Start setting up an AI employee in Slack on [Viktor](https://viktor.com). Create your account, click Add to Slack from inside Viktor, approve the permission screen, pick one or two channels, connect the one tool your first task needs, and give him that task. Onboard him as you would [a new hire](https://viktor.com/blog/ai-onboarding-without-hr): start narrow and expand his access once he earns trust. You’ll have a working AI employee in one sitting.

Viktor is the AI employee that lives in Slack and Microsoft Teams, connects to 3,200+ tools, and does the work. A chatbot answers questions in a thread and an AI assistant returns a draft — Viktor queries live data, runs the workflow across connected tools, and returns the finished deliverable. That might be a posted channel summary, an updated HubSpot record, or a new Linear ticket; he doesn’t hand you the steps, he completes them.

## You need a paid Slack plan and a work email; allow fifteen minutes

Slack access comes first. Slack’s AI agent features require a paid Slack plan. You also need a work email and ten to fifteen minutes. You don’t need a credit card for Viktor.

- **Workspace install rights:** By default any full workspace member can install apps, unless a Workspace Owner has turned on app approval. If yours has, a Workspace Owner or designated app manager approves once.
- **An account and setup time:** Use a work email to create your Viktor account if you don’t sign in with Slack. Installation takes minutes; the rest of the time goes to choosing access and checking his first task.

## Pick your build route before you install anything

There are four ways to put an AI agent in Slack, and the right one depends on what your team already runs and how much setup work you want to own.

- **Salesforce Agentforce:** the Salesforce-native agent route, licensed and configured through Salesforce for teams already standardized on that stack.
- **A custom Slack API app you build:** you create the Slack app, add a bot user, request OAuth scopes, subscribe to events, and wire your own LLM and agent framework. Pick this only when no off-the-shelf app fits — you own the hosting, the scope reviews, and the maintenance.
- **A third-party app from the Slack Marketplace, such as Viktor:** install, approve the permission screen, and start delegating. Marketplace apps have passed Slack’s review for scope justification, TLS, privacy policy, and AI/LLM disclosure, and they keep standard rate limits; commercially distributed apps that aren’t listed are throttled to 1 request per minute on conversations.history.
- **A no-code automation platform such as Zapier, Make, or n8n:** you build the trigger-action rules yourself, one workflow at a time.

Build from scratch only when no listed app covers the work; otherwise install one and spend the time on the first task instead. The rest of this guide covers the Viktor install.

## How to set up an AI employee in Slack, step by step

Do it in this order. Account first, then Slack, then channels, then one tool, then one task. You gate each step behind the last one, which keeps Viktor’s access narrow until you’ve seen him do good work.

### Step 1: Create your account and add Viktor to your workspace

Sign in with Slack at [viktor.com](https://viktor.com), or create the account with your work email. Inside Viktor, click Add to Slack. Slack shows a permission screen with the information Viktor requests permission to view and the actions he requests permission to perform. Review the list and approve it.

If your workspace requires [admin approval for new apps](https://slack.com/help/articles/222386767-Manage-app-approval-for-your-workspace), this is the Slack app approval you need; connected tools may require separate approval. Slack sends the request to all Workspace Owners and designated app managers. After one of them approves it, you can continue setup.

After approval, continue to the channel picker in Step 2.

### Step 2: Pick his first channels

Onboarding asks which channels to add him to. Choose one or two low-risk channels where you already know what good output looks like: your team channel plus one working channel like #growth or #support. Slack’s standard bot-token membership model limits message-history access to channels a person added the app to. Review Viktor’s requested [token type and scopes](https://viktor.com/blog/how-to-control-what-your-ai-employee-can-access) before treating channel membership as the complete access boundary.

You can add him to more channels later through [Slack’s Agents & apps tab](https://slack.com/help/articles/33076000248851-Work-with-AI-agents-in-Slack), or a full workspace member in a channel can invite him with /invite.

