{
  "title": "Slack permissions explained",
  "path": "/integrations/slack/permissions",
  "url": "https://escapev.ai/integrations/slack/permissions",
  "summary": "Every permission Escape Velocity requests from Slack, what each one is for, and how each commitment is enforced.",
  "kind": "disclosure",
  "markdown": "https://escapev.ai/integrations/slack/permissions.md",
  "integration": "slack",
  "sections": [
    {
      "section": "understand",
      "heading": "Read permissions: Respond when addressed and read messages",
      "blurb": "`@Escape Velocity` bot gathers context from messages and monitors channels for you.",
      "permissions": [
        {
          "scope": "app_mentions:read",
          "access": "read",
          "granted": "read",
          "purpose": "Delivers the messages that @-mention Escape Velocity. Without this the bot cannot hear you at all."
        },
        {
          "scope": "channels:read",
          "access": "read",
          "granted": "read",
          "purpose": "Lists the public channels in your workspace, so you can pick where the agents post."
        },
        {
          "scope": "groups:read",
          "access": "read",
          "granted": "read",
          "purpose": "Lists the private channels Escape Velocity has been invited to, and no others."
        },
        {
          "scope": "channels:history",
          "access": "read",
          "granted": "read",
          "purpose": "Reads messages and threads in a public channel the bot belongs to, so you and your agents can use the conversation as context."
        },
        {
          "scope": "groups:history",
          "access": "read",
          "granted": "read",
          "purpose": "Reads messages and threads in a private channel Escape Velocity has been invited to, and no others."
        },
        {
          "scope": "im:history",
          "access": "read",
          "granted": "read",
          "purpose": "Reads your one-to-one conversation with Escape Velocity, and no one else's messages."
        },
        {
          "scope": "mpim:history",
          "access": "read",
          "granted": "read",
          "purpose": "Reads a group direct message that includes Escape Velocity, so a thread there behaves like a thread in a channel."
        },
        {
          "scope": "files:read",
          "access": "read",
          "granted": "read",
          "purpose": "Downloads an image or file you attach to a message the agents can already read, so they can see what you sent. The bot cannot browse files anywhere else in your workspace."
        }
      ]
    },
    {
      "section": "change",
      "heading": "Write permissions: Post messages, add reactions, and join public channels",
      "blurb": "`@Escape Velocity` bot never joins a private channel without an invite.",
      "permissions": [
        {
          "scope": "chat:write",
          "access": "read and write",
          "granted": "write",
          "purpose": "Posts, edits and deletes the agents' own messages. Escape Velocity can only change the bot's own messages."
        },
        {
          "scope": "chat:write.public",
          "access": "read and write",
          "granted": "write",
          "purpose": "Posts to a public channel you have chosen, without needing an invite."
        },
        {
          "scope": "channels:join",
          "access": "read and write",
          "granted": "write",
          "purpose": "Joins new public channels, so a channel created after you connected still reaches the agents without anyone re-inviting the bot."
        },
        {
          "scope": "reactions:write",
          "access": "read and write",
          "granted": "write",
          "purpose": "Adds an emoji reaction to your message, so you know a long-running turn has started before the reply arrives."
        }
      ]
    }
  ],
  "promisesBlurb": "We value your trust and hold ourselves accountable to these commitments.",
  "promises": [
    {
      "claim": "We will never act as you in Slack",
      "enforcement": "`@Escape Velocity` bot holds bot scopes only. No user token is ever requested, so nothing the bot does can be attributed to your account."
    },
    {
      "claim": "We will never read a private channel you have not added us to",
      "enforcement": "Slack delivers private-channel history only to a bot that is a member, and `@Escape Velocity` bot holds no user token."
    },
    {
      "claim": "We will never read direct messages you are not having with us",
      "enforcement": "`im:history` and `mpim:history` cover only the conversations `@Escape Velocity` bot is part of. Slack never delivers a message from a conversation a bot is not in."
    }
  ]
}
