Connectors in scope

ConnectorClassInherentResidualToolsRecommendation
Remote MCP server (first-party, vendor-hosted)
High
Moderate
8
Enable with write and delete tools restricted. Read tools allowed; all outbound-notifying tools approval-gated; delete blocked.
Remote MCP server (first-party, vendor-hosted)
High
Moderate
9
Enable with export and write tools approval-gated. Read/search tools allowed subject to a completed Drive over-sharing review.
Remote MCP server (first-party, vendor-hosted)
High
Moderate
9
Enable read and draft-read tools. Approval-gate draft creation and all label modification. Record send as Blocked and monitor the consent-scope discrepancy.
Remote MCP server (first-party, vendor-hosted)
High
Moderate
9
Enable read tools subject to a Slack Connect and shared-file review. Approval-gate every posting tool. Verify canvas availability before deciding.
Slack workspace application (first-party)
High
Moderate
6
Approve as a single decision with the Slack connector - they cannot be separated. Verify compliance-export coverage of Slack-initiated conversations before approving. Block Claude Code routing unless decided deliberately alongside Claude Code on the web.
Slack workspace application + organization-provisioned agent identity
Critical
High
6
Do not allow the 3 August 2026 cutover to configure itself. Enable no channels until channel-level credential scope, Member Access mode and spend limits are decided. Block standing instructions by default.
Remote MCP server (third-party, vendor-hosted)
High
Moderate
6
Enable read tools. Approval-gate raw transcripts. Enablement should follow, not precede, legal review of the recording-consent position.
Remote MCP server (third-party, vendor-hosted)
High
Moderate
5
Do not enable until a lawful-basis assessment for prospect-data acquisition is documented. Then approval-gate every tool, set conservative credit limits, and inventory MCP-enabled Functions.
Slack workspace application (third-party data path - no Claude involvement)
Critical
High
5
Block the Slack read actions and the configurable bot name. Permit message posting only against a reviewed inventory of destination channels and payloads, since no runtime approval exists. Resolve R-28 before permitting any write into a channel Claude reads.
Slack workspace application (third-party data path - no Claude involvement)
Critical
Moderate
3
Block scheduled delivery of regulated result sets into channels. Treat the Hex Agent as the fourth AI assistant it is, not as an analytics feature.
Slack workspace application (third-party AI assistant)
High
Moderate
3
Establish whether the tenant uses the documented federated connector and whether any separate export or synchronisation pipeline exists. Confirm what query and session content is transmitted to Slack.
Slack workspace application (third-party AI assistant)
Critical
High
3
Extend this inventory to ChatGPT or record the governance asymmetry as accepted risk. Determine its connector surface - that gap is the finding.
Slack workspace application (third-party data path - no Claude involvement)
High
Moderate
3
Confirm secret-scanning coverage and unfurl behaviour for private repositories. Add Slack channel history to secret-remediation purge scope.
Slack workspace application (third-party data path - no Claude involvement)
High
Moderate
3
Confirm channel membership matches the CRM access model wherever record content lands. Turn off unfurl for objects carrying regulated data, and establish whose access renders previews. See V-31.
Slack workspace application (third-party data path - no Claude involvement)
High
Moderate
3
Separate the security and incident projects from general delivery work - a single default cannot serve both. Exclude those channels from AI assistant access.
Slack workspace application (third-party data path - no Claude involvement)
High
Moderate
2
Turn off unfurl for restricted spaces, and establish whose access renders previews - a single broad grant overrides every space restriction at render time. See V-31.
Slack workspace application (third-party data path - no Claude involvement)
High
Moderate
3
Block transcript and summary delivery to channels until the R-20 legal review has covered Zoom capture and Slack distribution.
Slack workspace application (third-party data path - no Claude involvement)
High
Moderate
3
Reconcile against the Drive connector decisions. Confirm whether sharing from Slack modifies Drive permissions.
Slack workspace application (third-party data path - no Claude involvement)
High
Moderate
3
Reconcile against the Calendar connector decisions - event creation from Slack currently bypasses a restriction the council applied deliberately.
Slack workspace application (third-party data path - no Claude involvement)
Moderate
Low
2
Review failure notification verbosity and any webhook augmentation.
Slack workspace application (third-party data path - no Claude involvement)
Moderate
Low
2
Confirm no board carries regulated or security content; if one does, treat it on the Jira basis.
Claude plugin - bundled skills plus one or more MCP servers, installed from a marketplace or a local directory
High
Moderate
7
Reconcile against the Slack connector decisions before approving - the same reach by an ungoverned route. Block the send tool. Confirm what Slack's MCP client approval permits.
Claude plugin - bundled skills plus one or more MCP servers, installed from a marketplace or a local directory
Critical
High
12
Do not approve on the current credential model. If a build need is proven, restrict to named users on managed endpoints and exclude recording, transcript, whiteboard and Team Chat scopes from the Zoom OAuth application.
Local execution surface (IDE extension or CLI running on the developer's endpoint, with filesystem and shell reach)
Critical
Moderate
6
Deploy admin-enforced requirements.toml before enabling: constrain approval policy, sandbox mode, web search and the MCP allowlist. Forbid the bypass flag. Establish the second vendor's agreement and retention position separately.
Local execution surface (IDE extension or CLI running on the developer's endpoint, with filesystem and shell reach)
Critical
Moderate
8
Deploy managed settings by MDM before broad adoption: secret-path denies, restrictive default permission mode, sandboxed Bash, an MCP server allowlist, and disableBypassPermissionsMode. Verify deployment on a sample of endpoints.
Browser extension (acts inside the user's authenticated browser session, with per-site permission grants)
Critical
Moderate
17
Decide whether the extension is permitted at all before tuning settings, and enforce that through Chrome enterprise extension policy. Where permitted, maintain a prohibited-site list and a policy on which site categories may receive an ongoing grant.