Skip to main content

Slack Bot Integration

Govern AI agents that run as Slack bots. Unlike LLM providers, Slack bots are not proxied at the transport layer — they're discovered, classified, and governed at the observation layer through workspace inspection and webhook ingestion.

What gets governed​

For Slack-based AI bots, Rivaro can:

  • Discover the bot through the Slack workspace adapter (lists workspace apps, identifies the AI ones)
  • Observe the bot's interactions via webhook ingestion (events forwarded to Rivaro)
  • Apply policy to detected violations on the observed content
  • Track ownership and identity for the bot as an agent in the agent estate

What's not currently supported (by design):

  • Inline blocking of Slack messages mid-thread — Slack's API doesn't expose a synchronous proxy point for bot messages.
  • Streaming. Slack doesn't stream.

If you need inline enforcement for a Slack-deployed agent, route the agent's underlying LLM traffic through Rivaro's LLM Gateway — the gateway sits between the agent and OpenAI/Anthropic/etc. before the agent renders into Slack.

Discovery setup​

POST /api/admin/discovery/connectors
{
"type": "slack",
"name": "Slack Workspace — Engineering",
"configuration": {
"botToken": "xoxb-...",
"appLevelToken": "xapp-...",
"workspaceId": "T01..."
}
}

Required Slack scopes:

  • bots:read
  • users:read
  • team:read
  • apps.connections:read (for App-Level token)

Once configured, the Slack discovery adapter periodically scans the workspace and surfaces apps it classifies as AI bots — based on app metadata, scopes used, and message patterns.

Webhook ingestion​

For observation of message content, configure a Slack Events API subscription pointing at:

https://your-org.rivaro.ai/api/v1/connectors/webhook/{webhookToken}

webhookToken is generated when you create a Slack training/observation connector — see Training-Data Connectors.

Messages are scanned at Lifecycle.TRAINING against the connector's enabled detectors.

Promoting a Slack bot to an AppContext​

When a Slack bot is found in discovery and you decide to govern it, promote it to a governed AppContext:

POST /api/governance/assets/{assetId}/promote
{
"targetType": "AGENT",
"reviewNotes": "Slack bot — engineering on-call helper"
}

The resulting AppContext appears in Agent Management alongside your other agents. You can assign an owner, attach policy rules, set authority envelopes, and track this bot in the agentic dashboard just like any other agent.

What the bot adapter reports​

The Slack bot adapter (SlackBotAdapter) declares:

  • getModelId(): slack-bot
  • isExternalRequest(): false — bots are integrated, not proxied
  • requiresApiKey(): false
  • requiresModel(): false
  • supportsStreaming: false

In the discovery feed, Slack-detected assets are matched to this adapter by provider=slack or platform=slack metadata.

Audit trail​

Every observed message and every promoted-to-AppContext bot produces:

  • A discovery finding (initial observation)
  • A session entry per conversation (if webhook ingestion is enabled)
  • Governance history records on the agent (owner changes, policy attachments)

Use the standard session and audit ledger views to inspect Slack bot activity.

Next steps​