Integrations
Settings › Integrations has a card per integration with its state. Slack and Microsoft Teams approve; email and webhooks report.
Approval requests go to a Slack channel, with Approve and Deny buttons. Noset matches the person who clicks by the email address of their Slack account, so it must belong to a member of your organization. Only people in the rule’s team can decide.
- On-prem: your organization’s own Slack app, with Add to Slack or by pasting its tokens. It connects over Socket Mode, so nothing has to reach your server from the internet.
- Noset Cloud: Add to Slack installs Noset’s app in your workspace; then pick the approvals channel. A private channel needs
/invite @Noset.
Microsoft Teams
Section titled “Microsoft Teams”Approval cards go to a Teams channel, with Approve and Deny. Noset matches the person who clicks by their Entra account, else their email.
- On-prem: your own Azure bot (its app id, secret and tenant). Noset makes the Teams app package from it; upload it in the Teams admin center. The bot’s messaging endpoint must be reachable from the internet.
- Noset Cloud: download Noset’s app package and have your tenant’s admin add it. Add the Noset bot to a team in your tenant; the bot posts a one-time code there, valid 24 hours. Enter the code it posts there to link your tenant. Cards then go to that channel until you pick another.
Noset sends invitations and, in Noset Cloud, sign-in links by email over SMTP: server, port, encryption, user name and password, sender address and name. Send a test mail before you save.
- On-prem: set it up in the setup wizard or under Settings › Integrations › Email. If the server’s env file sets
NOSET_SMTP_*, those settings win and the page shows them read-only. - Noset Cloud: Noset sends the email.
Webhooks
Section titled “Webhooks”Webhooks send events to your own systems. They only report: nothing an endpoint answers changes a decision.
- Add an HTTPS endpoint and pick its events:
approval.requested,approval.decided,approval.expired,rules.version_live,template.update,gate.alert,evidence.checkpoint. Send a test event sendswebhook.testat once. - Every delivery is a
POSTwith a JSON body and the headersNoset-Event,Noset-Delivery,Noset-TimestampandNoset-Signature: t=<unix seconds>,v1=<hex>. - Check the signature:
v1is the hex HMAC-SHA256 of<t>.<body>(the timestamp, a dot, the body exactly as received), keyed with the endpoint’s secret as shown (whsec_…, prefix included). Compare in constant time, and refuse atmore than five minutes from your clock. The secret is shown once, when you add the endpoint or rotate its secret. - Any 2xx within 10 seconds is a success. A failed delivery is tried again after 1 minute, 5 minutes, 30 minutes, 2, 6 and 12 hours. An endpoint that fails every delivery for a day is switched off until an admin switches it on again.
- Each endpoint keeps a delivery log for 30 days; you can send a delivery again.
- Endpoints must be public HTTPS addresses: never loopback, private or cloud-metadata addresses. Redirects are not followed.
Claude (Anthropic)
Section titled “Claude (Anthropic)”With your organization’s own Anthropic API key, Noset writes a short summary of why an agent asks, for the approval card, with personal data masked. The key is write-only: Noset never shows any part of it. Test it, then Save.
Approvers see the summaries once Show approvers the agent’s reasons is on under Settings › Organization. Turning it on waits for a second admin when there is one.
Evidence archive
Section titled “Evidence archive”The evidence archive copies your evidence to your own S3 storage with Object Lock, once a day. On-prem it is under Settings › Evidence; in Noset Cloud each organization sets its own under Integrations. See Verify the evidence.