GridKeeper

Slack security posture

See what's changing in your Slack before it becomes a problem.

GridKeeper watches admin roles, app permissions, sharing defaults, and Slack Connect exposure over time, and tells you exactly what changed, not just what's wrong right now.

Security Posture

Acme Corp

0
Attention
4
Worth a look
5
Good
5
Info
Changed since last check (1)
Owners & Admins
1 of 2 members changed to 2 of 2 (added j.rivera@acme.com)
Warn
Apps in this workspace
1 app holding sensitive scopes, from an unvetted publisher
Info

How it works

No dashboards to configure, no rules to write. Connect once, and the schedule does the rest.

Connect

Tell GridKeeper which Slack plan you're on, two clicks, no manual scope picking.

Capture a baseline

One full pass across identity, apps, sharing, and Connect exposure, this becomes the reference point for everything after.

GridKeeper checks again automatically

No need to remember to go back and look. Every scheduled check is compared against the last one.

Only what changed gets surfaced

Not the whole workspace re-explained every time, the specific thing that moved, when it moved, and what it was before.

What GridKeeper watches

A scored, point-in-time check across the areas that actually matter for a Slack workspace's security.

Access & Identity

Owner and admin sprawl, two-factor coverage, guest expiration, dormant accounts, workspace join policy.

App Governance

Sensitive scopes, who installed what, apps with nobody accountable, permission expansions over time.

Sharing & Connect

External channel exposure, Slack Connect invitations, and the specific setting that decides whether a shared channel's history survives a disconnect.

Why not just check Slack's own console?

You can, GridKeeper doesn't see anything a workspace admin couldn't already find. It's the difference between looking and remembering to look.

Continuous, not a snapshot

A manual review catches whatever's true the moment you look. GridKeeper checks on a schedule, so drift between reviews doesn't just quietly happen.

Real history, not just current state

Slack's own console shows you now. "Did this change last month" isn't a question it can answer. GridKeeper keeps that history.

Two minutes, not a project

No dashboards to build, no rules to write before it's useful. Connect and it starts working.

Read-only, by design

Not a v1 shortcut. This is a permanent commitment, revisited nowhere in the product.

GridKeeper never writes anything to your Slack.

No message posted, no setting changed, no app installed or removed, no approval granted. Every scope GridKeeper requests is read-only, and it stays that way.

GridKeeper never reads message content.

No history scope is requested, ever. What happens in your channels stays in your channels.

Findings are evidence, not inference.

Every card traces back to a real API response. When something can't be verified, GridKeeper says so instead of guessing.

Curious what that actually looks like?

The exact Slack scopes GridKeeper requests, and why each one is there.

View the trust page →