Skip to content

Slack access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Slack, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Slack connector needs.

Checks (9)

severity: medium Public Channel Creation Unrestricted fix difficulty: easy #

Restrict public channel creation to workspace admins or owners

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Channel management", find "Who can create public channels"
  4. Change the setting to "Workspace admins and owners only"
  5. Click "Save" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium App Management Unrestricted fix difficulty: easy #

Restrict app installation and management to workspace admins

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "App management", find "Who can install and manage apps"
  4. Set this to "Workspace admins and owners only"
  5. Click "Save" to apply the restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Guest Slash Commands fix difficulty: easy #

Restrict guest access to slash commands and app interactions

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Permissions
  3. Under "Guest permissions", review the slash command access setting
  4. Disable "Allow guests to use slash commands" or restrict to essential commands
  5. Click "Save" to apply the guest permission restriction

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Excessive Admins fix difficulty: easy #

Reduce the number of workspace admins to the minimum necessary

  1. Sign in to your Slack workspace as an Owner
  2. Navigate to admin settings > Members
  3. Filter by the "Admin" role to list all current admins
  4. Review each admin and identify those who no longer require elevated access
  5. Click the three-dot menu next to each unnecessary admin and select "Change account type"
  6. Demote them to "Member" and confirm the change

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Excessive Owners fix difficulty: easy #

Reduce the number of workspace owners to two or fewer

  1. Sign in to your Slack workspace as an Owner
  2. Navigate to admin settings > Members
  3. Filter by the "Owner" role to list all current owners
  4. Identify owners beyond the recommended maximum (typically 2)
  5. Click the three-dot menu next to excess owners and select "Change account type"
  6. Demote them to "Admin" or "Member" as appropriate

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high External Admin fix difficulty: easy #

Remove admin privileges from guest accounts

  1. Sign in to your Slack workspace as an Owner
  2. Navigate to admin settings > Members
  3. Search for the flagged external/guest user
  4. Click the three-dot menu next to the user and select "Change account type"
  5. Downgrade the user from Admin to "Single-channel guest" or "Multi-channel guest"
  6. If the guest no longer requires workspace access, deactivate the account

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Owner Redundancy fix difficulty: easy #

Ensure at least two workspace owners exist for business continuity

  1. Sign in to your Slack workspace as the Primary Owner
  2. Navigate to admin settings > Members
  3. Identify a trusted admin to promote to Owner
  4. Click the three-dot menu next to that member and select "Change account type"
  5. Select "Workspace Owner" and confirm the change
  6. Verify the promoted user can access owner-level settings

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Guest Multi Channel fix difficulty: easy #

Convert multi-channel guests to single-channel guests or full members as appropriate

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Members
  3. Search for the flagged multi-channel guest
  4. Review whether the guest truly requires access to multiple channels
  5. If single-channel access is sufficient, click "Change account type" and select "Single-channel guest"
  6. If broader access is justified, convert the user to a full member with appropriate permissions

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium App Approval Not Required fix difficulty: easy #

Require admin approval before app installation

  1. Sign in to your Slack workspace as an Owner or Admin
  2. Navigate to admin settings > Manage Apps
  3. Under "App Management Settings", enable "Require App Approval"
  4. Configure the approval request channel if desired
  5. Click "Save" to enforce the policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Slack checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial