
Knowledge & Wikis
Part of Collaboration data security and retention
Planning backups for shared team knowledge
Define what team knowledge must be recoverable, inspect export limits and check a safe recovery route.
Plan a knowledge backup around a usable recovered answer, not a completed export notification. Identify the pages and attachments people need to resume work, then decide how recent the copy must be. Give the backup its own access and disposal rules.
Define the recovery need
Choose important instructions, such as an onboarding procedure or customer handover guide. For each, record its owner, supporting files, permissions and approved state. Ask what the team would need if a page were replaced, a space deleted or the account unavailable.
Set an acceptable gap between the live version and the recoverable copy. Record whether people need readable offline content, restoration into the original service or both. Those are different outcomes.
Distinguish provider recovery from your copy
Confluence Cloud: Atlassian says its service backups are for application recovery and cannot roll back changes to your content. Its backup manager can produce a downloadable site export, with attachments included when selected. The download link lasts 14 days, and a new backup overwrites the previous one in the manager. Soft-deleted spaces are omitted.
Confluence databases appear in the exported tree but do not retain their content, data or functionality; the export also omits some user and group settings. Check both coverage and the intended recovery route.
Atlassian says you can import a site backup into another Confluence Cloud instance. Plan any rehearsal with an appropriately isolated destination and an administrator's recovery plan.
Notion: Notion offers workspace exports as HTML or Markdown, with CSV for databases and uploaded files included. Business and Enterprise workspaces can also export the whole workspace to PDF. Notion says this option is being withdrawn across workspaces by 31 August 2026; individual pages can still be exported as PDF.
Download links expire after 7 days. Pages the exporter cannot access, including another user's private pages, are omitted; teamspace settings may exclude more. Notion says re-uploading an export cannot instantly recreate a workspace. Before relying on an export, verify that the pages and uploaded files needed for a usable answer are present.
Notion also provides recovery routes within the service: pages remain in Trash for 30 days by default, and past page versions can be restored through edit history for a period that depends on the plan. For accidental deletions, Notion says it can restore a snapshot of a page from the past 30 days if you contact support. These routes are distinct from keeping an export you can access independently.
Microsoft 365 files: OneDrive's Restore your OneDrive feature can help eligible Microsoft 365 subscribers undo file and folder actions from the last 30 days. A file permanently deleted from the OneDrive Recycle Bin can never be recovered. Before restoring, review the selected activities in the activity feed; files created after the restore point are sent to the Recycle Bin.
Key Backup and Recovery Metrics Across Platforms
- Confluence Cloud Export Expiry14 days
- Notion Export Expiry7 days
- OneDrive Recovery WindowLast 30 days
- Notion Trash Retention30 days
- ACSC Guidance on Small to Medium Business Data SecurityRecommended best practices for data protection
Build and check the route
Keep the backup protected and separate from live systems where practical.
- Choose the pages, attachments and settings needed to make instructions usable.
- Record who may create, read and restore the copy.
- Set a frequency from the team's recovery need.
- Inspect the package for missing content, attachments and unreadable formats.
- Check a small, safe recovery route appropriate to the product; record what survives and what must be rebuilt.
Repeat the check after a product change, a new content type or a change of owner.
If the backup contains personal information and the organisation is subject to the Australian Privacy Principles, set a retention and disposal rule. The OAIC's APP 11 guidance says an APP entity must take reasonable steps to destroy or de-identify personal information it holds when it is no longer needed, subject to exceptions.


