Entitle for Slack | Entitle

Overview

Slack is a messaging and collaboration platform designed for teams and workplaces. It allows users to communicate, share files, and collaborate in real-time through channels, direct messages, and integrations with various other tools and services.

Entitle can be added as an app on Slack. This requires an Admin to configure the integration between Entitle and Slack through the Entitle admin console. Following the integration, the Entitle app is added to the list of available apps in your organization, but you will still need to add it to your Apps list. Users interact with the Entitle app through "/" (slash) commands. For details, see the Entitle for Slack end-user guide.

🚧

Important information

Slack requires a one-to-one authorization between the Entitle email address of a user and their Slack instance. Otherwise, the integration will not be able to authorize correctly when a user tries to use the Entitle app in Slack.

Install Entitle in Slack

Integrate Slack with Entitle

Only Entitle admins can configure the integration with Slack.

  1. Sign in to Entitle as an admin and go to Org settings > Integrations.
  2. In the System Integrations section, click the Slack option.
  3. On the Slack installation page, review where Entitle will be installed.
    On the Enterprise Grid plan, the Organization list shows the organization you are installing into. Under Request workspaces to grant this app access to, select up to five workspaces to grant the app access to. Workspaces where Entitle is already installed are listed already.
  4. Click Allow.
    The Entitle app is now integrated with Slack.

Slack workspaces and Enterprise Grid organizations

How Entitle connects depends on how your Slack account is organized.

On most Slack plans, your company has a single workspace, and Entitle connects to that workspace.

On the Enterprise Grid plan, your company has a Slack organization that contains several workspaces, for example one per department or region. Users, channels, and apps are managed centrally for the whole organization.

On Enterprise Grid, Entitle is installed in one of two ways:

InstallationWhat it coversWho can install it
Single workspaceOne workspace only. Other workspaces in the organization are unaffected.A workspace admin
Organization-wideThe whole organization, covering every workspace that an organization admin grants it access to.An organization admin
🚧

With an organization-wide installation, an organization admin must grant the app access to each workspace where people will use Entitle. Until a workspace is granted, Entitle cannot post in it, and the access request command does not work there.

Grant workspaces to an organization-wide installation

You can grant workspaces while you install, or at any time afterwards.

To grant workspaces during installation, use the Request workspaces to grant this app access to (optional) field on the Slack installation page, headed Allow the "Entitle" app to access Slack. Slack accepts up to five workspaces each time you install. Workspaces that Entitle is already installed in are listed in the field.

Slack consent page for an organization-wide installation, with a workspace selected in the Request workspaces field

To grant more workspaces, or to grant them later, use the Slack organization dashboard.

If connecting a single workspace fails when Entitle is installed organization-wide

When Entitle is installed organization-wide, you cannot also connect one of that organization's workspaces on its own. Attempting it fails with:

Entitle is already installed for this workspace's Slack organization, so it connects to the organization rather than to its individual workspaces.

This is expected. The organization-wide installation already covers every workspace it has been granted access to, so Entitle refuses the second connection rather than maintaining two connections to the same workspace.

To use Entitle in that workspace, ask a Slack organization admin to grant the existing organization-wide installation access to it. See Grant workspaces to an organization-wide installation.

📘

Slack still grants the workspace even when Entitle refuses the connection. If you select a workspace on the installation page during a refused attempt, Slack adds that workspace to the existing organization-wide installation.

Connect multiple tenants to one Slack installation

You can connect several Entitle tenants to the same Slack installation. People who belong to more than one of those tenants can then request access to any of them from Slack and can choose which tenant each request applies to. For example, connecting a production and a non-production tenant lets you test and run day-to-day access requests from one workspace.

Prerequisites

  • You must have the Admin role in every tenant you want to connect.
  • Every tenant must be hosted in the same BeyondTrust Cloud region. Entitle publishes one Slack app per region, so tenants in different regions cannot share an installation.
  • Every tenant must connect to the same installation: the same workspace if Entitle is installed per workspace, or the same organization if Entitle is installed organization-wide.
    Connect each tenant using the steps in Integrate Slack with Entitle, selecting the same workspace or the same organization each time. You do not need to install a second Slack app. Each tenant keeps its own connection to the shared installation.

Slack membership is not tenant membership. The tenant list shows only the tenants a user already belongs to. Adding someone to the Slack workspace does not grant them access to any tenant.

⚠️

Tenants connected to different workspaces do not share a tenant list, even when those workspaces belong to the same Enterprise Grid organization. A user working in one workspace sees only the tenants connected to that workspace. If you want one tenant list across several workspaces, install Entitle organization-wide instead.

Set up Slack channels

Connect a Slack channel to Entitle

For Entitle to send approval requests and notifications to a Slack channel, the Entitle bot must be a member of that channel. To add the bot to a channel:

  1. Open the Slack channel (public or private) where approval requests should appear.
  2. In the message field, enter:
   /invite @Entitle
  1. Press Enter.
    Once invited, the Entitle bot can post approval requests and notifications in the channel.

You can also add the Entitle bot using Slack's channel member management controls.

Slack channel approvals and notifications

Entitle supports routing access approval requests to Slack channels. When a request is sent to a channel, any channel member can approve or decline the request directly from Slack. Channel-based approvals enable teams to collaborate on approval decisions without assigning a specific individual approver.

When an approval workflow is configured to send notifications to a Slack channel, access requests generate notification messages directly in that channel.

🚧

Important information

To use Slack channel approvals and notifications, existing Slack integrations must refresh permissions.

