Now accepting SMB clients. Book a call →

Setup Guide

PUT YOUR AI AGENT
IN YOUR SLACK.

Your OLY.AI agent works out of a dedicated Slack channel, alongside a human coach from our team. This is the whole setup: connect Slack, create the channel, invite the agent. Most teams are done in about ten minutes, and you can revoke access at any time from your own Slack admin.

Before You Start

IT ONLY EXISTS WHERE
YOU INVITE IT.

Worth knowing before you send this to IT: a Slack app can only read conversations in channels it has been added to. Your agent has no view of the rest of your workspace: not other channels, not DMs, not anything it hasn't been invited to.

What the agent can do

  • Read messages in the channels you invite it to
  • Read files you share in those channels
  • Post messages, reports and files back to those channels
  • See who sent what, so it can address people by name

What it cannot do

  • Read channels it hasn't been added to, public or private
  • Read anyone's direct messages
  • Search your workspace history
  • Change workspace settings, or add and remove members

The short version for your security reviewer

We request channel-scoped permissions only. There are no admin scopes, no workspace-wide search, and no email-address access in the install. Remove the agent from a channel and its access to that channel ends immediately.

Option A · Recommended

ONE-CLICK INSTALL.
NO TOKEN TO HANDLE.

The fastest and safest route. Slack shows you exactly what you're approving, then passes the credential straight to us. Nobody has to copy, paste, or send a token anywhere. You'll need permission to install apps in your workspace; if you don't have it, your Slack admin can complete this step in about a minute.

  1. Start the install

    Click the button below, or ask your Slack admin to. Slack will ask which workspace you're installing into.

    Add OLY.AI to Slack

  2. Review the permissions

    Slack lists every permission the app is asking for before anything is granted. Read it, and it should match the scope table further down this page. If it asks for anything beyond that list, stop and tell us.

  3. Approve

    Slack sends the credential directly to our servers over an encrypted connection. It's stored encrypted, and it's never displayed to you or to us in plain text.

  4. Create the channel and invite the agent

    Now jump to setting up the channel below. That's the part that decides what your agent can actually see.

Option B · For teams with an app-approval policy

CREATE THE APP YOURSELF,
THEN HAND US THE KEY.

Some companies require that every Slack app is registered and owned by their own workspace, so the scopes and the off switch stay in-house. If that's your policy, create the app on your side and share the bot token with us. It takes a few more minutes and leaves the registration entirely under your control.

  1. Create a new Slack app

    Go to api.slack.com/apps and choose Create New App → From scratch. Name it something your team will recognize in a member list:

    OLY.AI Agent

    Pick the workspace you want it to live in. If you run Slack Enterprise Grid, install it to the specific workspace the team uses, not the whole org.

  2. Add the bot token scopes

    In the left sidebar open OAuth & Permissions, scroll to Scopes → Bot Token Scopes, and add each scope in the table below. Add only these. If a scope isn't on the list, we don't need it.

    ScopeWhy it's needed
    app_mentions:readSee when someone @mentions the agent
    channels:historyRead messages in public channels it's invited to
    groups:historyRead messages in private channels it's invited to
    chat:writePost replies, summaries and reports
    files:readOpen spreadsheets and PDFs you drop in the channel
    files:writeUpload the reports it produces
    users:readMatch user IDs to names, so it can address people properly
    reactions:writeAcknowledge a request with an emoji while it works

    Both history scopes are channel-scoped by design: they grant history only for channels the agent has been added to. We deliberately don't request chat:write.public, so the agent can't post anywhere it hasn't been invited either.

  3. Install it to your workspace

    Still on OAuth & Permissions, click Install to Workspace at the top and approve the summary Slack shows you. If your workspace requires admin sign-off, this is where the request goes out.

  4. Copy the bot token

    After install, the same page shows a Bot User OAuth Token. It starts with:

    xoxb-…

    Copy it once, and treat it like a password from this point on. Take the token that starts xoxb-, not the one starting xoxp-. The xoxp- prefix is a user token tied to your personal account, and we don't want it.

  5. Send it to us securely

    This is the step worth slowing down for. See how to send the token below, and don't email it.

Option B, Continued

HOW TO SEND US
THE TOKEN.

A bot token is a live credential. Anyone holding it can act as that app in your workspace, which is why where it ends up matters more than how quickly it gets to us.

Don't send it by email, Slack DM, or a web form

All three keep a permanent copy somewhere you don't control: mail archives, message history, a form provider's database, backups of all of the above. That copy outlives the person who sent it. Please don't paste the token into our contact form either; that form isn't built to hold secrets.

