Skip to main content
Slack rules belong to an Inkbox identity. Manage them in the Inkbox Console or with an organization admin API key. SDK and CLI examples require version 0.7.14 or later. Claimed agent keys can list and read their own identity’s rules, but cannot change rules or defaults.

Choose the default

Set modes through the identity update API, just like email and phone rules: The default is blacklist in both directions. Whitelist mode blocks unmatched people. Blacklist mode allows unmatched people. A shared mode update replaces both directional defaults. Do not combine shared and directional Slack fields in one update. Omitted fields stay unchanged; explicit null is not accepted. Identity responses report the effective directional modes. In the Console, choose the desired mode, then select Save changes to apply it; Cancel discards unsaved mode changes.
cURL

Match people or workspaces

A person’s exact rule wins over a workspace rule. A workspace rule wins over the directional default. A workspace rule is analogous to an email-domain rule: allowing the connected workspace does not allow every external participant in a shared channel. Use the Slack accounts on a contact card, contact import, or a verified user profile to select targets. Do not substitute a display name, email address, or the connection’s workspace for a person’s home workspace. In the Console, choose a contact first. If they have multiple Slack accounts, All saved Slack accounts is selected by default; you can choose one account instead. A contact with one account uses it automatically. Saving all accounts creates one exact rule per currently saved account; accounts added later are not covered automatically. If only some rules save, the Console shows progress and Retry remaining retries only the unfinished accounts. Contact rules govern communication, not native directory profiles or conversation-member lists. Reading that metadata does not grant permission to message someone or access their linked Inkbox contact.

Rule endpoints

Create with action (allow or block), match_type, and match_target. Optional direction is inbound, outbound, or both; omission means both. Lists return arrays. Filter with action, match_type, or direction, and paginate with limit and offset. An inbound or outbound filter also includes rules covering both directions. The organization-wide list additionally accepts agent_identity_id. Each rule contains id, agent_identity_id, action, match_type, match_target, direction, status, created_at, updated_at, and a nullable contact. A workspace rule has no single contact card. A PATCH can change action or direction. To change only one covered side while preserving the other, send action with apply_to: "inbound" or "outbound". Do not combine apply_to and direction. Compatible coverage can retain the existing rule ID. Duplicate coverage returns 409.
Rust exposes client.slack().contact_rules with list, list_all, get, create, update, and delete. Use SlackContactRuleCreateOptions, SlackContactRuleListOptions, and SlackContactRuleUpdateOptions. Set modes with IdentityFilterModeOptions and update_filter_modes.

Companion and mentions

Rules decide who may communicate. Webhook subscriptions decide which events reach your runtime. Subscribe to slack.mention_received for mentions; there is no separate mention-mode contact rule. Companion mode is the existing identity-level enabled preference. Slack requires an exact verified human account allowed in both directions to sponsor a conversation. Workspace allows and blacklist defaults do not make sponsors. Importing contacts or inviting the app does not activate Companion. A fresh qualifying sponsor message grants access to the whole channel or group DM, including all its threads. A new participant joining or the sponsor leaving requires fresh sponsorship; another participant leaving alone does not. Explicit blocks still apply.