| Connector | Class | Inherent | Residual | Tools | Recommendation |
|---|---|---|---|---|---|
Remote MCP server (first-party, vendor-hosted) | High | Moderate | 8 | Enable with write and delete tools restricted. Read tools allowed; all outbound-notifying tools approval-gated; delete blocked. | |
Remote MCP server (first-party, vendor-hosted) | High | Moderate | 9 | Enable with export and write tools approval-gated. Read/search tools allowed subject to a completed Drive over-sharing review. | |
Remote MCP server (first-party, vendor-hosted) | High | Moderate | 9 | Enable read and draft-read tools. Approval-gate draft creation and all label modification. Record send as Blocked and monitor the consent-scope discrepancy. | |
Remote MCP server (first-party, vendor-hosted) | High | Moderate | 9 | Enable read tools subject to a Slack Connect and shared-file review. Approval-gate every posting tool. Verify canvas availability before deciding. | |
Slack workspace application (first-party) | High | Moderate | 6 | Approve as a single decision with the Slack connector - they cannot be separated. Verify compliance-export coverage of Slack-initiated conversations before approving. Block Claude Code routing unless decided deliberately alongside Claude Code on the web. | |
Slack workspace application + organization-provisioned agent identity | Critical | High | 6 | Do not allow the 3 August 2026 cutover to configure itself. Enable no channels until channel-level credential scope, Member Access mode and spend limits are decided. Block standing instructions by default. | |
Remote MCP server (third-party, vendor-hosted) | High | Moderate | 6 | Enable read tools. Approval-gate raw transcripts. Enablement should follow, not precede, legal review of the recording-consent position. | |
Remote MCP server (third-party, vendor-hosted) | High | Moderate | 5 | Do not enable until a lawful-basis assessment for prospect-data acquisition is documented. Then approval-gate every tool, set conservative credit limits, and inventory MCP-enabled Functions. | |
Slack workspace application (third-party data path - no Claude involvement) | Critical | High | 5 | Block the Slack read actions and the configurable bot name. Permit message posting only against a reviewed inventory of destination channels and payloads, since no runtime approval exists. Resolve R-28 before permitting any write into a channel Claude reads. | |
Slack workspace application (third-party data path - no Claude involvement) | Critical | Moderate | 3 | Block scheduled delivery of regulated result sets into channels. Treat the Hex Agent as the fourth AI assistant it is, not as an analytics feature. | |
Slack workspace application (third-party AI assistant) | High | Moderate | 3 | Establish whether the tenant uses the documented federated connector and whether any separate export or synchronisation pipeline exists. Confirm what query and session content is transmitted to Slack. | |
Slack workspace application (third-party AI assistant) | Critical | High | 3 | Extend this inventory to ChatGPT or record the governance asymmetry as accepted risk. Determine its connector surface - that gap is the finding. | |
Slack workspace application (third-party data path - no Claude involvement) | High | Moderate | 3 | Confirm secret-scanning coverage and unfurl behaviour for private repositories. Add Slack channel history to secret-remediation purge scope. | |
Slack workspace application (third-party data path - no Claude involvement) | High | Moderate | 3 | Confirm channel membership matches the CRM access model wherever record content lands. Turn off unfurl for objects carrying regulated data, and establish whose access renders previews. See V-31. | |
Slack workspace application (third-party data path - no Claude involvement) | High | Moderate | 3 | Separate the security and incident projects from general delivery work - a single default cannot serve both. Exclude those channels from AI assistant access. | |
Slack workspace application (third-party data path - no Claude involvement) | High | Moderate | 2 | Turn off unfurl for restricted spaces, and establish whose access renders previews - a single broad grant overrides every space restriction at render time. See V-31. | |
Slack workspace application (third-party data path - no Claude involvement) | High | Moderate | 3 | Block transcript and summary delivery to channels until the R-20 legal review has covered Zoom capture and Slack distribution. | |
Slack workspace application (third-party data path - no Claude involvement) | High | Moderate | 3 | Reconcile against the Drive connector decisions. Confirm whether sharing from Slack modifies Drive permissions. | |
Slack workspace application (third-party data path - no Claude involvement) | High | Moderate | 3 | Reconcile against the Calendar connector decisions - event creation from Slack currently bypasses a restriction the council applied deliberately. | |
Slack workspace application (third-party data path - no Claude involvement) | Moderate | Low | 2 | Review failure notification verbosity and any webhook augmentation. | |
Slack workspace application (third-party data path - no Claude involvement) | Moderate | Low | 2 | Confirm no board carries regulated or security content; if one does, treat it on the Jira basis. | |
Claude plugin - bundled skills plus one or more MCP servers, installed from a marketplace or a local directory | High | Moderate | 7 | Reconcile against the Slack connector decisions before approving - the same reach by an ungoverned route. Block the send tool. Confirm what Slack's MCP client approval permits. | |
Claude plugin - bundled skills plus one or more MCP servers, installed from a marketplace or a local directory | Critical | High | 12 | Do not approve on the current credential model. If a build need is proven, restrict to named users on managed endpoints and exclude recording, transcript, whiteboard and Team Chat scopes from the Zoom OAuth application. | |
Local execution surface (IDE extension or CLI running on the developer's endpoint, with filesystem and shell reach) | Critical | Moderate | 6 | Deploy admin-enforced requirements.toml before enabling: constrain approval policy, sandbox mode, web search and the MCP allowlist. Forbid the bypass flag. Establish the second vendor's agreement and retention position separately. | |
Local execution surface (IDE extension or CLI running on the developer's endpoint, with filesystem and shell reach) | Critical | Moderate | 8 | Deploy managed settings by MDM before broad adoption: secret-path denies, restrictive default permission mode, sandboxed Bash, an MCP server allowlist, and disableBypassPermissionsMode. Verify deployment on a sample of endpoints. | |
Browser extension (acts inside the user's authenticated browser session, with per-site permission grants) | Critical | Moderate | 17 | Decide whether the extension is permitted at all before tuning settings, and enforce that through Chrome enterprise extension policy. Where permitted, maintain a prohibited-site list and a policy on which site categories may receive an ongoing grant. |