Integrate Your AssetsSaaS

Secure Slack Workspaces with Mondoo

Continuously scan a Slack workspace for misconfigurations and security issues.

Mondoo continuously scans a Slack workspace for misconfigurations and security issues. Deploy the integration once and assessments stay current as the workspace changes.

Prerequisites

  • Editor or Owner access to the Mondoo space
  • Access to a Slack workspace

Create a Slack API token for Mondoo

Mondoo authenticates to Slack with a user OAuth token from a new Slack app.

  1. On the Slack API website, go to Your Apps and select Create an App.

    Slack Create an app dialog

  2. Select From scratch.

    Slack Name app & choose workspace dialog

  3. Name the app (for example, mondoo-security), pick the workspace to secure, and select Create App.

    Slack app settings - Basic Information page

  4. Under Add features and functionality, select Permissions.

    Slack app settings - OAuth and permissions page

  5. Scroll to Scopes > User Token Scopes and add each of these scopes (select Add an OAuth Scope for each):

    • channels:read
    • groups:read
    • im:read
    • mpim:read
    • team:read
    • usergroups:read
    • users:read

    Slack app settings - user token scopes

  6. Scroll up to OAuth Tokens for Your Workspace and select Install to Workspace, then Allow to confirm.

    Slack app permissions confirmation

  7. Copy the User OAuth Token. You need it in the next section.

    Slack OAuth token

Add a Slack integration

In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select + INSTALL. On the integrations page, find the integration you want by browsing or searching by name:

  1. Under SaaS, select Slack.

    Add a Slack Integration in Mondoo

  2. In Choose an integration name, enter a name that identifies the workspace.

  3. In Enter the API token, paste the User OAuth Token you copied.

  4. Select START SCANNING.

On the Recommended Policies page, enable the policies you want Mondoo to score this integration against. To learn how policies work, read Manage Policies.

Learn more

On this page