual public link.”

Note the hedge, “within its capability”. The realistic exposure here is not a crawler discovering your page. It is a URL pasted into a shared document, a ticket, a Slack channel that later gained members, or an email thread that got forwarded. Public links are built to be shared. That is the risk model to plan around.

5. The audit, about ten minutes

The screen is documented on Manage public links across Confluence Cloud.

Step 1. Open the table. Confluence administration, then Settings, then Security in the left navigation, then the Public links tab.

Step 2. Do not read the status column as an answer. It shows whether each space allows public links. Atlassian is blunt about the limits of that:

“This doesn’t indicate whether anything is public — it simply indicates whether it’s possible to make anything public. A space could allow public links but have 0 active public links.”

The same page adds: “As a reminder, public links are allowed in all spaces by default.”

Step 3. Go through the Public content column. Selecting the number opens the per-space list of individual items. Read the status on each row, because the list holds two different states:

“It will only show content that are ON or BLOCKED. It won’t show content items that don’t have active public links and aren’t blocked.”

“ON = anyone with access to the content item can copy the public link and share it with anyone on the internet”

“BLOCKED = the content item’s public link is off and no one can turn it on until the content is unblocked”

Count the ON rows only

A BLOCKED row is already switched off. Counting the whole list, or trusting the column total without opening it, will inflate your number and send you chasing items that are not live.

Step 4. Compare the total to what you expected, then read the space names. A marketing or documentation space with public content is the feature doing its job. An HR, legal, finance or security space with public content is a different conversation.

Step 5. Check what you can actually enforce. This varies more than most people expect, which is the next section.

6. What you can actually enforce, by plan

ControlWhat it doesAvailability
Space set to NOT ALLOWED Stops new public links in that space, but “space admins in the space are free to change that to allow public links at any time” Confluence Standard and up
Space set to BLOCKED FROM ALLOWING “no one can turn on the public link for any content in that space and space admins are blocked from allowing public links” Confluence Premium and Enterprise only
Organisation wide public links control Blocks the feature across Confluence apps and switches existing links off Requires Atlassian Guard. Listed as “Not available” without it

The bottom row is the only control that removes the capability rather than discouraging it. Its behaviour is documented on Prevent public links:

“All existing public links will be turned off for content covered by the control. If you later change the control to allow public links, these links won’t be turned back on automatically.”

“Admins in Confluence can’t allow public links or change any public links settings in Global permissions or Space permissions when public links are blocked for an entire app.”

“When you change the control, it may take up to 10 minutes for the change to take effect in Confluence.”

The availability column comes from the table on What is a data security policy?, which lists Public links control as “Not available” for organisations without Guard, and available with Guard Standard and Guard Premium.

One detail from the same page that is easy to miss: the control also reaches Jira Product Discovery, which has its own public links in the Publish dialog. If you use JPD, that is a second surface you have probably not audited.

7. Two traps while you clean up

Space level behaves well. Turning off public links for a space switches its active links off, and they stay off:

“When you stop allowing public links in a specific space, all active public links in that space will change from an ON state to an OFF state.”

“If public links are ever allowed in that space again, all public links will remain in an OFF state until manually turned back ON.”

The global toggle does not. If someone switches the site wide toggle off and later back on, every per space decision you made is discarded:

“Any time an app admin allows public links on their site by turning the global toggle from an off to an on position, all spaces will automatically and immediately move to an “allowed” status, regardless of any prior setting. No status will be remembered from before.”

A careful afternoon setting thirty sensitive spaces to NOT ALLOWED can be undone by one person flipping the global switch twice, and nothing will tell you that it happened.

8. The genuinely hard part: history

The Public content column tells you what is public now. It does not tell you who turned things on, or when, or what was public last year and has since been switched off.

For that there is only the audit log, and Atlassian’s own knowledge base article, Identifying pages with Public Links enabled in Confluence Cloud, says so directly:

“For such a report including all pages shared externally, the following suggestion has been created: Audit pages that are actively shared with Public Links”

“While the feature is not implemented, a workaround could be to use the Audit logs of Confluence to find which pages had the setting enabled”

The workaround it describes: search the audit log for Public Links, take the Item affected value, which is the page ID, and open the page information view.

PAGE INFO BY ID
https://yoursite.atlassian.net/wiki/pages/viewinfo.action?pageId=<ID>

Source: Atlassian KB, Identifying pages with Public Links enabled in Confluence Cloud

And here is the catch that nobody mentions. That history expires. From View the audit log:

“Events remain in the log, by default, for one year.”

“you can adjust the log settings to keep events for as short as one standard month (31 days)”

“Once a week the system will run a clean up and delete any log entries that are older than the time frame you’ve set.”

If retention was ever turned down to 31 days, the record of who published what is already gone. Worth checking your retention setting while you are in there, because it is the difference between being able to answer a compliance question and not.

9. Stop this being news to you again

The most useful thing in this article takes five seconds. App admins are told automatically when someone allows public links for the entire site, but the per-link notification is a separate setting:

“App admins can also choose to be notified whenever anyone turns on a public link anywhere on your site.”

Your profile avatar, Settings, Email, Edit, and confirm the public links boxes are ticked. Space admins get the equivalent for their own spaces.

10. What I could not verify

This article is meant to be checkable, so here are its edges.

  • What exactly the Public content column counts. Atlassian describes it as the way into “more details about the active public links in that space”, but the list it opens contains both ON and BLOCKED rows. I could not find a statement of whether the column counts only ON, or both. That is why step 3 tells you to count the ON rows rather than trust the total.
  • Whether the per-link notification is on or off by default. The page says app admins “can also choose to be notified”, which reads like opt in, but the instructions for switching it off describe unchecking boxes, which reads like it may already be on. Check yours rather than assume.
  • Whether any public link has ever been indexed despite the protections. Atlassian’s sentence is hedged with “within its capability” and I have no evidence either way, so I am not going to speculate.
  • How many sites the October 2023 default affected. Atlassian publishes no figure.

The one number worth having

Open Confluence administration, Settings, Security, Public links, and add up the ON rows across your spaces. That is how much of your Confluence is reachable right now by anyone holding a URL, regardless of the restrictions you set on the parent pages or the spaces around it.

If that number is zero, you have lost ten minutes and gained a fact you can state in your next audit. If it is not zero, you now know which spaces to open first.

Quotations are reproduced from Atlassian’s public documentation as published on 25 September 2026 and are the property of Atlassian. Product behaviour changes; check the linked pages before acting on anything here.