Skip to content

Slack Notifications

Connect Parapet Security to your Slack workspace for real-time alert notifications with rich formatting.

Prerequisites

  • A Slack workspace where you have permission to add apps
  • Admin or Owner role in Parapet Security

Connecting Slack

Step 1: Navigate to Settings

  1. Log in to app.parapetsecurity.com
  2. Go to SettingsNotifications
  3. Click the Channels tab
  4. Find the Slack card

Step 2: Connect Workspace

  1. Click Connect to Slack
  2. You'll be redirected to Slack
  3. Select your workspace
  4. Click Allow to authorize Parapet Security

Permissions Requested

Parapet Security requests:

  • chat:write - Post notifications to channels
  • channels:read - List available channels
  • team:read - Get workspace information

Step 3: Select Channel

After authorization:

  1. You'll return to Parapet Security
  2. Click Select Channel
  3. Choose where notifications should go
  4. Click Save

Dedicated Channel

Create a dedicated #security-alerts channel for Parapet notifications. This keeps your other channels clean and makes it easy to find alerts.

Step 4: Test Connection

  1. Click Send Test Message
  2. Check your Slack channel
  3. You should see a test notification

Notification Format

Parapet Security sends rich Slack messages using Block Kit:

┌────────────────────────────────────────────────────────┐
│ 🔴 Critical Alert                                      │
├────────────────────────────────────────────────────────┤
│                                                        │
│ SSH Brute Force Attack Detected                        │
│                                                        │
│ Severity:    Critical                                  │
│ Confidence:  94%                                       │
│ Category:    Authentication                            │
│                                                        │
│ Affected:                                              │
│ • Host: web-server-01                                  │
│ • User: root                                           │
│ • Source IP: 45.227.253.98                            │
│                                                        │
│ ──────────────────────────────────────────────────     │
│                                                        │
│ Recommendation:                                        │
│ Block source IP at firewall immediately                │
│                                                        │
│ [View in Dashboard]  [Dismiss]                         │
│                                                        │
└────────────────────────────────────────────────────────┘

Message Elements

Element Description
Severity Icon Color-coded icon (🔴 🟠 🟡 🔵)
Title AI-generated alert summary
Details Key alert information
Affected Entities Hosts, users, IPs involved
Recommendation Top priority action
Actions Quick links to dashboard

Configuration Options

Severity Filter

Only notify for certain severity levels:

  1. Go to SettingsNotificationsOverview
  2. Set Minimum Severity
  3. Slack notifications will respect this setting

Channel Selection

Change the notification channel:

  1. Go to SettingsNotificationsChannels
  2. Click Change Channel under Slack
  3. Select the new channel
  4. Click Save

Multiple Channels

To send to multiple channels (e.g., different teams):

  1. Set up the primary channel in Parapet Security
  2. Use Slack workflows to cross-post to other channels

Team Feature

Direct multi-channel support is available on Team plans. Upgrade to Team for this feature.

Interactive Actions

Slack notifications include interactive buttons:

Button Action
View in Dashboard Opens alert detail in browser
Dismiss Marks alert as dismissed
Mark Reviewed Marks alert as reviewed

Permissions

Interactive actions require the user to be logged into Parapet Security with appropriate permissions.

Slack Digest

For lower-priority alerts, enable digest mode:

  1. Go to SettingsNotificationsAdvanced
  2. Enable Digest
  3. Set frequency (Hourly, Daily, Weekly)

Digest messages summarize alerts:

┌────────────────────────────────────────────────────────┐
│ 📊 Daily Security Digest                               │
├────────────────────────────────────────────────────────┤
│                                                        │
│ Alerts in the last 24 hours: 47                        │
│                                                        │
│ By Severity:                                           │
│ • Critical: 0                                          │
│ • High: 3                                              │
│ • Medium: 15                                           │
│ • Low: 29                                              │
│                                                        │
│ Top Affected Hosts:                                    │
│ 1. web-server-01 (12 alerts)                          │
│ 2. db-server-02 (8 alerts)                            │
│ 3. app-server-01 (5 alerts)                           │
│                                                        │
│ [View All Alerts]                                      │
│                                                        │
└────────────────────────────────────────────────────────┘

Disconnecting Slack

To remove the Slack integration:

  1. Go to SettingsNotificationsChannels
  2. Click Disconnect under Slack
  3. Confirm the disconnection

This:

  • Stops all Slack notifications
  • Revokes Parapet Security's access
  • Does not delete message history

Troubleshooting

"Slack connection failed"

  1. Ensure you have permission to add apps to the workspace
  2. Try a different browser or incognito mode
  3. Check if your Slack workspace has app restrictions

"Channel not found"

  1. The channel may have been deleted or renamed
  2. Click Change Channel to select a new one
  3. Ensure the Parapet Security app is still in the channel

"Test message not appearing"

  1. Check you're looking at the correct channel
  2. Verify the channel selection was saved
  3. Check Slack's notification settings aren't muting the channel

Reconnecting After Expiry

Slack tokens can expire. If notifications stop:

  1. Go to SettingsNotificationsChannels
  2. Click Reconnect under Slack
  3. Re-authorize the app

Security Considerations

  • Slack integration uses OAuth 2.0 (secure)
  • Tokens are encrypted at rest
  • Only workspace admins can authorize apps
  • Parapet Security doesn't access message history

Next Steps