Running the ISMS
Using document control
Purpose
Controlled documents are a core part of every ISMS: a policy is only valid once it has been approved — and it only takes effect once the people concerned have read it. Document control maps exactly that, right on the Confluence page: Approval (by defined people/groups) and Read confirmation, enabled per page individually or together, with an audit-proof log.
Where you work with it
| Place | What you do there |
|---|---|
| Below the page title of every page in the ISMS space | The entry “Dokumentenlenkung · Document control” shows your own state, e.g. “✍️ Your approval is requested”, “📖 Read confirmation pending” or “✅ Approved (v5)”. One click opens the dialog. |
| ISMS Hub → Document control | Three tabs: Overview (key figures: Controlled pages, Open approvals, Open confirmations, Confirmation rate), Jira issues and My tasks. |
| ISMS Hub → Setup & Configuration | The site-wide notifications switch (Jira administrators only, see below). |
Who may do what
| Task | Who |
|---|---|
| Set up control, start and withdraw rounds | Page owner or space administrator |
| Approve, reject, confirm reading | only the assigned person themselves |
| See status and progress | anyone who may read the page |
| See the named per-person state (Show breakdown) | only owners and space administrators |
Setting up control (owner/space admin)
- Open the page and click Dokumentenlenkung · Document control below the title. For you, the dialog has the tabs Status, Settings and Log.
- In the Settings tab, enable the blocks you need: Approval and/or Read confirmation (each section has an Enabled toggle).
- Under People & groups, pick the participants (search field “Search names or groups…”). Groups are resolved when a round starts (snapshot) — later group changes apply from the next round. Atlassian Teams cannot be selected; use the group behind the team.
- Approval only: choose the Approval rule — One approval is enough, Everyone must approve or Majority (more than 50%); the dialog does the maths: “With 5 approvers: 3 approval(s) needed.”
- Optional: set Due within (days, 0 = none) and Remind every (days, 0 = off); with both blocks active, Start read confirmation only after approval is granted (default: on) ensures the approved version is what gets confirmed.
- Choose the behaviour On a new page version: Ask (default, recommended), Always or Never.
- Optional: Check reachability shows before starting how many recipients would receive no e-mail (no Jira access).
- Click Save — or Save & start round to begin immediately. Later, steer rounds via Start new round and Withdraw round.
Approving or confirming (all participants)
- Open the page (link from the e-mail or from My tasks) and click the document-control entry below the title.
- Approvers: in the section “Your approval is requested”, optionally add a comment (“Comment (optional, recommended when rejecting)”) and click ✓ Approve or ✕ Reject.
- Read confirmation: tick “I have read and understood this document.” and click Confirm now.
Result: your decision is recorded immediately with name, timestamp and document version (“You approved/confirmed this version.”). Owners see the complete log in the Log tab; entries are never changed or deleted.
New page version
| Setting | Behaviour |
|---|---|
| Ask (default) | The owner decides per version in the dialog: Yes, required again (rounds restart) or No, editorial change (log entry only, the effective version is carried forward). Until decided, the overview shows the state outdated. |
| Always | Every new version restarts the rounds automatically. |
| Never | New versions always count as editorial — only the log is written. |
If a controlled page is deleted or moved to the trash, the control is suspended and open rounds are closed — the log is kept in full.
Notifications and Jira evidence
- Participants receive a personal e-mail per round via Jira — with instructions and a link to the page. Deciding always happens on the page itself; the e-mail deliberately contains no decision buttons.
- Platform limit: the e-mail only reaches accounts with access to the ISMS project (Jira licence). Confluence-only users get no e-mail — they see their task below the page title and in My tasks. The breakdown shows each person’s delivery state (Delivered / No email / Failed).
- Reminders run daily at the configured interval; overdue rounds are escalated once to the page owner.
- Per controlled document the app keeps one Jira collector issue (type Document) and per round one subtask (type Control Round, e.g. “Freigabe · Information security policy · v3”) as an audit-proof record — please do not delete them. The Jira issues tab shows both; the document-control values are authoritative, the Jira status is supplementary.
- The site-wide switch sits in Setup (card Document control — notifications, toggle “Send notifications (mentions + approval emails)”; default: on). With it off, everything keeps working — tasks then appear only in Confluence.
Licence
Reading always stays possible. Without a valid licence the dialog shows: “No valid licence is active for document control. Existing data stays visible, but changes and new approval/confirmation rounds are blocked.”
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20