Security and privacyConnectors and scopes

Connectors and scopes

The permissions each GuruSup Brain connector asks for when you approve it, and how webhook requests can be signed.

Only admins can connect a source. When you approve a connector, the app you connect shows its own consent screen with the permissions below.

Slack

Brain asks for these bot permissions:

PermissionLets the Brain app
channels:read, groups:read, mpim:readList public channels, private channels and group messages
channels:history, groups:history, mpim:historyRead messages in those conversations
users:read, users:read.emailRead Slack members' profiles, including email addresses
files:readRead files shared in those conversations
chat:writePost messages
im:write, im:historyOpen and read direct messages with the app, which Brain's questions to a colleague use

Brain reads a channel only after you invite the app to it. It does not read direct messages between people. See Data we process.

Brain also listens for Slack events such as new messages, people joining or leaving a channel, the app being uninstalled and tokens being revoked.

HubSpot

Brain asks for read-only access:

PermissionLets Brain
crm.objects.deals.readRead deals
crm.objects.contacts.readRead contacts
crm.objects.companies.readRead companies
crm.objects.owners.readRead record owners
sales-email-readRead sales emails

Brain processes deals, with their linked contacts and activity.

Notion

Notion does not show a list of scopes. When you connect, Notion asks which pages or sections to share with Brain, and Brain can only read what you share.

Brain checks the signature of the notifications Notion sends about changes, and rejects a request whose signature is missing or wrong.

Webhook

A webhook source has a URL that includes its access token. Anyone with the URL can send data to that source, so treat it like a password. You can replace the URL at any time by regenerating the token, and the old URL stops working.

You can also set a signing secret. If you do, sign the raw request body with HMAC-SHA256 and send the result in the X-Webhook-Signature header as sha256=<hex>. Brain rejects requests with a missing or wrong signature. If you leave the secret empty, Brain does not check a signature.