Least privilege by default
Connectors request the narrowest scopes that work: directory read, message send, and read-only cloud metadata. Nothing we do requires standing write access to your production systems.
Trust and security
Connecting an agent to your Slack or Teams workspace and your identity provider is a serious decision. This page is the honest version of what we request, what we refuse to request, and what happens to your data.
Trust
We are asking for access to your workspace directory and your cloud metadata, so the burden of proof is on us. Here is exactly how that access is scoped, stored and reviewed.
Connectors request the narrowest scopes that work: directory read, message send, and read-only cloud metadata. Nothing we do requires standing write access to your production systems.
OAuth tokens and webhook secrets are sealed with envelope encryption in a managed KMS, scoped per workspace, and rotated on a schedule you can audit.
Your messages, findings, evidence and directory data are never used to train foundation models. Sub-processors are contractually prohibited from doing so either.
US, EU or UK regions on annual plans, with the ability to pin evidence storage to a jurisdiction and delete on request.
Sensitive actions are human-gated. A reviewer must approve anything Sentinel sends to your executives before it reaches them, and you can require approval for every framework change.
SAML SSO with SCIM provisioning, immutable audit logs of every agent action and every admin change, and quarterly access reviews of our own team.
We will share our control matrix, sub-processor list, penetration test summary and DPA under NDA. Ask us anything, including the awkward questions.
Permissions
If a permission is not on this list, we do not request it. Scopes are shown to your admin at install time and can be reviewed at any point afterwards.
| Scope | Why we need it |
|---|---|
| Directory read (users, groups, roles) | To build the ownership graph and route asks to the right role. |
| Send direct messages | To open the conversation with an owner and follow up. |
| Post in approved channels | To log activity in the shared channel you nominate — never other channels. |
| Read replies in threads it started | To capture the answer as evidence and close the loop. |
| Read channel membership | To know who to escalate to when the owner does not respond. |
Controls
These are the practices we hold ourselves to, whether or not you ask about them during procurement.
We keep this list short on purpose. Each sub-processor is bound by a written agreement that includes confidentiality, security obligations and a prohibition on using your data to train models. You get 30 days notice before a new one is added to a plan you are on.
Cloud infrastructure
Hosting, storage, networking and key management
Model provider
Language understanding under a zero-retention, no-training agreement
Email delivery
Transactional email such as workspace setup confirmation and digests
Error monitoring
Crash and error telemetry with payload scrubbing enabled
We welcome reports from researchers. Email security@ciso.express with steps to reproduce; we acknowledge within one business day and will not pursue legal action against good-faith research.
Start free, connect Slack or Teams, and Sentinel assigns the first issues before you commit to anything.