Open verification items

RefPriorityScopeWhat to confirmStatus
V-01
Critical
Claude Tag (Slack)
The observed migration or opt-in state of the organization as at today, and whether channel enablement, Agent Identity credential scope, Member Access mode and spend limits have been set deliberately.
Not started
V-02
Critical
All Slack applications
Which of the connected applications have an executed agreement covering the data they actually receive, given that Slack holds no agreement with any Marketplace provider.
Not started
V-04
Critical
Hex (Slack app)
Every scheduled project delivery: destination channel, schedule, and the columns the output actually contains.
Not started
V-05
Critical
Slack workspace
The full installed-application list, reconciled against the thirteen found in the review, plus whether app installation requires administrator approval.
Not started
V-28
High
Slack workspace topology
Which Slack plan is in use, and if Enterprise Grid, how many Slack workspaces exist, which ones the Claude application is deployed to, and whether 'Default for future workspaces' is ticked.
Not started
V-32
Critical
Slack Plugin (Claude plugin)
Whether the Slack plugin is installed anywhere, and what Slack's own MCP client approval permits at tool level - specifically whether message sending can be restricted independently of search.
Not started
V-33
Critical
Zoom Plugin (Claude plugin)
Whether the Zoom plugin is installed, who holds exported bearer tokens, what scopes the Zoom Marketplace OAuth application actually grants, and whether the distribution bundles a Team Chat MCP server in addition to the three named in its README.
Not started
V-48
Critical
Claude in Chrome (browser extension)
Whether the organization falls within the vendor's stated exclusion of Claude in Chrome for organizations covered by HIPAA, and whether that statement is current. Confirm with the vendor directly rather than inferring from help-centre wording.
Not started
V-47
Critical
Claude in Chrome (browser extension)
Which tools the extension actually exposes to the surface your users have. This assessment observed arbitrary JavaScript execution, HTTP request reading, console reading, mouse and keyboard control, file upload, saved-workflow execution and multi-browser enumeration in the tool surface available to an agentic session. None of these appear in the support documentation describing the side panel. Establish whether the end-user experience exposes the same set, a subset, or something wider.
Not started
V-44
Critical
Claude in Chrome (browser extension)
Which permission option is pre-selected in the deployed extension build when the site permission prompt appears, and whether allow-once requires an additional interaction such as opening a dropdown. Capture a screenshot as the baseline. The same question applies to the connector approval prompts more generally.
Not started
V-45
Critical
Claude in Chrome (browser extension)
Whether the extension is already installed anywhere; which sites currently hold always-allow for those users; whether Team or Enterprise organization settings block the feature; and whether skip-all-permissions mode can be prevented centrally rather than by policy alone.
Not started
V-46
High
Claude in Chrome (browser extension)
Whether always-allow grants persist as documented in the deployed build, whether the approved-sites list populates, and whether the permission dialog times out in a way that registers as a denial.
Not started
V-43
High
Claude Code (VS Code extension / CLI)
Whether managed instruction content and PreToolUse hooks are deployed, and whether locally defined hooks are restricted. Instruction content and hooks are separate mechanisms with different force - one is context, the other blocks a call.
Not started
V-40
Critical
Codex (VS Code extension) and Claude Code (VS Code extension / CLI)
Whether either tool is in use on developer endpoints, and whether any managed policy has actually been deployed - Codex requirements.toml, Claude Code managed-settings.json.
Not started
V-41
High
Claude Code (VS Code extension / CLI)
Which MCP servers can be registered locally, whether project MCP servers are auto-approved, and how that list compares with the approved connector list in this workbook.
Not started
V-42
High
Codex Local (desktop, CLI, and IDE extension)
The ChatGPT Enterprise workspace agreement, retention position and whether zero data retention is configured; plus Codex Admin group membership and whether it is backed by the identity provider.
Not started
V-37
Critical
Gemini Enterprise (Slack app)
Whether the Gemini Enterprise Slack connector in this tenant uses FEDERATED SEARCH - queries sent to the Slack API at query time, no copy retained - or an ingestion configuration that copies Slack messages and files into a Google-side data store.
Not started
V-38
Critical
Claude Tag (Slack)
What happens to an organization that has not configured Claude Tag before the 3 August 2026 transition: automatic migration, opt-in required, or legacy behaviour retained.
Not started
V-39
High
Slack Plugin and Zoom Plugin
Whether Claude Code exposes per-tool permission controls for MCP servers registered by a plugin, and if so where those controls are set and whether they can be enforced centrally.
Not started
V-36
High
Zoom Plugin (Claude plugin)
Whether any Zoom bearer tokens have actually been exported on any endpoint, and whether the plugin is in use in skills-only mode. The vendor README confirms the skills function without the MCP servers, so skills-only is a supported configuration rather than a degraded one.
