# Slack permissions explained

Every permission Escape Velocity requests from Slack, what each one is for, and how each commitment is enforced.

## Read permissions: Respond when addressed and read messages

`@Escape Velocity` bot gathers context from messages and monitors channels for you.

| Permission | Access | What it is for |
| --- | --- | --- |
| `app_mentions:read` | Read | Delivers the messages that @-mention Escape Velocity. Without this the bot cannot hear you at all. |
| `channels:read` | Read | Lists the public channels in your workspace, so you can pick where the agents post. |
| `groups:read` | Read | Lists the private channels Escape Velocity has been invited to, and no others. |
| `channels:history` | Read | Reads messages and threads in a public channel the bot belongs to, so you and your agents can use the conversation as context. |
| `groups:history` | Read | Reads messages and threads in a private channel Escape Velocity has been invited to, and no others. |
| `im:history` | Read | Reads your one-to-one conversation with Escape Velocity, and no one else's messages. |
| `mpim:history` | Read | Reads a group direct message that includes Escape Velocity, so a thread there behaves like a thread in a channel. |
| `files:read` | Read | Downloads an image or file you attach to a message the agents can already read, so they can see what you sent. The bot cannot browse files anywhere else in your workspace. |

## Write permissions: Post messages, add reactions, and join public channels

`@Escape Velocity` bot never joins a private channel without an invite.

| Permission | Access | What it is for |
| --- | --- | --- |
| `chat:write` | Read and write | Posts, edits and deletes the agents' own messages. Escape Velocity can only change the bot's own messages. |
| `chat:write.public` | Read and write | Posts to a public channel you have chosen, without needing an invite. |
| `channels:join` | Read and write | Joins new public channels, so a channel created after you connected still reaches the agents without anyone re-inviting the bot. |
| `reactions:write` | Read and write | Adds an emoji reaction to your message, so you know a long-running turn has started before the reply arrives. |

## What Escape Velocity will never do

We value your trust and hold ourselves accountable to these commitments.

| Our commitment | What makes it true |
| --- | --- |
| We will never act as you in Slack | `@Escape Velocity` bot holds bot scopes only. No user token is ever requested, so nothing the bot does can be attributed to your account. |
| We will never read a private channel you have not added us to | Slack delivers private-channel history only to a bot that is a member, and `@Escape Velocity` bot holds no user token. |
| We will never read direct messages you are not having with us | `im:history` and `mpim:history` cover only the conversations `@Escape Velocity` bot is part of. Slack never delivers a message from a conversation a bot is not in. |
