> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Slack

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/slack.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=e0b8fff2fa0fbb945af1de7b12681ab8" alt="" noZoom width="126" height="126" data-path="images/connectors/slack.svg" />

  <h1>Slack</h1>
</div>

## Connection

Connecting sends you to Slack to approve Klef's access.

### Permissions

Minimum permissions the connection requires.

| Capability        | Required | Granted by (any one) |
| ----------------- | -------- | -------------------- |
| Provision members | Yes      | `admin`              |
| Read channels     | Yes      | `channels:read`      |

## slack.user

### Fields

| Field              | Type   | Required | Description                                                        |
| ------------------ | ------ | -------- | ------------------------------------------------------------------ |
| `userName` (Email) | string | Yes      | Email address the member signs in with.                            |
| `displayName`      | string |          | Name shown in Slack.                                               |
| `givenName`        | string |          | First name.                                                        |
| `familyName`       | string |          | Last name.                                                         |
| `title`            | string |          | Job title shown on the profile.                                    |
| `active`           | bool   |          | Whether the member is active. An inactive member is deactivated.   |
| `channels`         | grant  |          | Public channels the member belongs to. One row grants one channel. |
| `channels[]`       | string |          | Channel ID.                                                        |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in Slack, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field            |
| ------------- | ----------------------- |
| `userName`    | `worker.business_email` |

## Examples

### Employee lifecycle

Stage a Microsoft account before day one, switch on Microsoft 365 and Slack when they start, and shut both down when they leave.

```hcl theme={null}
stage active {
  target slack.user {
    userName    = worker.business_email
    displayName = worker.display_name
    title       = worker.job.name
    active      = true
    channels    = ["general", "announcements"]
  }
}
```

### Engineering access

The engineering group, a seat on the GitHub engineering team and the incident channels, with GitHub removed when they leave.

```hcl theme={null}
stage active {
  target slack.user {
    userName = worker.business_email
    channels = ["engineering", "incidents", "deploys"]
  }
}
```

### Contractor access

Unlicensed Microsoft, Slack and AWS access for contractors that expires on their end date, with a warning to their manager first.

```hcl theme={null}
stage active {
  target slack.user {
    userName    = worker.business_email
    displayName = "{{ worker.display_name }} (Contractor)"
    active      = true
    channels    = ["contractors"]
  }
}
```

### Leaver offboarding

Ask the manager to plan the handover, then close Microsoft, Slack and GitHub access on the last day and tell security.

```hcl theme={null}
stage terminated {
  target slack.user {
    userName = worker.business_email
    active   = false
    channels = []
  }
}
```
