
Slack
AccessAI AssistantNotifications
Communication
Mycroft posts control failures, expiring evidence and review reminders to Slack, and includes workspace membership in access reviews.
A finding routed to a channel the team already watches gets acted on. Mycroft reads workspace administration data covering members, guests, admin roles, retention and external sharing, and answers compliance questions in channel through its AI assistant.
How Mycroft connects to Slack
- How it connects
- An administrator installs the Mycroft app into your Slack workspace.
- What Mycroft can access
- Broad, because the Mycroft Assistant runs inside Slack. Alongside users:read and users:read.email, the app requests channels:history, im:history, files:read, files:write, chat:write, assistant:write, channels:join, app_mentions:read, reactions:read, reactions:write and commands.
Which controls Slack evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Slack to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Slack |
|---|---|---|---|
| SOC 2 | CC2.2 | Internal control information is communicated to those responsible for it. | Delivery records for control failure, evidence expiry and access review notifications, showing what was communicated to which owner and when. |
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Workspace member, guest and Slack Connect roster with admin and owner roles enumerated. |
| SOC 2 | CC6.3 | Access is removed when no longer required. | Workspace membership reconciled against the workforce roster, surfacing accounts and guests belonging to people who have left. |
| SOC 2 | CC6.7 | Movement and transmission of information is restricted. | External sharing and Slack Connect configuration, public channel inventory and file-sharing settings for the workspace. |
| SOC 2 | CC7.2 | Anomalies and control deviations are monitored and escalated. | Timestamped alert history proving detected control failures were escalated to a named owner promptly. |
| ISO 27001 | A.5.14 | Information transfer rules and agreements are in place. | External connection and sharing settings, including which external organizations are connected and who approved them. |
| ISO 27001 | A.5.10 | Acceptable use of information and assets is defined and applied. | Message and file retention configuration compared against the retention period stated in your published policy. |
| ISO 27001 | A.5.18 | Access rights are provisioned, reviewed and revoked. | Workspace membership and guest access included in the periodic access review with reviewer decisions recorded. |
What Mycroft collects automatically
Gathered from Slack on a schedule, dated and stored against the controls above.
- Workspace member, guest and Slack Connect roster with roles
- Workspace owner and administrator inventory
- Message and file retention configuration per workspace and channel type
- External sharing and Slack Connect settings, including connected organizations
- Public versus private channel inventory metadata
- Notification delivery history proving findings were escalated to named owners
- Two-factor authentication enforcement status on the workspace
Manual work this removes
The tasks that disappear from someone's quarter once Slack is connected.
- Relaying control failures manually after they are noticed
- Building the workspace member and guest list each quarter
- Chasing access review reminders over email
- Documenting message and file retention settings
- Identifying which external organizations have Slack Connect access
Slack and Mycroft: frequently asked questions
Does Mycroft read our Slack messages?
What does the Mycroft AI Assistant do in Slack?
Which notifications can we route to Slack?
Is Slack workspace access included in user access reviews?
Is Microsoft Teams supported?
We turn the compliance nightmare into a dream
Talk to us


