Capabilities
What Hiro Can Do
What Hiro Cannot Do
- Deactivate or suspend Slack users
- Send arbitrary messages to users
- Access message content in channels (only responds to @mentions and DMs)
Setup
Prerequisites
- Slack workspace admin access
- Admin role in Hiro
Connection Steps
1
Navigate to Integrations
Go to Settings > Integrations in Hiro and click Connect next to Slack.
2
Choose Enterprise Grid (optional)
If you’re on Slack Enterprise Grid and want session reset capabilities, check the Enterprise Grid option before connecting.
3
Authorize in Slack
You’ll be redirected to Slack. Review the requested permissions and click Allow.
4
Select notification channel
After connecting, select which channel should receive security alerts.
5
Send test notification
Click Test to verify alerts are working.
Permissions Requested
Enterprise Grid additional scope:
Features
Security Alerts
When detections occur, Hiro sends formatted alerts to your configured channel:- Detection title and severity
- Key details and indicators
- Link to view in Hiro dashboard
- Go to Settings > Integrations
- Select a channel from the dropdown
- Click Save
Interactive Bot
Your team can interact with Hiro directly in Slack: @mention in a channel:Session Reset (Enterprise Grid Only)
With Enterprise Grid, Hiro can force users to re-authenticate:Session reset requires the
admin.users:write scope, which is only available on Slack Enterprise Grid plans.How the Bot Works
When you @mention Hiro or send a DM:- Slack sends the message to Hiro
- Hiro’s AI agent processes your question
- The agent queries your connected integrations (Okta, AWS, etc.)
- Findings stream back to Slack in real-time
- If actions are needed, they’re proposed in the Hiro dashboard
Example Interactions
Check user activity:Troubleshooting
Bot not responding
- Verify the integration is connected in Settings > Integrations
- Check that you’re @mentioning the bot correctly
- Try sending a direct message to the bot instead
Alerts not appearing
- Verify a notification channel is selected
- Check that the bot has been added to the channel
- Try sending a test notification from Settings
”Missing scope” error
The connected Slack app may be missing required permissions. Disconnect and reconnect the integration.Next Steps
Okta
Connect identity management.
CrowdStrike
Connect endpoint protection.