Skip to content
Last updated

Connect Slack

WebDesktop

The Slack connector lets Treasure AI Studio agents work in the conversations your team already has. An agent can search months of messages for the decision nobody wrote down, pull a thread into a summary alongside your customer data, and post the result back to the channel that needs it — without anyone copying text between two windows. Use it when the answer to a question lives in Slack rather than in a table, or when the output of a chat belongs in a channel rather than in a file.

This connection can write. The agent posts, edits, deletes, uploads files, and adds reactions as the person who authorized it, so its messages carry that person's name and avatar. It also reads only what that person can read. See What the Agent Can Do for the full list of operations.

New to connections?

Read Connections first for the general model — the difference between a connector and a connection, and the administrator vs. user roles. This page covers the Slack-specific steps.

Objective

Enable the Slack connector for your account and authorize a connection, so the agent can search, read, and post Slack messages as you during a chat.

Prerequisites

  • Account administrator privileges in Treasure AI Studio — needed for Step 1 only (enabling the connector)
  • A Slack account in the workspace you want the agent to work in. The agent reads and writes as this account, so its reach follows your own Slack membership — see What the Agent Can See
  • Permission in your Slack workspace to authorize the Treasure AI Studio app. If your workspace requires admin approval for apps, a Slack workspace administrator approves it once for everyone

Who Does What

Setting Slack up touches three roles, and only the first two do any configuration. Each does its part once.

Role What They Do How Often
Treasure AI Studio administratorAdds the Slack connector in Connector Settings and saves it. There are no fields to fill in.Once for the organization
Slack workspace administratorNothing, unless the workspace restricts which apps its members may use. In that case, approves the Treasure AI Studio app.Once for the workspace, and only if apps are restricted
Each memberAuthorizes their own connection from Connections and approves the requested access in Slack.Once per person

There is no app to install, no bot user to invite to a channel, and no network policy rule to add.


Step 1 — Enable the Slack Connector (Administrator)

Treasure AI manages the Slack app for this connector, so there is nothing to register on the Slack API console and no client ID or secret to enter. The configuration form is empty.

  1. In Treasure AI Studio, open Settings → Connector Settings (under Organization).
  2. Click Add Connector (or Add your first connector) and choose Slack.
  3. Click Save. There are no fields to fill in. The connector is saved already enabled, so Slack appears under Available on every user's Connections tab straight away.
The Configure Slack form in Connector Settings, showing no input fields at all, only Save and Cancel buttons, beside a Setup Guide panel explaining that each member connects their own Slack account after saving and that the agent acts as the member who connected

That is the whole administrator setup. Nothing else needs configuring. The saved row carries an enable toggle, and turning it off does more than stop new authorizations: it withdraws Slack from the agent's permitted actions immediately, including in chats that are already running, so every existing connection stops working until you turn it back on. The Setup Guide panel beside the form makes the same point: after saving, each member connects their own Slack account, and the agent acts as the member who connected.

Enabling the connector grants write access

There is no read-only mode. Every member who connects gives the agent the ability to post, edit, and delete messages under their own name — including the messages they posted themselves in the Slack client, not only the ones the agent wrote — open a direct message with any member of the workspace, upload and delete files, and add reactions. The permissions are fixed for the connector and cannot be narrowed per member or per channel. Decide that this is acceptable for your organization before you enable it, and tell members what the agent will be able to do on their behalf. If you need to withdraw that access later, turning the connector off is enough: it takes effect at once, and members keep their connections for when you turn it back on.

No network policy change is needed

The Slack connector lists no egress domains, and Connector Settings shows no "allow this domain" reminder for it. That is deliberate: the agent's sandbox never calls the Slack API. The request is made by Treasure AI's connector service outside the sandbox, so your network policy — which governs sandbox egress — does not apply to it and does not need a new rule.

The saved connector rows show the difference directly. The Treasure Data connector above lists a reminder for each domain it needs the sandbox to reach; the Slack row carries none:

Connector Settings with two saved connectors: Treasure Data expanded to show ten 'Allow ... in your network policy' reminders for its API domains, and Slack below it with an enable toggle and no reminders at all

Step 2 — Authorize Your Connection (User)

Each member who wants the agent to work in Slack authorizes their own connection. You can do this ahead of time from Settings, or on demand from a chat.

  1. Open Settings → Connections.
  2. Under Available, find Slack and click Connect.
  3. In the Slack popup, check the workspace shown at the top right and change it if you are signed in to more than one, then review the requested permissions and click Allow.
  4. When the popup closes, Slack appears in your connected list with the date you connected it.
The Connections page with Slack in the connected list showing the date it was connected, and Treasure Data still listed under Available with a Connect button

A Slack workspace administrator does not normally have to do anything for this. Authorizing is the whole install, and the Connect button is the only entry point — there is no separate install page to visit. Slack records the app under your name in the workspace's installed apps, but no bot user joins, no channel is touched, and there is nothing for an administrator to configure afterwards.

The exception is a workspace that restricts which apps its members may use. Slack then shows a request form instead of an Allow button. Submit the request, wait for a workspace administrator or App Manager to approve the Treasure AI Studio app once for everyone, then repeat Step 2.

To remove the connection later, click the delete (trash) icon next to it. The agent immediately loses access, and anything it already posted stays in Slack, exactly as if you had posted it yourself. Slack still lists Treasure AI Studio under your authorized apps until you remove it there as well.

Connect from a chat instead

You don't have to authorize in advance. If you ask the agent about Slack before you've connected, it shows a Connection Required card in the chat — click Connect there to run the same authorization without leaving the conversation. See Connect from a chat.

A connection authorizes one Slack workspace — the one you picked in the popup. To move the agent to a different workspace, delete the connection and authorize again, choosing that workspace. Studio holds one Slack connection per member at a time, so an agent cannot search two workspaces in the same chat.


Step 3 — Use Slack in a Chat

Once Slack is connected, ask the agent in plain language — no commands and no configuration in the chat. For example:

  • "Search #product-launch for how we decided on the pricing tiers, and summarize the thread."
  • "What did I miss in #support-escalations yesterday? Group it by customer."
  • "Post the segment counts from this analysis to #marketing-ops, and thread the query underneath."
  • "Find every message from the last month mentioning churn, then cross-check the accounts against my CDP segment."

The agent chooses its own operations. It typically searches or lists conversations first and reads the messages it needs. Because writes go out under your name, name the target channel explicitly rather than relying on the agent to infer one. The agent posts as you, so it can write anywhere you can write yourself, and nowhere you cannot.

Slack search accepts modifiers, such as in:channel-name to limit a search to one channel and from: with a member's handle or Slack user ID, and the agent passes them through when you phrase a request that way.

If you haven't connected yet, the agent asks for the connection first. The Connection Required card names the connector by its internal id, slack, in lower case:

A chat where the agent reports that no Slack connection is set up yet and shows a Connection Required card reading 'The agent needs a connection to slack. Please connect to continue.' with Decline and Connect buttons

Click Connect, authorize as in Step 2, and the agent carries on by itself — it confirms the connection and goes straight to the work you asked for:

The same chat after authorizing, showing a green 'Connected: slack' confirmation followed by the agent listing the channels it can read, beginning with #jira, #company, #random and #design
Check a message before the agent posts it

A message the agent posts is indistinguishable from one you posted, and it reaches everyone in the channel immediately. Ask the agent to show you the draft first when the channel is large or the content is sensitive. The agent can edit or delete its own message afterwards, but people who already read it have already read it.


What the Agent Can Do

The Slack connector exposes 23 operations. The agent calls them on its own; you never invoke them by name.

Area Operations What They Do
Conversationsslack.list_channels, slack.list_conversations, slack.get_conversation, slack.open_conversationList the public channels and the conversations of every type you can see, read one conversation's metadata, and open or resume a direct message with one person.
Reading messagesslack.get_channel_messages, slack.get_thread, slack.get_message_permalinkRead recent messages in a conversation, read a thread's replies, and get a message's permalink.
Searchslack.search_messagesSearch the messages you can see, with Slack's search modifiers (in:, from:), sorting, and paging. Up to 100 results per read.
Writing messagesslack.post_message, slack.reply_message, slack.update_message, slack.delete_message, slack.schedule_message, slack.post_ephemeral_messagePost a message or a threaded reply, edit or delete a message you posted, schedule a message for later, and post a message visible to one person only. Plain text, Block Kit blocks, and attachments are all supported.
Reactionsslack.add_reaction, slack.remove_reaction, slack.get_reactionsAdd and remove emoji reactions, and read the reactions on a message.
Filesslack.upload_file, slack.list_files, slack.get_file, slack.delete_fileList and read metadata for the files you can see, upload a file from a URL, and delete a file.
Peopleslack.list_users, slack.get_userList the workspace's members and read one member's profile metadata.

What the Slack Connector Does Not Expose

  • No bot identity. The connector authorizes you, not a workspace-wide app, so there is no Treasure AI bot user to invite to a channel and no messages posted as an app. This is also why search works: Slack's search API accepts user authorization only.
  • No admin operations. The agent cannot create or archive channels, invite or deactivate members, change workspace settings, or read the audit log.
  • No Slack automation. Slash commands, interactivity, event subscriptions, and incoming webhooks are all off for this app. The agent acts only when you ask it to in a chat.
  • No file contents. The agent reads file metadata only — name, title, type and the Slack link. It never downloads a file, audio or otherwise.

