Skip to main content
The Slack integration delivers Forge Registry events to a selected channel and sends requester or owner updates by direct message when Forge can resolve a Slack identity. Authorized owners can approve or deny supported requests without leaving Slack.

Authentication

Forge connects with Slack OAuth. The user connecting Slack must be a Forge organization owner or administrator and must be allowed to install the Forge Slack app in the target workspace. Forge requests these bot scopes: The OAuth bot token is stored as a Forge-managed secret. Forge binds the OAuth callback to the initiating console user and organization, and the authorization state expires after ten minutes.

Events

Slack preferences currently cover Registry activity: Forge sends Registry requests to the configured Registry channel. Requester updates and owner-specific actions can be delivered by DM when a directory user is linked to a Slack user in the connected workspace. See Notifications to configure governance, Shadow AI, and Registry event delivery. See Ownership to route matching governance requests to specific users and groups.

Setup

Before connecting, confirm that:
  • You are a Forge organization owner or administrator.
  • You can approve app installation in the intended Slack workspace, or a Slack administrator is available to approve it.
  • A dedicated test channel exists. For a proof-of-concept, use a clearly named channel and tell its members before sending test notifications.
Then connect the workspace:
  1. In Forge, open Settings → Ownership, then find Slack.
  2. Select Connect Slack and authorize the Forge app for the intended workspace.
  3. Confirm that Forge shows the expected workspace as Connected.
  4. Choose the default channel used for governance, Shadow AI, and test notifications.
  5. Choose the Registry request channel. It can be the same channel.
  6. Enable only the event types that should send messages.
Private channels appear only when the installed app can see them. Archived channels are excluded from the picker. Reconnect Slack if the app was removed, its token was revoked, or the workspace installation changed.

Decisions

Supported request messages include Approve and Deny actions. Forge verifies the Slack request signature, connected workspace, Slack user, current request owner, request state, and requested scope before applying a decision. A denial requires a reason. Decisions are idempotent. Stale, duplicate, already-resolved, or unauthorized actions do not change the request. After a successful decision, Forge updates the original Slack message and records the Slack actor and outcome in the audit trail.

Data

Forge reads workspace identity, visible channel metadata, and user identity fields needed for routing. It does not ingest Slack message history as AI inventory or session content. The integration sends Forge-generated summaries and deep links; notification content is bounded to the event and destination.

Verification

After connecting:
  • Confirm the expected Slack workspace is shown as connected.
  • Confirm both channel selectors list the expected visible channels and exclude archived channels.
  • Under Test notifications, review the listed Slack destination, select Send test, and require a Sent Slack delivery for that exact channel.
  • Open Settings → Audit log, filter the action to admin_notifications.test_requested, and confirm the requesting actor and time. The notification delivery history provides the provider, destination, status, attempt count, and delivery time.
  • Submit a Registry request and verify that the configured Registry channel receives it. This is separate from the generic test notification.
  • Verify that a mapped requester or owner receives the expected direct message.
  • Complete one supported decision and confirm that both the Slack message and the Forge request show the same final state. Confirm the Slack actor and outcome in the audit trail.
A green generic test proves channel delivery only. It does not prove direct message identity matching or interactive approval authorization; run the DM and decision checks separately when those capabilities are in scope. If Forge shows Not connected, the shared Send test button may still be available for another enabled destination such as email or webhook. It does not test Slack until a workspace and default Slack channel are connected and shown in the destination preview. If channels cannot be listed, verify channels:read and groups:read and confirm the app can see the destination. If DMs do not arrive, verify the directory email matches the Slack account email and that users:read.email and im:write are present.

Notifications

Configure event delivery and verify recent notification outcomes.

Ownership

Assign governance work to the appropriate users and groups.