Sealed — User guide

Set up a workflow once per space, approve from the page itself, and let Sealed lock the page when the last approver signs off.

What Sealed does

Sealed puts an approval gate on a Confluence page and locks the page once it passes. Readers see the state under the page title. Approvers act from the same place.

Sealed shows up in five places: the byline under a page title, the panel that opens when you click it, the approval table macro, Approval workflow settings inside space settings, and the Approval dashboard where each person picks how much they want to hear.

Every request, approval, rejection, lock and release goes into an audit trail held in Atlassian-hosted storage. Each record carries a hash of the record before it, so a changed or missing record shows up.

Set up a space

A space admin does this once per space. Open space settings and choose Approval workflow settings. Confluence limits that screen to space admins, so ask one to open it if the screen tells you the Admin role is required.

Workflow and steps
Name the workflow, then add steps. Steps run in order. A step takes named users, groups, or both, and passes when all of its approvers approve or when any one of them does.
Default workflow
Mark one workflow as the default for the space. Sealed uses it for every request in that space. Without a default, nobody can request approval.
Groups that keep editing after a lock
Name the groups that can still edit an approved page. Leave this empty and Sealed locks nothing, so set it before you rely on locking.
How much the page shows
Header only, compact, or detailed. Detailed lists the approvers. Header only shows the state by itself. New spaces start on compact.
Groups that see no buttons
Members of these groups still see the approval state, without the buttons that act on it.
Label language
English or Japanese, English by default. This is the language Sealed writes into the page itself, so every reader sees the same words. The panel and the settings screens follow each reader's own Confluence language instead.

Request approval

Open the page, click the approval state under the title, and choose Request approval. Sealed picks up the space default workflow, expands each group into named approvers, and records the request.

Sealed fixes the approver list at the moment of the request. Editing the workflow later leaves pages already in review alone; the next request picks up the new definition.

Approve, reject, or ask for a revision

Only the approvers of the current step see the buttons. In a two-step workflow, the second step's approvers see nothing until the first step passes.

Approve
The step advances once it has the approvals it needs. When the last step passes, the page becomes approved and Sealed applies the lock.
Reject
Rejecting needs a comment. The page goes back to draft and the byline says so, so the author knows to make changes and resubmit.
Request revision
Use this to reopen an approved page. Sealed removes the lock, puts back the restrictions the page carried before, and returns the page to draft. The approvers of that page can do this.

What the lock does

When a page becomes approved, Sealed sets a Confluence update restriction naming the app itself and the groups you chose in space settings.

Read access does not change
Sealed touches the update restriction and nothing else. Everyone who could see the page still sees it.
The app stays in the list
Confluence rejects a restriction that evicts the caller, so the app user remains. That is also what lets Sealed take the lock off later.
No groups means no lock
When a space names no groups for editing after a lock, Sealed skips locking and records that it skipped, rather than locking everyone out of the page.
When the lock fails
Sealed keeps the approval and marks the byline with a warning instead of letting you believe the page is locked. This happens when the app user cannot change restrictions in that space.

Edits after approval

Anyone who kept edit rights can still change an approved page. When that happens, Sealed drops the approval rather than leaving a badge that no longer matches the content.

The byline then says the page was edited after approval. Request approval again to start a fresh round.

Sealed does not accept live docs. Confluence never tells Sealed that a live doc has changed, so an approval on one could not be dropped after an edit. Rather than let that happen quietly, Sealed refuses to start or complete an approval on a live doc. Create the document as a page.

Notifications

Sealed posts a footer comment that mentions the people involved, and Confluence sends its own notification from there. Sealed sends no mail of its own.

Every event
Requests and results both, including approvals, rejections and revision requests.
Requests only
You hear when someone needs your approval and stay quiet for results. This is the setting everyone starts on.
Nothing
Sealed leaves you out.

Sealed collects ten minutes of activity on a page into one comment, so five actions in a row produce one notification rather than five. Each person sets their own level on the Approval dashboard.

The approval table macro

Insert the approval table macro to show the approvers and the approval date in the body of the page. It reads the same state as the byline and carries no buttons, which makes it safe on a page that many people read.

Releasing locks

Space settings has a Locked pages tab. It lists the pages Sealed has locked in that space, with a release button on each row and a release all button above them. Sealed builds the list from the audit trail rather than from the pages themselves, so a page whose stored state was tampered with still appears.

Uninstalling releases what it can reach in the time Atlassian allows, which is not a guarantee on a large site. Release the locks from the Locked pages tab before you uninstall.

The audit trail

Sealed records who acted, on which page and which version of it, what they did, and when. The records live in Atlassian-hosted storage and each one is hashed against the record before it.

This release has no screen for reading or exporting the trail. The records are written and kept; a reader and a CSV export come in a later release.

Limits worth knowing

Approver counts
A step takes up to 100 approvers and a workflow up to 250 in total, counted after groups expand into people.
One default per space
A space carries one default workflow, and Sealed has no way to apply a workflow across many spaces at once.
No workflow picker
Requests always use the space default. Nobody is asked to choose.
No expiry
Approvals do not lapse on a schedule in this release.
Live docs
Sealed turns down approval requests and approvals on live docs, because Confluence does not tell it when a live doc has been edited. Reject and Request revision still work, so a live doc that was already in review can be sent back. Create documents that need approval as pages.
Two languages
English and Japanese.

When something looks wrong

The settings screen asks for the Admin role
Confluence blocks that screen for anyone who is not a space admin, and the request never reaches Sealed. Ask a space admin to open it.
You see the state but no buttons
Either you are not an approver of the current step, or your group sits in the list that hides buttons.
The byline says approved, lock not applied
The app user could not change restrictions in that space. Give the app permission to add and remove restrictions, then reopen the page and request approval again.
No notification arrived
Results reach only the people who chose every event, and everyone starts on requests only. Notifications also wait up to ten minutes while Sealed collects activity.

Support

Write to us and we will answer. Tell us the space key, the page, and what you expected to happen.

support@scritt.com