Skip to content

Software companies

Notion and Confluence: separating confidential HR and finance pages before a data review

By SourceX Editorial · Updated

Short answer

To separate confidential HR and finance pages in Notion and Confluence before a data review, triage space by space. Start from permissions, because restricted spaces and pages usually mark sensitive content, then check labels, owners and titles. Exclude HR, finance, legal and leadership spaces whole, and review mixed spaces such as engineering page by page.

Key takeaways

  • Permissions are the best first signal: teams tend to restrict the pages they already know are sensitive.
  • Whole spaces or teamspaces for HR, finance, legal and leadership are excluded by default, without page-by-page review.
  • Sensitive content leaks into open spaces through interview scorecards, one-to-one notes, headcount plans and vendor pricing.
  • Each excluded or included space needs a named owner's confirmation, recorded in one triage sheet.
  • Work from an export or a metadata list, never by changing live permissions in the wiki.

Why start with permissions?#

Permissions are the best first signal because people restrict the pages they already consider sensitive. In Confluence, space permissions and page restrictions show where access was deliberately narrowed, and a view restriction on a parent page also hides its child pages. In Notion, private pages, closed or private teamspaces, and pages shared only with named people play the same role.

Permissions are a starting point, not a verdict. Some HR pages sit in open spaces because nobody thought to restrict them, and some restricted pages are restricted for reasons unrelated to sensitivity, such as an unfinished draft. Owners and content checks close those gaps.

Sharing outside the company is a separate signal worth capturing. Pages shared with guests, contractors or customers, or published through public links, often hold material that belongs to someone else, such as a customer's onboarding plan or a contractor's statement of work. List them alongside restricted pages and review them as a group.

Space-by-space triage checklist#

The triage runs on a list of spaces or teamspaces with their metadata, not on page content. A workspace admin can usually produce that list without opening sensitive pages, which keeps the first pass limited to people who already have access.

Plan the export route at the same time, because each route behaves differently. Confluence Cloud space admins can export a whole space or selected pages to PDF, CSV, HTML or XML, and a Confluence site backup includes attachments only if they are selected. A Notion workspace export leaves out pages the exporting user cannot access, such as other members' private pages, so an export run by a regular member is not a complete inventory. Settle the route before the triage is finished, so the excluded spaces can be left out of the export itself rather than removed afterwards.

  • List every Confluence space and Notion teamspace with its owner, permission summary, approximate page count and last update date.
  • Classify each space as exclude, include after review, or mixed.
  • Inside mixed spaces, list pages with view restrictions or limited sharing and mark them excluded by default.
  • Search labels and tags such as confidential, hr, comp, finance, legal and board.
  • Search titles and text for sensitive terms, then read the hits.
  • Ask each space owner to confirm the classification in writing.
  • Record every decision, with the reason and the owner, in one triage sheet.

Which spaces should be excluded by default?#

Spaces built around people, money, legal matters or company strategy are excluded whole, because reviewing them page by page costs more than the little licensable content they hold. Spaces built around product, engineering and support work are where licensable knowledge lives, and they get page-level review.

Which spaces should be excluded by default?
Space or teamspaceTypical pagesDefault
People and HRCompensation bands, performance reviews, investigations, offer letters, org changesExclude
FinanceBudgets, forecasts, board decks, payroll, bank and vendor payment detailsExclude
LegalContracts, disputes, privileged advice, regulatory correspondenceExclude
LeadershipStrategy, fundraising, acquisitions, reorganization plansExclude
Personal spaces and private pagesDrafts, one-to-one notes, personal task listsExclude
SalesAccount plans, pricing approvals, deal reviewsReview; customer names and pricing come out
EngineeringArchitecture, runbooks, postmortems, design reviewsInclude after review
Support and successTroubleshooting guides, playbooks, known issuesInclude after review

Where sensitive pages hide in open spaces, and how to flag them#

HR and finance content often hides in spaces that look safe. Engineering managers keep hiring notes beside architecture docs, and product teams paste cost figures into planning pages. These are the places to check inside every mixed space.

Inside a mixed space, a few signals catch most sensitive pages, and each one is cheap to check. Combine them rather than relying on any single one, then send flagged pages to the space owner for a decision.

