Hack via Slack with MarcusBot

Guard's existing Slack integration delivered one-way webhook notifications. Marcus replaces that with a real Slack app: a multi-tenant OAuth install that delivers rich notifications via bot token, brings interactive Marcus conversations into your Slack channels, and ties every Slack interaction to a verified Guard identity so personalized queries and actions execute with the right permissions.
Highlights
- Multi-tenant OAuth install — a Guard admin clicks Add to Slack, completes OAuth v2, picks target channels, and the app is live. No webhook URL to paste or rotate.
- Channel binding and management — map specific Slack channels to your Guard tenant with a confirmation step before the connection is established, view all connected channels with per-row tenant mapping, and disconnect any channel through a confirmation-gated flow.
- Block Kit notifications — risk transitions, exposure alerts, and emergent-threat notifications arrive as structured Block Kit messages through the bot token rather than plain-text webhook payloads.
- Interactive conversations in Slack — mention Marcus in a connected channel to run the same queries and actions available in the Guard UI, with threaded replies keeping each conversation in context.
- Explicit account linking — a Slack user runs a one-time Connect your Guard account flow to bind their Slack identity to their Guard user. Subsequent queries and actions execute as that Guard identity, with full Guard RBAC applied.
- Revocable bindings — account links can be revoked from either Guard or Slack, immediately severing the identity binding without affecting other users.
- Product-facing status labels — Marcus surfaces finding statuses as Detected, Demonstrated, Resolved, Accepted, and Rejected — matching what the Guard UI shows.
Why This Matters
Email-match-only authorization (the approach used by many chat integrations) is spoofable via Slack Connect guests and mutable email attributes. Marcus's explicit binding model means every action in Slack is traceable to an authenticated Guard user, making it safe to expose Guard's full query and action surface through the chat interface. Findings, alerts, and workflows now reach the channels your team already uses for incident response and collaboration — without the context-switch back to the Guard UI.
Get Started
Go to Integrations > Notifications > Slack (Chat Bot), then click Add to Slack and complete the OAuth flow. After authorizing, bind one or more channels to your tenant. Each team member links their Guard account once by following the in-app prompt.
Documentation
https://docs.praetorian.com/en/articles/25815125222171-slack