Connector · Slack

Slack for your AI assistant, with nothing posted in your name unseen.

PrivacyFence connects an AI assistant to Slack with your own user token, so it sees the channels, direct messages and group chats you can see, and nothing more. There is no bot to invite. The assistant can find conversations straight away; it reads messages only after you have looked at them, and it sends nothing until you approve.

What the assistant can do

Find, read after review, send after approval.

Every Slack tool has a gate fixed in code. The Tools reference lists each one.

Without a card

Listing channels, direct messages and group chats, and resolving a message link someone pasted into the conversation. These calls are still audited.

Reviewed before release

A channel's recent history, a thread's replies, and message search. You see exactly which messages would be released, then allow or deny.

Needs your approval

Sending a message to a channel or direct message, and starting a group chat. The card shows the conversation and the full text before anything is posted.

Personal data

Message text is checked before you see the card.

Before a reviewed read is shown to you, PrivacyFence scans the message text locally for likely personal data in English, German and Hungarian: IBANs, card numbers, ID and tax numbers, salary information and similar. Sender names and channel names are not scanned. Email addresses and phone numbers are deliberately not flagged, because nearly every signature has them.

A match sends the read to a card even if an always-allow rule covers the channel, highlights what was found, and asks for a second confirmation. The audit log records the category, never the matched text.

The privacy filter can also withhold whole kinds of Slack data from the assistant: message content, thread content, people's identities, and the channel, direct-message and group-chat lists. Each is set in Settings → Privacy Filter → Slack.

How the PII check works · The privacy filter

Routine requests

Trust a channel, not the whole workspace.

An always-allow rule lets matching requests run without a card, and each one is still audited. For Slack, a rule can trust:

Named channels

Reading, or posting to, the channels and people you list. A search runs without a card only when every result is from one of them.

Public channels only

A search whose results all come from public channels.

Direct messages

One-to-one direct messages. This matches any one-to-one conversation, not only notes to yourself.

Group chats

Group direct messages, and starting one.

Likely personal data in a read still goes to a card. Every scope is in the scope catalogue.

Set it up

One Slack app per workspace, then each person approves it.

  1. An administrator creates a Slack app once per workspace, with user token scopes only, and packages its client ID and secret into an organization config bundle. The app is never publicly distributed.
  2. Each person installs the bundle, connects Slack from PrivacyFence's Settings page, and approves the app in the browser.
  3. The Slack tools appear to the assistant. The token stays with PrivacyFence and is never given to the AI client.

Set it up Connecting a service

Next

See how a request is approved.

Follow a read and a write through PrivacyFence, card by card.