Slack's September 2026 admin update is one of the heaviest governance months in recent memory. Slackbot can now delete Salesforce records from a conversation — and delete access rides along wherever create/update is already enabled. MCP server access can move into your identity provider. Apps and agents can be restricted to specific channels. And two deprecation dates are now on the calendar.
The headline new capability is Slack Code, a dedicated space for working with coding agents on a single project from planning through shipping. Below is the full breakdown: what changed, which plans get what, and the five actions every Slack admin should take this month.
Slack's September 2026 admin update introduces Slack Code (multiplayer channels for coding agents like Claude, Devin, the Vercel agent, and GitHub Copilot), a major governance cluster (Salesforce record deletion from Slackbot, IdP-managed MCP server access, per-channel app restrictions, and hidden "New" buttons on list views), and Slackbot skill sets for Business+ v2 and Enterprise+ plans. Two dates matter: older OS, app, and browser versions lose support on November 9, 2026, and the legacy Windows .exe installer is deprecated in March 2027. Vantage Point helps organizations turn monthly updates like these into a working governance and adoption plan across Slack, Salesforce, and HubSpot.
Slack Code is a dedicated space to work with a coding agent — Claude, Devin, the Vercel agent, or GitHub Copilot — on a single project, from planning through shipping. Code channels are temporary, auto-created channels built for multiplayer collaboration, so a team and its agents share one workspace instead of scattering agent output across DMs.
For admins, the immediate question is governance: which coding agents are approved in your environment, and who can spin up Code channels? Treat it like any new agent surface — pilot with a named team before broad rollout.
1. Slackbot can delete Salesforce records. Users can delete Salesforce records directly from a Slack conversation, with multi-select and undo. Slackbot checks each user's delete permissions first, so no one can delete records they don't own, and admins control the capability through the existing CRUD setting. The critical detail from the September email: enabling create/update already turns delete on too. If you enabled create/update in a prior month, delete is likely live in your org today.
2. MCP server access through your identity provider (Enterprise+). Instead of approving OAuth per employee, admins can control MCP server access centrally through the IdP — Okta only at launch. This is an additional, optional path alongside existing OAuth, not a replacement.
3. Channel restrictions for apps and agents (Enterprise+, Enterprise Grid). Admins can now allowlist or exclude specific channels for individual apps and agents, managed from the integrations page in organization settings. This is the control many security teams have wanted since agents arrived in Slack.
4. Restrict record creation in list views. Admins can hide the "New" button on standalone and related list views via list view and page layout button sets — a small change that closes a common data-quality gap.
Slackbot skills get three upgrades this month:
Also new: admins on Business+ and Enterprise plans can create, edit, and search scheduled tasks directly from the Tasks tab — no Slackbot conversation required. And admins on Business+ v2 and Enterprise Grid can ask Slackbot conversational questions about org member analytics.
A new Google Sheets step in Workflow Builder can select multiple rows, and it pairs with the Repeater step (Business+ and above) to loop a workflow over those rows. Two admin notes: if the Google Sheets connector is already enabled in your environment, this step turns on automatically — and a new admin toggle lets you opt out.
| Feature | Plans |
|---|---|
| Slack Code | Rolling out; coding agent availability varies |
| Slackbot skill sets, external skill sharing, distribution dashboard | Business+ v2, Enterprise+ |
| Tasks tab create/edit/search | Business+ and Enterprise |
| Member analytics through Slackbot | Business+ v2, Enterprise Grid |
| IdP-managed MCP server access (Okta) | Enterprise+ |
| Channel restrictions for apps and agents | Enterprise+, Enterprise Grid |
| Google Sheets multi-row step / Repeater | Business+ and above |
| Salesforce record deletion via Slackbot | Controlled by existing CRUD setting |
| Canvas comment-only sharing, card UI updates, trash state | Broadly available |
| IP allowlisting (coming soon) | Enterprise Grid, Enterprise+ |
| Date | What happens | Who's affected |
|---|---|---|
| Now | September features rolling out | Varies by plan (see table above) |
| November 9, 2026 | Older OS, app, and browser versions reach end of support | All workspaces on legacy versions |
| March 2027 | Windows .exe installer deprecated; MSIX becomes the path for new deployments | IT teams deploying on Windows |
Three items are flagged as coming soon rather than available now:
For last month's context, see our Slack August 2026 admin updates recap and the July 2026 admin updates post.
Slack Code is a dedicated space in Slack for working with a coding agent — Claude, Devin, the Vercel agent, or GitHub Copilot — on a single project from planning through shipping. Code channels are temporary, auto-created channels designed for multiplayer collaboration between teammates and agents.
Yes. Per Slack's September 2026 update, enabling create/update already turns delete on too. Slackbot checks each user's Salesforce delete permissions before acting, and there is an undo option, but admins should review the existing CRUD setting to confirm it matches their intent.
A skill set bundles related Slackbot skills into one shareable collection on Business+ v2 and Enterprise+ plans. Sharing the set gives a team every skill in it, individual skill access is still managed separately, and the collection stays in sync as the creator updates it. Skill authors can also share externally via a public link, and admins get a new distribution dashboard showing who has which skills.
No — existing installations continue to function and auto-update normally. The deprecation applies to the legacy Squirrel-based .exe installer: after March 2027 it disappears from the download page with no new releases. New deployments should use the MSIX package, which adds enhanced enterprise features and modern auto-updating.
Most Slackbot governance features — skill sets, external skill sharing, and the distribution dashboard — require Business+ v2 or Enterprise+. IdP-managed MCP server access (Okta only at launch) requires Enterprise+. Channel restrictions for apps and agents require Enterprise+ or Enterprise Grid. The Tasks tab improvements cover Business+ and Enterprise plans.
Yes, on Enterprise+. Slack now supports controlling MCP server access centrally through your identity provider — Okta only at launch — as an optional path alongside the existing per-employee OAuth approval flow.
Monthly admin updates are easy to read and hard to operationalize. Vantage Point's senior consultants help organizations turn feature announcements into decisions: which Slackbot permissions match your Salesforce governance model, how to sequence an MSIX rollout, and how channel restrictions and IdP-managed MCP access fit your security posture. Through our Salesforce implementation and advisory and managed services practices, we track these changes every month so your admin team doesn't have to triage them alone.
From the Slackbot CRUD review to the MSIX migration plan, Vantage Point's senior consultants can turn this month's update into a finished admin checklist for your organization. Contact Vantage Point to schedule a Slack and Salesforce governance session.
Vantage Point is a boutique CRM consulting firm helping businesses transform with Salesforce, HubSpot, and AI — 150+ clients, 400+ engagements, and a 4.71/5 average engagement rating. Learn more at vantagepoint.io.