Teams bot
The Teams bot lets you chat with a Nexus agent by sending a direct message in Microsoft Teams. It is the same agent that answers in Nexus Chat.
Set up the bot (administrators)
Settings in TAO
Open Admin → Platform Config → Connectors and find the card Microsoft Teams — Inbound Bot. It says: "NOT the Teams connector — that is configured in the catalog above and handles outbound messages and the Teams tools. This is the Azure Bot registration for inbound 1:1 chat with a Nexus agent."
| Setting | What it is |
|---|---|
| Teams Bot Enabled | The master switch. When off, every message is acknowledged and nothing happens |
| Approve from Teams | Sends approval cards in direct messages. Off by default |
| App ID | The Azure Bot's application ID |
| App password | The Azure Bot's secret |
| Tenant ID | The tenant for a single-tenant bot |
| Allowed tenants | The tenants allowed to use the bot. Leave empty to admit any tenant that has the bot installed |
If you list specific tenants, only those can use the bot, and everyone else is refused with "Tenant not permitted."
In Azure
- Create an Azure Bot registration and set its messaging endpoint to
https://(portal)/api/v1/teams/messages, replacing(portal)with your TAO address. - A single-tenant bot works: enter the Tenant ID in TAO. A single-tenant bot with no tenant ID gets an error when it replies. A multi-tenant bot also works.
- TAO checks every incoming message's token, so only real messages from Teams are accepted.
Let people notice it
For proactive messages, each person also needs Microsoft Teams switched on under Settings → Notifications → Delivery Channels.
Message the bot
Find the bot in Teams and open a one-to-one chat. When it is first added, it sends a welcome card: "Welcome to TAO Agent … I am your AI agent in Microsoft Teams. You can ask questions, query project knowledge, and orchestrate workflows directly from here. All actions respect your TAO permissions and governance boundaries."
The bot works only in one-to-one chats. In a group chat or channel it says "Nexus is only available in 1:1 direct chats to protect data privacy. Please send me a direct message."
Linking is automatic
There is no button to link Teams. The first time you message the bot, it recognises you automatically if either of these applies:
- You have connected a Microsoft or Teams account in Connectors.
- You signed in to TAO with single sign-on using your Microsoft account.
It never matches by email address and never falls back to a shared account. Once matched, you are linked from then on.
If it cannot tell who you are, it replies: "Your Microsoft Teams account is not linked to a TAO account. Please sign in to TAO at (portal) and connect Microsoft Teams under Settings → Connectors, or contact your workspace administrator."
In Settings → Connectors → TAO bot the Microsoft Teams row then shows Linked, with "Auto-linked · workspace (tenant)". If not linked it says "Connect Microsoft Teams above (or sign in via SSO), then DM the bot — it links automatically the first time you message it."
Ask something
Send a message. The bot shows a typing indicator, then sends one reply. It answers as a normal Nexus chat in your account, titled "Teams: (start of your message)". Mentions such as @TAO are removed from your text.
- Files the agent creates are listed as portal links under "Files generated:". You must be signed in to open them.
- If an action was queued for approval, the reply ends with "(Note: An action was queued for human approval. Please review and approve it at (portal)/approvals to proceed.)"
| Situation | Reply |
|---|---|
| The agent has nothing to say | "I completed your request but produced no text output." |
| An error | "Sorry, an error occurred while processing your request: (error)" |
| It could not be queued | "Sorry, I could not process your message due to an internal queuing failure. Please try again in a moment." |
| No model set up | "No AI model has been configured for your account. Please set a model at (portal)/settings/credentials." |
| An empty message | Ignored with no reply |
Commands
Type a command in the chat. The slash is optional: the bare words also work, because Teams sometimes pastes the menu title without it.
| Command | What it does |
|---|---|
/new (or reset) | Archives the current chat and starts a fresh one. The card reads "Fresh Conversation Started" and says your memories continue. Your model is kept, and the project is kept unless a default project is set |
/project | A card Select Active Project with a dropdown and Switch Project. A toggle, "Remember as my default project for new Teams conversations", saves it as your default |
/project default | The same card in "Set Default Project" mode, with Save Default |
/project clear-default | "Your Teams default project has been reset to Personal." |
/status | Session Status: Active Project, Default Project, Session ID (first 8 characters), Model and Pending Approvals |
/approvals | Pending Approvals, listing up to 5 actions with a note to approve them in the portal. If none: "You have no pending approvals waiting for your review." |
/help | TAO Agent Commands & Help. Any unknown command shows this too |
- Choices include Personal plus every project you own or belong to. A project you cannot access shows "Access Denied — You do not have membership access to that project. The active project was not changed."