What the Agent Can See

The Slack connector carries your own Slack authorization, so your Slack membership decides its reach:

  • Public channels in the connected workspace, whether or not you have joined them.
  • Private channels you are a member of, and no others.
  • Direct messages and group DMs you are part of, including their files.
  • Files shared in any of the above.

Slack enforces this when the request arrives, not Treasure AI Studio, and no prompt can widen it. A member cannot read a private channel through the agent that they cannot read in Slack. The agent can narrow the view — you can tell it to look only in one channel — but never widen it.

Your DMs are in scope

The connector's permissions include your direct messages, group DMs, and the files in them. An agent searching for a topic can surface a private conversation in your chat, and a chat you share with a colleague shows them what it found. If that is not acceptable, do not connect Slack — the permissions are fixed and cannot be reduced to public channels only.


Reference

ItemValue
ConnectorSlack
AuthenticationOAuth 2.0 Authorization Code with PKCE (user-to-machine), platform-managed Slack app
Authorization typeUser authorization only. No bot token, and no bot user added to your workspace
Slack scopes requestedSixteen user scopes: channels:read, groups:read, im:read, mpim:read, users:read, channels:history, groups:history, im:history, mpim:history, files:read, reactions:read, chat:write, im:write, files:write, reactions:write, search:read
Required configurationNone. The administrator saves the connector with no fields to fill in
AccessRead and write — 23 operations across conversations, messages, search, reactions, files, and members
Agent identityActs as the authorizing Slack account. Messages, edits, deletions, uploads, and reactions all appear under that person's name
Where requests are madeTreasure AI's connector service, outside the agent's sandbox
Egress domainsNone — the sandbox never reaches the Slack API, so no network policy rule is required
Search results per read100 maximum, paged
Channel messages per read100 maximum. Thread replies are not capped by the connector
Conversations or members per read200 maximum, except slack.list_channels, which returns 100
Files per read1,000 maximum
File upload sourceA publicly reachable HTTP or HTTPS URL, up to 100 MB. The agent cannot upload a file that exists only in its own sandbox
Token lifetimeTwelve hours, refreshed automatically. Slack token rotation is on, so a leaked token expires on its own rather than lasting indefinitely
Connections per memberOne, covering one Slack workspace
Why the connection expires and renews

Slack issues this connector a token that lasts twelve hours and replaces it on every renewal. Treasure AI refreshes it for you, so a connection keeps working across sessions and you do not need to reconnect on a schedule. The short lifetime is deliberate: the authorization can read every conversation you can see and post under your name, so a token that leaked would stop working within half a day instead of remaining valid until somebody noticed. You normally reconnect only if the authorization is revoked on the Slack side.

Troubleshooting

IssueSolution
Slack isn't listed on the Connections tabAn administrator must add the Slack connector in Connector Settings and enable it.
Slack shows a request form instead of an Allow buttonYour workspace requires administrator approval for apps. Submit the request, and ask a Slack workspace administrator to approve the Treasure AI Studio app. Then connect again.
The agent can't find a private channel you're inAsk the agent to list conversations rather than channels: slack.list_channels returns public channels only, and private channels appear only through slack.list_conversations. If that still finds nothing, confirm you authorized the workspace the channel belongs to — a connection covers one workspace, and the popup's workspace picker is easy to miss.
The agent can't post to a channelIt posts as you, so it can only post where you could post yourself. Join the channel in Slack, or ask to be invited if it is private, then ask again.
The agent can't read a channel a colleague mentionedExpected if you are not a member of it. The connector carries your Slack membership and cannot widen it. Join the channel in Slack, or ask to be invited if it is private, then ask again.
Search returns nothing for a message you can see in SlackConfirm the message is in the workspace you connected, since one connection covers one workspace. Slack search covers messages, not the contents of files or snippets. Narrowing the query with in:channel-name or from: helps when the right message is buried rather than missing.
A message the agent posted shows your name, not a botExpected. The connector authorizes you, so everything the agent writes is posted as you. There is no bot identity to post as.
The agent can't edit or delete a messageEditing is limited to the messages you posted, including ones you posted in the Slack client yourself. Deleting follows whatever your own Slack account is allowed to delete.
An action fails with a missing permission errorThe connector requests a fixed set of sixteen scopes at authorization time. If your authorization predates a change to that set, delete the connection and reconnect to request the current scopes.
The agent says the connection needs to be reconnectedThe authorization expired or was revoked on the Slack side. Reconnect from Settings → Connections.
The connector disappeared from the Connections tabAn administrator may have disabled it. Your connection is kept, but the agent cannot use Slack until the connector is enabled again.

Next Steps