Who can see what

There is one rule, and everything else follows from it: approval visibility follows the page. If you can read the page you can see its approval status. If you cannot, you see nothing, and you are not notified about it either.


#At a glance

Who

Status and counts

Event history

Anyone who can read the page

VISIBLEVISIBLE

A signed-out reader on a public page

VISIBLEHIDDEN

Somebody who cannot read the page

HIDDENHIDDEN

#Signed-out readers on a public page

If a page is public and carries the approval macro, somebody who is not signed in can see the status and the counts, for example that three people approved and one is still pending.

They never see the event history. The list of who did what and when is not sent to an anonymous reader at all, so the History display tells them the log is unavailable rather than showing them an empty table.


#Restricted pages

Approvals work perfectly well on restricted pages. So that it can keep reading and updating the approval, the app adds itself to the page restriction list.

People still see only what their own permissions allow, and reviewers who cannot read the page are filtered out of notifications rather than being sent a link they cannot open.


#Notifications follow the same rule

Emails and Slack messages only go to people who can actually read the page. Add a reviewer who has no access and they are silently skipped rather than sent something useless.


#Published sites

On a Capable Site the macro renders as a static snapshot with the status and counts. It is not interactive and carries no history, which is the same boundary as a signed-out reader in Confluence. See Sites.


#AI assistants

An assistant sees exactly what you see. Every lookup runs with your own access, so it cannot surface an approval on a page you could not open yourself. See Rovo and AI assistants.


#A few things that catch people out

  • Visibility and permission are different questions. What you are allowed to do is in Who can do what.

  • Counts are visible to anonymous readers. Names and comments are not.

  • A request that seems to be ignored is often a permission problem, not a people problem.

  • Search results obey the same rule, so a report never shows you a page you cannot read. See Search and reporting.



One rule to remember: if they can read the page, they can see the approval.