Stria and Slack

Scope checks on the channels you nominate — and a consent screen with four scopes on it.

Plans: Available on every plan. Connecting requires workspace admin rights. See plans and pricing

Client requests do not only arrive by email. In a shared Slack channel, "while you're in there,

could you also…" reads as conversation rather than a change of scope, and it is gone by the time you

next open the agreement. Connecting Slack lets Stria check the channels you nominate against the

scope your client signed.

The four scopes it asks for

Slack's own consent screen is the authority here, but it should hold no surprises:

ScopeWhat it grants
channels:historyRead messages in public channels it has been added to
groups:historyRead messages in private channels it has been added to
channels:readList public channels, so you can pick one by name
groups:readList private channels, for the same reason

Two read scopes and two list scopes. Read what it can see, name what it can list — nothing else.

The four it refuses to ask for

This list matters more than the one above, because a scope you were never asked for is one you

cannot accidentally grant.

RefusedWhy
chat:writeWould let Stria post into your Slack. It never needs to — findings appear in Stria, and nothing is written back to a channel or sent to a client.
search:readWould let Stria search the whole workspace. Slack names it among the scopes granting extensive access without clear need, and a channel that receives events has no use for search.
users:read.emailWould read every workspace member's email so a sender could be matched to a client automatically. You tell Stria which client a channel is about instead.
files:readWould read files shared in the channel. Only message text is examined.

There is no write scope of any kind. Stria cannot post, react, rename, invite, or send a direct

message, and no configuration changes that.

What it cannot reach, at any scope

A private direct message between you and your client is not reachable. Not at these scopes and

not at any others — a Slack bot token does not cover another person's DMs, so no scope request would

change it. If the expensive requests arrive in a DM, forwarding the message is the route, not this.

Group DMs are joinable in principle and are not included in the initial grant, which is why the

consent screen lists four scopes rather than six.

Setting it up

  1. In Settings → Integrations, start the Slack connection. Slack's consent screen lists exactly what

is about to be requested.

  1. Nominate the channels Stria may read. This is an allow-list — nothing is read until you name a

channel, and adding the app to a channel is a separate act from installing it.

  1. Associate each nominated channel with a client, so a request has a scope to be checked against.
  2. Lock a scope baseline for that client if you have not already. Without one there is nothing to

check against, and this is the most common reason detection looks silent.

What it costs against your plan

Scope checks are metered as AI actions, and Slack detection is metered daily as well as monthly —

because how much a client sends you is not your decision. Messages that are plainly not requests are

filtered before any allowance is spent, and a message that cannot be matched to a client costs

nothing rather than being checked against a guess.

If you would rather connect nothing

You do not have to. Forwarding a client message gives you the same check with no OAuth grant at all.

See making client email arrive without forwarding.

When detection is on but nothing is appearing, the four checks in order

covers it.

Other connections

  • Stria and Stripe — Your Stripe account, your money, your merchant relationship — Stria issues the invoice.
  • Stria and Xero — Invoices and payments pushed to your ledger, and reconciliation read back.
  • Stria and QuickBooks Online — Invoices and payments pushed to your ledger, and reconciliation read back.
  • Stria and Asana or Linear — Push an approved item to the tracker your team already works in. One way, one item at a time.
  • Webhooks and the API — Signed HTTPS events when work is approved or money moves, plus token-authenticated endpoints.

Start your 14-day trial · See plans and pricing · Partner API reference