Security & Data Compliance

Recorded assessment details and open approval fields follow the CSCoE documentation template.

AMR

  • Application record and link: [To be completed].

  • Accountable application owner: [To be completed].

ServiceNow application record

  • Application/service record and link: [To be completed].

  • Support assignment group: [To be completed].

ACT

  • Application record and link: [To be completed].

Security Risk Assessment (SRA)

Field Recorded information

Application

Slack KB Agent

Status

Approved, as recorded in the existing application documentation

Reference

RI0038086

Last approved

2026-06-18, as recorded in the existing application documentation

Assessment record link

[To be completed]

Reviewer

[To be completed]

Next review due

[To be completed]

Assessment scope and covered environments

[To be completed]

  • The status, reference, and date come from earlier documentation; the assessment record was not independently verified.

  • Confirm coverage of the current model gateway, integrations, and deployed environments against the SRA record.

Data classification

The approved classification and permitted Slack thread content are [To be completed]. The following classes are the template’s classification categories, not approval to process any category.

Class Category Approved for this application?

C1

Public

[To be completed]

C2

Internal

[To be completed]

C3

Confidential

[To be completed]

C4

Strictly confidential

[To be completed]

  • Redacted Slack thread text is sent to the configured model endpoint.

  • Confirm permitted content, destinations, processing regions, retention, and privacy terms for the chosen route.

  • Redaction neither classifies content nor removes every secret or personal identifier.

  • Submit only content approved for that model endpoint; never submit credentials.

Security features & guardrails

  • Authentication: signed HTTP Slack requests or authenticated Socket Mode; GitHub App/OAuth authorization; per-user Confluence PATs with MuleSoft service credentials.

  • Authorization: only the draft creator may edit, cancel, or approve it; GitHub publishing checks the repository allowlist and selected authorization mode.

  • Credential storage: GitHub user tokens and Confluence PATs are encrypted using TOKEN_ENCRYPTION_KEY; deployment secrets are sourced through External Secrets Operator and Vault.

  • Storage: drafts and OAuth state can use SQLite on the configured persistent volume; volume encryption and backup controls are [To be completed].

  • Audit logging: application events include request/user identifiers, destination, action, and outcome; the audit repository is currently in-memory, so durable retention is [To be completed].

  • Guardrails: recognizable secret patterns are redacted before model input; publishing requires creator approval; thread-count and message-count limits bound input size.

  • Transport: keep Slack signature verification enabled and use trusted TLS configuration for integrations. The checked-in Helm default sets jiraVerifySsl: false; review the deployment’s CA configuration before claiming verified Jira transport security.

Outstanding confirmations

  • Application-register and SRA links, reviewer, and next review date.

  • Approved data classes and model-processing regions.

  • Retention, deletion, backup, and audit requirements.

The application owner and security reviewer must complete these fields from the approved records.