- After a successful switch: "Project Switched — Active project switched to (name)… Future queries in this chat will access this project's documents, tools, and memory space."
- If your default project is no longer accessible, the bot warns "Your default project is no longer accessible (membership revoked or project archived). Starting this conversation in your Personal workspace so you can continue working. Use
/projectto select an accessible project or update your default." - Teams' own Remove chat history only clears what you see in Teams. The chat and memories stay. Use
/newfor a clean start.
Approvals in Teams
By default, a queued approval arrives as a plain message with an Open approvals link to the portal. If an administrator turned on Approve from Teams, you get a card.
The card shows the action title and product (for example "Slack · Post Message"), a tier line (Irreversible or Affects your environment), a short summary, and Approve, Reject and Open in portal.
- Destructive actions need you to type the name shown on the card ("Type (name) to approve"). A wrong name says "That doesn't match. Nothing was done." After five wrong tries you are locked out of approving that item from chat for an hour: "Too many attempts — decide this one in the portal." Reject is always one click.
- While it works, the card says "Approved in progress…" or "Rejected in progress…". Then it shows the outcome: "Approved in Teams · Executed", "Rejected in Teams · Not performed", "Approved in Teams · Failed: (error) (full detail in the portal)" or "Approved in Teams · Outcome unknown — check before retrying". A decision made elsewhere reads "in the portal" or "in Slack".
- The decision also appears in Approvals with an "Approved in Teams" badge.
- If a card cannot be posted, you get a plain message instead: "Approval needed: (details)" with an "Open approvals" link.
Only the person the approval belongs to can decide it. Anyone else gets "Only the person this approval belongs to can decide it."
| Message | Meaning |
|---|---|
| "This was already decided." | Someone decided it first |
| "This build can't run this action — review it in the portal." | It cannot be approved from chat |
| "Approve this one in the portal." | This action must be approved in the portal |
| "Approving from Teams is turned off — use the portal." | The administrator switched it off |
| "Type the name shown on the card to approve." | You left the name box empty |
| "Couldn't record that — try again or use the portal." | The decision did not save |
| "This approval link is invalid." / "This approval no longer exists." | The card is out of date |
| "Too many attempts — decide this one in the portal." | More than 20 clicks in five minutes, or a lockout |
Chat approvals cover connector actions only. Workflow and desktop approvals are decided in the portal.
Notifications
When Microsoft Teams is switched on under Settings → Notifications → Delivery Channels ("DM me via the TAO bot in Teams"), the bot messages you when an approval is queued or a scheduled task finishes. It is off by default. You must be linked, the bot must be enabled, and you must have messaged the bot once first so it can reach you. The page says: "Delivered as a chat from the TAO bot in Teams. Message the bot once first so it can reach you." Messages go to your most recent Teams chat with the bot.
Unlink and default project
In Settings → Connectors → TAO bot, on the Microsoft Teams row:
- Unlink asks "Unlink Microsoft Teams?" and says messaging the bot shows the "link your account" prompt again, and your default project is kept. A toast says "Microsoft Teams unlinked from the TAO bot."
- Default project for Microsoft Teams bot chats sets where new chats start. A toast says "Default project for bot chats updated." If your saved default is no longer accessible you are told new chats start in Personal.
Security
- Every message is checked to be a genuine Teams message before anything runs.
- A message from an untrusted address or a tenant not on the allowlist is refused.
- You are matched one person at a time. There is no mapping of a whole tenant to an organization, and no shared fallback account.
- The agent runs as you, with your own project access and permissions.
- Approvals can be decided only by their owner.