  1. Go to Org settings > Integrations. On the existing Slack tile, click the vertical ellipses and select Add connection.
  2. Configure the new Slack connection, selecting the same Slack workspace that you used before. This process updates the Entitle app permissions in Slack.
    Do not uninstall the Entitle app from Slack to refresh permissions. Uninstalling removes the Entitle bot from every channel and disconnects every tenant on that installation.

View request behavior for channel-based approvals

When approval requests are routed to a Slack channel, the behavior of the View request option depends on the user's status in Entitle.

  • Authorized Entitle user: The user exists in Entitle and has permission to view the request. Selecting View request opens the request details in the Entitle web app.
  • Known user without request access: The user exists in Entitle and can approve or decline the request from Slack, but is not explicitly authorized to view the request in Entitle. In this case, selecting View request is blocked for security reasons.
  • Unknown (unregistered) user: The user is a member of the Slack channel but does not exist in Entitle. Selecting View request returns an unauthorized error.
    This behavior affects only the View request option. The Approve and Decline actions are still available. If a user is not logged in or registered, they are prompted to authenticate before their action can be applied.

What users see in Slack

Add Entitle to your Apps list

In some cases, the Entitle app is added to your Apps list automatically. Otherwise, follow these steps.

  1. In the left navigation menu, click More > Apps.

    Screenshot on how to add entitle on slack
  2. Click the Entitle app to add it to your Apps list.

Screenshot of entitle app on slack

Sign in to Entitle from Slack

Each user signs in to Entitle from Slack once per tenant. Signing in to one tenant does not sign a user in to the others, so someone who belongs to two connected tenants signs in twice.

This one-time authentication lets Entitle verify a Slack user's identity, mitigating a vulnerability that could occur if unverified email addresses were configured in Slack workspaces. For security reasons, this prompt cannot be turned off.

Until a user signs in to the selected tenant, the access request dialog shows a notice naming that tenant, with a Login button. Clicking it opens Entitle in the browser and completes the sign-in for that tenant.

Access Request dialog with the sign-in prompt above the Tenant list
📘

If a user switches the Tenant list to a tenant they have not signed in to yet, the sign-in notice appears again for that tenant. They remain signed in to the first tenant.

The Tenant list

The Tenant list appears at the top of the access request dialog, and only for users who belong to more than one connected tenant. A user who belongs to only one tenant does not see it.

For tenants accessed through BeyondTrust Pathfinder, each entry is labelled with the tenant's site name. When no site name is available, the entry is labelled with the tenant's domain instead.

Switching the Tenant list reloads the permissions, bundles, and durations for the tenant selected, and the request is created in that tenant.

If a user belongs to none of the connected tenants, the dialog reports that their user is not registered in the Entitle system. Add the user to a tenant in Entitle. Adding them to the Slack workspace is not enough.

⚠️

Give each connected tenant a name that identifies it clearly. Two tenants with the same name produce two identical entries in the list, and users cannot tell them apart.

Permission request flow

For instructions on how to create a new permission request on Slack, see the Entitle for Slack end-user guide.

Once an access request is submitted, the approver receives a message via Slack with a summary of the request, including the duration, justification, and linked ticket, if available.

Example of slack message

Once the permission is approved, another message is displayed to the end-user, indicating that the request has been approved.

Example Slack message

Log in using ephemeral credentials

Some services, such as MongoDB, do not support SSO or may not be configured to work with the organization IdP. In such cases, the end-user is required to log in directly to the service using ephemeral credentials received through Slack. For details, see the Entitle for Slack end-user guide.

Comments

You can add comments to the request as well as receive notifications on comments that were added by others.

📘

Comments are not available for approval requests sent to Slack channels. This restriction helps prevent sensitive request details from being exposed in shared channels.

When a comment is added to the request, the following notification displays on Slack:

Click View comment to see the comment in the context of the request itself.

The comment will be visible in the request details screen of the specific request in the Entitle web app. Through there, you will be able to reply to any existing comments or add new ones.

Comments

You can add comments to the request as well as receive notifications on comments that were added by others.

📘

Comments are not available for approval requests sent to Slack channels. This restriction helps prevent sensitive request details from being exposed in shared channels.

When a comment is added to the request, the following notification displays on Slack:

Screenshot of notification on slack

Click View comment to see the comment in the context of the request itself.

The comment will be visible in the request details screen of the specific request in the Entitle web app. Through there, you will be able to reply to any existing comments or add new ones.

Troubleshoot a connection

A failed connection still leaves the app installed in Slack. Slack completes the installation when it issues the credentials, before Entitle validates the request, so an error in Entitle does not undo it. Remove the app from the Slack organization dashboard, or from the workspace app list, before trying again.

Disconnecting in Entitle does not uninstall the Slack app. Use Org settings > Integrations to disconnect a tenant. The Entitle app stays installed in Slack.

Reconnecting does not repair a broken connection. When you reinstall over an installation that already exists, Slack returns the same credentials it issued originally, with their remaining lifetime, so nothing is renewed. To reset a connection, uninstall the Entitle app from Slack, then connect the tenant again from Org settings > Integrations.

⚠️

Uninstalling from Slack disconnects every tenant on that installation. If several tenants share a workspace, uninstalling the Entitle app removes the connection for all of them, not only the one you are troubleshooting. Disconnect the single tenant from Entitle instead, unless you intend to disconnect them all.

Uninstalling removes the bot from every channel. If you uninstall and reinstall the Entitle app, you must re-invite the bot to each channel where approvals appear.


Did this page help you?

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.