Settings

Integrations

Slack, Microsoft Teams, and the API and MCP endpoints.

RolesAdminRoute/settings?tab=integrationsShown toAll organizations

What it is

The Integrations tab is a small catalogue of ways to reach Noru from other tools: the REST API, MCP for AI clients, and a Slack app that answers questions in your workspace. These are outbound and conversational surfaces. They do not collect evidence; connectors that pull data from your systems live under Data sources.

Where to find it

SettingsIntegrations
Available Integrations grid with REST API, MCP Access, Slack, and Microsoft Teams cardsAvailable Integrations grid with REST API, MCP Access, Slack, and Microsoft Teams cards
Connected integrations show a Connected badge and the workspace name.

Key actions

Connect Slack

Click the Slack card. The Connect Slack Workspace dialog opens.
Review "What you'll get" and "Try these commands". Under Enable Features, decide whether to keep Slash Commands and Bot Mentions on; both are on by default.
Click Connect. A Slack authorization popup opens; approve the app for the workspace you want. Allow popups if the browser blocks it.
The popup closes and the card shows Connected with the team name.
Connect Slack Workspace dialog with feature list, example commands, and Enable Features checkboxesConnect Slack Workspace dialog with feature list, example commands, and Enable Features checkboxes
The connect dialog. After connecting, the same dialog is titled Slack Configuration.

Change or disconnect Slack

Click the Slack card again. The dialog is now Slack Configuration. Toggle Slash Commands or Bot Mentions and click Save Changes, or click Disconnect to remove the app from the workspace.

Use Slack

CommandWhat it does
/noru statusGet overall compliance status
/noru frameworksList connected frameworks
/noru risksShow active risks
/noru helpList the commands
@Noru followed by a questionAsk the assistant; it reads controls, frameworks, and risks to answer

Open API and MCP details

The REST API card opens the API documentation at api.noru.tech. The MCP Access card opens a dialog with two setups: "Option A: Sign in with OAuth (recommended)" for interactive clients, and "Option B: Bearer API key (CI & headless)" with a ready-to-paste mcpServers block. Go to Developer Settings takes you to the Developer tab to create a key.

Statuses and fields

CardCategoryState
REST APIDeveloper ToolsAlways available; needs an API key
MCP AccessDeveloper ToolsAlways available; OAuth or API key
SlackProductivityConnected with team name, or not connected
Microsoft TeamsProductivityComing Soon; the card is not clickable

Tips and gotchas

Slack permissions

The app requests app_mentions:read, channels:read, chat:write, commands, groups:read, im:read, mpim:read, team:read, and users:read. It reads messages only where it is mentioned or where a slash command is used.

Slack answers are read-only summaries. Anyone in the workspace channel can see them, so connect the app to a channel whose audience matches who may see your risk register.

The authorization popup expires if it is left idle. If it sat open for a while, close it and click Connect again.

What Noru does not do

The Slack app does not create, edit, or approve anything in Noru; every command and mention is read-only. Slack is not a data source: connecting it collects no evidence about your Slack workspace. Microsoft Teams is not yet available.

Last updated on