By the time a company is ten people, Slack holds more sensitive material than most of its systems.
Customer screenshots, API tokens pasted "just for a second," production error logs, contract links, candid talk about pricing and strategy. A compromised Slack account isn't a leaked joke — it's a second inbox with files attached, and nobody treats it like one because nobody has to install anything to use it.
The admin console already has the controls. This is the one-afternoon pass that turns them on — full checklist with the exact settings in the Slack workspace security checklist.
The admin handshake (do this first):
- Confirm who owns the workspace. Many were created by a founder's personal account or an early contractor. If the owner left, reclaim it today.
- Exactly two workspace owners — one primary, one backup, both with MFA. Zero is a deadlock; five is a hole.
- Every admin should be a current employee with a reason to be one. Demoting the rest is one click.
Invite controls (who can let strangers in):
- Require admin approval for invites. The default — any member invites anyone — is how a well-meaning hire adds a client, a friend, and a trial vendor to the same workspace.
- Restrict invites to your email domain, and rotate the join link if it has ever been pasted anywhere public.
The guest audit nobody runs:
Export the guest list and compare it against who actually works with you right now. The freelancer from the Q1 redesign is still reading #general the way it reads today — including the layoff talk and the pricing arguments. Deactivate single-channel guests the day an engagement ends, and review the list quarterly. Guests accrete exactly like SaaS subscriptions: one at a time, each defensible, the pile unaccountable.
Apps, bots, and webhooks (the quietest leak path):
- Turn on app approval. Nothing with a Slack token joins without a named human saying yes.
- Hunt down incoming webhooks. Teams paste those URLs into CI and monitoring scripts because it takes thirty seconds — but they're bearer credentials. Anyone holding one posts to your channels as your tools. List owners; rotate anything not written down.
- The rule that saves you during the next incident: tokens, passwords, private keys, and customer PII never get typed into chat. Not "temporarily." Not "then delete it." Deleted is not purged, and screenshots outlive deletions. If a secret did land in a channel: rotate the credential first, delete the message second.
Slack Connect (the doors to other companies):
Connect channels are a shared perimeter you don't fully control. Restrict who can create them, label them loudly (ext- prefix), and treat unexpected attachments there the way you'd treat them in email — verify out-of-band, because borrowed trust is exactly what social engineering is made of.
When something goes wrong anyway:
Compromised account: revoke all sessions, change the password, check apps and webhooks created in the last 48 hours, and scan recent posts — attackers use chat to propagate because chat links get clicked. The first half hour matters; the first 30 minutes is a free one-page playbook for exactly that window.
The full checklist adds retention policy, Slack Connect file rules, session hygiene, device loss, and the quarterly 30-minute pass — with the admin paths for each setting: Slack workspace security checklist.
If you want the audit sheets that turn it into per-person, per-channel tables (guest, channels, apps, verdict, owner), the Ops Starter Kit ($14) covers incident response for small teams, and the Automation Starter Pack ($19) automates the reviews so the purge happens without anyone remembering to remember. Launch week: 30% off any paid kit with code HIVE-LAUNCH30 at checkout.
Top comments (0)