Slack access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Slack, Black Cat runs 9 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Slack connector needs.
Checks (9)
severity: medium Public Channel Creation Unrestricted fix difficulty: easy #
Restrict public channel creation to workspace admins or owners
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Channel management", find "Who can create public channels"
- Change the setting to "Workspace admins and owners only"
- Click "Save" to apply the restriction
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium App Management Unrestricted fix difficulty: easy #
Restrict app installation and management to workspace admins
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "App management", find "Who can install and manage apps"
- Set this to "Workspace admins and owners only"
- Click "Save" to apply the restriction
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Guest Slash Commands fix difficulty: easy #
Restrict guest access to slash commands and app interactions
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Permissions
- Under "Guest permissions", review the slash command access setting
- Disable "Allow guests to use slash commands" or restrict to essential commands
- Click "Save" to apply the guest permission restriction
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Admins fix difficulty: easy #
Reduce the number of workspace admins to the minimum necessary
- Sign in to your Slack workspace as an Owner
- Navigate to admin settings > Members
- Filter by the "Admin" role to list all current admins
- Review each admin and identify those who no longer require elevated access
- Click the three-dot menu next to each unnecessary admin and select "Change account type"
- Demote them to "Member" and confirm the change
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Owners fix difficulty: easy #
Reduce the number of workspace owners to two or fewer
- Sign in to your Slack workspace as an Owner
- Navigate to admin settings > Members
- Filter by the "Owner" role to list all current owners
- Identify owners beyond the recommended maximum (typically 2)
- Click the three-dot menu next to excess owners and select "Change account type"
- Demote them to "Admin" or "Member" as appropriate
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high External Admin fix difficulty: easy #
Remove admin privileges from guest accounts
- Sign in to your Slack workspace as an Owner
- Navigate to admin settings > Members
- Search for the flagged external/guest user
- Click the three-dot menu next to the user and select "Change account type"
- Downgrade the user from Admin to "Single-channel guest" or "Multi-channel guest"
- If the guest no longer requires workspace access, deactivate the account
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Owner Redundancy fix difficulty: easy #
Ensure at least two workspace owners exist for business continuity
- Sign in to your Slack workspace as the Primary Owner
- Navigate to admin settings > Members
- Identify a trusted admin to promote to Owner
- Click the three-dot menu next to that member and select "Change account type"
- Select "Workspace Owner" and confirm the change
- Verify the promoted user can access owner-level settings
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Guest Multi Channel fix difficulty: easy #
Convert multi-channel guests to single-channel guests or full members as appropriate
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Members
- Search for the flagged multi-channel guest
- Review whether the guest truly requires access to multiple channels
- If single-channel access is sufficient, click "Change account type" and select "Single-channel guest"
- If broader access is justified, convert the user to a full member with appropriate permissions
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium App Approval Not Required fix difficulty: easy #
Require admin approval before app installation
- Sign in to your Slack workspace as an Owner or Admin
- Navigate to admin settings > Manage Apps
- Under "App Management Settings", enable "Require App Approval"
- Configure the approval request channel if desired
- Click "Save" to enforce the policy
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2