This article lists the permissions requested when installing Netskope for Slack Enterprise, what each permission allows, why it is needed, and what happens if it is not granted. Permissions are grouped by who they act as: your administrator’s own Slack account, or the Netskope app itself.
Permissions Acting as Netskope App (Bot Token)
These permissions are granted to the Netskope app itself (shown in Slack as @netskope_bot), and only apply to the channels and conversations it has been added to.
| Permission required by Netskope | Claim/Permission value | Description | Purpose | Trade-off if not allowed |
|---|---|---|---|---|
| Manage private channels the app has been added to | groups:write | Manage private channels that "Netskope for Slack Enterprise" has been added to and create new ones. | Allows the app to create a private, restricted channel to hold flagged content when a policy violation requires it to be moved to a controlled space. | Netskope cannot create restricted channels to contain policy-violating content. |
| Send messages | chat:write | Send messages as @netskope_bot. | Allows the app to notify administrators or users directly in Slack about policy violations or required actions. | Netskope cannot deliver in-Slack notifications; alerts would need to be delivered another way, if available. |
| Upload, edit, and delete files | files:write | Upload, edit, and delete files as "Netskope for Slack Enterprise". | Allows the app to upload replacement or redacted file content as part of remediating a policy violation. | Netskope cannot remediate file-based violations that require uploading replacement content. |
| View files the app has access to | files:read | View files shared in channels and conversations that "Netskope for Slack Enterprise" has been added to. | Enables the app to review file content for data loss prevention scanning within channels it has been added to. | Files in those channels may be excluded from content inspection. |
| View private channel information the app has access to | groups:read | View basic information about private channels that "Netskope for Slack Enterprise" has been added to. | Enables the app to identify private channels it has been added to, supporting monitoring and reporting. | Those private channels are excluded from monitoring and reporting. |
| View direct message information the app has access to | im:read | View basic information about direct messages that "Netskope for Slack Enterprise" has been added to. | Enables the app to identify direct message conversations it has been added to, supporting monitoring. | Those direct messages are excluded from monitoring. |
| Start direct messages | im:write | Start direct messages with people. | Allows the app to initiate a direct message conversation when delivering a notification. | The app cannot start new direct message conversations to deliver notifications. |
Permissions Acting as Administrator (User Token)
These permissions are granted under the identity of the administrator who installs the app, and apply across your organization.
| Permission required by Netskope | Claim/Permission value | Description | Purpose | Trade-off if not allowed |
|---|---|---|---|---|
| Confirm administrator identity | - | View information about your identity. | Confirms the identity of the administrator installing the app. | The app cannot complete installation without this basic identity check. |
| View all messages and files across your organization | discovery:read | View all of your organization's messages (including all private channels and direct messages), as well as your organization's files. | Enables Netskope to scan and inspect Slack content across your organization for sensitive data, policy violations, and compliance risks. | Netskope cannot scan or monitor any content in your Slack organization. Data loss prevention and content inspection stop working entirely. |
| Modify or remove organization messages and files | discovery:write | Make changes to your organization's messages (including all messages in private channels and direct messages), as well as your organization's files. | Allows Netskope to remove, quarantine, or restore messages and files identified as policy violations. | Netskope can still detect a policy violation but cannot act on it. Violating content remains in place. |
| Access workspace profile information | admin.users:read | Access your workspace's profile information. | Enables Netskope to build a directory of your organization's users, supporting accurate reporting on who has access to sensitive content. | Netskope cannot identify individual users, which limits user-level reporting and access insights. |
| View channel details | admin.conversations:read | View your channel's member list, topic, purpose, and channel name. | Enables Netskope to identify existing channels so that remediation actions, such as moving flagged content to a restricted channel, reuse an existing channel instead of creating duplicates. | Netskope may create duplicate restricted channels, or certain remediation actions may fail. |
| View organization audit events | auditlogs:read | View events from all workspaces, channels, and users (Enterprise Grid only). | Enables Netskope to monitor administrative and security events across your organization, supporting anomaly detection and compliance reporting. | Netskope cannot monitor administrative or security events, reducing visibility into account changes or potential compromise. |
| View public channel information | channels:read | View basic information about public channels in your workspace. | Enables Netskope to identify public channels in your workspace as part of ongoing monitoring and reporting. | Public channel information is excluded from monitoring and reporting. |
| Manage public channels | channels:write | Manage your public channels and create new ones on your behalf. | Allows Netskope to create or manage public channels when needed to support policy enforcement. | Netskope cannot create or manage public channels on your behalf. |
| View private channel information | groups:read | View basic information about your private channels. | Enables Netskope to identify private channels as part of ongoing monitoring and reporting. | Private channel information is excluded from monitoring and reporting. |
| Manage private channels | groups:write | Manage your private channels and create new ones on your behalf. | Allows Netskope to create or manage private channels when needed to support policy enforcement. | Netskope cannot create or manage private channels on your behalf. |
| View direct message information | im:read | View basic information about your direct messages. | Enables Netskope to identify direct message conversations as part of ongoing monitoring. | Direct message conversations are excluded from monitoring. |
| Start direct messages | im:write | Start direct messages with people on your behalf. | Allows Netskope to send direct notifications, such as policy violation alerts, on your behalf. | Netskope cannot send direct message notifications on your behalf. |
| Start group direct messages | mpim:write | Start group direct messages with people on your behalf. | Allows Netskope to send notifications to multiple people at once on your behalf, such as coordinated policy alerts. | Netskope cannot send group direct message notifications on your behalf. |
| View files you can access | files:read | View files shared in channels and conversations that you have access to. | Enables Netskope to review file content for data loss prevention scanning. | Some files may be excluded from content inspection. |
| Upload, edit, and delete files | files:write | Upload, edit, and delete files on your behalf. | Allows Netskope to remediate policy violations by editing or removing files on your behalf. | Netskope cannot remediate file-based policy violations on your behalf. |

