Slack workspace security checklist for small teams: your chat app is part of the perimeter

By the time a company is ten people, the workspace chat holds more sensitive material than most of its systems: customer screenshots, API tokens pasted "just for a second," production error logs, contract links, candid talk about salary and strategy. A compromised Slack account isn't a leaked joke — it's a second inbox with files attached. Slack knows this; the admin console has the controls. This checklist is the quarterly pass that turns them on, in one sitting, and keeps the chat perimeter as managed as the rest of your Google Workspace.

1. The admin handshake (do this first, it gates everything else)

2. Invite controls (who can let strangers in)

3. The guest audit (the accounts everyone forgets)

4. Apps and bots (the third-party floor you never see)

5. Webhooks and integrations (the quietest leak path)

6. Message retention and data controls (decide what chat remembers)

7. External sharing and Slack Connect (the doors to other companies)

8. Device and session hygiene (the account end)

9. The quiet things that matter later (compliance, exits, audits)

10. When something goes wrong anyway

Slack security for a small team is an afternoon, once: lock the admin tier, gate the invites, purge the guests, approve the apps, own the webhooks, decide the retention, and calendar the quarterly pass. The Ops Starter Kit ($14) includes the audit sheets that turn this checklist into a per-person, per-channel table — guest, channels, apps, verdict, owner — and the Automation Starter Pack ($19) automates the reviews so the purge happens without anyone remembering to remember. Launch week: 30% off any paid kit with code HIVE-LAUNCH30 at checkout.