last updated 1 August 2026
So someone installed kudoSnap.
You're probably here because a bot started DMing people and you'd like to know what it is, who let it in, and whether it stays. All fair. Here's everything, roughly in the order you'd want it.
What it is
kudoSnap is an employee recognition tool, and a narrow one: peer to peer, no manager layer, nothing public.
It sends people in your workspace a short question about a coworker — who explains things clearly, who stays calm, who they trust to own something — and sends the answer to that coworker with no name attached.
One question a day at most, on weekdays, in a DM. Nothing is posted in a channel.
How it got here
Someone in your workspace clicked “Add to Slack.” They didn't need your approval, and that isn't a loophole they found — it's a consequence of what kudoSnap asks for.
Slack requires admin approval when an app requests permissions that warrant review. kudoSnap requests none of those. It cannot read messages, cannot post in channels, and cannot see files, so it installs the way a status app installs.
Whoever installed it is recorded, and we'll tell you who if you email us.
What it can see
All seven permissions it holds, and what each one specifically doesn't give it:
| Permission | What it lets us do | What it does not |
|---|---|---|
| channels:read | See which public channels exist and who's in them | Read a single message in any of them |
| groups:read | See who's in a private channel the bot was invited to | Read those messages, or see private channels it wasn't invited to |
| mpim:read | See who's in a group DM the bot is part of | Read those messages |
| users:read | See names, avatars, and timezones from the member directory | See email addresses — that's a separate scope we don't request |
| users.profile:read | Read the department field your Slack admin defined, so recognition can be grouped by team | Read profile fields we don't ask for, or any custom field's history |
| chat:write | Send you a DM and draw the app's Home tab | Post in any channel, public or private |
| team:read | See your workspace's name and email domain | See anything about the individuals in it |
There is no message-history scope in that list, which is the load-bearing detail: message content is not readable by this app under any of these grants.
What it can't do
Read messages. Post in a channel, public or private. Read files or emails. Accept any negative input about anyone — there is no text box and every question asks who is good at something.
It also can't produce a ranking, a “most recognized” list, a manager-scoped view, or an export. Not “we choose not to” — those screens and that query do not exist in the product.
Nothing it holds is designed to reach a performance review, and nothing in it is structured in a way that would survive being used for one.
What everyone in your workspace can already see
This is the entire reporting surface, and your employees are looking at the same screen you are. Anyone in the workspace can sign in with Slack — there is no admin tier with more in it.
This month in your workspace
- of people heard something specific and good about themselves
- 63%of people heard something specific and good about themselves
- answered at least one question
- 71%answered at least one question
- people haven't been recognized yet
- 9people haven't been recognized yet
Most noticed: Connection, then Delivery
Everyone in this workspace can sign in and see this. There is no admin version with more in it.
The real one lives at admin.kudosnap.com. Sign in with Slack — if you're in the workspace, you're in.
It also groups those same counts by the department field in Slack, if your workspace defines one. Team-level totals, visible to everyone, never individual votes and never scoped to one manager's reports.
Nothing here renders for a workspace under eight people, because in a group that small an aggregate is trivially back-derivable and “one person hasn't been recognized” identifies them.
What your employees have been told
Probably the more useful question, since the risk you're weighing is whether staff are upset rather than whether the software is sound.
Everything on who sees what is what we tell them, in the same words, with the same receipts. It is not a different page for a different audience — you are reading the employee version right now, and so are they.
If you want it gone
A Slack workspace owner or admin removes it the standard way: Slack admin → Manage apps → kudoSnap → Remove. No conversation with us required, and nothing about the removal is delayed or rate-limited.
Removal stops every DM immediately. The moment Slack revokes the token, kudoSnap cannot send your workspace anything — that part needs nothing from us and cannot be delayed by us.
Erasing what's already stored is a second step, and being straight with you: it is manual today. Email the address below and the workspace's data — users, votes, recognitions, and everything derived from them — is deleted within seven days, and we confirm in writing when it's done. Automatic deletion on removal is being built; until it exists we're not going to describe it as if it were.
If you'd rather keep it and exempt specific people, email us and we'll do that instead. Either answer is fine.
A person to email
hello@kudosnap.com reaches Alessandro, who built it. Usually within a day. If you need something for a ticket — the scope list, a written retention statement, confirmation of who installed it — ask and you'll get it in writing.
The boring reference version of all of this is on /security, which is built to be attached to a ticket.