Slack bot
The Slack bot lets you chat with a Nexus agent by sending a direct message in Slack. In Slack it is called TAO Assistant. Its welcome message calls it "TAO Agent".
Set up the bot (administrators)
An administrator installs the bot once for the whole Slack workspace. People in the workspace then message it, and nobody installs anything individually.
What you need
- Permission to change Platform Config (admin config permission).
- The ability to create an app in your Slack workspace.
Settings in TAO
Open Admin → Platform Config → Connectors and find the card Slack — TAO Bot. It states: "NOT the Slack connector — that is configured in OAuth Provider Credentials above and handles the Slack tools (as the connected user). This is the 'TAO Assistant' Slack app for 1:1 chat with a Nexus agent."
| Setting | What it is |
|---|---|
| TAO Slack Bot Enabled | The master switch. When off, the bot does nothing |
| Approve from Slack | Lets approval cards appear in direct messages. Off by default |
| App ID | Every request from Slack must come from this app |
| Client ID and Client Secret | Used to install the bot and for "Sign in with Slack" |
| Signing secret | Used to check that every request really comes from Slack |
| Allowed workspaces | A comma-separated list of workspace IDs. Leave empty to admit any workspace that installs the app |
Changes apply within about 30 seconds without a restart.
Set up the Slack app
Create the app
At api.slack.com/apps choose Create New App → From an app manifest, and paste the manifest your TAO team provides.
Copy the keys
On Basic Information, copy the App ID, Client ID, Client Secret and Signing Secret.
Set the scopes
The bot needs exactly these bot token scopes:
chat:write,im:history,im:read,im:write,users:readandcommands. Leave Token Rotation off.Set the web addresses
Replace
(portal)with your TAO address.Where in Slack Address Event Subscriptions: Request URL https://(portal)/api/v1/slack/eventsInteractivity: Request URL https://(portal)/api/v1/slack/interactionsSlash command /tao: Request URLhttps://(portal)/api/v1/slack/commandsOAuth redirect URLs https://(portal)/api/v1/slack/install/callbackandhttps://(portal)/api/v1/slack/link/callbackUnder Event Subscriptions, subscribe to the bot events
message.imandapp_home_opened. On App Home, turn on the Messages tab and allow users to send messages. Turn on public distribution so other workspaces can install it.Enter the values in TAO
Paste the App ID, Client ID, Client Secret and Signing Secret into the card, switch on TAO Slack Bot Enabled, and save. Optionally add an allowlist, and switch on Approve from Slack.
Install it into the workspace
In the card's Workspaces panel, click Add to Slack. The panel notes: "Installing adds TAO to the whole Slack workspace — people there then DM it; nobody installs it individually." Approve in Slack. You return to the admin page with "Installed into workspace X."
Screenshot placeholderScreenshot to add: The Workspaces panel with the Add to Slack button and an Installed workspace.
The panel lists each workspace as Installed or Uninstalled, with "Not installed in any workspace yet." when empty. If something goes wrong you see "Install failed: (code)". Reinstalling updates the same row. If someone removes the app from Slack, the workspace is marked uninstalled automatically.
Message the bot
Find it
Look for TAO Assistant in the Apps section of Slack, and open a direct message. The first time you open its Home tab, it sends you a welcome:
Welcome to TAO Agent — I am your AI agent in Slack. DM me to ask questions, query project knowledge, and orchestrate workflows. All actions respect your TAO permissions and governance boundaries.
It lists the commands and has an Open Portal button. If you message the bot anywhere other than a direct message, it replies "I only work in direct messages, to protect data privacy. Please send me a DM instead."
Link your TAO account
The bot has to know which TAO user you are. It never guesses from your email address. Your account is recognised in this order:
- An existing link. If you were linked before, you are recognised straight away. A disabled link or an inactive account gets no reply.
- Automatic link. If you connected the Slack connector in Connectors, and it matches your Slack workspace and user, the bot links you silently.
- Link yourself. Otherwise the bot replies "Your Slack account is not linked to a TAO account. Connect your Slack account under Settings → Connectors (or ask your workspace admin), then message me again." with an Open My Connectors button.
Open Connectors
In TAO, go to Settings → Connectors and find the TAO bot section.
Link your account
On the Slack row click Link your TAO account. You are taken to Sign in with Slack. You must already be signed in to TAO, and must stay signed in as the same person.
Return to TAO
Slack sends you back to Connectors. The row now says Linked ("Linked by you · workspace T…"). TAO stores only your Slack identity and never keeps a Slack token.
Screenshot placeholderScreenshot to add: The TAO bot section with the Slack row showing Linked by you and an Unlink link.
