Rhythms in Slack: Permissions and Security FAQ

Last updated: August 11, 2026

This document outlines the permissions required for Rhythms Slack App to function effectively within your workspace. These permissions enable RhythmsAI to streamline how your team works towards its goals β€” updating OKRs, submitting check-ins, and getting answers, without leaving Slack.

Each permission is listed along with its specific purpose, ensuring you have a clear view of why it's necessary and how it contributes to Rhythms's functionality.

Content and info about channels & conversations

Permission

Purpose

View basic information about public channels in your workspace

Lists the channels you can add Rhythms to, so you can pick them during setup or by asking in chat

View basic information about private channels that Rhythms has been added to

Identifies the conversation so replies land in the right thread

View messages and other content in public channels that Rhythms has been added to

Reads the thread it has been invited into, so answers reflect what the team has already discussed

View messages and other content in private channels that Rhythms has been added to

Same, for private channels it has been explicitly added to

View messages and other content in direct messages that Rhythms has been added to

Enables one-to-one conversations with Rhythms

View messages and other content in group direct messages that Rhythms has been added to

Enables small-group conversations with Rhythms

View messages that directly mention @Rhythms in conversations that the app is in

How Rhythms knows it is being asked something, rather than reading along

View files shared in channels and conversations that Rhythms has been added to

Lets you use a screenshot, PDF, document or voice note already in the thread as part of your request

View emoji reactions and their associated content in channels and conversations that Rhythms has been added to

Powers πŸ›‘ to stop a running answer, and records πŸ‘/πŸ‘Ž as feedback

View Rhythms URLs in messages

Recognizes a Rhythms link so it can show a preview of it

Content and info about your workspace

Permission

Purpose

View the name, email domain, and icon for workspaces Rhythms is connected to

Links the Slack workspace to the right Rhythms workspace

View people in your workspace

Matches a Slack user to their Rhythms account, so answers respect that person's permissions

View email addresses of people in your workspace

Confirms a person belongs to your company's email domain before creating a Rhythms account for them

Perform actions in channels & conversations

Permission

Purpose

Send messages as @Rhythms

Allow Rhythms to post replies and send notifications

Send messages as @Rhythms with a customized username and avatar

Shows the user'sΒ name and photo on messages Rhythms posts on your behalf. For example when you tap a quick reply β€” so the thread reads as a conversation rather than everything appearing as the bot.

Send messages to channels @Rhythms isn't a member of

Allows Rhythms to post into a public channel the user has chosen, without that channel first having to add the bot. Used when the user ask Rhythms to post an update or summary to a channel β€” either once, or on a schedule.

Start direct messages with people

Sends OKR check-in reminders and provide response to questions

Join public channels in your workspace

Lets you add Rhythms to a channel by asking in chat, instead of a separate admin trip

Show previews of Rhythms URLs in messages

Expands a pasted Rhythms link into a readable card β€” withheld automatically if anyone in the channel lacks access to the item

Add and edit emoji reactions

Shows ⏳ while working and clears it when done

Perform actions in your workspace

Permission

Purpose

Add shortcuts and/or slash commands that people can use

Provides the Quick question shortcut, the delete-message shortcut, and the model-selection command

FAQs

Q1. Can we limit which channels Rhythms sees?

Yes, Rhythms only reads channels it is a member of. Admin can manage that list from inside Rhythms, or by using /invite in Slack directly.

Q2. Does Rhythms train AI models on our Slack data?

No. Slack content is used to answer the request at hand within your tenant. It is not used to train the AI models.

Q3. Is the app deployable across our whole Enterprise Grid org?

No. Installs are scoped to a single workspace, so each workspace is a separate consent and a separate token.

Q4. Why does Rhythms need our members' email addresses?

Email is the only stable identifier we use to automatically link Slack profiles to Rhythms accounts. This ensures the right OKRs, permissions, and @mentions apply without manual setup.

What bounds it: We only read directory metadata (no messages or files). Emails are used purely for identity matching and are held under your tenant's strict isolation and retention policies.

Q5. Can a Slack user who has no Rhythms account get one automatically?

Only if an admin allows it. This is an explicit tenant setting to govern who can use Rhythms in Slack and we support three modes:

  • Follow the tenant's join policy (default)

  • Invite-only

  • Open

Even under open, provisioning additionally requires the member's email domain to match the tenant's own domain,Β the same rule that governs an open join policy on the web. So a Slack Connect external, or a member on any other domain, is refused. Bots, deactivated Slack accounts, and previously-closed Rhythms users are never provisioned.

Q6. How do we revoke access?

Admins can always uninstall the Rhythms app from inside their Rhythms Tenant/Slack workspace.