Capabilities
What Hiro Can Do
| Capability | Description |
|---|---|
| Send alerts | Push security detections to a configured channel |
| Respond to questions | Answer security queries when @mentioned or DMed |
| Reset user sessions | Force re-authentication (Enterprise Grid only) |
What Hiro Cannot Do
- Deactivate or suspend Slack users
- Send arbitrary messages to users
- Access message content in channels (only responds to @mentions and DMs)
Setup
Prerequisites
- Slack workspace admin access
- Admin role in Hiro
Connection Steps
Navigate to Integrations
Go to Settings > Integrations in Hiro and click Connect next to Slack.
Choose Enterprise Grid (optional)
If you’re on Slack Enterprise Grid and want session reset capabilities, check the Enterprise Grid option before connecting.
Permissions Requested
| Scope | Purpose |
|---|---|
chat:write | Send alert messages to channels |
channels:read | List channels for notification selection |
im:read, im:write | Receive and respond to direct messages |
users:read, users:read.email | Look up user information |
app_mentions:read | Respond when @mentioned |
| Scope | Purpose |
|---|---|
admin.users:write | Reset user sessions |
Features
Security Alerts
When detections occur, Hiro sends formatted alerts to your configured channel:- Detection title and severity
- Key details and indicators
- Link to view in Hiro dashboard
- Go to Settings > Integrations
- Select a channel from the dropdown
- Click Save
Interactive Bot
Your team can interact with Hiro directly in Slack: @mention in a channel:Session Reset (Enterprise Grid Only)
With Enterprise Grid, Hiro can force users to re-authenticate:Session reset requires the
admin.users:write scope, which is only available on Slack Enterprise Grid plans.How the Bot Works
When you @mention Hiro or send a DM:- Slack sends the message to Hiro
- Hiro’s AI agent processes your question
- The agent queries your connected integrations (Okta, AWS, etc.)
- Findings stream back to Slack in real-time
- If actions are needed, they’re proposed in the Hiro dashboard
Example Interactions
Check user activity:Troubleshooting
Bot not responding
- Verify the integration is connected in Settings > Integrations
- Check that you’re @mentioning the bot correctly
- Try sending a direct message to the bot instead
Alerts not appearing
- Verify a notification channel is selected
- Check that the bot has been added to the channel
- Try sending a test notification from Settings
”Missing scope” error
The connected Slack app may be missing required permissions. Disconnect and reconnect the integration.Next Steps
Okta
Connect identity management.
CrowdStrike
Connect endpoint protection.