Confirm your identity on [workspace name]
Sure.
Post messages to [workspace name]
CodeStream will be able to send messages to any channel or person on your workspace.
Sure. This is a great alternative to "Send messages as you"
Access all content in [workspace name]
CodeStream will be able to read all messages, files, and profiles that you can access.
Absolutely not okay. This is the deal-breaker for me. Where is this data stored? How is it protected? Who has access to it? What is your disclosure policy for breaches?
Lacks explanation as to why this is required or an explanation as to what specific actions CodeStream will take with this most dangerous of permissions.
Suggested change: only access content in certain channels.
Receive all events from [workspace name] in realtime
CodeStream will be able to receive all messages and activity that occurs in [workspace name] as well as send messages on your behalf.
Lacks explanation as to why this is required or an explanation as to what specific actions CodeStream will take with this permission.
Suggested change: Send messages as a CodeStream bot user, or only send messages as me in certain channels. Make it obvious to other users when sending these messages that it was sent by CodeStream
Note that none of this is covered in http://codestream.com/privacy or https://codestream.com/terms
Edited 2019-18-01 -- my comments on the permissions that were previously being requested are preserved below
Access and modify information about your channels and direct messages
Access and modify information about your channels and direct messages
CodeStream will be able to access and modify information about your public channels, private channels, direct messages, and group messages (including name and purpose), as well as archive and create new ones.
Not okay.
Lacks explanation as to why this is required or an explanation as to what specific actions CodeStream will take with this dangerous permission.
Suggested change: Only access certain channels.
View email addresses of people on your workspace
View email addresses of people on your workspace
CodeStream will be able to view the email addresses of your Slack workspace’s members.
Those people have not agreed to your terms and conditions or privacy policy.
Suggested change: remove this permission.
Access your workspace’s Do Not Disturb settings
Access your workspace’s Do Not Disturb settings
CodeStream will be able to access your workspace’s Do Not Disturb settings, including each workspace member’s schedule, who is currently snoozing notifications, and when all Do Not Disturb sessions are scheduled to expire.
Those people have not agreed to your terms and conditions or privacy policy.
Suggested change: remove this permission and require each user to grant it themselves.
Access your profile and your workspace’s profile fields
Access your profile and your workspace’s profile fields
CodeStream will be able to access your profile fields, as well as any data you’ve entered in them.
I guess this is fine.
Modify emoji reactions
Modify emoji reactions
CodeStream will be able to add and remove emoji reactions from messages and files, on your behalf.
Lacks explanation as to why this is required or an explanation as to what specific actions CodeStream will take with this permission.
Suggested change: only add/remove emoji reactions to messages posted by CodeStream, or in certain channels.
Access content in your workspace’s channels and direct messages
Access content in your workspace’s channels and direct messages
CodeStream will be able to read any messages you can see in public channels, private channels, direct messages, and group messages.
Absolutely not okay. This is the deal-breaker for me. Where is this data stored? How is it protected? Who has access to it? What is your disclosure policy for breaches?
Lacks explanation as to why this is required or an explanation as to what specific actions CodeStream will take with this most dangerous of permissions.
Suggested change: only access content in certain channels.
Access your workspace’s profile information
Access your workspace’s profile information
CodeStream will be able to access profile information for all users on [workspace name], including names and contact information.
Those people have not agreed to your terms and conditions or privacy policy.
Suggested change: remove this permission.
Send messages as you
Send messages as you
CodeStream will be able to send messages on your behalf to [workspace name].
Lacks explanation as to why this is required or an explanation as to what specific actions CodeStream will take with this permission.
Suggested change: Send messages as a CodeStream bot user, or only send messages as me in certain channels. Make it obvious to other users when sending these messages that it was sent by CodeStream