Skip to main content
ConfigView pulls Slack data through one Slack app that you create in your own account. Enterprise Grid customers get extra org-wide data from that same app — not from a second one.
Most Slack customers are not on Enterprise Grid. Grid is Slack’s largest tier, sold separately from Free, Pro and Business+. If you are not on it, Part 1 is your entire setup — skip Part 2. The admin endpoints do not exist on other plans and will keep returning errors no permission can fix, so leave the admin scripts disabled. You are not missing data you could have switched on.Not sure? You are on Enterprise Grid if your Slack admin page shows an Organization level above your workspaces, or if your workspace URL sits under an org with multiple workspaces.
One app issues both token types: a bot token (xoxb-...) for workspace data, and — once you add user scopes in Part 2 — a user token (xoxp-...) for the admin endpoints. ConfigView stores them as SLACK_BOT_TOKEN and SLACK_ADMIN_USER_TOKEN and sends whichever one each endpoint requires. Two tokens, one app. Part 3 (the /configview slash command) is optional and needs only the Part 1 setup.

Part 1: Slack Workspace Ingestion

Set up the ConfigView workspace app so ConfigView can pull your workspace data (users, channels, user groups, custom emoji, recent files) into the dashboard.

Step 1: Create the ConfigView Slack App

  1. Go to: https://api.slack.com/apps
  2. Click Create New App
  3. Choose From scratch
  4. App Name: ConfigView
  5. Pick your workspace from the dropdown
  6. Click Create App

Step 2: Add Bot Token Scopes

  1. In the left sidebar, click OAuth & Permissions
  2. Scroll down to Scopes > Bot Token Scopes
  3. Click Add an OAuth Scope and add each of the following:

Step 3: Install the App to Your Workspace

  1. Scroll to the top of OAuth & Permissions
  2. Click Install to Workspace
  3. Review the permissions and click Allow
  4. Copy the Bot User OAuth Token (starts with xoxb-)
Keep this token safe. You will add it to ConfigView in the next step.

Step 4: Add the Token to ConfigView

  1. Go to your ConfigView dashboard: https://{companyname}.configview.com/admin/integrations/Slack
  2. Under Credentials, enter the value and click the save icon on its row:
    • SLACK_BOT_TOKEN: Paste the xoxb-... token you copied

Step 5: Enable the Workspace Scripts in ConfigView

  1. Go to: https://{companyname}.configview.com/admin/integrations/Slack
  2. Click Connect. ConfigView creates its tables and schedules every collector at your default run time.
  3. The collectors it will start running — stop any you do not want under Collectors:
  4. Click Verify now to confirm the credentials work.
    • Users — All workspace members with email, admin status, 2FA, timezone
    • Channels — Public and private channels with member counts
    • Channel Members — Which users are in which channels
    • User Groups — Handle-based groups (e.g. @engineering)
    • User Group Members — Which users belong to which groups
    • Custom Emoji — All custom workspace emoji
    • Files (recent) — Files uploaded in the last 7 days
    • Bots — Bot user accounts and the apps that own them
Note: Channel Members depends on Channels; User Group Members depends on User Groups; Bots depends on Users. ConfigView wires these dependencies automatically — parent scripts always run first.

Step 6: Verify

  1. Go to: https://{companyname}.configview.com/admin/status/
  2. Run the Slack health check
  3. The workspace section should pass:
    • Secret Manager: SLACK_BOT_TOKEN
    • Slack bot auth
    • users.list scope (users:read)
    • users:read.email scope
    • conversations.list scope (channels:read + groups:read)
    • usergroups.list scope (usergroups:read)
    • emoji.list scope (emoji:read)
    • files.list scope (files:read)
If a check fails, verify:
  • The SLACK_BOT_TOKEN secret is saved correctly (no extra spaces)
  • The bot has been installed to the correct workspace
  • All scopes from Step 2 were added before installing
The admin sections of the health check will show Skipped until you complete Part 2. That is expected on non-Enterprise plans.

Workspace Data Tables

All tables include a run_at column for historical tracking.

