> For the complete documentation index, see [llms.txt](https://docs.p0.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.p0.dev/integrations/notifier-integrations/slack.md).

# Slack

Install the P0 Security Slack integration to request, approve, and receive just-in-time access notifications for cloud resources in Slack.

{% hint style="info" %}
Installing P0 on Slack takes about 2 minutes.
{% endhint %}

### Before you begin

Make sure you are either "Workspace Admin" or "Workspace Owner" for your workspace, or ask a user with one of these roles to install the P0 Slack integration.

### Adding Slack

1. On [p0.app](https://p0.app), navigate to "Integrations", then select Slack:

<figure><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-5828b75d2bd1dde9dd04542046ba6135ac6661cf%2Fimage.png?alt=media" alt="" width="563"><figcaption></figcaption></figure>

2. Click "Install integration". You'll be redirected to Slack's OAuth install page:

<figure><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-d3a059e68c261754105d50ecff9f609316ca31d5%2FScreenshot%202024-03-04%20at%206.14.51%E2%80%AFPM.png?alt=media" alt="" width="408"><figcaption></figcaption></figure>

3. Choose the workspace where you want P0 installed, and select a channel where you want P0 to post.

{% hint style="warning" %}
The Slack channel you specify must be a public channel.
{% endhint %}

After you finish adding the Slack bot, your integration should look like this (just with your own information of course):

<figure><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-f44175049e07b862e05476a51cef5c179c6061fe%2Fimage.png?alt=media" alt="" width="563"><figcaption></figcaption></figure>

And that's it. You're ready to use p0 to grant least-privileged, just-in-time access to members of your organization!

### Slack Settings

{% hint style="info" %}
P0 can create and manage a <mark style="color:blue;">@P0Approvers</mark> Slack group to automatically notify approvers when access requests are made.

If you want P0 to manage this group, you will need to configure Slack (in your Slack's admin settings page) so that anyone except guests can create and modify user groups.
{% endhint %}

<figure><img src="https://3783273641-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSQNwGQz62W737pY0FzVb%2Fuploads%2Fgit-blob-e0b4544c80d8ac74b985f6f4591bacf16457de11%2Fimage.png?alt=media" alt="" width="563"><figcaption></figcaption></figure>

### Permissions requested

When you install the P0 Slack app, Slack's OAuth screen will ask you to approve the following bot token scopes. Here's what each one is used for:

<table><thead><tr><th width="200">Scope</th><th>Why P0 needs it</th></tr></thead><tbody><tr><td><code>incoming-webhook</code></td><td>Lets you pick the default channel where P0 posts access-request and evidence notifications when you install the app (step 3, above). P0 stores the channel you choose and posts there.</td></tr><tr><td><code>channels:join</code></td><td>Lets the P0 bot join that public notification channel on its own, so it can start posting there without someone having to manually <code>/invite</code> it first.</td></tr><tr><td><code>channels:read</code></td><td>Required by Slack in order to call <code>conversations.join</code> on a public channel; P0 doesn't separately look up or use channel metadata with it.</td></tr><tr><td><code>chat:write</code></td><td>Lets P0 post and update messages — access-request notifications to approvers, status updates (approved/denied/expired) to requesters, and replies to the <code>/p0</code> slash command.</td></tr><tr><td><code>im:write</code></td><td>Lets P0 open a direct message with a specific user so it can send them a private notification (e.g. "your request was approved").</td></tr><tr><td><code>im:read</code></td><td>Companion permission to <code>im:write</code>; lets P0 maintain the DM conversation it opens with a user.</td></tr><tr><td><code>commands</code></td><td>Powers the <code>/p0</code> slash command, which lets users request and manage cloud access directly from Slack.</td></tr><tr><td><code>users:read</code></td><td>Lets P0 look up a Slack user's profile — used to identify who invoked <code>/p0</code> or clicked a button in a P0 message.</td></tr><tr><td><code>users:read.email</code></td><td>Lets P0 read a Slack user's email address, which it uses to match that Slack account to the corresponding P0 user account — both when notifying a P0 user in Slack, and when authenticating a Slack user who runs <code>/p0</code>.</td></tr><tr><td><code>usergroups:read</code></td><td>Lets P0 read the membership of the <mark style="color:blue;">@P0Approvers</mark> Slack group described above. This only takes effect if your Slack workspace's admin settings allow apps to create and modify user groups; otherwise P0 skips group management and falls back to notifying approvers without it.</td></tr><tr><td><code>usergroups:write</code></td><td>Lets P0 create and update the membership of the <mark style="color:blue;">@P0Approvers</mark> Slack group, keeping it in sync with your current approvers.</td></tr></tbody></table>
