Skip to main content
gunjanm
Expert ⭐️
June 14, 2023
Released

Sally Security Concerns - PSA

Related products:CS Other Features
  • June 14, 2023
  • 37 replies
  • 1023 views

Although I don’t agree that this should be an “Idea”, I was told to come over here by Support. I expect to hear from Gainsight security team about this. 

Given Gainsight Sally can be added to any Slack channel, we did some testing with our Slack Connect channel with Myranda, our Enterprise Support Analyst at Gainsight. We added Gainsight Sally to our channel, triggered a simple C360 Summary query, and asked whether Myranda can see the information - she can.

All of it.

In fact, she can see the other prompts but upon attempting to interact with it, she is thrown with an error as she is not a provisioned user. It even cleared out the original output when she interacted with a query with no threaded further information.

It seems that no matter what I query, Myranda as an external user to Slack, can see the information.

We need to be able to secure who can add Sally to which channel, as we have plenty of customer channels that users (CSMs) could easily provide extremely sensitive information to.

Should this be a reason for us to back out on Sally altogether, when we are planning to launch this to all employees in a month? The hype that we have created for Gainsight with Sally could easily kill our ability to use Gainsight altogether because of this massive security issue.

37 replies

gunjanm
gunjanmAuthor
Expert ⭐️
July 4, 2023

@manu_mittal Thanks for the update. Two questions.

  1. What about existing public/external channels that have this bot?
  2. Also, that still seems like a workaround and not a real solution to the fundamental issue. The responses should initially only go to the requestor. The requestor doesn't have enough context to know what they're consenting to without seeing the response first, right?
Gunjan
Abinash
Contributor ⭐️⭐️⭐️
July 6, 2023

Hey Gunjan - Please see below the responses to your queries:

  1. So Sally will have to be reauthorised (updated) from the Admin settings section to inherit the new changes and these will be reflected on all the existing Public/External channels
  2. The requestor will have two options through the warning message:  (a) to have the information sent as a direct message to self OR (b) post the information in the channel

Hope this helps.

Abinash John
gunjanm
gunjanmAuthor
Expert ⭐️
July 6, 2023

@Abinash it does, thank you!

Gunjan
bradley
Expert ⭐️
July 6, 2023

@Abinash will the Sally re-authorization send everyone a welcome message/email like it normally does when you turn it on? It would be great to just stealth turn it back on/reset it.

Abinash
Contributor ⭐️⭐️⭐️
July 7, 2023

No Bradley, these changes are independent of the existing welcome emailer sent to first time users. Re-authorization will not send any additional email to existing users.

Abinash John
Abinash
Contributor ⭐️⭐️⭐️
August 1, 2023

Hello Team,

Sharing the update on this request. We have released an enhancement for Sally bot in Slack that addresses the security concern raised in this post. This is now available for all customers to consume as part of the recent July 2023 product release. Quick pointers on this below:

  • Customers will have to re-authorise Sally from their Admin settings page to access the new changes
  • No change or impact for customers who do not re-authorise

Appreciate all the inputs and patience!

Regards

Abinash

Abinash John
Abinash
Contributor ⭐️⭐️⭐️
August 2, 2023
Planned→Implemented
Abinash John