For most apps, the end of Connect is an inconvenience: a tool gets replaced. For a document control app it is a records problem. The approvals and signatures it holds are the proof that a procedure was reviewed and released, and an auditor can ask for them long after the app that produced them is gone.
What Atlassian has announced
| When | What it means |
|---|---|
| March 2026 | Apps built on Connect can no longer receive updates. |
| 31 January 2027 | Connect reaches end of support. Atlassian will only address critical security issues, and has said Connect apps "will not continue on in a steady state": breakages will become more frequent and the experience will degrade. |
Atlassian has not said that Connect apps will be switched off on that date. For controlled documents that is not much comfort: a system you can no longer rely on to retrieve its records is a finding waiting to happen, whether or not it still opens.
Why this is a records question
If your documents fall under FDA 21 CFR Part 11, the regulation is explicit about what has to survive. Among the controls it requires for closed systems:
- "The ability to generate accurate and complete copies of records in both human readable and electronic form suitable for inspection, review, and copying by the agency." (§11.10(b))
- "Protection of records to enable their accurate and ready retrieval throughout the records retention period." (§11.10(c))
And a signed record has to show, in any human-readable form, the printed name of the signer, the date and time of the signature, and its meaning, such as review or approval (§11.50). ISO 9001 and ISO 13485 frame it differently but arrive at the same place: approval records are retained for a defined period and must remain retrievable.
The retention period is yours, not the app's. If the records live only inside an app that is about to stop being maintained, they need to be secured while it still works.
First, find out where your records live
| Where the app keeps approvals | What happens when the app goes |
|---|---|
| In Confluence itself: page properties, labels or the page history | Mostly stays with the page, although without the app to interpret it. |
| In the app's own storage inside Atlassian | Goes when the app is uninstalled or stops working. |
| On the vendor's own servers | Depends entirely on the vendor. Ask them how, and until when, you can get it back. |
The vendor's documentation or privacy policy usually says which applies. If it doesn't, ask.
What to export while the app still works
- The approval record of every controlled page. Which version was approved, by whom, when, with what meaning, and the current status and next review date.
- The audit trail. Requests, approvals, rejections, comments and re-approvals, with their timestamps: the history, not just the latest state.
- A human-readable copy of each approved version with its signatures shown, typically a PDF per document. It is the form an auditor will actually look at.
- How the records were produced. The app's name and version and the date of the export. If the app was a validated system, this belongs in its validation file.
- A controlled place to keep all of it, with its own retention period and access control, outside the app you are leaving.
Is your app affected at all? Connect apps haven't been able to publish updates since March 2026, so a cloud version released after that on the Marketplace means the app is no longer on Connect. A "Runs on Atlassian" badge on the listing also means Forge. If neither applies, ask the vendor: "Is your Confluence app on Forge, and if not, what is your plan for 31 January 2027?" A vendor that moves its own app to Forge normally brings your records along, and this guide becomes a precaution rather than a necessity.
What to ask of a replacement
- Is an approval tied to a specific version of the page? When someone edits an approved page, it should stop showing as approved.
- Can approved pages be locked so controlled content doesn't drift between reviews?
- Is the workflow defined once, or copied into every space, where the copies diverge?
- Do documents fall due for periodic review on their own, and show as overdue when nobody signs them off?
- Is there one audit view of every controlled page with its state, approver, approval date and next review date?
- Where is the data stored? A "Runs on Atlassian" app keeps it inside your Atlassian instance.
- If you need Part 11 electronic signatures: does the vendor state and document Part 11 support, including the signature manifestation of §11.50 and audit trails, and give you material to validate it? If it isn't documented, assume it isn't there.
Replacing a validated system is a change, and changes go through change control. Plan the validation of the new system before the old one fails, not after.
Document Control for Confluence, our app, is built on Forge and runs entirely on Atlassian infrastructure. An approval belongs to a specific version of a page and is cleared when the page is edited; approved pages can be locked to their approvers; one workflow can cover every space by space or label; reviews fall due on schedule; and an audit view lists every governed page with its state, approver and dates. It does not provide 21 CFR Part 11 electronic signatures. It is free for up to ten users, and currently in Atlassian Marketplace review.
Documentation · Privacy and security · Document control for ISO 9001 in Confluence