Not started
V-34
High
Granola, Zoom (Slack app) and Zoom Plugin
Whether the recording-consent legal review covers all three paths to meeting content: Granola capture, Zoom capture with Slack distribution, and direct retrieval of recordings and transcripts through the Zoom MCP server.
Not started
V-35
High
All plugins
The installed plugin inventory across the organization, which marketplaces are allowlisted, whether auto-update and auto-install are enabled, and whether local directory installs are blocked by endpoint managed settings.
Not started
V-31
High
GitHub, Salesforce, Jira Cloud, Confluence Cloud and Google Drive (Slack apps)
For each of the five Slack applications that render inline previews: whether a preview renders under the individual reader's own linked account, or under a single application-level credential - and if the latter, what that credential can reach in the source system.
Not started
V-30
High
Clay (Slack app)
Whether the Clay Slack application is actually installed in the Slack workspace. It was not among the thirteen applications found in the workspace review, but is assessed here as a path arising from the Clay MCP connector already in use.
Not started
V-29
High
Claude organization
Which connectors users are permitted to authorize at organization level - the measure that actually bounds what the Slack surface can reach.
Not started
V-06
High
Google Mail (Gmail)
The OAuth scopes actually granted to the Claude application - specifically whether gmail.send is present despite the vendor stating send is not exposed.
Not started
V-07
High
Google Calendar
Whether the create, update, delete and RSVP tools are actually present in the connector, resolving the conflict between the vendor's documentation site and its knowledge base.
Not started
V-08
High
All Claude connectors
The current per-tool permission state for every connector, compared against the Recommended Setting column in this workbook.
Not started
V-09
High
Claude organization
Which connectors are enabled organization-wide, by whom, and whether individual users can add others.
Not started
V-10
High
Claude organization
Whether custom connector addition is restricted, and whether verified-domain connectors are restricted to the enterprise.
Not started
V-11
High
Claude (Slack app)
Whether the compliance export and audit log capture Slack-initiated Claude conversations, which are stored separately from Claude chat history.
Not started
V-12
High
Claude (Slack app)
Whether Claude Code on the web is enabled, and whether coding mentions in Slack route into a Claude Code session with repository access.
Not started
V-13
High
Google Drive
Whether a Drive over-permission and external-sharing review has been completed, and what it found for regulated content.
Not started
V-14
High
Slack (connector)
The inventory of Slack Connect channels and externally-shared channels, and which of them receive automated content from connected applications.
Not started
V-15
High
Granola
The Granola Enterprise MCP member scope configuration - Personal notes, Public notes, both or neither - and confirmation that admins fall outside those member controls.
Not started
V-16
High
Granola and Zoom
The legal position on meeting recording and transcription consent, covering capture without a visible recording participant and onward distribution into Slack.
Not started
V-17
High
Clay
Clay MCP membership, the default and per-user credit limits, the inventory of Functions toggled 'Enable for MCP', and the state of the 'Allow querying all accounts' toggle.
Not started
V-18
High
Clay
Whether a documented lawful-basis and privacy assessment exists for third-party prospect data acquisition and enrichment.
Not started
V-19
High
Clay (Slack app)
Every configured Clay-to-Slack and Slack-to-Clay workflow step: destination channels, payload fields, trigger conditions, and the bot display names in use.
Not started
V-20
High
GitHub (Slack app)
Secret-scanning coverage, whether alerting itself posts secrets into channels, and unfurl behaviour for private repositories.
Not started
V-21
High
Salesforce, Jira Cloud, Confluence Cloud
Which objects, projects and spaces notify into which channels; whether unfurl and preview rendering is enabled for restricted content; and whether channel membership is at least as restrictive as the source system's access model.
Not started
V-22
Moderate
Google Drive and Calendar Slack apps
Whether these apps reinstate capability that the corresponding Claude connector decision restricts - particularly event creation with external attendees, and whether sharing from Slack modifies Drive permissions.
Not started
V-23
Moderate
dbt Cloud (Slack app)
Failure notification verbosity, and what any webhook augmentation attaches to error threads.
Not started
V-24
Moderate
Trello (Slack app)
Whether any Trello board carries regulated, security or clinical content.
Not started
V-25
Moderate
ChatGPT (Slack app)
What connector surface exists on the OpenAI side, whether it is reachable from Slack, and what Slack scopes were granted at install.
Not started
V-26
Moderate
All Claude connectors
Chat and project retention settings, and whether they are aligned to the records schedule.
Not started
V-27
Moderate
Slack (connector)
The Slack message and file retention policy, and how it compares to the records schedule.
Not started