Integrations and admin approval
Last updated: June 29, 2026
Some apps let any user connect on their own. Others — especially work and enterprise accounts — require an administrator to approve Highlight before individual users can connect. This is set by your organization, not by Highlight.
What to do if you hit “approval required”
Today, each integration that needs admin approval has to be approved individually by your admin. If you’re blocked:
Note which app you’re trying to connect (for example, Slack, GitHub, or Notion).
Reach out to your IT or workspace administrator and ask them to approve Highlight for that app.
Share the information below so they understand how Highlight works and how your data is protected.
Highlight for administrators — security overview
Share this information with your IT or security team when approving Highlight integrations.
What Highlight is
Highlight is an AI assistant that helps people work faster across the apps on their computer. With a user’s permission, it connects to tools like calendars, Slack, GitHub, Notion, Linear, Granola, and others to surface relevant context and help with everyday tasks.
How integrations work
Connections use standard OAuth authorization. The user signs in to the service directly and approves access — Highlight never sees or stores the user’s password.
Access is scoped to what the user already has permission to see in the source app.
Admins keep control: where a provider supports admin approval, the integration stays blocked until your team approves it, and access can be revoked at any time from the provider’s admin console.
Users can disconnect any integration themselves from Highlight’s settings.
Security and compliance
SOC 2 — Highlight maintains a SOC 2 program; the SOC 2 report is available through the Trust Center.
Data encryption — data is encrypted, and encryption key access is restricted.
Penetration testing — conducted as part of Highlight’s security program.
Access controls — unique account authentication is enforced and production access is restricted.
Data handling — customer data is deleted when a customer leaves; a Data Processing Agreement (DPA) is available.
Subprocessors
Highlight’s core subprocessors include AWS (incl. AWS Bedrock), Anthropic, Cloudflare, and GitHub. The current list is maintained in the Trust Center.
Where to verify and request documents
The Highlight Trust Center hosts the live list of controls, subprocessors, and compliance documents, including the SOC 2 report and DPA (some documents may require a quick request to access):