Attachment Guard

Check a file out before you edit it, so your team can see you have it. If someone replaces it anyway, Attachment Guard tells you, records what happened, and can put the earlier version back.

What a check-out does, and what it doesn't

A check-out signals intent and detects what actually happened. It is not a hard lock.

Confluence Cloud gives apps no way to block an upload — every signal available to an app arrives after the file has already been replaced. So Attachment Guard notices the change, usually within a few minutes, tells the person who had the file checked out, and records who did it and which version changed.

We would rather say that plainly than have you discover it during an audit. In practice, knowing who changed what, when, and being able to put it back is what a document control process needs.


Checking a file out

  1. Open the page holding the attachment
  2. Click ••• at the top right → AppsAttachment locks
  3. Tick one or more files
  4. Optionally type a short note saying why — "Rev C release — do not edit"
  5. Click Lock selected

The note is worth adding. Anyone who looks at the file sees it, and if someone replaces the file anyway, the note appears in the message they receive. It turns a check-out from an obstruction into an explanation.

You can check out several files at once. If one of them fails — because a colleague got there first — the others still succeed, and you are told exactly which one did not and why.

Releasing a file

Same panel: tick the files and click Unlock selected. You can only release your own check-outs.

To see everything you have checked out across a whole space, use the space-level view described below.


When someone replaces a checked-out file

Within a few minutes of the file being replaced, Attachment Guard:

Repeat changes to the same file within an hour produce one message rather than a stream, but every one of them is recorded.

The check-out stays in place after an override. That is deliberate — it keeps the file visibly contested rather than quietly clearing the signal that something went wrong.

Putting the earlier version back

In the panel, next to the override, click Restore.

This takes the content the file had before the change and uploads it as a new version. Nothing is deleted. The version somebody else uploaded stays in the file's history, because a record you can tidy up afterwards is not a record.

Once restored, the override moves to the already restored list and is no longer offered for restore. If the same file is overridden again later, that new override counts as unresolved on its own.


Seeing the whole space

In the space sidebar, open Attachment lock audit. Two tabs:

Checked out

Every file currently checked out in the space: who has it, how long they have had it, and why. Files held over a week and over a month are highlighted, because the usual cause is someone finishing and forgetting rather than work still in progress.

Use Show only mine to see what you personally still hold.

Audit

Every check-out, release, override and restoration, filterable by last 30 days, quarter, year, or all time. Counts across the top show how many overrides happened and how many files remain unresolved.

Export as CSV produces the full period as text you can copy into a spreadsheet. The export identifies people by Atlassian account ID rather than display name, deliberately: names change, and a record filed with an auditor needs to identify accounts unambiguously years later.


For space administrators

If you administer the space, you can release a file checked out by somebody else — for when a colleague is away or has left with a file still held.

Select the file and click Force unlock, either in the page panel or from the space-level view.

Every forced release is recorded against your name. That is the point: an administrator override should be visible, not silent.

Administrator rights come from Confluence itself. Anyone who administers the space can do this; there is no separate list to maintain.


Licensing

Free for sites of up to 10 users.

If a licence lapses, the app keeps working in a reduced form: existing check-outs stay visible and you can still release files you hold. New check-outs and one-click restore require an active licence.

Releasing your own files is never withheld. A lapsed licence must not leave your documents stuck behind a paywall — and Confluence's own version history remains available to you regardless.


Where your data lives

Attachment Guard is built on Atlassian Forge and runs entirely on Atlassian's infrastructure. Check-out records and history are stored in Forge storage inside your own environment.

The app runs no servers of its own and sends nothing to any third party. It does not read or store the contents of your files, except while a restore is in progress, when it moves an earlier version from Confluence back into Confluence.

It stores no personal data. Records hold Atlassian account IDs, never names or email addresses. Names shown on screen are looked up as a page is rendered and discarded immediately.


Common questions

Can it stop someone overwriting a file? No, and no Confluence Cloud app can — the platform provides no way to block an upload. It detects the change, tells you, and helps you put it back.

How quickly will I know? Usually a few minutes. Confluence delivers these signals asynchronously, so it is not instant.

What if two people check out the same file at the same moment? One wins. In the rare case where two requests land in the same instant, both may briefly appear to succeed — the history records what happened, which is the same guarantee the rest of the app makes.

Does it work on any file type? Yes. It works on the attachment, not its contents.

What happens to our records if we uninstall? The app loses access to your site. Your attachments and all their Confluence version history are untouched — they belong to Confluence, not to this app.


Support

Written and supported by Makhsat Alzhanov at Alzhan Group LLC. Your email reaches a person, not a queue.

First response within one business day. If something is broken and blocking your team, say so in the subject and it will be treated that way.

📧 support@alzhangroupllc.com

When reporting a problem, the page URL and roughly when it happened are usually enough to find it.