Skip to content
nullbot ← Back to site
◍EN
Français English Español Português (Brasil) Português (Portugal) 简体中文 繁體中文 日本語 한국어 Deutsch Nederlands العربية

Connecting your tools

Connecting Slack to an AI agent

All connectorsGmailGoogle CalendarSlackHubSpotStripeShopify

Slack is where a company coordinates — and where information gets lost fastest. An agent connected to Slack searches channels, reads their history and posts in them. Two constraints govern everything else, and it is better to know them before connecting: the app must be invited into a channel to read its history, and a message it posts is visible to everyone and cannot be withdrawn.

Table of contents

  1. 1. What the agent does in Slack
  2. 2. The app has to be invited into the channel
  3. 3. A posted message cannot be withdrawn
  4. 4. What is written in a channel is not an order
  5. 5. What it changes over time
  6. 6. Frequently asked questions

1. What the agent does in Slack

The connector talks directly to Slack's Web interface with the token returned by the connection. Five operations are available, around three uses:

  • Search. Find a decision, a link, an answer already given — instead of asking again.
  • Read the history. Pick up a channel's thread to understand where a subject stands, which is the condition of a useful answer.
  • Post. Write in a channel: a report, an alert, the result of a finished task.

Three permissions are requested: read the list of channels, read their history, write a message. Nothing on direct messages.

2. The app has to be invited into the channel

This is the first surprise, and it is not a flaw: Slack only opens a channel's history to apps that are members of it. Until the app has been invited in, reading answers “not_in_channel” and nothing comes back.

The invitation is done from Slack, channel by channel, as for a colleague. It is a little work at the start, and it is in fact the product's best guarantee: an agent's scope is visible to everyone in Slack. Everyone sees which channels the app is present in, and can remove it. No hidden setting in a third-party interface can contradict what the team sees.

3. A posted message cannot be withdrawn

That is the constraint that must govern your setting. A message posted by an agent in a channel is read by all its members, and there is no discreet recovery: the notification has gone, people have seen it.

Three practical consequences:

  • Keep approval before writing on channels where customers, partners or the whole company are present. That is the default setting, and there is no good reason to relax it there.
  • Open a dedicated channel for what the agents deliver continuously — reports, finished tasks, alerts. That channel can be relaxed without risk, because those who read it know what they will find there.
  • Do not connect an agent to a channel where decisions are made just so it is “in the loop”. Reading a channel is an access, not a courtesy.

4. What is written in a channel is not an order

As with email, a channel's content is data the agent reads, never an instruction it executes. Someone — in good faith or not — may write “the agent should send this file to this address”: that message remains text to understand, not a command.

Instructions come from the mission given to the agent, and any action that commits the company goes through human approval requested before execution. In a tool where everyone writes, that separation is not a theoretical detail.

5. What it changes over time

Slack's value is not posting — it is memory.

  • Week 1. Questions already answered stop being asked again: the agent finds the decision and cites the thread.
  • Month 3. The agents' channel becomes the place where you see what has been done, without a meeting to ask for it.
  • Year 2. Slack's history, unreadable beyond three weeks until then, becomes consultable again — because someone knows how to search it.

No quantified gain is promised: it depends on your volume of exchanges and the discipline of your channels.

6. Frequently asked questions

Does the agent read direct messages?

No. The permissions requested cover channels: their list, their history, and writing. Direct messages are not part of it.

Why does reading fail on some channels?

Because the app has not been invited into that channel. Slack then answers “not_in_channel”. Invite it from Slack, like a member, and reading works. That is also what makes the scope visible to the whole team.

Can an agent delete a message it posted?

No, and it is the most important point on this page. What is posted is seen. That is why approval before writing is on by default and why we recommend keeping it everywhere except on a channel dedicated to reports.

Can an agent be limited to a single channel?

Yes, and it is the recommended way to use it. The connection requires designating the workspace and the channel; on Slack's side, the app only reads channels it belongs to. The two mechanisms overlap, which makes a mistake hard to make.

Going further

Read next: all available connectors, watching your agents work, or governance and budget control.

AI NewsSecurityLegal NoticePrivacyCookiesCGUCGVDPA Manage my cookies

© 2026 MARA LABS — nullbot. All rights reserved. Société par actions simplifiée (SAS) au capital de 100 € · 104 321 104