Connectors and scopes
The permissions each GuruSup Brain connector asks for when you approve it, and how webhook requests can be signed.
Only admins can connect a source. When you approve a connector, the app you connect shows its own consent screen with the permissions below.
Slack
Brain asks for these bot permissions:
| Permission | Lets the Brain app |
|---|---|
channels:read, groups:read, mpim:read | List public channels, private channels and group messages |
channels:history, groups:history, mpim:history | Read messages in those conversations |
users:read, users:read.email | Read Slack members' profiles, including email addresses |
files:read | Read files shared in those conversations |
chat:write | Post messages |
im:write, im:history | Open and read direct messages with the app, which Brain's questions to a colleague use |
Brain reads a channel only after you invite the app to it. It does not read direct messages between people. See Data we process.
Brain also listens for Slack events such as new messages, people joining or leaving a channel, the app being uninstalled and tokens being revoked.
HubSpot
Brain asks for read-only access:
| Permission | Lets Brain |
|---|---|
crm.objects.deals.read | Read deals |
crm.objects.contacts.read | Read contacts |
crm.objects.companies.read | Read companies |
crm.objects.owners.read | Read record owners |
sales-email-read | Read sales emails |
Brain processes deals, with their linked contacts and activity.
Notion
Notion does not show a list of scopes. When you connect, Notion asks which pages or sections to share with Brain, and Brain can only read what you share.
Brain checks the signature of the notifications Notion sends about changes, and rejects a request whose signature is missing or wrong.
Webhook
A webhook source has a URL that includes its access token. Anyone with the URL can send data to that source, so treat it like a password. You can replace the URL at any time by regenerating the token, and the old URL stops working.
You can also set a signing secret. If you do, sign the raw request body with HMAC-SHA256 and send the result in the X-Webhook-Signature header as sha256=<hex>. Brain rejects requests with a missing or wrong signature. If you leave the secret empty, Brain does not check a signature.