AW-009

Type: Connector disposition

Subject: Clay (Slack app)

Decision requested: Approve the proposed disposition for Clay (Slack app) across its 5 assessed actions

Inherent / residual: Critical / Moderate

Control owner: Slack Workspace Admin + Clay Workspace Admin

Context: 5 assessed actions. No Claude runtime control on this path. Administrative actions proposed: Do not enable x3, Permit with restrictions x2. Proposed for Blocked: Configurable bot display name on posted messages; Retrieve messages from a channel; Retrieve channel members. Class: Slack workspace application (third-party data path - no Claude involvement). Control point: Slack app approval (Slack admin) + Clay workflow step configuration. Control owner: Slack Workspace Admin + Clay Workspace Admin.

Risks: R-27 [Critical inherent / High residual] Aggregate outbound surface across the estate | R-28 [Critical inherent / High residual] Slack functions as a laundering layer around Claude tool permissions | R-30 [High inherent / Moderate residual] Clay's Slack app is an unattended bidirectional path outside every control plane in this workbook | R-31 [Critical inherent / High residual] Slack is the aggregation point for the enterprise data estate

Open verification: V-19 [High] Every configured Clay-to-Slack and Slack-to-Clay workflow step: destination channels, payload fields, trigger conditions, and the bot display names in use. | V-30 [High] Whether the Clay Slack application is actually installed in the Slack workspace. It was not among the thirteen applications found in the workspace review, but is assessed here as a path arising from the Clay MCP connector already in use.

Ruling:

Amendment or condition: