Skip to content

Software companies

Slack retention settings: what to keep before an AI data review

By SourceX Editorial · Updated

Short answer

Slack retention policy best practices before an AI data review come down to one rule: freeze deletion until the review has decided what to keep. Check workspace, channel and file retention settings, keep engineering, incident, support escalation and product channels intact, and confirm with counsel that no legal hold applies before anyone shortens retention afterward.

Key takeaways

  • Pause any shortening of Slack retention until an AI data review has decided what is worth keeping.
  • Depending on the plan, retention may be set for the whole workspace, adjusted per channel and handled separately for files, so check every level.
  • Engineering, incident, support escalation and product decision channels usually hold the most useful history.
  • A legal hold overrides any retention plan, and an AI data review never overrides a legal hold.
  • Record each retention decision with a date and an owner so later reviewers can trust the archive.

Why retention settings matter before an AI data review#

Slack retention settings decide whether the reasoning behind your product still exists when an AI data review asks for it. Slack is often the only place that records why a release was rolled back, how an outage was diagnosed or what support and engineering agreed about a recurring bug.

Many software companies shortened retention years ago to reduce risk or clutter, and some are about to do it now. A review that arrives after a purge can only assess what survived, so the first practical step is a freeze: no retention changes and no bulk deletions until the review is finished.

Which Slack settings should you check first?#

The Slack settings to check first are the ones that delete content automatically: workspace message retention, channel-level overrides, file retention and any connected app that removes messages. By default, Slack keeps all messages and files for the lifetime of the workspace; once an admin sets a custom deletion period, Slack's help center is clear that the deletion is permanent.

Record what you find before touching anything. The current value of a setting and the date it last changed tell a reviewer how far back each channel can reach. Options differ by plan, so confirm each one in your admin settings and in Slack's current documentation rather than relying on memory.

Which Slack settings should you check first?
SettingWhat to recordDo-not-purge rule
Workspace message retentionCurrent policy and when it last changedDo not shorten until the review signs off
Channel-level overridesChannels with shorter or longer retention than the defaultDo not shorten overrides on candidate channels
File retentionWhether files expire separately from messagesDo not purge files linked from candidate channels
Private channels and direct messagesWhether different rules apply to themLeave as is; exclusion is decided later, not by deletion
Organization-level policies on enterprise plansPolicies that override workspace settingsConfirm no pending policy change
Connected apps and botsAny app that deletes, archives or copies messages, and under which termsPause auto-delete apps; take review copies with Slack's own export tools
Export accessWhich conversation types your plan can export and who can run the exportConfirm before changing billing or plan; private channel and DM exports depend on the plan

Which channels are worth keeping intact?#

The channels worth keeping intact are the ones where people explain decisions about the product and its customers. Those threads carry human-generated reasoning that Jira tickets and pull requests summarize only briefly, and they are what an AI data review looks for in a software company's Slack.

Bot and integration channels deserve a second look before anyone writes them off. A channel where a GitHub or paging app posts alerts looks like noise, but the human replies threaded under each alert often show triage decisions, and the bot posts carry the identifiers that link a conversation back to a pull request or an incident ticket.

Other channels still need a retention decision, but they rarely belong in a review. HR, compensation, legal and social channels stay under your normal policy and are flagged as excluded from any review export.

  • Incident and on-call channels, including postmortem discussions.
  • Release and deploy channels where rollbacks and hotfixes are debated.
  • Support escalation channels where agents bring customer problems to engineers.
  • Product and design channels where scope and tradeoffs are decided.
  • Architecture and platform channels that record technical choices and rejected options.
  • Customer success channels about renewals and churn risk, flagged for customer-name review.

How to write the do-not-purge rule#

A do-not-purge rule is a short written instruction that stops all deletion in Slack until a named person lifts it. Writing it down matters because retention changes are often made by an IT admin following an older plan, with no idea that a review has started.

Keep the rule narrow and dated. It should name the review, the owner, the channels or settings it covers and how exceptions are approved, so it does not quietly become a permanent policy.

  • Name the owner, usually the COO or head of IT, and the person who can lift the freeze.
  • List the settings frozen: workspace retention, channel overrides, file retention and auto-delete apps.
  • Ban channel deletion and bulk message removal while the freeze stands; archiving a channel is fine.
  • Set an exception route for urgent removals, such as a leaked credential, with counsel copied.
  • State the end condition: review sign-off, followed by a documented retention decision.

