Pondros menu

For administrators

What the Slack app can access

The permissions Pondros asks for in Slack, what each is for, and what installing it does not grant. Written for the Slack admin approving the install.

In short

Pondros is a Slack app that posts as Pondros, never as a person. It joins your public channels when it’s installed, reads messages where it’s present so it can catch the asks people make, and DMs people about their tasks. It asks for nothing that would let it delete your messages, remove people, or act as anyone.

Slack shows every permission below on the approval screen before anything is installed. If you’re the admin being asked to approve Pondros, this page is for you.

What the app can do

These are the bot permissions the install requests, and what each one is used for.

Slack permissionWhat Pondros uses it for
chat:write, chat:write.publicPost replies, task cards, follow-ups and recaps.
channels:read, groups:readList channels for the channel picker.
channels:history, groups:history, mpim:historyRead messages in channels and group DMs it's in, so it can catch asks and keep a conversation going without being tagged again.
channels:joinJoin public channels, at install and when someone picks a channel.
channels:manageCreate the #pondros channel where recaps land.
im:read, im:write, im:historyOpen a DM with a person and read their replies to it.
users:read, users:read.emailMatch a Slack member to their Pondros account by email.
team:readShow your workspace's name and icon.
app_mentions:readReceive @Pondros mentions.
files:read, files:writeRead a file attached to an @mention, and upload documents it made into the thread.
commandsThe /pondros slash command.
reactions:writeAdd a ✅ to a message it turned into a task.
assistant:writeAppear in Slack's AI assistant panel.

Permissions for your own DMs

The same approval screen asks the person installing for a second, personal set of permissions, under Content and info about you. They let Pondros catch the asks in that person’s own direct messages. Granting them doesn’t switch anything on: DM watching starts off, and each person turns it on for themselves. See Your DMs.

Slack permissionWhat Pondros uses it for
im:history, im:read, mpim:history, mpim:readRead the DMs and group DMs of the person who authorised it, only once they turn DM watching on.
channels:history, groups:historyRead channels that person can see, on their behalf.
search:readSearch Slack with that person's own search results.
users:readResolve who is who in those messages.

What it can’t do

  • Post, edit or delete as a person. It holds no permission to write as anyone; everything it posts is posted as Pondros.
  • Delete anyone’s messages. The only messages it removes are its own.
  • Read direct messages between other people. A person’s DM permission only ever covers that person’s own conversations, and only after they turn it on.
  • Join a private channel by itself. Slack doesn’t allow it; someone in the channel has to type /invite @Pondros.
  • Remove people, change channel settings, or manage your workspace.

What installing changes

  • A #pondros channel. Pondros creates a public channel called #pondros for recaps and nudges, and invites the person who installed it.
  • It joins your public channels. At install it joins every public channel, so it can be tagged anywhere, and the setup screens let you pick the channels that matter most. To take it out of a channel, remove the app from that channel in Slack’s channel settings.
  • A Pondros workspace. Installing creates your team’s Pondros account, with the installer as its first admin. Nobody else has to sign up.
  • A first read of your workspace. Pondros reads recent channel history to build a picture of your company: its people, projects and open work. See Data retention and deletion for what it keeps.

Where it replies

In a channel, Pondros answers when someone tags @Pondros, and replies in that message’s thread. It doesn’t join conversations nobody asked it into, but it does read the channel to catch asks, which it confirms with a ✅ on the message and a DM to whoever made it. See How Pondros works.

Removing it

Remove Pondros from Slack’s app settings, or press Disconnectunder Slack in Pondros’s Settings → Connectors. Either revokes every permission above at once.

Note

Disconnecting Slack doesn’t delete your tasks or boards. To delete everything, an admin deletes the workspace; see Data retention and deletion.