### Step 3: Review his channel access

Open each selected channel’s Agents & apps tab and confirm that Viktor appears there. Treat each channel invitation as an access decision, and review the permission screen for user tokens or elevated scopes that can extend beyond standard bot-token channel membership.

### Step 4: Connect his first tool

Connect the one tool your first task needs, whether that’s HubSpot, Google Drive, Notion, or Linear, from [Viktor’s integrations page](https://viktor.com/integrations). Connect your CRM if the task is a pipeline check, or Google Drive if the task summarizes a document the team keeps referring to. Skip anything the task can run without, however useful it looks on the list.

Viktor connects to 3,200+ tools, but today you connect one. Where the tool offers a read-only connection, start there and add write access only when a task has to change data.

### Step 5: Run his first task and verify

@mention him in one of the channels from Step 2 with a small, checkable task:

> @Viktor summarize the last 30 messages in this channel into 5 bullets and flag anything that still needs a decision.

You can read 30 messages yourself, so you can check his five bullets against the source messages. Read the thread against what he returned and ask two questions:

- Does every decision still sitting open appear in his list?
- Did he flag anything the team already settled?

Once Step 4 is done, follow with a tool-backed task. An example: “@Viktor list the HubSpot deals that haven’t changed stage in 14 days and post them here.” Keep it small enough to verify and real enough to matter.

[Add Viktor to your Slack workspace and give it a first task](https://viktor.com/?utm_source=blog&utm_medium=cta&utm_campaign=how-to-set-up-your-ai-employee-in-slack). Start with $100 in free credits. No card required.

## If you build your own Slack app instead

You own the plumbing — which means more control and more steps.

1. **Create the Slack app and add a bot user.** Go to Slack’s app configuration, create a new app, and add a bot user to it.
2. **Add the bot token scopes your agent needs.** At minimum: `app_mentions:read` to see @-mentions, `chat:write` to post messages, `chat:write.public` to post in public channels the app hasn’t joined, `channels:history` and `groups:history` to read message history in channels someone added it to, and `users:read` for the member list. See the full [scope reference](https://docs.slack.dev/reference/scopes).
3. **Install the app to the workspace.** This issues the Bot User OAuth Token, which starts with `xoxb-`. That token represents the app itself and stays valid even if the person who installed it leaves.
4. **Subscribe to events and set your request URL.** Subscribe to `app_mention` at minimum, then point the request URL at your endpoint so the app receives messages.
5. **Get admin approval if the workspace requires it.** Approval requests go to all Workspace Owners and designated app managers. They can approve individual optional scopes rather than the whole package.

Two things to keep in mind before you finalize your scope list. First, scopes are additive — once granted, they can’t be removed without revoking the token entirely. Second, a bot token (`xoxb-`) can only read channels a person has explicitly added the app to. User tokens (`xoxp-`) carry the authorizing user’s much broader access. Request the smallest scope set that does the job.

## Wiring the model and the agent framework

When you build your own Slack agent, three layers sit between the incoming message and the reply the user sees. Here is how they connect:

1. **Slack sends the event.** A user @mentions your bot or DMs it. Slack fires an `app_mention` event to the HTTPS endpoint you registered in the App Manifest.
2. **A Slack SDK handles the handshake.** A library such as Bolt for Python or Bolt for JavaScript verifies the request signature, acknowledges the event within Slack’s three-second window, and carries thread context forward so replies land in the right conversation.
3. **An agent framework runs the tool-calling loop.** Frameworks such as the Claude Agent SDK, OpenAI Agents SDK, or Pydantic AI take the verified message, call whichever tools you have connected — calendars, CRMs, databases, APIs — and pass results back to the model you have chosen until the task is complete. The framework is model-agnostic; you wire in the model at configuration time.
4. **Your code posts the result.** Once the loop resolves, your code calls `chat.postMessage` with the `chat:write` scope to deliver the finished output to the channel or thread.

