L&S Slack Subscription Guidance

This article summarizes L&S cybersecurity guidance on the purchase and/or use of Slack for university purposes.

Slack is a commonly used communication platform owned by Salesforce. It is cloud-based and provides a variety of features including the ability to message within a group or between individuals, share files, and hold audio or video conferences. It is widely used in the research community. 

Slack offers a free service and three subscription tiers: Pro, Business+, and Enterprise Grid. Each tier offers progressively more functional and security features. The free service can be discontinued or changed at any time, provides few backup or export features, and has a short retention period. The limitations of the free service affect any Slack channel with a timeline longer than 90 days, impacting fulfillment of retention requirements and availability of records for public records requests, grievances, or other legal interactions. These conditions make the free service unsuitable for those hosting a Slack Workspace and channels for university business. 

Short Retention period
Slack’s free service displays your content for only 90 days. Once beyond the 90 day limit, your messages and files are no longer available in the Slack interface. As of August 26, 2024, a single year of content is stored on the Slack servers, accessible only if you upgrade to a subscription plan. After one year, Salesforce/Slack will permanently delete the data.

Message Backup
Message backup is one of the key differences among the services and requires extra scrutiny. Only public channel messages can be exported from Slack’s free service or from the Pro tier. The Business+ and Enterprise tiers allow subscribers to apply for more complete exports which may include private channels and direct messages. All of the tiers export data in the form of XML-based JSON files. These will have to be imported into another tool or workspace, or be programmatically manipulated for easy viewing. 

Service Agreement
Salesforce’s Main Services Agreement specifically calls out unique conditions for the Slack free services. The services are provided “as-is” with limited vendor liability. The vendor isn’t required to provide notice if the service or account is discontinued. Salesforce does not assert that the free services will be “uninterrupted, timely, secure, or free from error.” 

Slack’s subscription plan details show the differences between the free service and the subscription plans. At this time, the Pro plan is the most economical while allowing unlimited message and file history that is required to meet UW records retention schedules and the Wisconsin Public Records Law.

Note that as of December 2023, new subscriptions must pay a fee for each active member of a Slack workgroup. More information is in the Slack FAQ, including a way to view the billable users . 


Related Resources
Data Stewardship, Access, and Retention
https://policy.wisc.edu/library/UW-403

Public Records Guidelines for Employees
https://compliance.wisc.edu/2023-public-records-guidelines-for-employees/

Slack service agreement
https://slack.com/main-services-agreemen

UW-Madison Records Retention Schedules and Disposition
https://www.library.wisc.edu/archives/records-management/uw-madison-records-retention-schedules-and-disposition/



KeywordsSlack, requirements, subscription, data, retention, legal, public records, university business, cybersecurity, risk, guidance   Doc ID138185
OwnerSusan W.GroupL&S KB
Created2024-06-28 15:30:31Updated2024-10-15 14:32:52
SitesL&S KB
Feedback  0   0