The Vantage View | Salesforce

Slack September 2026 Admin Updates: What Changed and What to Do

Written by David Cockrum | Sep 10, 2026, 7:21:51 PM

Slack's September 2026 admin update is one of the heaviest governance months in recent memory. Slackbot can now delete Salesforce records from a conversation — and delete access rides along wherever create/update is already enabled. MCP server access can move into your identity provider. Apps and agents can be restricted to specific channels. And two deprecation dates are now on the calendar.

The headline new capability is Slack Code, a dedicated space for working with coding agents on a single project from planning through shipping. Below is the full breakdown: what changed, which plans get what, and the five actions every Slack admin should take this month.

Quick Answer

 

Slack's September 2026 admin update introduces Slack Code (multiplayer channels for coding agents like Claude, Devin, the Vercel agent, and GitHub Copilot), a major governance cluster (Salesforce record deletion from Slackbot, IdP-managed MCP server access, per-channel app restrictions, and hidden "New" buttons on list views), and Slackbot skill sets for Business+ v2 and Enterprise+ plans. Two dates matter: older OS, app, and browser versions lose support on November 9, 2026, and the legacy Windows .exe installer is deprecated in March 2027. Vantage Point helps organizations turn monthly updates like these into a working governance and adoption plan across Slack, Salesforce, and HubSpot.

Key Takeaways (TL;DR)

  • What changed: Slack Code debuts, Slackbot gains skill sets and external skill sharing, Salesforce record deletion arrives in Slackbot, and apps/agents can be channel-restricted.
  • The buried detail: enabling Slackbot create/update on Salesforce records already turns delete on too — review that setting now.
  • Plan gates: most Slackbot governance features require Business+ v2 or Enterprise+; IP allowlisting (coming soon) is Enterprise Grid and Enterprise+.
  • Deadlines: OS/browser end of support November 9, 2026; Windows .exe installer deprecated March 2027 (existing installs keep working).
  • How Vantage Point helps: our managed services and ongoing support team operationalizes monthly platform changes so admins don't chase them alone.

What Changed in Slack's September 2026 Admin Update

The headline: Slack Code

Slack Code is a dedicated space to work with a coding agent — Claude, Devin, the Vercel agent, or GitHub Copilot — on a single project, from planning through shipping. Code channels are temporary, auto-created channels built for multiplayer collaboration, so a team and its agents share one workspace instead of scattering agent output across DMs.

For admins, the immediate question is governance: which coding agents are approved in your environment, and who can spin up Code channels? Treat it like any new agent surface — pilot with a named team before broad rollout.

The governance story: four changes that need admin decisions

1. Slackbot can delete Salesforce records. Users can delete Salesforce records directly from a Slack conversation, with multi-select and undo. Slackbot checks each user's delete permissions first, so no one can delete records they don't own, and admins control the capability through the existing CRUD setting. The critical detail from the September email: enabling create/update already turns delete on too. If you enabled create/update in a prior month, delete is likely live in your org today.

2. MCP server access through your identity provider (Enterprise+). Instead of approving OAuth per employee, admins can control MCP server access centrally through the IdP — Okta only at launch. This is an additional, optional path alongside existing OAuth, not a replacement.

3. Channel restrictions for apps and agents (Enterprise+, Enterprise Grid). Admins can now allowlist or exclude specific channels for individual apps and agents, managed from the integrations page in organization settings. This is the control many security teams have wanted since agents arrived in Slack.

4. Restrict record creation in list views. Admins can hide the "New" button on standalone and related list views via list view and page layout button sets — a small change that closes a common data-quality gap.

Slackbot skill sets and skill distribution (Business+ v2, Enterprise+)

Slackbot skills get three upgrades this month:

  • Skill sets: bundle related skills into a shareable collection. Sharing one set gives a team the whole collection, individual skill access is still managed separately, and skills stay in sync as the creator updates the set.
  • External sharing: skill authors can generate a public link. Recipients in other orgs see a consent card and add their own copy.
  • Distribution dashboard: admins can see who has a skill, when it was added, and manage member and group assignments from a new admin dashboard.

Also new: admins on Business+ and Enterprise plans can create, edit, and search scheduled tasks directly from the Tasks tab — no Slackbot conversation required. And admins on Business+ v2 and Enterprise Grid can ask Slackbot conversational questions about org member analytics.

Collaboration and usability updates

  • Canvas comment-only sharing: canvas owners can share with comment-only permissions — inline comments and emoji reactions, no edit access. Deleted canvas and list files now move to a trash state instead of being permanently removed right away.
  • Card-based UI updates: refreshed website, forwarded-message, and media preview cards, plus adjustments to how attachments, link previews, and inline media are arranged in messages.
  • Migration user matching: Org Owners can search by name or email to find the right user to merge during a migration, even when the system doesn't surface a match automatically. If you're mid-migration, our integration and data migration services team can help plan the merge strategy.
  • "Tools" is now "Agents & tools": a naming update only — no new AI or agent features. The landing page now surfaces popular agents, and you can manage recent agent conversations from the tab's sidebar.
  • Private Salesforce Channels: Salesforce record channels can now be set to fully private.
  • Archived public channels retain membership: membership now persists indefinitely after archiving, matching private channel behavior. Previously, membership reset if a channel stayed archived past a 5-day grace period.

Workflow Builder: multi-row Google Sheets step

A new Google Sheets step in Workflow Builder can select multiple rows, and it pairs with the Repeater step (Business+ and above) to loop a workflow over those rows. Two admin notes: if the Google Sheets connector is already enabled in your environment, this step turns on automatically — and a new admin toggle lets you opt out.

