Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

All integrations
SL
COLLAB·Beta

Slack

Discover installed Slack apps, scopes, and per-user grants across the workspace.

WHAT IT DOES

What ScopeMantle can do with Slack.

  • Inventory every installed Slack app, custom integration, and workflow with its full scope set
  • Map per-user app authorizations across the workspace via the Slack admin API
  • Stream audit log events for installs, scope changes, and uninstalls into the normalized stream
  • Surface bot users and their channel memberships for least-privilege review
  • Open Slack messages from policy actions for triage in your security or IT channel

LEAST PRIVILEGE

What we read, and what we don't.

We read
  • admin.apps:readEnumerate installed apps and custom integrations
  • admin.users:readResolve workspace users for app authorization mapping
  • auditlogs:readStream workspace audit log events (Enterprise Grid)
  • team:readIdentify the workspace and team metadata
We never
  • Read channel messages, DMs, or any user-generated content
  • Post messages on behalf of users, only the ScopeMantle bot user posts, and only into channels you opt in
  • Modify app installations, scopes, or workspace settings without an explicit governance policy
  • Access huddles, calls, or Slack Connect external channel content

SETUP

Connect in a few steps.

  1. 01

    Install the ScopeMantle Slack app

    Install from the ScopeMantle app directory listing. The default install requests only the read scopes listed above.

  2. 02

    Authorize at the org level (Enterprise Grid)

    For Enterprise Grid customers, authorize at the org owner level so ScopeMantle can inventory apps across every workspace in the org.

  3. 03

    Choose your governance channel

    Pick the Slack channel that should receive governance approvals and alerts. ScopeMantle only posts there, never to user channels, unless you wire additional rules.

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.