Part 2: Slack Enterprise Grid Admin Ingestion

Skip this section unless you are on Slack Enterprise Grid. The endpoints below exist only on Enterprise Grid. On any other plan they fail regardless of scopes, so leave the admin scripts disabled.
This part promotes the app you already created in Part 1 to an organization-level install and adds admin scopes to it. You do not need a second app. The Slack requirement is that the app be installed on the entire org rather than on a single workspace — not that it was originally created at the org level. An existing workspace app can be opted in, which is what this section does. It adds: every workspace, per-workspace user membership, approved/restricted apps and their OAuth scopes, role assignments, information barriers, invite requests, and member activity analytics.

Step 1: Opt the App In to Org-Level Install

  1. Sign in to Slack as an Org Owner (required to see org-level options)
  2. Go to: https://api.slack.com/apps and open the ConfigView app you created in Part 1
  3. In the left sidebar, find Org Level Apps
  4. Click Opt-in
Your app can now be installed by an Org Admin or Owner across the whole organization instead of on one workspace.
If you do not see Org Level Apps in the sidebar, you are not signed in as an Org Owner, or the account is not attached to an Enterprise Grid org. Contact your Slack admin — this cannot be granted from inside the app settings.

Step 2: Add User Token Scopes (Admin)

  1. In the left sidebar, click OAuth & Permissions
  2. Scroll down to Scopes > User Token Scopes (not Bot Token Scopes)
  3. Click Add an OAuth Scope and add each of the following:
These are User Token Scopes, added alongside the Bot Token Scopes already on this app from Part 1. Do not remove the bot scopes — the same app serves both, and the workspace collectors still need the bot token.

Step 3: Install at the Org Level

  1. Scroll to the top of OAuth & Permissions
  2. Click Install to Organization (it says “Organization” rather than “Workspace” once the app is opted in)
  3. Review the admin permissions and click Allow
  4. Copy the User OAuth Token (starts with xoxp-)
  5. Copy the Bot User OAuth Token as well (starts with xoxb-) — see the warning below
This reinstall rotates your bot token. Installing to the organization issues a new xoxb- token, and the workspace collectors from Part 1 keep using the old one until you update it. If you skip this, Slack collection that was working will start failing with invalid_auth.Update both secrets in the same sitting: paste the new xoxb- value over SLACK_BOT_TOKEN, and the xoxp- value into SLACK_ADMIN_USER_TOKEN (Step 4). Then run Verify now on the Slack integration page and confirm the workspace scripts still pass before you walk away.
Note: The token is a user token tied to whichever Org Owner installs the app. If that person leaves the company, the token may stop working. Use a dedicated service account (an Org Owner account owned by IT, not a personal account) wherever possible.

Step 4: Add Both Tokens to ConfigView

  1. Go to: https://{companyname}.configview.com/admin/integrations/Slack
  2. Under Credentials, set both of these, clicking the save icon on each row:
  1. Click Verify now and confirm the workspace checks still pass, not just the admin ones
Both tokens come from the same app and must coexist: ConfigView sends the bot token to the workspace endpoints and the user token to the admin endpoints. Updating only the admin token is the common mistake — the workspace collectors then keep failing on the stale bot token while the admin ones look healthy.

Step 5: Enable the Admin Scripts in ConfigView

  1. Go to: https://{companyname}.configview.com/admin/integrations/Slack
  2. Click Connect. ConfigView creates its tables and schedules every collector at your default run time.
  3. In the Slack section, enable the additional admin scripts:
  4. Click Verify now to confirm the credentials work.
    • Workspaces (Admin) — Every workspace in the Enterprise Grid org
    • Workspace Admins — Which users are admins of each workspace
    • Org Users (per Workspace) — User-to-workspace membership matrix
    • Approved Apps — Apps approved org-wide or per workspace, with their OAuth scopes
    • Restricted Apps — Apps explicitly restricted org-wide or per workspace
    • App Requests — Pending install requests
    • App Scopes — Normalized table of every (app, scope) pair, with sensitivity flag
    • Conversations (Org-wide) — Channels visible across the entire org
    • Role Assignments — Admin/Owner/etc. role grants
    • Information Barriers — Configured barriers between user groups
    • User Group Channels — Channels each user group is auto-added to
    • Invite Requests — Pending invitations awaiting approval
Most admin scripts depend on Workspaces (Admin) so the org’s workspace list is available to iterate. App Scopes depends on Approved Apps + Restricted Apps. ConfigView handles all of this automatically.

