Slack logo

Slack

AccessAI AssistantNotifications
Communication

Mycroft posts control failures, expiring evidence and review reminders to Slack, and includes workspace membership in access reviews.

A finding routed to a channel the team already watches gets acted on. Mycroft reads workspace administration data covering members, guests, admin roles, retention and external sharing, and answers compliance questions in channel through its AI assistant.

How Mycroft connects to Slack

How it connects
An administrator installs the Mycroft app into your Slack workspace.
What Mycroft can access
Broad, because the Mycroft Assistant runs inside Slack. Alongside users:read and users:read.email, the app requests channels:history, im:history, files:read, files:write, chat:write, assistant:write, channels:join, app_mentions:read, reactions:read, reactions:write and commands.

Which controls Slack evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Slack to satisfy it. Collection runs on a schedule and every result is timestamped.

Slack compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Slack
SOC 2CC2.2Internal control information is communicated to those responsible for it.Delivery records for control failure, evidence expiry and access review notifications, showing what was communicated to which owner and when.
SOC 2CC6.1Logical access controls restrict access to information assets.Workspace member, guest and Slack Connect roster with admin and owner roles enumerated.
SOC 2CC6.3Access is removed when no longer required.Workspace membership reconciled against the workforce roster, surfacing accounts and guests belonging to people who have left.
SOC 2CC6.7Movement and transmission of information is restricted.External sharing and Slack Connect configuration, public channel inventory and file-sharing settings for the workspace.
SOC 2CC7.2Anomalies and control deviations are monitored and escalated.Timestamped alert history proving detected control failures were escalated to a named owner promptly.
ISO 27001A.5.14Information transfer rules and agreements are in place.External connection and sharing settings, including which external organizations are connected and who approved them.
ISO 27001A.5.10Acceptable use of information and assets is defined and applied.Message and file retention configuration compared against the retention period stated in your published policy.
ISO 27001A.5.18Access rights are provisioned, reviewed and revoked.Workspace membership and guest access included in the periodic access review with reviewer decisions recorded.

What Mycroft collects automatically

Gathered from Slack on a schedule, dated and stored against the controls above.

  • Workspace member, guest and Slack Connect roster with roles
  • Workspace owner and administrator inventory
  • Message and file retention configuration per workspace and channel type
  • External sharing and Slack Connect settings, including connected organizations
  • Public versus private channel inventory metadata
  • Notification delivery history proving findings were escalated to named owners
  • Two-factor authentication enforcement status on the workspace

Manual work this removes

The tasks that disappear from someone's quarter once Slack is connected.

  • Relaying control failures manually after they are noticed
  • Building the workspace member and guest list each quarter
  • Chasing access review reminders over email
  • Documenting message and file retention settings
  • Identifying which external organizations have Slack Connect access

Slack and Mycroft: frequently asked questions

The Slack app's scopes include channels:history and im:history, so it can read message history in the conversations it is present in. That is what lets the Mycroft Assistant answer questions in channel. It also holds files:read, chat:write, files:write and assistant:write for the same reason. The app only sees conversations it has been added to.
It answers compliance questions against your own program: what a control requires, which evidence is expiring, what a finding means, who owns an open item, and what remains before an audit. Because it is grounded in your Mycroft data rather than general guidance, the answers are specific to your environment.
Control test failures, evidence that is expiring or expired, access review assignments and overdue reviewers, new vulnerability findings above a severity threshold you set, and changes in audit readiness. Routing is per-channel, so security findings and reviewer reminders don't have to share a room.
Yes. Members, guests and Slack Connect participants are reconciled against your workforce roster like any other system. Guests invited for a project that ended eighteen months ago are among the more common findings in a first review.
Slack is the supported communication platform today. Microsoft-native teams typically connect Entra ID for identity and access evidence and receive notifications by email until a Teams integration is available.

We turn the compliance nightmare into a dream

Talk to us