Type: Estate-level
Subject: Estate-level
Decision requested: Accept that permission settings bind where Claude reads, not where data arrives - and fund control at the systems that write into Slack
Inherent / residual: Critical / High
Control owner: InfoSec + source system owners
Context: Any system permitted to write into a channel Claude reads strips the approval gate from its own output. Every individual setting can be exactly as approved and the combination still bypasses it.
Risks: R-28 [Critical inherent / High residual] Slack functions as a laundering layer around Claude tool permissions | R-31 [Critical inherent / High residual] Slack is the aggregation point for the enterprise data estate
Open verification: V-05 [Critical] The full installed-application list, reconciled against the thirteen found in the review, plus whether app installation requires administrator approval.
Ruling:
Amendment or condition: