Software & SaaS
Slack September 2026 Update: Passkeys, Agent Filters, Sidebar Tabs and New Admin Controls
Slack’s September update is less about one headline feature and more about how the SaaS is adapting to a workspace filled with people, apps and AI agents. Passkey sign-in arrives for several plans, Activity can separate agent activity from people, sidebar tabs become reorderable, and admins get new visibility and network controls.
Digital Pulse Brief • Published September 29, 2026 • Based on Slack’s current changelog and Help Center documentation

What changed in Slack this September
- Passkey sign-in: Slack says members of Free, Pro and Business+ workspaces can sign in using a fingerprint, face or device PIN.
- People, agents and apps filters: Activity can now separate notifications by source so agent activity does not have to compete with messages from people.
- Reorderable sidebar tabs: users can rearrange sidebar tabs around the way they work.
- Slackbot surface skills: developers can expose skills directly inside Slackbot surfaces so users can discover relevant actions without switching conversations.
- AI/tool analytics: Slack says owners and admins can review Slackbot tool and MCP server usage in the analytics dashboard.
- Enterprise IP allowlists: Org Owners and Org Admins can restrict Enterprise access to approved IP ranges.
Slack passkeys: what they change
The most immediately useful update for many users is passkey sign-in. Slack’s September changelog explicitly lists the feature for Free, Pro and Business+ workspaces. A passkey lets a user authenticate with the security mechanism already built into a device or password manager — typically Face ID, a fingerprint reader or a device PIN — instead of entering a traditional Slack password.
Slack’s current sign-in documentation says users can add and remove passkeys from my.slack.com/account/settings under the Passkeys section. It also notes that some third-party password managers may only display one passkey even when Slack shows multiple passkeys in account settings.
A passkey does not automatically cancel an organization’s other authentication rules. Slack’s sign-in documentation says that if a workspace or organization requires two-factor authentication, the user will still need the required 2FA code. Enterprise organizations may also rely on SSO and additional identity controls.
How to set up a Slack passkey
- Open my.slack.com/account/settings in a browser.
- Find Passkeys and select Expand.
- Select Add Another Passkey.
- Complete the authentication prompt from your device or password manager.
- Keep another valid sign-in method available until you have confirmed the passkey works across the devices you actually use.
To remove a passkey, Slack says to select Remove next to it and confirm Delete Passkey. Slack signs the user out and asks them to sign in again after removal.
Activity can finally separate people from agents
Slack has been rebuilding Activity into a unified triage view for DMs, mentions, thread replies, reminders and app notifications. September adds a distinction that becomes more important as organizations deploy more autonomous agents: filters for people, agents and apps.
That sounds small, but it addresses a real information-design problem. A workspace with automated agents can generate a large volume of status updates, suggestions and tool results. If those signals share one notification stream with colleagues, human messages can become harder to spot. Slack’s new filter lets a user focus on agent work when reviewing automation, then switch back to people when the priority is human communication.
Slack does not specify a separate plan restriction for this filter in the September changelog. Availability may still depend on staged rollout and the Activity experience available to the workspace.
Sidebar tabs are becoming personal, not fixed
Slack also says users can now reorder sidebar tabs. This is a usability change rather than a new collaboration feature, but it matters because Slack’s sidebar is carrying more surfaces than it did when the product was mainly channels and DMs.
Teams now navigate Activity, Later, canvases, tools, agents and other work surfaces. Reordering tabs gives users a way to put the surfaces they use every day ahead of those they rarely touch. Slack’s September changelog does not state a plan restriction for the tab-ordering change.
Slackbot skills and MCP analytics: what admins and builders get
Two September changes are aimed more directly at organizations building around Slackbot and AI tools.
Skills inside Slackbot surfaces. Slack says builders can include relevant skills when they create a Slackbot surface. A surface is an interactive Slackbot experience where information and actions can be presented together. Exposing a skill in the surface reduces the need for a user to leave the current context and start a separate conversation to find the right capability.
Tool and MCP server usage analytics. Owners and admins can use Slack’s analytics dashboard to see usage data for Slackbot tools and Model Context Protocol servers. For teams connecting Slackbot to external business systems, this provides a basic governance question that was difficult to answer from user anecdotes alone: which connected tools are actually being used?
Slack’s public September changelog does not list detailed plan requirements for these two changes. Organizations should check their own workspace licensing and admin console before treating them as universally available.
Enterprise IP allowlists are a real security control — with a rollout risk
For Enterprise organizations, Slack now documents IP allowlists that let Org Owners and Org Admins restrict access to approved network ranges such as office networks or an approved VPN.
The control is powerful because it changes where a user may access the organization, not just how they authenticate. Slack warns that enabling an allowlist will sign out people who are currently connecting from an IP address outside the approved ranges.
That makes deployment planning important. Before enabling the restriction, an admin should account for remote workers, VPN egress addresses, disaster-recovery access, mobile usage and any corporate networks that leave through different public IPs. Slack’s documentation says the feature is available to Org Owners and Org Admins on Enterprise subscriptions.
Feature availability at a glance
| September feature | Slack-published availability | Important caveat |
|---|---|---|
| Passkey sign-in | Free, Pro, Business+ | Existing SSO/2FA policies can still apply. |
| Activity filters for people, agents, apps | No separate plan restriction stated in September changelog | Slack says features are gradually rolling out. |
| Reorder sidebar tabs | No separate plan restriction stated | May appear progressively by workspace. |
| Slackbot surface skills | No detailed plan list in changelog | Relevant mainly to Slackbot builders and workspaces using those surfaces. |
| Slackbot tool/MCP analytics | Owners/admins; plan not specified in changelog | Actual dashboard options depend on workspace capabilities. |
| IP allowlists | Enterprise; Org Owners and Org Admins | Users outside approved IP ranges are signed out when enabled. |
Do you need to update the Slack desktop app for these features?
Not necessarily. Slack’s Windows release notes show version 4.52.171 dated September 28, 2026, but Slack describes that desktop build as a bug-fix release rather than the carrier of these workspace features.
Features such as Activity filters, sidebar configuration and admin controls can be enabled server-side and rolled out gradually. If a feature in Slack’s September changelog is missing from your workspace, updating the app is sensible, but it does not guarantee immediate access. Licensing, admin configuration and staged rollout can still determine what appears.
What should Slack users do now?
Individual users: If your plan is listed for passkeys, add one on a device you control and verify that your recovery/sign-in path still works. Then check Activity for the new source filters and move your most-used sidebar tabs higher.
Workspace owners: Review whether growing agent and app activity is burying human notifications. The new Activity filtering is useful only if teams know it exists and build it into their catch-up habits.
AI/platform admins: Inspect Slackbot tool and MCP usage before adding more connectors. Adoption data can help distinguish useful integrations from connections that create governance overhead without meaningful use.
Enterprise security teams: Treat IP allowlists as a network-access change, not a harmless toggle. Inventory remote-access paths and approved VPN ranges first.
Why this update matters for SaaS teams
Slack’s September release is a good example of how collaboration SaaS is changing as agents become participants in the workspace. The product now has to solve three problems at once: authenticate humans more securely, keep machine-generated activity understandable, and give administrators enough observability to govern the connected tools.
That also explains why seemingly unrelated changes — passkeys, agent filters, MCP analytics and IP allowlists — belong in the same release story. Slack is no longer only organizing messages. It is increasingly organizing access, automation and software-to-software work inside the same interface.
For a broader view of how subscription software differs from locally controlled deployments, see DPB’s SaaS vs on-premise software guide. Slack’s growing connection to enterprise AI also overlaps with our Salesforce AIforce explainer and Meta Muse for Small Business coverage.
Frequently asked questions
Does Slack support passkeys in 2026?
Yes. Slack’s September 2026 changelog says passkey sign-in is available for members of Free, Pro and Business+ workspaces. Slack’s account settings let users add or remove passkeys.
Can a Slack passkey replace two-factor authentication?
Not automatically. Slack’s sign-in documentation says users still need the required 2FA code when their workspace or organization enforces two-factor authentication.
Can I hide AI-agent notifications in Slack?
Slack’s September update adds Activity filters for people, agents and apps, allowing users to narrow the notification stream by source.
Who can configure Slack IP allowlists?
Slack documents IP allowlists for Enterprise organizations. Org Owners and Org Admins can configure approved ranges. Slack warns that users outside those ranges are signed out when the allowlist is enabled.
Sources
Get clear AI, technology and business insights in your inbox
Breaking developments, practical explainers, reviews and useful tech intelligence — without the noise.
SaaS vs On-Premise Software: Cost, Security, Control and the Hybrid Reality in 2026
Made on YouTube 2026: AI Editing, Custom Feeds, Live Dubbing and the Features That Matter