Notion databases deserve a specific look. A database in an engineering teamspace can carry a property such as salary band, rating or start date that turns an innocent-looking table into an HR record. Check database properties as well as page text.

  • Interview scorecards, hiring loop notes and candidate databases kept by engineering teams.
  • One-to-one templates and meeting notes that include performance feedback.
  • Team retrospectives and incident postmortems that name individuals.
  • Headcount, level and promotion planning inside engineering or product planning pages.
  • On-call pay, bonus or overtime arrangements in operations runbooks.
  • Vendor pricing, invoices and contract terms on procurement or tooling pages.
  • Embedded spreadsheets and dashboards that pull from finance systems.
Where sensitive pages hide in open spaces, and how to flag them
SignalHow to checkWhat it catches
View restrictions or limited sharingRestriction or sharing lists from the admin view or export metadataPages someone already judged sensitive
Labels and tagsLabel search in Confluence; tag or property filters in NotionPages marked confidential, HR, comp or finance
Page owner or creatorOwner field compared with the HR, finance and leadership rosterHR and finance work filed in the wrong space
Sensitive termsSearch for salary, compensation, severance, investigation, termination, payroll, wire, forecast, term sheetUnlabeled pages in open spaces
Attachments and embedsList attached spreadsheets, PDFs and embedded dashboardsFiles that hold the sensitive data while the page text looks harmless

Illustrative: a data integration SaaS triages two wikis#

Illustrative: a fictional data integration software company runs Confluence for engineering and support and Notion for company operations. The COO leads a triage before a data review.

In Confluence, the engineering and support spaces are kept for review, while an engineering leadership space holding hiring plans and level guides is excluded whole. A text search finds restricted performance documents filed under the engineering space, which are excluded. In Notion, the people, finance and leadership teamspaces are excluded without review, and an interview scorecard database inside the engineering teamspace is excluded on its own. Each owner signs off in the triage sheet, and the review set ends up narrower and far easier to prepare than the full workspace.

The triage also surfaces a handful of customer onboarding plans shared with external guests in the support space. They are moved to the review queue with the sales pages, because they name customers and their internal contacts.

How SourceX approaches internal documentation#

SourceX starts with metadata only: which wikis you use, which spaces exist and roughly how many years they cover. No pages are shared during the fit check, and HR, finance and legal spaces are expected to stay out of scope.

In the Rights and Preparation steps of the SourceX five-step transaction, the triage sheet becomes the record of what was excluded and why, and it feeds the privacy record and release authorization in the SourceX Evidence Packet.

Frequently asked questions

Should we tighten permissions in Confluence or Notion before the review?

Not as part of the review. Changing live permissions can disrupt teams and hides the signal you are using to triage. Work from a metadata list or an export copy, and handle any permission fixes you discover as a separate internal clean-up.

Are company handbooks and policy pages worth including?

Sometimes. Published policies such as security procedures or engineering standards carry little personal data, but their value is modest compared with design reviews, runbooks and postmortems. Exclude any handbook section that describes compensation, benefits or disciplinary processes in specific terms.

What about page history and comments?

Older page versions can contain text that was later removed because it was sensitive, and inline comments can name people. Unless revision history clearly adds value, export the current version only and review comments with the same rules as page text.

Who should sign off on excluded spaces?

The space owner confirms the classification, and the HR and finance leads confirm that their own spaces, and any pages they own in other spaces, are fully out. The COO signs the triage sheet as a whole.

Can a classification tool do the triage for us?

A tool can flag pages faster, but it cannot know your org chart, which customers are confidential or why a page was restricted. Use it to prioritize the human review, and keep owner sign-off as the final decision for each space.

Do links to Google Drive, Slack or other tools inside pages matter?

Yes, in two ways. Linked files are usually not exported with the page, so the content behind them is out of scope unless exported separately, but the link text and URLs can still reveal file names, customer names or channel names. Strip or replace them during preparation.

Sources

  • Confluence Cloud space admins can export a space, or selected pages in it, to PDF, CSV, HTML or XML from Space settings. Source
  • A Confluence Cloud site backup includes attachments only if selected. Source
  • Pages the exporting user cannot access, such as other users' private pages, are not included in a Notion workspace export. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify