Integration Category
Communication Integrations
Slack and Microsoft Teams — ManySignal delivers interactive security alert notifications with action buttons so analysts can approve responses, escalate, and investigate without leaving their collaboration workspace.
What security teams do in Slack and Teams with ManySignal
Communication integration FAQs
How does ManySignal send alerts to Slack?
ManySignal sends formatted Slack messages with verdict details, affected entity summary, confidence score, and interactive action buttons. Analysts can approve responses, add notes, or escalate directly from the Slack message without opening the ManySignal UI.
Can analysts interact with ManySignal investigations from Slack?
Yes. ManySignal's Slack integration supports slash commands and interactive message buttons. Analysts can run /ms investigate to look up a user or IP, approve a pending response action, or reassign an investigation — all from Slack.
Does ManySignal monitor Slack for insider threats?
ManySignal ingests Slack audit logs for admin actions, data export events, and DLP-triggered messages. User-level message content monitoring requires Slack's DLP API, with alerts from Slack DLP forwarded to ManySignal for correlation.
How does Microsoft Teams integration work differently from Slack?
Teams integration uses Adaptive Cards for rich, interactive alert notifications in security channels. Action buttons on the card (Isolate host, Suspend user, Close as false positive) call ManySignal's API directly. Audit event ingestion for Teams is available via the Microsoft 365 connector.
Can ManySignal create dedicated incident channels in Slack?
Yes. When a Critical investigation is created, ManySignal can automatically create a Slack channel named for the incident (e.g., #incident-20260809-003), invite the relevant analysts, and post the initial investigation context.
Does ManySignal monitor Zoom for security events?
ManySignal ingests Zoom admin activity logs including user management changes, recording access events, and security setting modifications. Meeting-level content is not monitored.
How are ManySignal alert notifications formatted in Teams?
Teams messages use Adaptive Card format with color-coded severity indicators, entity summary, top evidence items, and action buttons. Critical alerts use red accent; High use orange; Medium use amber.
Can I route different alert types to different Slack channels?
Yes. ManySignal's notification routing is fully configurable: Critical alerts go to #soc-critical, Cloud alerts to #cloud-security, Identity alerts to #identity-security. Routing rules are based on severity, section, entity type, or custom conditions.
Does ManySignal support on-call rotation for Slack/Teams notifications?
ManySignal integrates with PagerDuty for on-call management. Critical verdicts can page the on-call analyst via PagerDuty, who then receives the full context in Slack or Teams once they acknowledge the page.
Is Slack audit log monitoring separate from alert notifications?
Yes. Slack audit log ingestion (for security monitoring of your Slack workspace) is configured via the Slack connector. Alert notifications to Slack channels are configured separately in ManySignal's notification settings.
Get security alerts where your team already works
Connect ManySignal to Slack or Teams and get interactive incident notifications in minutes.