Set organisation policies for apps on Enterprise Grid

Who can use this feature?
  • Org owners 
  • Available on the Enterprise Grid subscription

By default, members of an Enterprise Grid org can install any app to their workspaces. Org owners can set organisation policies for all workspaces in their org to manage app installation and use.


Set an app management policy for your org

An app management policy turns app approval on for every workspace in your org. When app management is enabled, members can only install and use any apps that have been approved. Org owners can approve or restrict apps for their entire org, but workspace owners and app managers will be responsible for reviewing app requests for their workspaces. Follow the steps below to turn on app management for your org:

  1. From your desktop, click your workspace name in the top left.
  2. Select Settings & administration from the menu, then click on Organisation settings.
  3. From the left sidebar, click Settings, then select Organisation policies.
  4. Click the Apps tab at the top of the page.
  5. Next to App management, click Add policy.
  6. Tick the box next to Require app approval.
  7. Click Save policy. Then, select Create policy.

Note: If you don't set an app management policy for your org, workspace owners can still choose to require app approval for workspaces they manage.

Manage Sign in with Slack permissions

Some third-party apps offer the option to sign in to their service with Slack account credentials. When an app management policy is set, members can sign in to other services with their Slack account by default, but org owners can require approval for apps that include the Sign in with Slack identity scope for every workspace in their org:

  1. From your desktop, click your workspace name in the top left.
  2. Select Settings & administration from the menu, then click on Organisation settings.
  3. From the left sidebar, click Settings, then select Organisation policies.
  4. Click the Apps tab at the top of the page.
  5. Next to App management, click the  pencil icon.
  6. Under People who can manage Sign in with Slack restrictions, select Org owners from the drop-down menu.
  7. Tick or untick the box next to Don't require pre-approval for Sign in with Slack apps.
  8. Select Save policy. Then, click Create policy.

Note: To allow workspace owners to manage Sign in with Slack permissions for their workspaces, select Delegate to workspaces from the drop-down menu under People who can manage Sign in with Slack restrictions.

If a member submits a request to sign in to another service with their Slack account, workspace owners and app managers will only be prompted to approve the app's Sign in with Slack scope. If an app also offers other functionality, the app will need to be approved separately.


Set other app installation policies

Org owners can set two other app installation policies, whether app approval has been turned on for all workspace in their org or not:

  • App Directory installations
    Only allow members to install apps from the Slack App Directory.
  • Guest app use restrictions
    Allow multi-channel guests to use slash commands and shortcuts in channels that they belong to.
  1. From your desktop, click your workspace name in the top left.
  2. Select Settings & administration, then click Organisation settings.
  3. From the left sidebar, click Settings, then select Organisation policies
  4. Click the Apps tab at the top of the page. 
  5. Next to the app policy, click Add policy
  6. Tick the box next to the policy description and click Save policy.
  7. Click Create policy.