Slack Schema#
graph LR
SlackBot -- CREATED --> SlackChannel
SlackBot -- CREATED --> SlackGroup
SlackBot -- MEMBER_OF --> SlackChannel
SlackBot -- MEMBER_OF --> SlackGroup
SlackGroup -- MEMBER_OF --> SlackChannel
SlackTeam -- RESOURCE --> SlackBot
SlackTeam -- RESOURCE --> SlackChannel
SlackTeam -- RESOURCE --> SlackGroup
SlackTeam -- RESOURCE --> SlackUser
SlackUser -- CREATED --> SlackChannel
SlackUser -- CREATED --> SlackGroup
SlackUser -- MEMBER_OF --> SlackChannel
SlackUser -- MEMBER_OF --> SlackGroup
SlackBot#
A Slack bot with ThirdPartyApp and compatibility SlackUser labels.
Ontology Mapping: This node uses the ontology label
ThirdPartyApp.
Additional Labels: This node also uses
SlackUser.
Additional Label Definitions:
SlackUser: A slack node participating in the shared SlackUser graph interface.
Properties#
Ontology-generated fields are shown in italics.
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Slack bot ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
deleted |
Whether the bot is deleted. |
|
is_app_user |
Whether the bot is an application user. |
|
is_bot |
Whether the account is a bot. |
|
name |
Yes |
Slack bot name. |
real_name |
Bot display name. |
|
_ont_client_id |
Yes |
Normalized field sourced from |
_ont_enabled |
Yes |
Normalized field sourced from |
_ont_name |
Yes |
Normalized field sourced from |
_ont_source |
Module that populated this node’s ontology fields. |
Relationships#
(:SlackBot)-[:CREATED]->(:SlackChannel): A Slack bot created a channel.(:SlackBot)-[:CREATED]->(:SlackGroup): A Slack bot created a user group.(:SlackBot)-[:MEMBER_OF]->(:SlackChannel): A Slack bot is a member of a channel.(:SlackBot)-[:MEMBER_OF]->(:SlackGroup): A Slack bot is a member of a user group.(:SlackTeam)-[:RESOURCE]->(:SlackBot): A Slack workspace contains a bot account.(:User)-[:AUTHORIZED]->(:ThirdPartyApp): generated by analysis jobOntology - User AUTHORIZED ThirdPartyApp linking.Properties:
Field
Description
scopes
Property generated by analysis job:
Ontology - User AUTHORIZED ThirdPartyApp linking.
SlackChannel#
A channel in a Slack workspace.
Properties#
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Slack channel ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
created |
Channel creation timestamp. |
|
is_archived |
Whether the channel is archived. |
|
is_general |
Whether this is the workspace’s general channel. |
|
is_org_shared |
Whether the channel is shared across an organization. |
|
is_private |
Whether the channel is private. |
|
is_shared |
Whether the channel is shared across workspaces. |
|
name |
Yes |
Slack channel name. |
num_members |
Number of channel members. |
|
purpose |
Channel purpose. |
|
topic |
Channel topic. |
Relationships#
(:SlackBot)-[:CREATED]->(:SlackChannel): A Slack bot created a channel.(:SlackBot)-[:MEMBER_OF]->(:SlackChannel): A Slack bot is a member of a channel.(:SlackGroup)-[:MEMBER_OF]->(:SlackChannel): A Slack user group is a member of a channel.(:SlackTeam)-[:RESOURCE]->(:SlackChannel): A Slack workspace contains a channel.(:SlackUser)-[:CREATED]->(:SlackChannel): A SlackUser-labeled account created a channel.(:SlackUser)-[:MEMBER_OF]->(:SlackChannel): A SlackUser-labeled account is a member of a channel.
SlackGroup#
A Slack user group with the canonical UserGroup label.
Ontology Mapping: This node uses the ontology label
UserGroup.
Properties#
Ontology-generated fields are shown in italics.
