Capabilities
User Sync
AccessOwl periodically syncs a list of users along with their assigned permissions.
Provisioning
AccessOwl creates or removes user accounts with the specified permissions during access requests or revocations.
Directory Sync
AccessOwl syncs (creates, removes, or deactivates) users from directories like Slack, Microsoft365, Okta, or Google into the AccessOwl users database.
Setup
- For automated provisioning either add a new application or open “Applications” and click the +-symbol and click continue
- Follow the setup instructions and assign the integration account as a “Workspace Owner”
User Groups
AccessOwl provisions Slack access through Slack User Groups. Each User Group carries its own set of channels, so assigning a User Group to a member grants them access to those channels. We recommend creating team-based User Groups (for example @Marketing, @HR, @Engineering) mapped to the channels each team needs, then referencing them in your Access Templates. Onboarding then grants each new hire the right channels automatically.User Groups are created and edited in Slack, not in AccessOwl. See Slack’s Create and edit user groups guide.
Troubleshooting
'Guest' or 'Multi-Channel Guest' requests are automatically reassigned
'Guest' or 'Multi-Channel Guest' requests are automatically reassigned
Currently Guest and Multi-Channel accounts can’t be provisioned through AccessOwl. These need to be manually invited by stating the channels you want to grant access to.
Access revocation to remove a 'Workspace Admin' are automatically reassigned
Access revocation to remove a 'Workspace Admin' are automatically reassigned
AccessOwl can only remove Admins when the Integration Account’s permission is “Workspace Owner”
A recreated Slack user shows as @deactivateduser
A recreated Slack user shows as @deactivateduser
When a Slack account is deleted and recreated, the AccessOwl record can stay tied to the person’s old, deactivated Slack account, so mentions point at that one instead of the recreated account. A deactivated Slack account keeps the email address bound to it, which is why deactivating alone does not release the person.Delete the old account fully on the Slack side, then run a directory sync in AccessOwl to relink the person to the active account.
An offboarded user still looks active in the Slack app
An offboarded user still looks active in the Slack app
Slack’s admin page is the source of truth. Open Manage members in Slack and check the Billing Status column. If it says Deactivated, the account is deactivated and AccessOwl’s offboarding went through.The Slack app can still show the person as active for a while. Slack keeps the name and profile picture on a deactivated account, so the photo itself never changes, and the Slack desktop app caches member profiles, so it can keep showing the old state after the deactivation is through. Reload the app with Cmd+R (Ctrl+R on Windows), or open the profile in the browser at app.slack.com, and it shows as deactivated.