Who's Affected: Plan Availability

Feature Plans
Slack Code Rolling out; coding agent availability varies
Slackbot skill sets, external skill sharing, distribution dashboard Business+ v2, Enterprise+
Tasks tab create/edit/search Business+ and Enterprise
Member analytics through Slackbot Business+ v2, Enterprise Grid
IdP-managed MCP server access (Okta) Enterprise+
Channel restrictions for apps and agents Enterprise+, Enterprise Grid
Google Sheets multi-row step / Repeater Business+ and above
Salesforce record deletion via Slackbot Controlled by existing CRUD setting
Canvas comment-only sharing, card UI updates, trash state Broadly available
IP allowlisting (coming soon) Enterprise Grid, Enterprise+

What Admins Should Do Now: Five Actions

  1. Review the Slackbot CRUD setting today. Delete is on wherever create/update is on. Decide whether that matches your data-governance intent, and confirm which users carry delete permissions in Salesforce. This belongs in your broader compliance and security posture.
  2. Decide on the Google Sheets multi-row step. It auto-enables if the connector is already on. Either communicate the new capability to workflow builders or use the new toggle to opt out.
  3. Start the MSIX migration plan. The legacy Windows .exe installer is deprecated March 2027. Existing installations continue to function and auto-update — this affects new deployments only — but IT teams should standardize on the MSIX package (enhanced enterprise features, modern auto-updating) well before then. Downloads and packaging details live on Slack's download page.
  4. Audit OS, browser, and app versions before November 9, 2026. Older versions reach end of support that day per Slack's support lifecycle policy. Pull the exact version list from Slack's Help Center and inventory your fleet against it.
  5. Enterprise+ admins: evaluate IdP-managed MCP access and channel restrictions. If you run Okta, centralizing MCP approval in the IdP removes per-employee OAuth reviews. Channel restrictions let you keep sensitive agents out of the wrong channels.

Timeline and Coming Soon

Date What happens Who's affected
Now September features rolling out Varies by plan (see table above)
November 9, 2026 Older OS, app, and browser versions reach end of support All workspaces on legacy versions
March 2027 Windows .exe installer deprecated; MSIX becomes the path for new deployments IT teams deploying on Windows

Three items are flagged as coming soon rather than available now:

  • IP allowlisting (Enterprise Grid, Enterprise+): define approved IP ranges to control workspace access, with org-level default policies and workspace-level overrides. Unapproved IPs are blocked.
  • Transcript-only option for huddles.
  • "Important" unreads in Slack Activity: automatically surfaces each user's most important unreads at the top of Activity.

For last month's context, see our Slack August 2026 admin updates recap and the July 2026 admin updates post.

Frequently Asked Questions

What is Slack Code?

Slack Code is a dedicated space in Slack for working with a coding agent — Claude, Devin, the Vercel agent, or GitHub Copilot — on a single project from planning through shipping. Code channels are temporary, auto-created channels designed for multiplayer collaboration between teammates and agents.

Does enabling Slackbot create/update on Salesforce records also enable delete?

Yes. Per Slack's September 2026 update, enabling create/update already turns delete on too. Slackbot checks each user's Salesforce delete permissions before acting, and there is an undo option, but admins should review the existing CRUD setting to confirm it matches their intent.

What is a Slackbot skill set?

A skill set bundles related Slackbot skills into one shareable collection on Business+ v2 and Enterprise+ plans. Sharing the set gives a team every skill in it, individual skill access is still managed separately, and the collection stays in sync as the creator updates it. Skill authors can also share externally via a public link, and admins get a new distribution dashboard showing who has which skills.

Is the Windows Slack app going away in March 2027?

No — existing installations continue to function and auto-update normally. The deprecation applies to the legacy Squirrel-based .exe installer: after March 2027 it disappears from the download page with no new releases. New deployments should use the MSIX package, which adds enhanced enterprise features and modern auto-updating.

Which Slack plans get the September 2026 governance features?

Most Slackbot governance features — skill sets, external skill sharing, and the distribution dashboard — require Business+ v2 or Enterprise+. IdP-managed MCP server access (Okta only at launch) requires Enterprise+. Channel restrictions for apps and agents require Enterprise+ or Enterprise Grid. The Tasks tab improvements cover Business+ and Enterprise plans.

Can we manage MCP server access through Okta now?

Yes, on Enterprise+. Slack now supports controlling MCP server access centrally through your identity provider — Okta only at launch — as an optional path alongside the existing per-employee OAuth approval flow.

How Vantage Point Helps

Monthly admin updates are easy to read and hard to operationalize. Vantage Point's senior consultants help organizations turn feature announcements into decisions: which Slackbot permissions match your Salesforce governance model, how to sequence an MSIX rollout, and how channel restrictions and IdP-managed MCP access fit your security posture. Through our Salesforce implementation and advisory and managed services practices, we track these changes every month so your admin team doesn't have to triage them alone.

Need Help Operationalizing Slack's September Changes?

From the Slackbot CRUD review to the MSIX migration plan, Vantage Point's senior consultants can turn this month's update into a finished admin checklist for your organization. Contact Vantage Point to schedule a Slack and Salesforce governance session.

Vantage Point is a boutique CRM consulting firm helping businesses transform with Salesforce, HubSpot, and AI — 150+ clients, 400+ engagements, and a 4.71/5 average engagement rating. Learn more at vantagepoint.io.