GridKeeper

Keeps watch over your Slack.

See what's changing before it becomes a problem. GridKeeper checks admin roles, apps, guests, sharing and Slack Connect on a schedule, and tells you exactly what changed, not just what's wrong right now.

Sample data. Acme Corp is a made-up organization.

What GridKeeper watches

The settings and accounts that decide who can get into your Slack and what can leave it, checked on a schedule, with every change kept.

Access & Identity

SSO and password sign-in, owners and admins, guests without an expiry, dormant accounts, how long sessions last.

Apps & Workflows

Apps with nobody accountable, access tied to one person, sensitive permissions and when they grew, workflows with no manager.

Sharing & Connect

Public file links, who controls Slack Connect, the organizations you share channels with, and invitations still open.

Every card says what it found

Each check is graded Good, Worth a look or Attention, and says in one line what it found. When GridKeeper cannot verify something, the card says so instead of guessing.

Sample data.

Open a card for the detail

Each row names the account, app or setting, where it is and since when. Accept a row you have checked, with your reason, and it stops counting against you. Anything new brings the card back.

Sample data.

Every change, on record

The change history is append-only: nothing in it is edited or removed, so any admin can see what changed and when, even when a colleague ran the check. Turn on monitoring and GridKeeper emails you when something worth a look changes.

Sample data.

Bring in your workspace owners

On Enterprise Grid, the people who run each workspace know its apps and guests best. GridKeeper gives them a page of their own.

Send a finding to the workspace it is in

An app with no owner, access tied to one person, sensitive permissions: send it to that workspace's owners, who sign in as Delegates. They answer in GridKeeper that it is fixed, or that it should stay and why. The conversation is kept with the finding.

Sample data.

Guests reviewed every 90 days

Each Delegate is asked to review their workspace's guests every 90 days, and you see who reviewed each guest and when, and which workspaces are overdue.

Sample data.

Why not just check Slack's own console?

You can. GridKeeper doesn't see anything an owner couldn't already find. It's the difference between looking and remembering to look.

Continuous, not a snapshot

A manual review catches whatever's true the moment you look. GridKeeper checks on a schedule, so drift between reviews doesn't quietly happen.

History, not just the current state

Slack's console shows you now. "Did this change last month?" isn't a question it can answer. GridKeeper keeps that history.

Minutes, not a project

No dashboards to build and no rules to write before it's useful. Connect, and it starts checking.

Never writes to your Slack

Not a first-version shortcut. It is how GridKeeper is built.

GridKeeper never writes anything to your Slack.

No message posted, no setting changed, no app installed or removed, no approval granted. There is no write call anywhere in the product, and there never will be.

Two of the permissions Slack makes us ask for are broader than reading, and we would rather name them here than have you find them yourself. Slack does not offer a narrower version of either, and GridKeeper calls neither.

conversations.connect:manage, on every plan, because Slack bundles reading your Slack Connect invitations together with approving and declining them. admin, on Pro and Business+ only, because Slack gives smaller plans no read-only route to when someone last signed in, who installed an app, or which paid seats nobody uses. The trust page sets out exactly what each one covers.

GridKeeper never reads message content.

No history scope is requested, ever. What happens in your channels stays in your channels.

Findings are evidence, not inference.

Every card traces back to a real API response. When something can't be verified, GridKeeper says so instead of guessing.

How GridKeeper is secured

What we hold about your Slack deserves the same care you give Slack itself.

Your data stays in Ireland

It is stored, processed and emailed from there.

Slack tokens are encrypted

With AES-256-GCM, under a key kept outside the database, and never written to a log.

Each organization is walled off

Every request is checked on the server against the organization it belongs to, and the database refuses everything else.

Only owners get in

Sign in with Slack. Only your org's owners, and the workspace owners they add, and Slack is asked again every hour that they still hold the role.

Sessions end

After 30 days at most. Signing out ends every session you have open, not just the one in front of you.

Talk to us

Need to chat, or need help using GridKeeper? Write to support@gridkeeper.app.

More on the Trust & Scopes page →

GridKeeper is in a private pilot

GridKeeper opens to a small number of organizations first, by invitation. Ask for one and we will get back to you.

Ask for a pilot invite