Docs
Sign in

Slack bot

The Slack bot lets you chat with a Nexus agent by sending a direct message in Slack. In Slack it is called TAO Assistant. Its welcome message calls it "TAO Agent".

Screenshot to add: A direct message with the TAO Assistant in Slack with a reply under a Thinking placeholder.

Set up the bot (administrators)

An administrator installs the bot once for the whole Slack workspace. People in the workspace then message it, and nobody installs anything individually.

What you need

  • Permission to change Platform Config (admin config permission).
  • The ability to create an app in your Slack workspace.

Settings in TAO

Open Admin → Platform Config → Connectors and find the card Slack — TAO Bot. It states: "NOT the Slack connector — that is configured in OAuth Provider Credentials above and handles the Slack tools (as the connected user). This is the 'TAO Assistant' Slack app for 1:1 chat with a Nexus agent."

SettingWhat it is
TAO Slack Bot EnabledThe master switch. When off, the bot does nothing
Approve from SlackLets approval cards appear in direct messages. Off by default
App IDEvery request from Slack must come from this app
Client ID and Client SecretUsed to install the bot and for "Sign in with Slack"
Signing secretUsed to check that every request really comes from Slack
Allowed workspacesA comma-separated list of workspace IDs. Leave empty to admit any workspace that installs the app

Changes apply within about 30 seconds without a restart.

Set up the Slack app

  1. Create the app

    At api.slack.com/apps choose Create New App → From an app manifest, and paste the manifest your TAO team provides.

  2. Copy the keys

    On Basic Information, copy the App ID, Client ID, Client Secret and Signing Secret.

  3. Set the scopes

    The bot needs exactly these bot token scopes: chat:write, im:history, im:read, im:write, users:read and commands. Leave Token Rotation off.

  4. Set the web addresses

    Replace (portal) with your TAO address.

    Where in SlackAddress
    Event Subscriptions: Request URLhttps://(portal)/api/v1/slack/events
    Interactivity: Request URLhttps://(portal)/api/v1/slack/interactions
    Slash command /tao: Request URLhttps://(portal)/api/v1/slack/commands
    OAuth redirect URLshttps://(portal)/api/v1/slack/install/callback and https://(portal)/api/v1/slack/link/callback

    Under Event Subscriptions, subscribe to the bot events message.im and app_home_opened. On App Home, turn on the Messages tab and allow users to send messages. Turn on public distribution so other workspaces can install it.

  5. Enter the values in TAO

    Paste the App ID, Client ID, Client Secret and Signing Secret into the card, switch on TAO Slack Bot Enabled, and save. Optionally add an allowlist, and switch on Approve from Slack.

  6. Install it into the workspace

    In the card's Workspaces panel, click Add to Slack. The panel notes: "Installing adds TAO to the whole Slack workspace — people there then DM it; nobody installs it individually." Approve in Slack. You return to the admin page with "Installed into workspace X."

    Screenshot to add: The Workspaces panel with the Add to Slack button and an Installed workspace.

The panel lists each workspace as Installed or Uninstalled, with "Not installed in any workspace yet." when empty. If something goes wrong you see "Install failed: (code)". Reinstalling updates the same row. If someone removes the app from Slack, the workspace is marked uninstalled automatically.

Message the bot

Find it

Look for TAO Assistant in the Apps section of Slack, and open a direct message. The first time you open its Home tab, it sends you a welcome:

Welcome to TAO Agent — I am your AI agent in Slack. DM me to ask questions, query project knowledge, and orchestrate workflows. All actions respect your TAO permissions and governance boundaries.

It lists the commands and has an Open Portal button. If you message the bot anywhere other than a direct message, it replies "I only work in direct messages, to protect data privacy. Please send me a DM instead."

Link your TAO account

The bot has to know which TAO user you are. It never guesses from your email address. Your account is recognised in this order:

  1. An existing link. If you were linked before, you are recognised straight away. A disabled link or an inactive account gets no reply.
  2. Automatic link. If you connected the Slack connector in Connectors, and it matches your Slack workspace and user, the bot links you silently.
  3. Link yourself. Otherwise the bot replies "Your Slack account is not linked to a TAO account. Connect your Slack account under Settings → Connectors (or ask your workspace admin), then message me again." with an Open My Connectors button.
  1. Open Connectors

    In TAO, go to Settings → Connectors and find the TAO bot section.

  2. Link your account

    On the Slack row click Link your TAO account. You are taken to Sign in with Slack. You must already be signed in to TAO, and must stay signed in as the same person.

  3. Return to TAO

    Slack sends you back to Connectors. The row now says Linked ("Linked by you · workspace T…"). TAO stores only your Slack identity and never keeps a Slack token.

    Screenshot to add: The TAO bot section with the Slack row showing Linked by you and an Unlink link.

If it fails you see an error code in the address, such as session_mismatch, exchange_failed, userinfo_failed or missing_identity. The portal does not show a message for these, so check the row status. If that Slack identity is already linked to another TAO account you see: "This Slack identity is already linked to a different TAO account. Ask that account's owner to unlink it first, or link a different Slack account."

Ask something

Send any message. The bot posts "Thinking…" and replaces it with the answer. It answers as a normal Nexus chat in your account. A new chat is titled "Slack: (start of your message)".

  • Replies longer than about 3,900 characters are split. The rest arrive as thread replies under the first message.
  • Links and bold text are converted to Slack's format.
  • If an action was queued for approval, the reply ends with "(Note: An action was queued for human approval. Please review and approve it at (portal)/approvals to proceed.)"
  • Files the agent creates appear under "Files generated:" as portal links, so you must be signed in to open them. Working files show as "N working file(s) from this run is/are in the portal."
SituationReply
The agent has nothing to say"I completed your request but produced no text output."
An error"Sorry, an error occurred while processing your request: (error)"
It could not be queued"Sorry, I could not process your message due to an internal queuing failure."
No model set up"No AI model has been configured for your account. Please set a model at (portal)/settings/credentials."

Commands

Slack reserves the slash, so there is a single command, /tao, with a word after it. Typing the bare word in the direct message also works.

CommandWhat it does
/tao newArchives the current chat and starts a fresh one. Reply: "Started a fresh conversation. Active project: (name)". Your memories remain
/tao projectShows a project picker. Choosing a project switches at once ("Active project switched to X."). Remember current as default saves it as your default ("Remembered your active project as the default for new Slack conversations.")
/tao project clear-defaultResets your default to Personal ("Your Slack default project has been reset to Personal.")
/tao statusShows your active project, default project, session ID (first 8 characters), model and pending approvals, with Switch Project and New Chat buttons
/tao approvals"You have N pending action(s) awaiting your review." or "You have no pending approvals.", with an Open Approvals button
/tao helpLists the commands

Choices include Personal plus every project you own or belong to. Picking one you cannot access shows "Access Denied: You do not have membership access to that project. The active project was not changed." If your default is no longer accessible, /tao status shows "(Access Revoked)" and warns that new chats land in Personal.

Approvals in Slack

By default the bot sends a plain message with an Open approvals button, and you decide in the portal. If an administrator turned on Approve from Slack, you get an interactive card instead.

Screenshot to add: An approval card with Approve, Reject and Open in portal buttons.

The card shows Approval needed, the action title and its product (for example "Slack · Post Message"), a tier line (Irreversible or Affects your environment), and the buttons Approve, Reject and Open in portal.

  • When you click, the card shows "Approve in progress…" and then the result: "Approved in Slack · Executed", "Rejected in Slack · Not performed", "Approved in Slack · Failed: (error) (full detail in the portal)" or "Approved in Slack · Outcome unknown — check before retrying".
  • Destructive actions open a window titled Confirm approval: "This cannot be undone." Type the name shown to approve. A wrong name says "That doesn't match. Nothing was done." After five wrong tries, even the right name is refused: "Too many attempts — decide this one in the portal."
  • Reject is always one click.
  • The decision is also recorded on the Approvals page, with the badge Approved in Slack or Rejected in Slack.

Only the person the approval belongs to can decide it. Anyone else, or an unlinked or disabled account, sees "Only the person this approval belongs to can decide it."

MessageMeaning
"This was already decided."Someone decided it first
"This build can't run this action — review it in the portal."It cannot be approved from chat
"Approve this one in the portal."This action must be approved in the portal
"Approving from Slack is turned off — use the portal."The administrator switched it off. Checked on every click
"Couldn't record that — try again or use the portal."The decision did not save
"This approval no longer exists."It was withdrawn

More than 20 clicks in five minutes is refused. Chat approvals cover connector actions only. See Approvals.

Notifications

To get a message from the bot when an approval is queued or a scheduled task finishes, turn on Slack under Settings → Notifications → Delivery Channels ("DM me via the TAO bot in Slack"). It is off by default, and it needs a linked account and the administrator's bot switch on. See Chat Channels.

Unlink and default project

In Settings → Connectors → TAO bot, on the Slack row:

  • Unlink asks "Unlink Slack?" and shows "Slack unlinked from the TAO bot." Your default project is kept.
  • Default project for Slack bot chats sets where new chats start. A toast says "Default project for bot chats updated."

Security

  • Every request is checked with Slack's signature, and old or replayed requests are rejected.
  • The bot reads only your direct message with it, never channel history.
  • The bot's workspace token is stored encrypted. The sign-in step uses your identity only, and the token is discarded at once.
  • You keep your own permissions. The bot cannot do what you cannot.
  • Slack is linked one person at a time. The allowlist is the only workspace-level control.

Known gaps

Related pages