What the integration does
Once connected, the &Open app lets your team:
Get notified in Slack about gifting activity, such as a gift invitation being created or redeemed, or a gift being fulfilled and delivered.
Check their own gifting activity for the month, how much gifting budget they have left, and the campaigns they can send from, with the
/giftand/andopenslash commands.Send a gift to one person from Slack, using a campaign that's already set up in &Open.
Get a Slack message when their employer sends them a gift.
Use the app's home tab as a way into &Open to set up and manage their notification subscriptions.
Expand &Open links pasted into Slack into a card showing the current campaign or gift detail.
The permissions we request, and why
When you install &Open, Slack shows you a consent screen listing the permissions ("scopes") the app asks for. Here is each one and the feature it powers.
App permissions (the &Open bot)
These let the &Open app act inside your workspace: post updates, answer commands, and work out who a gift belongs to.
Scope | Why it's needed |
| Post gift status updates and command replies as the &Open app. |
| Post gift updates into public channels. Today the app posts only to channels it's been added to, so we request this to save asking you to re-approve the app if that changes. |
| Provide the |
| During installation you pick one initial channel for &Open notifications, and this lets the app post gift updates there. You can add more channels later with your own subscriptions. |
| List your public channels so you can choose where notifications go, and confirm which channels the app can post to. |
| The same, for private channels you've invited the app into. |
| Match Slack accounts to gift senders and gift recipients, and show the right name in notifications and command replies. |
| Match a gift to the right person by email address. This is how a message like "your gift is on the way" reaches the employee it belongs to, and how a gift you send from Slack gets attached to the right gift recipient. |
| Read your workspace name, domain, and icon so the app knows which &Open account this workspace connects to. |
| See when someone posts an &Open link in a channel the app is in, so the app knows to expand it. Slack only sends us links for the domains we register, so we never see any other link your team shares. |
| Attach the card to the message, showing the campaign or gift detail from &Open. |
Some of these scopes cover more than the integration uses today, so the app asks for them once at install and you don't have to re-approve it later.
Permissions tied to the person who connects
When you authorize the app, Slack also grants a small set of read-only scopes on your own account: channels:read, groups:read, users:read, and users:read.email. These let the app run the same channel and people lookups on behalf of the admin who set up the connection. They don't let &Open act as you or post on your behalf.
What we don't ask for
Just as important is what we don't request. The &Open app can't:
Read your messages or conversation history. We request no history scopes, so the app never sees the content of your channels or direct messages.
Access your files. We request no file scopes.
Manage your workspace. We request no admin, user-management, or workspace-configuration scopes.
The app expands &Open links only. Slack restricts link expansion to the domains an app registers, so we never see links to any other site.
The app only reads the directory information (channels, people, email addresses) it needs to route gift notifications and match gifts to people, and only writes the gift updates and command replies described above.
Questions and answers
Who can see the detail in an expanded &Open link?
Everyone in the channel where the link was posted. The card shows the same information the &Open page shows, so treat posting a link the same way you'd treat sharing the page.
How do we remove the app or revoke access?
An admin can remove the &Open app from your workspace's app management settings at any time. This immediately invalidates the app's access tokens and stops all notifications. We read and write nothing after removal.
Does the app keep access indefinitely?
Installing the app creates access tokens that stay valid until the app is removed. Remove the app and they stop working straight away.
Can anyone in our workspace send a gift from Slack?
Only people who already have an &Open account with access to an active campaign and enough gifting budget. Installing the Slack app doesn't grant anyone new permission to spend, and the budget rules you've set in &Open still apply.
Who should install the app?
An account administrator. Installing and authorizing the app needs the right access in both &Open and Slack.
Can we connect more than one Slack workspace?
No. Each &Open account connects to a single Slack workspace.
Who do we contact with questions?
Email hello@andopen.co and we'll connect you with the right person on our team.
