GridKeeper

Trust & Scopes

Every permission GridKeeper asks for, and why.

Nothing here is theoretical. Each scope below is tied to a real, working check, traced from the Slack API call back to the exact permission it needs. Nothing is requested "just in case."

What GridKeeper never asks for

No scope that reads message content, ever. No scope that lets GridKeeper post, edit, delete, or send anything. No scope that lets GridKeeper install, remove, or approve an app on your behalf. If a future feature would need one of these, that's a different, clearly-labeled product, not GridKeeper.

Bot token scopes

Three are requested on every connection. Three are Pro and Business+ only, because on Enterprise Grid the same ground is covered by the org-wide user scopes below, and asking for both would be asking for more than is needed. One is Enterprise Grid only.

ScopeWhat it lets GridKeeper seePlan
conversations.connect:manageSlack Connect channel invitations, so pending and outgoing requests can be flagged.All
team:readBasic identity of the workspace or org you connected, nothing more.All
users:readOn every plan, whether a person signed in to GridKeeper still holds an owner role, read through GridKeeper's own app rather than one person's access. On Pro and Business+, also the member, guest, and bot roster, needed for two-factor coverage and dormant account checks.All
users:read.emailEmail addresses, so a finding names a real person rather than an internal Slack ID.Pro+
channels:readPublic channel inventory, for the sharing and Slack Connect exposure checks.Pro+
groups:readPrivate channels GridKeeper's bot has actually been added to. This is deliberately partial, GridKeeper cannot see a private channel it hasn't been invited into, and says so on the relevant card rather than guessing at the rest.Pro+
usergroups:readYour user groups and which channels each one adds its members to, private channels included. A group can carry a private channel, and adding somebody to the group puts them inside it: Slack records that as an ordinary invite, so the group itself is the only place it can be seen.Grid

User token scopes

What's requested depends on which plan you connect as, GridKeeper only asks for the narrower set your plan can actually use.

ScopeWhat it lets GridKeeper seePlan
users:readReads the role of whoever connects with an invitation or signs in, so only an owner can connect or sign in, and identifies Owners and Admins on a single workspace.All
openidSign in with Slack: which Slack account is signing in to GridKeeper. Requested only when someone signs in.All
emailSign in with Slack: the address of the person signing in, so your company can see who has access.All
profileSign in with Slack: the name of the person signing in, shown beside their address.All
adminSee the callout below, this one gets its own explanation.Pro+
admin.apps:readWhich apps are installed or requested, and their approval status, org-wide.Grid
admin.conversations:readChannel inventory across every workspace in the org, including externally shared channels.Grid
admin.roles:readWho holds each of Slack's admin roles, such as Roles Admin or Legal Holds Admin, org-wide.Grid
admin.teams:readEnumerates the workspaces in the org. Every other per-workspace check depends on this running first.Grid
admin.users:readMember and guest roster and roles, org-wide.Grid
admin.workflows:readWhich workflows exist, who owns them, and whether ownership has lapsed.Grid
auditlogs:readRecovers settings Slack exposes no direct getter for, like SSO enforcement, by reading the audit log.Grid

The two scopes that are broader than reading

Slack's permission model does not offer a read-only version of everything, so two of the scopes in the table above allow more than GridKeeper does with them. Being direct about that is worth more than a table that quietly implies otherwise. GridKeeper contains no write call to Slack anywhere, on any plan, which is a fact about how the product behaves rather than a promise made here.

conversations.connect:manage, requested on every plan. Slack bundles reading your Slack Connect invitations together with approving them, declining them, and disconnecting an outside organization. GridKeeper only lists them. We checked for a narrower route rather than assuming there was none: a token holding only team:read asked Slack for the list of connected organizations, and Slack refused, naming this scope as the one required. Dropping it would remove the Slack Connect checks altogether.

admin, requested on Pro and Business+ only. Slack's legacy workspace-admin scope, broad and not limited to reading. On those plans it is the only way to see three things: dormant accounts (last login), who installed an app and when, and paid seats nobody is using. Enterprise Grid does not need it, because the narrower admin.* scopes cover that ground, so a Grid install is never asked for it.

How GridKeeper is secured

What GridKeeper keeps about your Slack, and how it is protected. Checked against the OWASP ASVS level 1 requirements in October 2026; the findings and their fixes are written up, and we share them on request.

Where your data is

Stored in Ireland, processed in Dublin, and emailed from Ireland. The privacy policy names every provider.

Slack tokens

Encrypted with AES-256-GCM under keys derived for that purpose alone and kept outside the database. No token is ever written to a log.

One organization cannot reach another

Every request takes the organization from the signed-in session and refuses any other. Row-level security is on for every table, so only GridKeeper's server can read or write, and no database key reaches the browser.

Who can sign in

Sign in with Slack, owners only: your org's owners and the workspace owners they add. Slack is asked every hour whether each still holds the role.

Sessions

A signed cookie that scripts cannot read and that is sent over HTTPS only, lasting 30 days at most. Signing out ends every session you have open.

Changes come from GridKeeper's own pages

Anything that changes data is a request another site cannot send, and the pages refuse to be framed by other sites.

Need to chat with us, or need help using GridKeeper? Write to support@gridkeeper.app.