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Slack user group ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
channel_count |
Number of channels linked to the user group. |
|
created_by |
ID of the account that created the user group. |
|
date_create |
User group creation timestamp. |
|
date_delete |
User group deletion timestamp. |
|
date_update |
User group update timestamp. |
|
description |
User group description. |
|
handle |
User group mention handle. |
|
is_external |
Whether the user group is external. |
|
is_subteam |
Whether this is a subteam. |
|
name |
Yes |
Slack user group name. |
updated_by |
ID of the account that last updated the user group. |
|
user_count |
Number of user group members. |
|
_ont_description |
Normalized field sourced from |
|
_ont_name |
Yes |
Normalized field sourced from |
_ont_source |
Module that populated this node’s ontology fields. |
Relationships#
(:SlackBot)-[:CREATED]->(:SlackGroup): A Slack bot created a user group.(:SlackBot)-[:MEMBER_OF]->(:SlackGroup): A Slack bot is a member of a user group.(:SlackGroup)-[:MEMBER_OF]->(:SlackChannel): A Slack user group is a member of a channel.(:SlackTeam)-[:RESOURCE]->(:SlackGroup): A Slack workspace contains a user group.(:SlackUser)-[:CREATED]->(:SlackGroup): A SlackUser-labeled account created a user group.(:SlackUser)-[:MEMBER_OF]->(:SlackGroup): A SlackUser-labeled account is a member of a user group.
SlackTeam#
A Slack workspace with the canonical Tenant label.
Ontology Mapping: This node uses the ontology label
Tenant.
Properties#
Ontology-generated fields are shown in italics.
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Slack workspace ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
domain |
Slack workspace domain. |
|
email_domain |
Email domain associated with the workspace. |
|
is_verified |
Whether the workspace is verified. |
|
name |
Yes |
Slack workspace name. |
url |
Slack workspace URL. |
|
_ont_domain |
Yes |
Normalized field sourced from |
_ont_name |
Yes |
Normalized field sourced from |
_ont_source |
Module that populated this node’s ontology fields. |
Relationships#
(:SlackTeam)-[:RESOURCE]->(:SlackBot): A Slack workspace contains a bot account.(:SlackTeam)-[:RESOURCE]->(:SlackChannel): A Slack workspace contains a channel.(:SlackTeam)-[:RESOURCE]->(:SlackGroup): A Slack workspace contains a user group.(:SlackTeam)-[:RESOURCE]->(:SlackUser): A Slack workspace contains a user account.
SlackUser#
A Slack user account with the canonical UserAccount label.
Ontology Mapping: This node uses the ontology label
UserAccount.
Properties#
Ontology-generated fields are shown in italics.
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Slack user ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
deleted |
Whether the user is deleted. |
|
display_name |
User’s display name. |
|
Yes |
User’s email address. |
|
first_name |
User’s first name. |
|
has_mfa |
Whether multi-factor authentication is enabled. |
|
is_admin |
Whether the user is a workspace administrator. |
|
is_email_confirmed |
Whether the user’s email is confirmed. |
|
is_owner |
Whether the user is a workspace owner. |
|
is_restricted |
Whether the user is a restricted guest. |
|
is_ultra_restricted |
Whether the user is an ultra-restricted guest. |
|
last_name |
User’s last name. |
|
name |
Yes |
Slack username. |
profile_phone |
User’s profile phone number. |
|
profile_title |
User’s profile title. |
|
real_name |
User’s full name. |
|
team |
ID of the user’s Slack workspace. |
|
_ont_email |
Yes |
Normalized field sourced from |
_ont_firstname |
Yes |
Normalized field sourced from |
_ont_fullname |
Yes |
Normalized field sourced from |
_ont_has_mfa |
Yes |
Normalized field sourced from |
_ont_inactive |
Yes |
Normalized field sourced from |
_ont_lastname |
Yes |
Normalized field sourced from |
_ont_source |
Module that populated this node’s ontology fields. |
|
_ont_username |
Yes |
Normalized field sourced from |
Relationships#
(:SlackTeam)-[:RESOURCE]->(:SlackUser): A Slack workspace contains a user account.(:SlackUser)-[:CREATED]->(:SlackChannel): A SlackUser-labeled account created a channel.(:SlackUser)-[:CREATED]->(:SlackGroup): A SlackUser-labeled account created a user group.(:SlackUser)-[:MEMBER_OF]->(:SlackChannel): A SlackUser-labeled account is a member of a channel.(:SlackUser)-[:MEMBER_OF]->(:SlackGroup): A SlackUser-labeled account is a member of a user group.(:User)-[:HAS_ACCOUNT]->(:UserAccount)