Two constraints shape what the retrieval layer can do. Slack’s API terms prohibit using Slack API data to train a large language model, and they prohibit persistent copies, archives, or indexes of another organization’s Slack data. That means retrieval must be query-by-query — you fetch what you need at the moment of the request and do not store it.

**Who should own this loop:** a team that can host the endpoint, monitor latency and failures, rotate credentials, and ship fixes when Slack updates its event schema. If that capacity exists in-house, building gives you full control over model choice and tool connections. If it does not, a managed agent is the lower-risk path.

## Who can talk to Viktor, and who manages Slack app access?

One install serves the [full workspace members](https://viktor.com/blog/how-to-roll-out-an-ai-employee-to-your-whole-team) who can use AI apps. Full workspace members in a channel he’s in can @mention him or DM him, so the account manager in #client-acme and the analyst in #ops-updates both start delegating the day he arrives. Slack guests cannot use AI apps or agents.

Workspace Owners manage [Slack app settings and permissions](https://viktor.com/blog/who-should-manage-your-ai-employee), and designated app managers can review requests. The person who added Viktor can return to viktor.com for the Viktor account, while Slack controls channel and workspace app access.

## What happens to your Slack data?

Zeta Labs isolates each customer workspace and never uses customer data to train models.

That isolation prevents another company running Viktor from reaching anything in your workspace, and it prevents your workspace from reaching anything in theirs.

Viktor is SOC 2 Type 1 certified, with SOC 2 Type 2 in progress. [Viktor’s security posture](https://viktor.com/blog/how-to-run-security-due-diligence-on-an-ai-employee) also includes CASA Tier 3, and Zeta Labs has ISO 27001 underway.

## How do you keep control as more people use him?

Widen his access the way you’d widen a new hire’s: one channel at a time, after the last one went well. In practice, the second channel goes in only after he has returned work in the first that you read and kept. The third follows the same test.

Add an integration once a task needs it, which usually means a task stalled because he couldn’t reach the tool. An unused connection is scope you’re carrying for no reason.

Before high-stakes actions such as sending an external email or deploying to production, Viktor asks for explicit confirmation and waits for someone to approve before he acts.

If a channel no longer needs him, remove him from it through the channel’s Agents & apps tab. Channel removal limits his access to that channel. A Workspace Owner or appointed app manager removes him from the workspace through Slack’s app management.

## Questions that come up during first installs

These answers cover installation rights, starting channels, tool access, and the first task.

### Do I need to be a Slack admin?

1. If your workspace requires app approval, a Workspace Owner or designated app manager must approve the request. After approval, you can continue setup.

### Where do I start, viktor.com or Slack?

viktor.com. Create your account there, then click Add to Slack from inside Viktor. The permission screen and channel setup follow from that one action.

### Does each team member install Viktor separately?

1. Adding him once puts him in the workspace for full workspace members. New full members who join a channel he is in can @mention him with no extra setup. Slack guests cannot use AI apps or agents.

### Which channels should he join first?

One or two low-risk internal channels where you already know what good output looks like. Client-facing shared channels can wait until you have watched a few tasks land internally.

### What should his first task be?

Anything whose source data you can scan yourself in under a minute. If you can, you can judge his answer the moment it posts.

### Do I connect all my tools during setup?

1. Connect the one tool your first task needs. Add the next one when a task stalls without it.

### What does this cost?

- **Slack licensing** — agent features require a paid Slack plan; the bot itself doesn’t consume a paid seat (bots are free members under Slack’s Fair Billing Policy).
- **Salesforce Agentforce** — licensed separately through Salesforce.
- **From-scratch build** — adds LLM token usage, hosting, and ongoing engineering time to maintain the agent loop.

Viktor is usage-based: $100 in free credits, no card required. Paid plans start at $50/month. Every feature and integration is available on every plan.

### What does Viktor see in Slack?

Check the permission screen. Standard bot tokens can read message history only in channels a person added the app to, while user tokens and elevated scopes can provide broader access.