Skip to content

Why these permissions

These are the existing Forge scopes already granted at install. This page explains why Shell needs each one. We are not adding or changing scopes.

ScopeWhy Shell needs itUsed by (commands)
read:confluence-space.summary / read:space:confluenceList spaces and navigate the site treels, cd, tab completion at /
write:confluence-spaceCreate folders that become pages/structures where space writes applymkdir / space-adjacent writes as already shipped
search:confluenceCQL-backed discoveryfind (-name, -mtime, -prune, …)
read:page:confluenceRead page metadata and bodiesls, ls -l, cat, tree, less, pipes
read:content-details:confluenceRicher page detail where neededdetailed listing / history-related reads
write:page:confluence / write:confluence-contentCreate/update/move/copy pagestouch, mv, cp, chmod writes
delete:page:confluenceMove pages to trash / removerm / del (and moves that Confluence models as delete+create where applicable)
read:attachment:confluenceList page attachmentsattach ls
write:attachment:confluence / delete:attachment:confluenceRename / trash attachmentsattach mv -y, attach rm -y

mv and cp stay same-space only (at most 100 sources). This is not a cross-space bulk migrator.

chmod lists or changes explicit page restrictions. Space-level permission admin is out of scope.