Rhythms in Slack: Permissions and Security FAQ

Last updated: September 11, 2026

This article lists the Slack permissions the Rhythms Slack app asks for when a Rhythms Admin installs it, and what each one is used for. Together they let Rhythms update OKRs, record check-ins, and answer questions without your team leaving Slack.

Each permission is listed along with its specific purpose, so you can see why it is needed and what Rhythms does with it.

Content and info about channels & conversations

Permission

Purpose

View basic information about public channels in your workspace

Lists the channels you can add Rhythms to, so you can pick them during setup or by asking in chat

View basic information about private channels that Rhythms has been added to

Identifies the conversation so replies land in the right thread

View basic information about group direct messages that Rhythms has been added to

Identifies a group DM so replies land in the right conversation

View messages and other content in public channels that Rhythms has been added to

Reads the thread it has been invited into, so answers reflect what the team has already discussed

View messages and other content in private channels that Rhythms has been added to

Same, for private channels it has been explicitly added to

View messages and other content in direct messages that Rhythms has been added to

Enables one-to-one conversations with Rhythms

View messages and other content in group direct messages that Rhythms has been added to

Enables small-group conversations with Rhythms

View messages that directly mention @Rhythms in conversations that the app is in

How Rhythms knows it is being asked something, rather than reading along

View files shared in channels and conversations that Rhythms has been added to

Lets you use a screenshot, PDF, document or voice note already in the thread as part of your request

View emoji reactions and their associated content in channels and conversations that Rhythms has been added to

Powers πŸ›‘ to stop a running answer, and records πŸ‘/πŸ‘Ž as feedback

View Rhythms URLs in messages

Recognizes a Rhythms link so it can show a preview of it

Content and info about your workspace

Permission

Purpose

View the name, email domain, and icon for workspaces Rhythms is connected to

Links the Slack workspace to the right Rhythms workspace

View people in your workspace

Matches a Slack user to their Rhythms account, so answers respect that person's permissions

View email addresses of people in your workspace

Confirms a person belongs to your company's email domain before creating a Rhythms account for them

Perform actions in channels & conversations

Permission

Purpose

Send messages as @Rhythms

Allow Rhythms to post replies and send notifications

Send messages as @Rhythms with a customized username and avatar

Shows the user'sΒ name and photo on messages Rhythms posts on your behalf. For example when you tap a quick reply β€” so the thread reads as a conversation rather than everything appearing as the bot.

Send messages to channels @Rhythms isn't a member of

Allows Rhythms to post into a public channel the user has chosen, without that channel first having to add the bot. Used when the user ask Rhythms to post an update or summary to a channel β€” either once, or on a schedule.

Start direct messages with people

Sends OKR check-in reminders and provide response to questions

Join public channels in your workspace

Lets you add Rhythms to a channel by asking in chat, instead of a separate admin trip

Manage public channels that Rhythms has been added to and create new ones

Lets an admin remove Rhythms from a channel from the Rhythms admin settings page, instead of running /remove in Slack. Rhythms uses this permission only to take itself out of a channel β€” it never creates, renames or archives a channel, and never adds or removes anyone else.

Act as an App Agent in Slack

Presents Rhythms in Slack's native agent surface, and keeps the thread's status ("thinking", "responded") and title in sync while it works. It sets status and titles only β€” it does not write message content with this permission.

Show previews of Rhythms URLs in messages

Expands a pasted Rhythms link into a readable card β€” withheld automatically if anyone in the channel lacks access to the item

Add and edit emoji reactions

Shows ⏳ while working and clears it when done

Perform actions in your workspace

Permission

Purpose

Add shortcuts and/or slash commands that people can use

Provides the Quick question shortcut, the Continue in Rhythms DM shortcut, the delete-message shortcut, and the model-selection command

Connect the Rhythms MCP server to Slack

Lets Slack's own AI (Slackbot) ask Rhythms about your goals, reviews, documents, decisions and commitments when someone asks a question there. Each person signs in to Rhythms separately for this, and only the data that person is already allowed to see is returned

FAQs

Q1. Can we limit which channels Rhythms sees?

Yes, Rhythms only reads channels it is a member of. Admin can manage that list from inside Rhythms, or by using /invite in Slack directly.

Q2. Does Rhythms train AI models on our Slack data?

No. Slack content is used to answer the request at hand within your tenant. It is not used to train the AI models.

Q3. Is the app deployable across our whole Enterprise Grid org?

No. Installs are scoped to a single workspace, so each workspace is a separate consent and a separate token.

Q4. Why does Rhythms need our members' email addresses?

Email is the only stable identifier we use to automatically link Slack profiles to Rhythms accounts. This ensures the right OKRs, permissions, and @mentions apply without manual setup.

What bounds it: We only read directory metadata (no messages or files). Emails are used purely for identity matching and are held under your tenant's strict isolation and retention policies.

Q5. Can a Slack user who has no Rhythms account get one automatically?

Only if an admin allows it. This is an explicit tenant setting to govern who can use Rhythms in Slack and we support three modes:

  • Follow the tenant's join policy (default)

  • Invite-only

  • Open

Even under open, provisioning additionally requires the member's email domain to match the tenant's own domain,Β the same rule that governs an open join policy on the web. So a Slack Connect external, or a member on any other domain, is refused. Bots, deactivated Slack accounts, and previously-closed Rhythms users are never provisioned.

Q6. How do we revoke access?

A Rhythms Admin can uninstall the Rhythms app from Settings β€Ί Workspace β€Ί Collaboration platforms: open the menu on the Slack card and choose Uninstall. A Slack admin can also remove the app from the Slack side. Uninstalling ends notifications, reminders, mentions and chat replies in Slack for everyone in the workspace; to change permissions without losing history, use Reinstall instead.

Q7. Do we need to be a Rhythms customer before installing the Slack app?

No. Use the "Add to Slack" option on rhythms.ai, or sign up at app.rhythms.ai with Continue with Slack. Rhythms creates a workspace for your Slack team and installs the app in the same flow. If your company already has a Rhythms workspace, you are asked to choose it instead of creating a new one, and a Rhythms Admin can also install from Settings β€Ί Workspace β€Ί Collaboration platforms at any time.

Q8. How reliable are the AI-generated answers and summaries in Slack?

Rhythms uses large language models to draft check-ins, summaries and answers. AI-generated content can occasionally be incomplete or wrong, so review anything important before you act on it or share it. Nothing is saved to a goal or document until you confirm the draft in the thread. If you see incorrect or objectionable output, react with πŸ‘Ž on the message or email support@rhythms.ai.