---
title: "Restricting app edit access via data security policies"
canonical: "https://support.appfire.com/space/SUPPORT/3070754825/Restricting%20app%20edit%20access%20via%20data%20security%20policies"
format: markdown
---
## Summary

Learn how to prevent any app from accessing or editing content in specific confidential spaces in Confluence Cloud using Atlassian Data Security Policies.

---

## Use Case

### **Scenario**

You have specific Confluence spaces containing highly confidential information. You need to ensure that the Comala Document app cannot view or edit any content within these restricted spaces.

### The Challenge

In Confluence Cloud, apps operate using a site-level "app identity." Standard attempts to restrict the app, such as removing the "Add-on user" from Space Permissions or applying manual Page Restrictions, are often unreliable. In many cases, the app may still appear to have edit access, or permissions may seem to "revert" because of the global scopes granted to the app at the site level.

### Solution

To effectively "block" an app from specific spaces without uninstalling it globally, you must use **Atlassian Data Security Policies**. This is the most secure method to override app-level permissions at the space level.

#### Prerequisites

- **Permissions:** You must be an Atlassian Organization **Administrator**.
- **Plan:** This feature requires a Confluence **Premium** or **Enterprise** plan.

#### Instructions

1. **Open Atlassian administration:** Navigate to <u>[admin.atlassian.com](https://admin.atlassian.com/)</u> and select your Organization.
2. **Navigate to security policies:** Go to **Security** > **Data security policies**.
3. **Create a new policy:**
  - Click **Create policy**.
  - Give the policy a name (for example, "Restrict Comala Access for Confidential Spaces").
4. **Add app access rule:**
  - Under the **Rules** tab, find **App access**.
  - Set the rule to **Blocked**.
  - Select the **Comala Document app** you want to block from the list of apps.
5. **Select spaces:**
  - Go to the **Coverage** tab.
  - Add the specific confidential **Spaces** where you want this restriction to apply.
6. **Activate:** Save and activate the policy.

#### Validation

Once the policy is active, the Comala app identity is strictly prevented from reading or writing user-generated content in those specific spaces. Any existing workflow bylines or app elements will cease to function on pages within those spaces.

#### Important impact notes

- **Workflow interruption:** When the app is blocked via a Data Security Policy, **Comala workflows and automation will NOT function** in those spaces. The app cannot read the page content to apply status changes or signatures.
- **Read/Write access:** This policy blocks both viewing (Reading) and editing (Writing). It is an "all or nothing" security layer for the selected spaces.

---

### Additional Resources

- [https://support.appfire.com/space/CDCCL/631114144/App+scope+and+permissions](https://support.appfire.com/space/CDCCL/631114144/App+scope+and+permissions)
- [https://developer.atlassian.com/cloud/confluence/data-security-policy-developer-guide](https://developer.atlassian.com/cloud/confluence/data-security-policy-developer-guide)