Send it as a one-time secret link instead

Use whichever of these your company already has. All three create a link that self-destructs after a single view:

  • 1Password: share an item, set it to expire after one view
  • Bitwarden Send: set maximum access count to 1
  • onetimesecret.com: free, no account needed

Then send us the link, and tell us over a separate channel that it's on the way. If the link has already been opened when we get to it, we'll assume it's been intercepted and ask you to rotate the token.

What we do on our side

The token is stored encrypted at rest, scoped to your account alone, and never written to logs. It's used only to run your agent in the channels you've invited it to. If you ever want it gone, say the word and we'll delete it, or revoke it yourself, which works instantly and doesn't require us at all.

Both Options

CREATE THE CHANNEL,
INVITE THE AGENT.

Installing the app doesn't give your agent visibility into anything yet. This is the step that does, and it's why we ask for a dedicated channel rather than dropping the agent into a busy one.

  1. Create a dedicated channel

    In Slack, click + → Create a channel. We suggest:

    #oly-agent

    Make it private if the work involves financials, payroll or anything else you'd rather not have workspace-wide. Private is the more common choice for finance teams, and it changes nothing about how the agent works.

  2. Add the people who'll work with it

    Keep it tight to start: the two or three people who'll actually assign work. Your OLY.AI coach joins this channel too, so you can ask questions and request changes without opening a ticket anywhere.

  3. Invite the agent

    Type this in the channel and hit enter:

    /invite @OLY.AI Agent

    Slack will confirm it's joined. From this moment the agent can see this channel, and still nothing else.

  4. Say hello

    Mention it and give it something to do. A good first test:

    @OLY.AI Agent what can you see in this channel?

    You should get a reply within a few seconds confirming what it has access to. If nothing happens, check troubleshooting below.

Later On

ONE CHANNEL PER JOB,
NOT ONE FOR EVERYTHING.

Most teams start with a single channel and expand once they trust it. When you do, give each agent its own channel rather than piling everything into one. It keeps the context clean and makes it obvious who's responsible for what.

  • A finance agent in #oly-finance, an ops agent in #oly-ops, each scoped to its own domain.
  • Invite the same way: /invite @OLY.AI Agent in the new channel.
  • Removing it from one channel doesn't affect any other.
See What a Second Agent Costs

A typical setup after a few months

#oly-agent: the original, general
#oly-finance: close, variance, cash
#oly-ops: vendor and inventory reporting

Each one sees only itself. None of them can see the others.

The Off Switch

HOW TO REVOKE ACCESS.

You should know how to turn this off before you turn it on. All three of these work without involving us, and take effect immediately.

  1. Remove it from one channel

    In that channel, run /remove @OLY.AI Agent. Its access to that channel ends immediately; other channels are unaffected.

  2. Uninstall the app entirely

    Go to Settings & administration → Manage apps, find the app, and remove it. Every token issued to it dies at once, across every channel.

  3. Rotate the token

    If you created your own app and think the token may have been exposed, open OAuth & Permissions, revoke the existing token, reinstall to generate a fresh one, and send us the new one the same secure way. Tell us when you do, so we're not surprised by the interruption.

IF SOMETHING ISN'T WORKING

The agent isn't responding in the channel

Check it's actually a member. Click the channel name and look at the Integrations tab. If it's not listed, run /invite @OLY.AI Agent again. If it is listed and still silent, tell your coach; it's almost always something on our side at that point, not yours.

Slack says the app needs admin approval

Your workspace restricts app installation, which is a sensible default. Slack will have sent a request to your admins, and approving it is a couple of clicks on their side. Send them this page if they want to see the permissions first.

It can't read a file I shared

Files uploaded before the agent joined aren't visible to it. Re-share the file in the channel and it'll pick it up. Files shared in other channels are never visible, by design.

We use Slack Enterprise Grid

Install to the specific workspace your team works in rather than org-wide. If you need it across several workspaces, tell us which ones and we'll walk through it on a call. Grid has a few org-level settings worth getting right the first time.

Can we use Microsoft Teams instead?

Slack is where the agent and coaching experience is most complete today. If Teams is a requirement for you, raise it on the discovery call and we'll be straight with you about what's ready and what isn't.

Do you need this before the discovery call?

No. Nothing here is needed to book or run a discovery call. This is a build-phase step, and your coach will do it with you on a screen share if you'd rather not do it alone.

Want Us to Set This Up With You?

Your coach will walk through it on a screen share and confirm the agent is working before you leave the call. If you're not a client yet, start with fifteen minutes and we'll show you what it would do in your channel.

Book Discovery Call