Case Study: freeCodeCamp achieves per-user Slack AI agent permissions with Kipwise

A Kipwise Case Study

Preview of the freeCodeCamp Case Study

freeCodeCamp proves per-user Slack agent permissions in 7-day pilot with Kipwise

freeCodeCamp faced a challenge with their Slack AI agent operating under a single shared bot token, which collapsed user privileges and erased attribution. This meant every action appeared to be performed by the bot, making it impossible to audit who had actually authorized writes to systems like GitHub or requested reads of private knowledge, creating a significant security and operational governance issue. They partnered with vendor Kipwise to address this.

Kipwise implemented a solution using their Agent to enforce per-user permissions instead of a shared bot identity. This involved storing individual user OAuth grants securely behind a gateway, selecting the correct token type for each tool call, and performing live authorization checks. The result was proper user attribution for all actions, the ability to respect individual user access controls, and a clear, actionable audit trail that security teams could use, preventing privilege-collapse incidents.


View this case study…

Kipwise

28 Case Studies