Built on Atlassian Forge

Shakamize Document Approval and Audit Trail for Confluence

Document control with page approvals, locking and an audit trail you can verify, for ISO 9001, SOX and quality management.

Approval panel on a controlled Confluence page

Screenshot coming soon

The approval panel on a controlled page, showing the current approved revision, the pending step and the approvers.

Document control that holds up under review

Built for teams running ISO 9001 quality management, SOX controls and internal audit programmes on Confluence.

Approvals that actually lock the page

An approved page stops being editable.

Most approval add-ons record that a page was approved and then let anyone keep editing it. The approved version and the live version drift apart, and the approval record quietly stops meaning anything. Here, approval locks the page. Changing it requires an explicit, recorded step that starts a new revision and a new approval cycle, so what is marked approved is what a reader sees.

  • Configurable review and approval steps per space or page
  • Locking on approval, with a recorded unlock that supersedes the approved revision
  • Reviewers and approvers see exactly which revision they are signing off

Approval state and lock on a controlled page

Screenshot coming soon

The lock state on an approved page, with the recorded unlock action that starts a new revision.

A tamper-evident audit trail you can verify yourself

You check the record. You do not have to take our word for it.

Every approval event is written into a hash-linked chain, where each entry commits to the one before it. You can run the verification yourself and export the result, so the integrity of the record is something you demonstrate to an auditor rather than something you assert on a vendor’s behalf.

  • Each event is chained to its predecessor, so an altered or removed entry breaks verification
  • Verification is run by you, over an export you hold, and produces evidence you can keep
  • Events capture the action, the version it applied to, the basis for the decision and the time

Audit trail with chain verification result

Screenshot coming soon

The audit trail for a document, with the result of a verification run the customer triggered.

A register and reporting that answer the audit question

What is approved, what is overdue, and who signed it.

A document register lists controlled pages with their approval state, current approved revision, approvers and review dates. Overdue reviews surface instead of being discovered during an audit. Everything is exportable, so the record leaves with you and does not become a reason you cannot switch tools.

  • Register of controlled documents with state, revision and owners
  • Overdue and upcoming periodic reviews surfaced ahead of time
  • Export of the register and the audit trail for offline evidence

Document register with approval state and review dates

Screenshot coming soon

The register of controlled documents, showing approval state, approved revision, approvers and overdue reviews.

It runs entirely on Atlassian infrastructure

The app is built on Atlassian Forge and runs inside Atlassian’s own platform. There is no external server of ours in the path, no customer data is transmitted to a third-party service, and there is no separate account for your team to create.

For a security review, that means the surface to assess is the app’s declared Forge scopes and its behaviour inside your Atlassian site, and nothing else.

What we claim, precisely

  • The audit trail is tamper-evident, not tamper-proof. The guarantee is that alteration of a recorded entry can be detected by verification, not that alteration is impossible. Verification detects modified or removed entries within the chain; it does not by itself detect a chain truncated at its most recent end.
  • Verification is something the customer runs over an export they hold. The checker is published as source at github.com/shakamize/document-control-verifier under the Apache 2.0 licence, with a release for every version and the SHA-256 of the file on each release page. The documentation marks what has shipped and what has not.
  • That an approval happened is a permanent record. Attributing it to a named person is not: an approver who exercises a right of erasure is removed from the trail by name, the approval stays, and the record still verifies.
  • We describe the app as support for ISO 9001, SOX and internal audit document control. We make no claim of compliance with, or suitability for, any specific named e-signature or electronic attestation standard.
  • We state that the app runs on Atlassian infrastructure and sends no customer data to external services. We make no data residency guarantee.

Getting started

Installation, space configuration, approval workflow setup and audit trail verification are covered in the documentation. Questions before you install are welcome.