Slack
Send task notifications to a Slack channel, approve and retry with buttons, and control tasks with a slash command — each action run with the member's own role.
A chat channel sends notifications about tasks to Slack. With the app's signing secret, people can also act from
Slack. Set it up in Settings → Chat (administrators; permission settings.manage) or through
/orgs/:orgId/chat-channels in the API.
Create a Slack app with an incoming webhook
At api.slack.com/apps, create an app, turn on Incoming Webhooks and add one for the channel. In the
dashboard, add a Slack chat channel and paste the webhook URL. Choose the notices it takes and, optionally, the
projects it is limited to.
Add the signing secret (for buttons and commands)
Paste the app's Signing Secret (Slack: Basic Information). After saving, the channel shows a request
URL. In the Slack app, set it as the Interactivity request URL and as the request URL of a slash command,
for example /agent.
Link Slack accounts
Each member links their own account in Settings → Your account → Slack with their Slack member ID (Slack: profile → ⋮ → Copy member ID).
Send test posts a test message and shows what Slack answered.
Notices
| Notice | Default |
|---|---|
| Approval required, input required, recovery required, task failed, budget reached | On |
| Task completed, provider limit, worker offline, budget warning | Off |
Approval requests arrive with Approve and Deny buttons, recovery notices with Retry.
Slash command
| Command | Effect |
|---|---|
status | The tasks that wait for a person |
approve <task> / deny <task> [reason] | Decide an approval |
answer <task> <text> | Answer a task's question |
retry <task> / cancel <task> | Retry from the checkpoint, or cancel |
help | The list of commands |
<task> is a task ID or its last 6 characters.
Who an action runs as
- Every request from Slack is checked against Slack's signature, and refused when it is older than 5 minutes.
- An action runs as the organization member whose Slack member ID sent it, with that member's role, and is audited as that member. A viewer cannot approve from Slack either.
- Someone who is not linked is told how to link. A Slack member ID can belong to one member per organization.
Security
The webhook URL and the signing secret are credentials: they are stored encrypted and never shown again. On a
shared installation (DEPLOYMENT_MODE=cloud or REQUIRE_PUBLIC_CALLBACK_URLS=true, and so on the managed cloud)
webhook URLs must be public https addresses.
Verification status
Tested against a local fake of Slack that follows Slack's documentation (signatures, buttons, slash commands), not yet a real Slack workspace.