In a team that lives in Slack, the decision sits in a thread
In a team that lives in Slack, half the calls exist nowhere but in a thread. The discount granted to a client is settled there, the reason a supplier was dropped is explained there, and the version of the process people actually follow reads better there than in the official document. It is written down, it is dated, and nobody owns it.
An AI plugged in without that knowledge answers with the confidence of a new joiner. It quotes the old price, suggests the supplier you walked away from, describes the process as it stood two years ago. The model is not the problem; nobody ever gave it what the company knows. We have written about that at length.
Connecting Slack settles that half of the problem. The other half is what decides whether you do it at all, and it is what the AI will be allowed to read once it is connected.
Channels, never direct messages
The read scope is not a setting you discover afterwards. Here is what the Slack connector reads, and what it never even asks for.
Direct messages are not filtered out after being read; they cannot be read at all, because Kastel never asks Slack for the permission that exposes them. You can check that yourself in Slack, on the app's permissions screen.
How a private channel enters your Kastel
Nothing enters a private channel by default. It takes three moves, and all three are yours.
You authorise the app in your workspace
The authorisation covers reading and nothing else. Kastel asks Slack for no write permission at all, so it cannot post, reply or edit a message even if someone asked it to.
You invite Kastel into the private channel, one channel at a time
Slack requires membership before an app can read a channel's history. Authorising the app is therefore not enough: without an explicit invitation into that specific channel, it stays invisible. It is the same gesture as adding a colleague, and it leaves the same trace in the channel.
Reading follows the channel's members, not your org chart
A private channel is filed under the department its members belong to. If those members span more than one department, or if one of them cannot be identified in your organisation, the content is filed nowhere and waits for an administrator's decision. Until then, nobody reads it.
A public channel is already readable by your whole company
This is where a sales page would be tempted to lie by omission. A public channel in your Slack can be read by anyone in your workspace today, without Kastel. When Kastel takes it in, it files it at company level, because that is where it already sits.
So Kastel does not close your Slack down, and it does not widen anything either. That is the only tenable promise: the permissions you have already set in Slack are the ones that apply. If a public channel holds something not everyone should read, the question is not about your AI, it is about that channel. The difference between setting a sharing preference and governing it lives exactly there.
A whole thread counts as one decision
A single message often means nothing. “Fine by me for the discount” only makes sense with the replies above it, the ones that say which discount and which client. Your Kastel therefore takes in the whole thread, root message and replies together, as one unit of context.
That is what avoids the out-of-context quote, the most common failure of an assistant plugged into a team messenger: answering with a sentence that is perfectly accurate, lifted out of a conversation that said the opposite two messages later.
What this connector does not do
The first load is slow, and that is a Slack limit rather than a Kastel choice. Slack caps apps that are not published on its Marketplace at one request per minute on a channel's history, fifteen messages at a time. An internal app, built by your own team for your own workspace, has no such cap. Both regimes are documented by Slack.
Reading is the only verb. Kastel posts nothing, replies to nobody, corrects no message, and asks Slack for no write permission.
Synchronisation is a periodic reconciliation rather than a live feed. Slack publishes no deletion log, so a deleted message is noticed on the following pass. It is not erased for that: it is marked as gone at the source and stays readable by the same people as before, until an administrator decides to erase it. An answer already given that cited it has to remain verifiable.
Install the free core and connect your Slack.
Kastel's core is free to self-host, with every connector and no size limit. The connection guide shows the exact moves, including how a private channel gets invited in.
Read the connection guide