If it fails you see an error code in the address, such as session_mismatch, exchange_failed, userinfo_failed or missing_identity. The portal does not show a message for these, so check the row status. If that Slack identity is already linked to another TAO account you see: "This Slack identity is already linked to a different TAO account. Ask that account's owner to unlink it first, or link a different Slack account."
Ask something
Send any message. The bot posts "Thinking…" and replaces it with the answer. It answers as a normal Nexus chat in your account. A new chat is titled "Slack: (start of your message)".
- Replies longer than about 3,900 characters are split. The rest arrive as thread replies under the first message.
- Links and bold text are converted to Slack's format.
- If an action was queued for approval, the reply ends with "(Note: An action was queued for human approval. Please review and approve it at (portal)/approvals to proceed.)"
- Files the agent creates appear under "Files generated:" as portal links, so you must be signed in to open them. Working files show as "N working file(s) from this run is/are in the portal."
| Situation | Reply |
|---|---|
| The agent has nothing to say | "I completed your request but produced no text output." |
| An error | "Sorry, an error occurred while processing your request: (error)" |
| It could not be queued | "Sorry, I could not process your message due to an internal queuing failure." |
| No model set up | "No AI model has been configured for your account. Please set a model at (portal)/settings/credentials." |
Commands
Slack reserves the slash, so there is a single command, /tao, with a word after it. Typing the bare word in the direct message also works.
| Command | What it does |
|---|---|
/tao new | Archives the current chat and starts a fresh one. Reply: "Started a fresh conversation. Active project: (name)". Your memories remain |
/tao project | Shows a project picker. Choosing a project switches at once ("Active project switched to X."). Remember current as default saves it as your default ("Remembered your active project as the default for new Slack conversations.") |
/tao project clear-default | Resets your default to Personal ("Your Slack default project has been reset to Personal.") |
/tao status | Shows your active project, default project, session ID (first 8 characters), model and pending approvals, with Switch Project and New Chat buttons |
/tao approvals | "You have N pending action(s) awaiting your review." or "You have no pending approvals.", with an Open Approvals button |
/tao help | Lists the commands |
Choices include Personal plus every project you own or belong to. Picking one you cannot access shows "Access Denied: You do not have membership access to that project. The active project was not changed." If your default is no longer accessible, /tao status shows "(Access Revoked)" and warns that new chats land in Personal.
Approvals in Slack
By default the bot sends a plain message with an Open approvals button, and you decide in the portal. If an administrator turned on Approve from Slack, you get an interactive card instead.
The card shows Approval needed, the action title and its product (for example "Slack · Post Message"), a tier line (Irreversible or Affects your environment), and the buttons Approve, Reject and Open in portal.
- When you click, the card shows "Approve in progress…" and then the result: "Approved in Slack · Executed", "Rejected in Slack · Not performed", "Approved in Slack · Failed: (error) (full detail in the portal)" or "Approved in Slack · Outcome unknown — check before retrying".
- Destructive actions open a window titled Confirm approval: "This cannot be undone." Type the name shown to approve. A wrong name says "That doesn't match. Nothing was done." After five wrong tries, even the right name is refused: "Too many attempts — decide this one in the portal."
- Reject is always one click.
- The decision is also recorded on the Approvals page, with the badge Approved in Slack or Rejected in Slack.
Only the person the approval belongs to can decide it. Anyone else, or an unlinked or disabled account, sees "Only the person this approval belongs to can decide it."
| Message | Meaning |
|---|---|
| "This was already decided." | Someone decided it first |
| "This build can't run this action — review it in the portal." | It cannot be approved from chat |
| "Approve this one in the portal." | This action must be approved in the portal |
| "Approving from Slack is turned off — use the portal." | The administrator switched it off. Checked on every click |
| "Couldn't record that — try again or use the portal." | The decision did not save |
| "This approval no longer exists." | It was withdrawn |
More than 20 clicks in five minutes is refused. Chat approvals cover connector actions only. See Approvals.
Notifications
To get a message from the bot when an approval is queued or a scheduled task finishes, turn on Slack under Settings → Notifications → Delivery Channels ("DM me via the TAO bot in Slack"). It is off by default, and it needs a linked account and the administrator's bot switch on. See Chat Channels.
Unlink and default project
In Settings → Connectors → TAO bot, on the Slack row:
- Unlink asks "Unlink Slack?" and shows "Slack unlinked from the TAO bot." Your default project is kept.
- Default project for Slack bot chats sets where new chats start. A toast says "Default project for bot chats updated."
Security
- Every request is checked with Slack's signature, and old or replayed requests are rejected.
- The bot reads only your direct message with it, never channel history.
- The bot's workspace token is stored encrypted. The sign-in step uses your identity only, and the token is discarded at once.
- You keep your own permissions. The bot cannot do what you cannot.
- Slack is linked one person at a time. The allowlist is the only workspace-level control.