Slack integration

Approve remediations without leaving Slack

Approval requests arrive as Slack cards. A linked owner or admin approves or dismisses, the change runs through the same checks as in the app, and the card shows what happened.

It does not take commands or answer questions in Slack.

The problem

The person who can approve a change is usually in Slack, not in your FinOps console. Requests that wait for someone to open another dashboard sit for days while the waste keeps running up the bill.

How it works

  1. Connect

    An owner or admin installs the GetFinOps Slack app, sets the approvals channel, and links their Slack account.

  2. Decide

    A card posts when an approval is requested. A linked owner or admin presses Approve & execute or Dismiss.

  3. See the result

    The change runs through the normal checks, and the original card updates to show whether it ran, rolled back, was blocked or failed.

  • Per account

    Slack channel for approval and safety-block cards, set in Automation Safety

  • 5 minutes

    after which a click is rejected; every click must carry a valid Slack signature

  • Every click

    the person’s role is read from GetFinOps; Slack is never trusted for it

  • 1 run

    per override, which lifts only the production block for that approval

Capabilities

Approve or dismiss AWS remediations from a Slack card that then shows the result.

  1. Cards in the right channel

    Each new approval request posts a card with the action, resource, estimated monthly saving, severity and cloud account. It goes to that account’s channel if you set one, otherwise to the workspace approvals channel.

  2. Decide with one click

    Press Approve & execute or Dismiss on the card. GetFinOps checks the Slack signature, finds the linked GetFinOps user and reads their role again before anything happens. Only owners and admins can decide.

  3. The same checks as the app

    An approval made in Slack runs through the same execution path as one made in the dashboard. The account’s environment label decides whether the production block applies, and an account with no label counts as production. Guardrails, the post-check and automatic rollback for reversible actions still apply.

  4. Blocks you can see and override

    When the safety policy stops an approved run, a Slack card can name the account, action and reason. An owner or admin can press “Override & run once”, which lifts only the production block, for that one run.

In depth

Connecting Slack

An owner or admin connects Slack from Settings → Notifications, using Slack’s standard app install. The install request is signed and tied to the browser that started it, so a copied install link cannot be completed by someone else.

The bot token Slack returns is stored encrypted with AES-256-GCM and is never included in what the settings page reads back. Disconnecting removes the install and every linked Slack account, and is recorded in the audit trail.

  • The app asks Slack for permission to post messages, including in public channels it has not joined.
  • It can list public and private channels.
  • It can read user profiles, including email addresses.

Where cards go

Each workspace sets one approvals channel by its Slack channel ID, and the settings page asks you to invite the GetFinOps bot to it. You can also set a channel per cloud account under Settings → Automation Safety, so approvals for a production account go to a production channel. An account without its own channel uses the workspace channel.

Each card shows:

  • the action and the resource it targets;
  • the finding’s description, estimated monthly saving and severity;
  • the cloud account, by label and account ID;
  • Approve & execute, Dismiss, and a link to the remediation page in GetFinOps.

What is checked when someone clicks

A click from Slack arrives without a GetFinOps login, so every check runs again on the server before anything changes.

  • The request must carry a valid Slack signature and be less than five minutes old.
  • The Slack workspace must be the one connected to this GetFinOps workspace.
  • The Slack user must be linked to an active GetFinOps user in that workspace. People are never matched by their Slack email address.
  • That user’s role is read from GetFinOps and must be owner or admin.
  • The approval must belong to the same workspace and still be pending. Only the first decision is recorded.
  • Approving needs a paid plan or an active trial. Dismissing works on any plan.

After a decision

The decision is recorded in the audit trail against the approver, marked as made in Slack. An approved change then runs through the same execution path as an approval made in the dashboard. If the account is labelled production or has no label, the default production block stops it unless the account’s safety policy allows production or the block is overridden. The guardrails, the post-check and, for reversible actions, automatic rollback also apply.

The same card is then updated. Its buttons are removed, and it shows the outcome: executed, rolled back after a failed post-check, blocked by the safety policy, or failed with the reason. A dismissed request updates the card to say no changes were made.

Safety blocks and single-use overrides

If the safety policy stops a run, for example on an account marked as production, GetFinOps can post a notice to the app’s notifications. This is off by default. You turn it on for the workspace or for a single account in Settings → Automation Safety.

Where Slack is connected, a Slack card also names the account and shows the action, resource, environment and reason, and a linked owner or admin can press “Override & run once”. Admins can also override a block in the app.

  • An override lifts only the production block, for one run of that approval.
  • Permanently blocked actions, such as terminating instances or deleting databases, stay blocked, and every other guardrail still runs.
  • Each block can be overridden once, and the override is recorded in the audit trail.
  • If that action type was allowed to run on its own, it drops back to “approve each”.

What it does not do

  • It does not let members or viewers approve or dismiss.
  • It does not take commands or answer questions in Slack. The app posts cards and handles their buttons.
  • It has no channel picker; channels are set by Slack channel ID.
  • It does not send safety-block notifications until you turn them on.
  • It is not switched on for self-hosted installs.
  • It does not widen what can be changed: remediation runs in AWS only.

FAQ

Questions

Is approving in Slack as safe as approving in the app?

It goes through the same checks. The click must carry a valid Slack signature, come from the connected Slack workspace, and belong to a Slack user linked to an active GetFinOps owner or admin. After that, the same safety policy, guardrails and post-check run as for an approval made in the app, including the default production block for an account labelled production or not labelled at all.

Who can approve from Slack?

Owners and admins whose Slack account is linked. The admin who installs the app is linked during the install. Other owners and admins link themselves with Sign in with Slack under Settings → Notifications. Approving needs a paid plan or an active trial; dismissing works on any plan.

Can production approvals go to a different channel?

Yes. Set a Slack channel on a cloud account in Settings → Automation Safety, and that account’s approval and safety-block cards go there. Accounts without their own channel use the workspace approvals channel.

What does “Override & run once” bypass?

Only the production block, for one run of one remediation that was already approved. Permanently blocked actions, such as terminating an instance, stay blocked, and the other guardrails still run. Each block can be overridden once, and the override is recorded in the audit trail.

Does it work on a self-hosted install?

It ships switched off there. The integration needs a Slack app and its credentials configured for the install.

Try free — no credit card

Create a workspace and connect an AWS or GCP account, or book a demo first.