← All use cases
SaaSNetwork

Communication & Collaboration Agents

Slack AI, Microsoft Copilot for Teams, Google Workspace Duet AI, Notion AI

What it is

Agents summarising conversations, drafting replies, searching across channels, and acting on communication content.

What it accesses

All messages across all channels, email history, meeting recordings, documents, and in some cases credentials shared in messages.

What can go wrong

As Slack AI demonstrated, a hidden instruction in a public channel can redirect the agent to retrieve credentials from private channels. The attack requires no special access and leaves no trace.

How Sunbeam helps
Scanner finds it

SaaS scanner detects Slack AI, M365 Copilot, and Google Duet AI deployments with their permission scope and channel access.

CIM controls it

CIM contracts define which channels and data sources each agent is authorised to read. Cross-channel queries require explicit approval.

Related incident
See what happened when this went wrong →
Relevant regulations
GDPR Article 32
NIS2 Directive
ISO 27001 A.8
Detection surfaces
SaaS
Network

Find every communication & collaboration agent in your organisation.

Under 10 minutes. Five surfaces. No prior knowledge required.

Talk to us