All integrations
Slack integration

Investigate without leaving Slack.

Native OAuth bot, channel-routed alerts, and a /tracelight slash command for one-shot lookups. Drop an email or username into your investigations channel and get a cited summary back in under a minute.

What's in this integration

  • /tracelight slash command — type `/tracelight email jane@acme.com` and get a cited summary back in-thread
  • Per-workspace bot installation via Slack OAuth v2
  • Alert digests routed to any channel — severity-graded, link-back to the case
  • HMAC-signed alert webhook (defense in depth — even if the URL leaks, posts can be verified)
  • Bot tokens encrypted at rest with AES-256-GCM

Setup

  1. 1
    Dashboard → Integrations → Add to Slack
  2. 2
    Authorize in your Slack workspace (need admin install permission)
  3. 3
    Pick the channel for monitor alerts (defaults to where the bot was added)
  4. 4
    Try it: type /tracelight email yourcoworker@yourdomain.com in any channel

Events you can subscribe to

alert.firedmonitor.matchcase.createdcase.completed

See the full event payload schemas at /zapier + /docs.

Wire it up.

Sign up, head to Dashboard → Integrations, and turn this on in 60 seconds.

Other integrations
Zapier
Wire Tracelight events into 6,000+ Zapier-connected apps. HMAC-signed webhooks make Zaps tamper-proof.
Discord
Channel webhook for alert digests + per-event notifications. SSRF-guarded outbound dispatch.
Microsoft Teams
Adaptive Card alerts in any Teams channel via incoming-webhook URL. Works with both classic O365 connectors and the new Workflows.
Notion
Pipe Tracelight events into a Notion database — auto-log every case, alert, or report into your team workspace.
Linear
Auto-create Linear issues for high-severity Tracelight alerts. Useful for teams running investigations like an engineering project.
HubSpot
Sync Tracelight cases + alerts into HubSpot CRM as deal records, contacts, or activity timeline entries.
Salesforce
Tracelight events → Salesforce Cases or custom objects via Flow Builder + the generic webhook integration.
Splunk
Stream Tracelight audit events + alerts into Splunk via HEC. Useful for SOCs running Tracelight as one of many investigation feeds.
Datadog
Tracelight alerts → Datadog events. Use Datadog's monitor language to set up follow-on alerting on Tracelight signals.
Jira
Auto-create Jira issues from high-severity Tracelight alerts. Useful for SOC + investigation teams running case management in Jira.
ServiceNow
Stream Tracelight alerts into ServiceNow as incident records. For enterprise SOCs running ITSM-style alert workflows.
GitHub
Auto-open GitHub issues from Tracelight alerts. Useful for security teams running incident response in Issues + Projects.
Asana
Auto-create Asana tasks from Tracelight alerts + cases. Useful for investigation teams running case management in Asana.
ClickUp
Tracelight events → ClickUp tasks. For teams running case management in ClickUp.
Microsoft 365
Tracelight events into Microsoft 365 — Outlook calendar holds for incidents, OneDrive report archival, Power Automate flows.
Trello
Tracelight events → Trello cards. For investigation teams running Kanban-style case management.
Calendly
Auto-schedule investigator follow-up calls when high-severity alerts fire. Useful for client-facing PI shops.
Generic webhooks
Subscribe any HTTPS endpoint to Tracelight events. HMAC-SHA256 signing. SSRF-safe. Zero glue.