This reference explains the Slack bot permissions requested by Bigmind and how each is used. For customer setup instructions, see Connect and use Slack.
#Permissions by feature
Bigmind connects using a Slack bot token. The base connection supports user matching, notifications, and Bigmind link previews. Additional authorization enables channel sync, the DM agent, or the channel agent. Features share some scopes; a permission is granted once even when several features use it.
| Feature | Scopes added to the base connection | What enables the feature |
|---|---|---|
| Channel sync | channels:read, channels:history, groups:read, groups:history | Authorize channel sync, add the app to a channel, and associate it with a CRM account. |
| Bigmind Agent in DMs | im:history, assistant:write, files:read | Authorize the DM agent and enable it in Bigmind. |
| Bigmind Agent across channels | app_mentions:read, files:read, channels:read, channels:history, groups:read, groups:history | Authorize the channel agent, add the app to an eligible channel, and choose Internal channel. |
The channel agent also uses the base users:read, users:read.email, and chat:write permissions. Channel sync is not a prerequisite for either agent experience. Having a scope does not automatically enable every Bigmind feature that can use it.
#Base connection scopes
| Scope | How Bigmind uses it |
|---|---|
chat:write | Send notifications, setup prompts, and agent replies as the Bigmind app. |
im:write | Open a direct conversation between Bigmind and a Slack user for message delivery. |
users:read | Read workspace member profiles for user matching and channel eligibility checks. |
users:read.email | Match Slack members to their Bigmind accounts by email, so requests use the correct person's permissions. |
links:read | Receive events when supported Bigmind URLs are shared so Bigmind can prepare a preview. |
links:write | Attach previews to supported Bigmind links shared in Slack. |
#Channel and agent scopes
| Scope | Features | How Bigmind uses it |
|---|---|---|
channels:read | Channel sync; channel agent | Read public-channel information for channel selection, membership checks, and shared-channel checks. |
channels:history | Channel sync; channel agent | Read accessible public-channel messages for customer context or an agent conversation. |
groups:read | Channel sync; channel agent | Read private-channel information where the app has access. |
groups:history | Channel sync; channel agent | Read messages in private channels the app has joined, for syncing or agent context. |
app_mentions:read | Channel agent | Receive messages that mention @Bigmind and use them to start threaded agent conversations. |
im:history | DM agent | Receive and process messages sent in direct conversations with Bigmind. |
assistant:write | DM agent | Support Slack's agent experience, including working status, suggested prompts, and thread titles. |
files:read | DM agent; channel agent | Retrieve accessible attachments, including voice notes, images, and documents, for agent processing and display in the corresponding Bigmind chat. |
These are Slack bot scopes, not permission to act as a human Slack user. In particular, DM access applies to conversations involving the app, not private conversations between other people. See Slack's official scope reference, assistant:write reference, and files:read reference for Slack's definitions.
#How access is limited
- Customer channel sync: Bigmind syncs channels the app can access that have been associated with a CRM account. Authorizing history access alone does not associate or sync every channel.
- Private channels: Add the app explicitly before Bigmind can access their conversations.
- Channel agents: Configure each channel separately. Bigmind blocks agent mentions in externally shared channels and channels containing external members or guests. Every human member must be an active member of the same Bigmind organization.
- Agent identity: Slack users are matched to Bigmind by email. Each request runs with the requesting member's Bigmind permissions. In a channel thread, everyone in the channel can see the reply, including answers based on that member's accessible resources.
- Conversation context: Channel agents read recent Slack context directly and can retrieve more messages from that same channel. This does not require customer channel sync or a CRM association.
- Attachments: File access is used for attachments supplied to agent conversations. It is not a request to upload, edit, or delete Slack files.
#Reviewing or changing authorization
Use the feature-specific authorization buttons on Bigmind's Slack integration page. Slack shows the permissions being approved; an installation with several features may show their combined permissions. Existing installations may have additional permissions from earlier authorizations or an administrator-managed app configuration. Review the actual installation in Slack when auditing access.
Disabling a feature in Bigmind stops that feature; it does not itself revoke Slack OAuth scopes. Manage the app's granted access through Slack's app administration. If reinstalling or changing permissions, reauthorize through Bigmind to update the connection. Disconnecting Slack affects all features using that workspace connection.
For step-by-step setup, return to the Slack integration guide.
