Risk register

IDTitleInherentResidualTreatmentStatus
R-01
Indirect prompt injection via externally-authored calendar content
High
Moderate
Reduce - residual remains permanently
Open
R-02
Indirect prompt injection via document bodies and comment threads
High
Moderate
Reduce - residual remains permanently
Open
R-03
OAuth scope over-grant at consent
High
High
Accept + monitor - vendor dependency
Open
R-04
Egress and vendor-side retention of regulated data
High
High
Transfer - another function must deliver
Open
R-05
Chained exfiltration: Drive read to Calendar outbound write
Critical
High
Reduce - residual remains permanently
Open
R-06
Attribution gap between agent-performed and user-performed actions
Moderate
Moderate
Detect only - cannot prevent
Open
R-07
Over-shared content amplification
High
Low
Mitigate - can be closed
Open
R-08
Vendor documentation conflict on calendar write capability
Moderate
Moderate
Accept + monitor - vendor dependency
Open
R-09
Multi-surface reach on a single grant
Moderate
Moderate
Accept + monitor - vendor dependency
Open
R-10
Per-user grant inventory with no central revocation view
Moderate
Moderate
Accept + monitor - vendor dependency
Open
R-11
Substitution by unmanaged third-party MCP servers for the same services
High
Low
Mitigate - can be closed
Open
R-12
Irreversible deletion with outbound cancellation notice
High
Low
Mitigate - can be closed
Open
R-13
Free/busy disclosure of third parties including external attendees
Moderate
Low
Mitigate - can be closed
Open
R-14
Writes landing outside DLP, labeling, and retention scope
Moderate
Low
Mitigate - can be closed
Open
R-15
Reduced connector logging fidelity in agentic surfaces
High
High
Accept + monitor - vendor dependency
Open
R-16
Email-borne indirect prompt injection
High
Moderate
Reduce - residual remains permanently
Open
R-17
Gmail send scope surfaced at consent while the capability is not exposed
High
High
Accept + monitor - vendor dependency
Open
R-18
Slack direct-message and Connect-channel reach
High
Moderate
Reduce - residual remains permanently
Open
R-19
Claude in Slack retires 3 August 2026; permissions do not carry over
High
Low
Mitigate - can be closed
Open
R-20
Meeting recording and transcription consent
High
High
Transfer - another function must deliver
Open
R-21
Runtime workspace selection and dynamic client registration
Moderate
Low
Reduce - residual remains permanently
Open
R-22
Acquisition of third-party personal data without an assessed lawful basis
High
High
Transfer - another function must deliver
Open
R-23
Credit metering as financial exposure, with no direct connection revocation
Moderate
Low
Reduce - residual remains permanently
Open
R-24
Capability ambiguity between read-only querying and Function-driven writes
Moderate
Moderate
Accept + monitor - vendor dependency
Open
R-25
Organization agent identity inverts the permission model
Critical
High
Reduce - residual remains permanently
Open
R-26
Persistent channel memory with no default retention schedule
High
Low
Mitigate - can be closed
Open
R-27
Aggregate outbound surface across the estate
Critical
High
Reduce - residual remains permanently
Open
R-28
Slack functions as a laundering layer around Claude tool permissions
Critical
High
Reduce - residual remains permanently
Open
R-29
The Slack app is a single invocation surface for the entire connector estate
High
Moderate
Reduce - residual remains permanently
Open
R-30
Clay's Slack app is an unattended bidirectional path outside every control plane in this workbook
High
Moderate
Reduce - residual remains permanently
Open
R-31
Slack is the aggregation point for the enterprise data estate
Critical
High
Reduce - residual remains permanently
Open
R-32
Four AI assistants share the same Slack channels
Critical
High
Reduce - residual remains permanently
Open
R-33
Data-platform output delivered into Slack channels
High
High
Transfer - another function must deliver
Open
R-34
Source code, diffs and inadvertently committed secrets rendered into Slack
High
High
Detect only - cannot prevent
Open
R-35
Duplicate ungoverned paths for data already assessed as Claude connectors
High
Low
Mitigate - can be closed
Open
R-36
Second meeting-capture path compounding the recording-consent position
High
High
Transfer - another function must deliver
Open
R-37
Systems-of-record content rendered into channels
High
Moderate
Reduce - residual remains permanently
Open
R-38
Slack holds no business associate agreement with any Marketplace application provider
Critical
Critical
Transfer - another function must deliver
Open
R-39
Slack app approval is a separate administrative process from connector governance
Moderate
Low
Mitigate - can be closed
Open
R-40
Bearer tokens persisted in plaintext on the endpoint (Zoom Plugin only)
Critical
Low
Mitigate - can be closed
Open
R-41
Plugin skills are auto-loading instruction content, and the vendor does not verify plugin contents
Critical
High
Reduce - residual remains permanently
Open
R-42
A second Slack MCP server reaching the same workspace
High
Moderate
Reduce - residual remains permanently
Open
R-43
A third path to meeting content, reaching recordings and transcripts directly
High
High
Accept + monitor - vendor dependency
Open
R-44
Plugin governance is a separate admin surface from connector governance
High
Low
Mitigate - can be closed
Open
R-45
Plugins reach surfaces outside Claude administration
Moderate
Low
Reduce - residual remains permanently
Open
R-50
The safe permission choice may not be the default one
High
Moderate
Reduce - residual remains permanently
Open
R-51
The extension reaches whatever the browser is signed into
Critical
High
Reduce - residual remains permanently
Open
R-52
Reported defects in the persistence of site permission grants
Moderate
Moderate
Accept + monitor - vendor dependency
Open
R-56
Vendor states Claude in Chrome is not available to organizations covered by HIPAA
Critical
Critical
Transfer - another function must deliver
Open
R-53
Arbitrary script execution inside authenticated origins
Critical
High
Reduce - residual remains permanently
Open