Slack
The Slack integration lets an agent use Slack as a tool while it helps someone: search messages and files, look up people and conversations, spin up a channel and invite the right people, and — when you enable it — perform governed workspace admin actions such as archiving a stale channel or removing an offboarded user. The agent acts as the person it’s helping for everyday actions, so it only ever sees and does what that person could already see and do in Slack.This is not the Slack channel. This integration is about an agent using Slack
while a conversation happens somewhere else (the web widget, Teams, and so on). If
you instead want employees to chat with the agent inside Slack, set up the
Slack channel — a separate, complementary feature.
Modules
Set up read access
Read access takes about a minute and needs nothing in your Slack admin settings — Cobalt hosts the Slack app.1
Add the integration
From your agent, open Integrations, choose Slack, and keep the
Messaging module on. Reads are on by default; the write modules below are off
until you turn them on.
2
Attest to the access requested
Review the read permissions (search, channels, DMs, files, profiles). The
higher-impact ones are flagged. Confirm, name the integration, and save.
3
Let people authorize themselves
The first time the agent uses a Slack tool for someone, that person is asked to
connect Slack. From then on the agent acts as them and is limited to what they can
already see in Slack.
Set up channel management (optional)
Turn on the Channel management module to let the agent create channels, invite people, and set topics as the asking person.1
Enable the module
On the Slack integration, switch on Channel management and the tools you want.
2
Attest to the additional permissions
Creating and managing channels are higher-impact, so Cobalt asks you to explicitly
confirm the extra permissions before saving.
Set up admin actions (optional)
Admin actions operate on your whole workspace, so they run under a separate admin authorization and are governed by policy. Slack offers two ways to authorize, depending on your plan — pick yours with the tier selector on the integration’s authorization screen.1
Enable the Admin module
Switch on the Admin module. Its tools stay in an Awaiting authorization
state — and the rest of the integration keeps working — until you complete the step
below.
2
Authorize — Enterprise Grid
If your workspace is on Enterprise Grid, choose that tier and click Connect.
You’ll sign in once as an Org Admin to grant the admin permissions. Tokens are
stored encrypted; Cobalt never shows them again.
3
Authorize — Pro / Business+ / Plus
If you’re not on Enterprise Grid, choose that tier and paste a
workspace-owner User OAuth token (
xoxp-…). Admin actions Slack doesn’t permit
outside Enterprise Grid are clearly marked Requires Enterprise Grid and stay
unavailable.4
Confirm what the agent may do
Admin actions are gated: destructive ones (removing a member, archiving a channel)
ask for confirmation at the moment they run, and actions are limited by policy —
anything outside what you’ve permitted is denied rather than performed. Every action
is written to the audit trail.
What it does and doesn’t do
It does- Search and read Slack as the asking person (messages, files, channels, DMs, threads, profiles).
- Create channels, invite people, and set topics as the asking person.
- Perform governed, audited workspace admin actions (remove/invite a member, create/archive a channel, create a user group, change a role).
- Link every result back to Slack so people can open it in one click.
- Post messages or send DMs as you. The agent can create a channel and invite people, but composing and sending messages on your behalf is intentionally not part of this version — it surfaces the new channel’s link so you post the first message yourself.
- Replace the Slack channel. This integration doesn’t host conversations in Slack — see the Slack channel for that.
- Download file contents. File results include a link you open in Slack, not the file’s bytes.
- Bypass Slack’s permissions. Everyday actions run as the asking person and respect their Slack access; admin actions run only within the authorization and policy you set.
Troubleshooting
- An admin action says “Requires Enterprise Grid.” That action isn’t available with a non-Grid workspace-owner token. Either upgrade the workspace’s Slack plan or skip that action.
- The admin tools show “Awaiting authorization.” The Admin module is on but admin authorization hasn’t been completed — finish the connect/paste step on the authorization screen.
- An admin action was denied. It fell outside the policy you’ve permitted, or a destructive action wasn’t confirmed. Check the audit trail for the reason.
- “That channel isn’t visible.” For as-yourself actions, the agent only sees channels the asking person belongs to — have them join the channel in Slack, or use an admin action if appropriate.
FAQs
Is this the same as adding Slack as a channel?
Is this the same as adding Slack as a channel?
No. The Slack channel lets employees chat with the agent inside Slack. This
Slack integration lets the agent use Slack as a tool during a conversation that’s
happening elsewhere. They’re independent and can both be on at once.
Whose identity do Slack actions use?
Whose identity do Slack actions use?
Everyday actions (search, read, create channel, invite) run as the person the agent
is helping, using their own Slack authorization. Admin actions run under the
separate admin authorization you set up, and are governed by policy and audited.
Do I have to register a Slack app?
Do I have to register a Slack app?
Not for reads or channel management — Cobalt hosts that Slack app. Enterprise Grid
admin authorization is a one-time Connect as an Org Admin; non-Grid admin
authorization uses a workspace-owner token you paste.
Can the agent post messages or DM people for me?
Can the agent post messages or DM people for me?
Not in this version. Sending messages as you is intentionally held back; the agent can
scaffold a channel and invite people, then hand you the link to post the first message.
Will the agent ever see private channels or DMs someone can't access?
Will the agent ever see private channels or DMs someone can't access?
No. For as-yourself actions the agent is limited to exactly what that person can see in
Slack — Slack enforces it, not Cobalt.
Related
- Integrations overview — how integrations work in general.
- Slack channel — chatting with the agent inside Slack (the separate feature).
- How Cobalt works — where integrations fit.
