Sensitive data connections for external integrations
Workspace Admins can mark data connections as sensitive so the Hex Agent treats them carefully in Threads started outside of the Hex app.
- Users require an Admin role to access this setting.
- Sensitive data connection settings apply to both the Hex Agent in Slack and the Hex MCP Server.
When a user starts a Thread from an external integration — like the Hex Agent in Slack or the Hex MCP Server — the Hex Agent automatically selects from connections the user has access to. That means a casual question in Slack or an MCP chat could route analysis against data you'd rather keep off those surfaces.
Marking a connection as Sensitive tells Hex to treat it differently in those workflows:
- The Hex MCP Server never uses sensitive connections.
- The Hex Agent in Slack follows a workspace setting that controls whether the agent can use sensitive connections, and how replies appear when it does.
Connections marked Standard remain available to the Hex Agent in Slack and MCP, subject to the user's ordinary connection access.
For best practices on descriptions, exclusions, and connection permissions, see Optimizing your data connections for the Hex Agent.
Configuration
Mark connections as Standard or Sensitive in either:
- Settings → Integrations → Configure sensitive data connections for external integrations

- Settings → Data sources → select a data connection → Access

To choose how the Hex Agent handles sensitive connections in Slack, see Hex Agent data connection permissions.
Related documentation
- Hex Agent in Slack: using the agent in Slack, permissions, and sensitive-connection reply behavior.
- Hex MCP Server: connecting Claude, Cursor, and other MCP clients to Hex.