Step 6: Verify

  1. Go to: https://{companyname}.configview.com/admin/status/
  2. Run the Slack health check
  3. The admin section should now pass:
    • Secret Manager: SLACK_ADMIN_USER_TOKEN
    • Slack admin auth
    • admin.teams.list scope (admin.teams:read)
    • admin.users.list scope (admin.users:read)
    • admin.apps.approved.list scope (admin.apps:read)
    • admin.apps.restricted.list scope (admin.apps:read)
    • admin.apps.requests.list scope (admin.apps:read)
    • admin.conversations.search scope (admin.conversations:read)
    • admin.roles.listAssignments scope (admin.roles:read)
    • admin.barriers.list scope (admin.barriers:read)
    • admin.usergroups.listChannels scope (admin.usergroups:read)
    • admin.inviteRequests.list scope (admin.invites:read)
If a scope check fails, the most common cause is that the scope was added in Bot Token Scopes rather than User Token Scopes. Re-check Step 2, then reinstall to the organization for the change to take effect.

Tuning: Files window

The Files (recent) script (Part 1) defaults to the last 7 days. If you want a wider or narrower window, set the environment variable on the server:
Larger windows produce significantly more rows; start at 7 and widen only if needed.

Admin Data Tables

All tables include a run_at column for historical tracking.

Part 3: Slack Bot (Query Runner)

Run ConfigView queries directly from Slack using the /configview slash command. This uses the bot side of the same ConfigView app — the Part 1 setup is enough, and nothing here requires Enterprise Grid.

Step 1: Add Bot Scopes

  1. Go back to: https://api.slack.com/apps
  2. Select your ConfigView app (the workspace app from Part 1)
  3. Go to OAuth & Permissions > Bot Token Scopes
  4. Add the following additional scopes:
  1. You will be prompted to reinstall the app. Click Reinstall to Workspace and approve.
Important: After reinstalling, the bot token stays the same. You do not need to update the secret in ConfigView.

Step 2: (Optional) Add Signing Secret

The signing secret lets ConfigView verify that incoming requests are genuinely from Slack.
  1. In your Slack app settings, go to Basic Information
  2. Scroll to App Credentials
  3. Copy the Signing Secret
  4. In ConfigView, go to https://{companyname}.configview.com/admin/integrations/Slack
  5. Add a secret: Name: SLACK_SIGNING_SECRET, Value: paste the signing secret
This is optional but recommended for production use.

Step 3: Enable the Slash Command

  1. In the left sidebar, click Slash Commands
  2. Click Create New Command
  3. Fill in:
    • Command: /configview
    • Request URL: https://{companyname}.configview.com/api/slack/command
    • Short Description: Run ConfigView queries
    • Usage Hint: [help | run <query_id>]
  4. Click Save

Step 4: Enable Interactivity

This lets users click the “Run” buttons in the query list.
  1. In the left sidebar, click Interactivity & Shortcuts
  2. Toggle Interactivity to On
  3. Set Request URL to: https://{companyname}.configview.com/api/slack/interaction
  4. Click Save Changes

Step 5: Invite the Bot to a Channel

  1. Open the Slack channel where you want the bot to post (e.g. #configview-alerts)
  2. Type: /invite @ConfigView
Create a dedicated channel like #configview-alerts to keep query results organized.

Step 6: Mark Queries as Slack-Enabled

  1. Go to: https://{companyname}.configview.com/admin/query/
  2. Open a saved query and click SAVE to open its Save Custom Query settings
  3. Toggle Enable for Slack bot to on
  4. Fill in the Slack summary — this is the description users see when browsing queries in Slack
  5. Click Save at the bottom of the dialog

Step 7: Test It

  1. Open the Slack channel where the bot was invited
  2. Type: /configview
  3. You should see a list of slack-enabled queries with Run buttons
  4. Click Run on a query — the bot posts the results to the channel
You can also run a query directly by ID:
Or get help:

Bot Commands


Message Format

The bot posts formatted messages with:
  • Query name as the header
  • Row count summary
  • Table of results (up to 10 rows, 6 columns)
  • Truncation notice if results exceed the display limit

Troubleshooting