A legal hold comes before any retention plan or data review. If litigation, an investigation or an audit is reasonably anticipated, counsel may require relevant Slack messages to be preserved, and shortening retention during that period may create serious problems.

Slack's own legal hold feature, where your plan includes it, saves messages and files sent by all members in a held conversation regardless of retention settings, even if members edit or delete them. Where it is not available, preservation relies on exports and process, which makes the do-not-purge rule more important.

The two decisions run separately. An AI data review does not override a hold, and a hold does not authorize licensing anything it preserves. This is general information, not legal advice, so confirm the position for your company with counsel before changing retention in either direction.

  • Ask counsel in writing whether any hold, dispute, audit or regulatory request covers Slack content.
  • If a hold exists, record its scope: custodians, channels, date range and who can release it.
  • Keep held content out of any review export unless counsel approves its use separately.
  • Revisit the retention plan only after the hold is released and the release is documented.

Illustrative: a routing software company pauses a cleanup#

Illustrative: a fictional route planning software company decided after a security review to cut Slack retention across the workspace. The IT lead had the change scheduled when the COO started a data inventory that included Slack, Jira and GitHub.

The COO froze the change and ran a quick review. The incident channel held years of outage diagnosis threads that linked to Jira tickets and GitHub pull requests, and the support escalation channel showed how agents and engineers resolved hard customer cases. Both were kept and exported. Retention was shortened for social channels as planned, and the HR channel was flagged as excluded from any later export.

How SourceX looks at Slack history in a review#

SourceX looks at Slack history as supporting context for engineering, support and product records rather than as a standalone dataset. The fit check uses metadata only, such as channel categories, date ranges and linked systems, and no messages are shared at that stage.

Slack's API terms bar third-party apps from bulk exporting message and file data or using it to train large language models, except where an additional agreement expressly allows it. Any archive a company later considers for licensing therefore starts from exports the company took itself, and the Rights step reviews those terms alongside employee notices.

Slack threads rarely travel alone. In the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, they are usually scoped alongside the Jira issues or incident records they explain, direct messages and sensitive channels are typically left out, and the SourceX Evidence Packet records which channels were included and who authorized their release.

Frequently asked questions

Does freezing retention increase our risk?

A freeze keeps data longer than planned, so it carries some risk, which is why it should be short, scoped and documented. Freeze the channels and settings the review needs, keep normal access controls, and set a clear end condition. Counsel can weigh the extra exposure against the cost of losing records you cannot recreate.

Should we export Slack before the review or after?

Export candidate channels before any setting changes, and keep the export in company-controlled encrypted storage. Slack lets owners and admins on every plan export public channels; exports that include private channels and direct messages are available only on Business+ and Enterprise, and owners must apply to use them. Nothing is shared outside the company during an initial review.

Can employees' direct messages be part of an AI data review?

Direct messages are usually excluded. Employees reasonably expect them to be more private, workplace privacy laws may apply, and their business value is lower than channel discussions. If any direct messages are considered, counsel should review notices and policies first, and employees are typically told in writing what is in scope.

What if retention has already deleted old messages?

Slack treats retention deletions as permanent, so deleted messages cannot be restored from Slack itself. Look for copies elsewhere: earlier exports, eDiscovery or archiving tools, and integrations that posted summaries into Jira, GitHub or Confluence. Record the gap in your inventory so reviewers know which years each channel actually covers.

Does archiving a Slack channel delete its messages?

Archiving a channel closes it to new messages but generally keeps its history, subject to your retention settings, while deleting a channel removes its content. During a freeze, archive channels you no longer use rather than deleting them. Check Slack's current documentation for how archived channels behave on your plan before relying on that difference.

Who should own Slack retention decisions?

Retention decisions usually sit with the COO or head of IT, with counsel approving anything that touches legal holds or regulated data. Engineering and support leaders should confirm which channels hold useful history. Whoever owns the decision should record it with a date and a reason.

Sources

  • Slack's retention help article states that by default Slack retains all messages and files for the lifetime of the workspace, that admins can instead set custom deletion periods, and that message and file deletion is permanent. Source
  • Slack states that when a legal hold is in place, messages and files sent by all members in a conversation are saved regardless of retention settings, even if members edit or delete content. Source
  • Workspace Owners and Admins on all plans can export messages and file links from public channels; exports of public and private channels plus direct messages are available on Business+ and Enterprise, and owners must apply to use them. Source
  • Slack's API Terms of Service state that a provider of an application offered for use outside its own organization may not use API Data to train a large language model, and may not bulk export Slack message and file data except where an additional agreement expressly allows it. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify