> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sammylabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Slack Integration

> Secure, privacy-first Slack integration for policy notifications, JIRA ticket creation, and knowledge ingestion

Sammy Labs provides a comprehensive Slack integration that transforms Slack workspaces into intelligent knowledge management and policy tracking hubs. This integration delivers three core features that work together to create a seamless workflow where policies are discovered, tracked, analyzed, and actioned—all within Slack.

## Security First: Built with Privacy by Design

<Warning>
  **SAMMY on Slack follows the principle of least privilege** and is designed to only respond when explicitly invoked (e.g., an @mention in a thread). It does not inject itself into random public channels or send unsolicited messages.
</Warning>

**From the app manifest, SAMMY is granted access only to:**

<Columns cols={2}>
  <Card title="Read @mentions" icon="at">
    `app_mentions:read` - Detect when users explicitly mention @SAMMY
  </Card>

  <Card title="Post messages" icon="paper-plane">
    `chat:write` - Send responses and notifications to threads
  </Card>

  <Card title="Read files" icon="file">
    `files:read` - Access files in channels where SAMMY is added
  </Card>

  <Card title="Read channel history" icon="clock-rotate-left">
    `channels:history` - Read messages only in public channels SAMMY is explicitly added to
  </Card>
</Columns>

<Info>
  While Slack permissions allow SAMMY to read messages within channels it is added to, **SAMMY's application logic only processes and responds to user-triggered interactions** in channels where users have chosen to involve the bot.
</Info>

### What This Means for Your Organization

<Columns cols={3}>
  <Card title="No Passive Monitoring" icon="eye-slash">
    SAMMY never monitors or logs conversations in the background
  </Card>

  <Card title="User-Initiated Only" icon="hand-point-up">
    Processing only occurs when you @mention SAMMY or click an action button
  </Card>

  <Card title="Explicit Consent" icon="shield-check">
    You control exactly when and where SAMMY operates
  </Card>
</Columns>

***

## Core Capabilities

<Columns cols={3}>
  <Card title="Policy Notifications" icon="bell">
    Automated policy updates delivered to Slack channels with rich formatting and actionable buttons
  </Card>

  <Card title="JIRA Ticket Creation" icon="ticket">
    One-click JIRA ticket creation from policy notifications with automated analysis
  </Card>

  <Card title="Knowledge Ingestion" icon="brain">
    Thread-based knowledge extraction and storage via @sammy mentions
  </Card>
</Columns>

***

## Feature 1: Policy Notifications to Slack

### Overview

Policy notifications automatically deliver policy updates to configured Slack channels when new policies are detected or updated. These notifications include rich formatting, actionable buttons, and country-specific team mentions.

### User Experience

When a new policy is detected, a formatted notification appears in your designated Slack channel:

```
📋 POLICY UPDATE    🇬🇧 United Kingdom    employment_law

*New UK Employment Policy: Remote Work Guidelines*

✅ Status: Active    ✓ Verified: High Confidence

📝 Summary:
The new UK Employment Policy establishes comprehensive guidelines for remote work 
arrangements, including eligibility criteria, equipment requirements, and performance 
expectations...

💼 Impact:
This policy affects all UK-based employees working remotely. Key changes include 
mandatory equipment audits, updated performance review cycles...

🔗 Sources:
• https://example.com/policy/remote-work-uk
• https://internal.wiki/remote-work-guidelines

[Create JIRA Ticket]  [View in Dashboard]
```

### Features

<Columns cols={2}>
  <Card title="Rich Formatting" icon="paintbrush">
    Modern Slack Block Kit components with emojis, visual indicators, and hyperlinks
  </Card>

  <Card title="Smart Truncation" icon="scissors">
    Long content automatically truncated with "See more..." links for readability
  </Card>

  <Card title="Country Mentions" icon="globe">
    Automatic tagging of country-specific teams based on policy jurisdiction
  </Card>

  <Card title="Actionable Buttons" icon="hand-pointer">
    Create JIRA tickets or view policies in dashboard with single click
  </Card>
</Columns>

### How It Works

<Steps>
  <Step title="Policy Detection" icon="radar">
    New or updated policies are automatically detected by the system
  </Step>

  <Step title="Notification Delivery" icon="paper-plane">
    Rich, formatted notification sent to your designated Slack channel
  </Step>

  <Step title="Team Alerts" icon="users">
    Country-specific teams automatically mentioned for relevant policies
  </Step>

  <Step title="Take Action" icon="hand-pointer">
    Click "Create JIRA Ticket" or "View in Dashboard" to take immediate action
  </Step>
</Steps>

<Note>
  The notification channel can be configured in your Sammy Labs dashboard settings.
</Note>

### Use Cases

<Tabs>
  <Tab title="Compliance Teams" icon="shield-check">
    Get notified immediately when new policies are detected, with full context for compliance review and action.
  </Tab>

  <Tab title="Legal Teams" icon="gavel">
    Track policy changes with complete source documentation and verification status for legal analysis.
  </Tab>

  <Tab title="Operations" icon="gears">
    Understand impact of policy changes on workflows and operational processes with automated summaries.
  </Tab>

  <Tab title="Multi-Country" icon="earth-americas">
    Country-specific teams automatically tagged for relevant policy updates in their jurisdiction.
  </Tab>
</Tabs>

***

## Feature 2: JIRA Ticket Creation from Slack

### Overview

Create JIRA tickets directly from Slack policy notifications with a single click. The system analyzes the policy in context, creates a JIRA ticket with analysis results, and sends confirmation back to Slack.

### User Experience

<Steps>
  <Step title="Click Button" icon="hand-pointer">
    User clicks "Create JIRA Ticket" button on policy notification
  </Step>

  <Step title="Review Form" icon="edit">
    Modal opens with pre-filled policy data (summary, description, priority, custom fields)
  </Step>

  <Step title="Submit Request" icon="paper-plane">
    User confirms settings and submits; receives "⏳ Processing policy analysis..." message
  </Step>

  <Step title="Analysis Processing" icon="robot">
    System ingests thread, analyzes policy, and creates JIRA ticket with research
  </Step>

  <Step title="Confirmation" icon="check">
    Slack thread receives "✅ A Jira ticket has been created: \[TICKET-URL]" message
  </Step>
</Steps>

### What Happens Next

After you submit the JIRA ticket request:

<Steps>
  <Step title="Analysis Begins" icon="robot">
    The system analyzes the policy in context to gather relevant research and insights
  </Step>

  <Step title="JIRA Ticket Created" icon="ticket">
    A JIRA ticket is automatically created with the analysis results attached
  </Step>

  <Step title="Confirmation Posted" icon="check">
    You receive a confirmation message in the Slack thread with a link to the JIRA ticket
  </Step>
</Steps>

<Info>
  The entire process typically completes in under a minute. You'll receive status updates in the Slack thread so you know exactly what's happening.
</Info>

***

## Feature 3: Knowledge Ingestion via @sammy Mentions

### Overview

Mention @sammy in any Slack thread to ingest the entire thread as knowledge. The system processes text, videos, and attachments, extracts structured information, and stores it in your organization's knowledge layer.

### User Experience

Simply mention the bot in any thread:

```
User: @sammy process this thread

Bot: Got it! Your thread has been ingested to your knowledge layer.
```

**Behind the scenes:**

* Complete thread is fetched from Slack
* Videos are downloaded and analyzed
* Text content is processed and structured
* Memories are extracted and stored
* Content becomes searchable in knowledge base

### How It Works

<Steps>
  <Step title="Mention @sammy" icon="at">
    Simply @mention SAMMY in any thread you want to capture
  </Step>

  <Step title="Instant Confirmation" icon="reply">
    SAMMY confirms immediately: "Got it! Your thread has been ingested..."
  </Step>

  <Step title="Content Processing" icon="gears">
    All thread messages, videos, and attachments are processed in the background
  </Step>

  <Step title="Knowledge Storage" icon="hard-drive">
    Extracted knowledge becomes searchable in your organization's knowledge base
  </Step>
</Steps>

### Video Processing

When videos are detected in threads, the system performs advanced AI analysis:

<Info>
  Videos are analyzed using Vertex AI with a specialized documentation extraction prompt that identifies:

  * Product features and how-to guides
  * Technical documentation (APIs, SDKs)
  * Workflows and processes
  * Configuration and setup instructions
  * Business information (pricing, SLAs)
  * Policies and guidelines
  * Troubleshooting guides
</Info>

**Video Processing Steps:**

1. **Detection** - Videos in the thread are automatically identified
2. **Secure Processing** - Videos are processed in secure, encrypted storage
3. **AI Analysis** - Advanced AI extracts structured documentation from video content
4. **Cleanup** - Temporary files are immediately deleted after processing
5. **Indexing** - Extracted content becomes searchable in your knowledge base

### Content Types Supported

<Columns cols={2}>
  <Card title="Text Messages" icon="message">
    All thread messages with author attribution and timestamps
  </Card>

  <Card title="Videos" icon="video">
    MP4, MOV, and other formats with AI-powered content extraction
  </Card>

  <Card title="Attachments" icon="paperclip">
    Files and documents shared in thread
  </Card>

  <Card title="Links" icon="link">
    URLs referenced in messages with context
  </Card>
</Columns>

### What Gets Captured

**Content Stored:**

* All thread messages with author attribution
* Video transcripts and extracted insights
* File attachments and shared documents
* Links and references from the conversation
* Full conversation context and threading

**Privacy Options:**

* **Internal** - Accessible only within your organization
* **Public** - Available in your organization's public knowledge base

<Note>
  You control the privacy settings when ingesting content. Internal memories remain completely private to your organization.
</Note>

### Use Cases

<Tabs>
  <Tab title="Meeting Notes" icon="users">
    @sammy after a meeting to capture discussion, decisions, and action items automatically
  </Tab>

  <Tab title="Product Demos" icon="presentation">
    @sammy on demo threads to extract feature documentation from videos and discussions
  </Tab>

  <Tab title="Training Sessions" icon="graduation-cap">
    @sammy on training threads to create searchable knowledge base from educational content
  </Tab>

  <Tab title="Policy Discussions" icon="comments">
    @sammy on policy discussion threads to preserve context and decisions
  </Tab>

  <Tab title="Technical Q&A" icon="code">
    @sammy on technical threads to build documentation from troubleshooting discussions
  </Tab>
</Tabs>

### Example

```
User: @sammy process this thread

Thread Content:
├─ Message 1: "Here's how to enable 2FA..."
├─ Message 2: [Video: Product demo]
└─ Message 3: "The API endpoint is /api/v2/auth/2fa"

Bot: Got it! Your thread has been ingested to your knowledge layer.

What Happens:
├─ All 3 messages captured with full context
├─ Video analyzed and documentation extracted
└─ Everything becomes searchable in your knowledge base
```

***

## Security & Data Protection

### How We Keep Your Data Safe

Our integration implements enterprise-grade security to ensure your data remains protected and isolated:

<Tabs>
  <Tab title="Request Verification" icon="shield">
    **Every Request is Verified**

    * All Slack requests are cryptographically verified to ensure authenticity
    * Timestamp validation prevents replay attacks
    * Only legitimate requests from Slack are processed
  </Tab>

  <Tab title="Encrypted Storage" icon="lock">
    **Your Credentials Stay Secure**

    * All workspace tokens are encrypted at rest
    * Credentials never exposed in logs or responses
    * Secure vault storage with enterprise-grade encryption
  </Tab>

  <Tab title="Data Isolation" icon="users-rectangle">
    **Complete Organization Isolation**

    * Your data is completely separated from other organizations
    * Database-level security prevents cross-organization access
    * Zero possibility of data leakage between organizations
  </Tab>

  <Tab title="Secure Communication" icon="shield-check">
    **Encrypted Transmission**

    * All communications use HTTPS/TLS encryption
    * End-to-end security for all data in transit
    * Industry-standard security protocols
  </Tab>
</Tabs>

### Minimal OAuth Permissions

<Check>
  The Sammy Labs Slack integration follows the **principle of least privilege**, requesting only the absolute minimum permissions necessary for core functionality. We deliberately exclude permissions for private channels, DMs, and workspace-wide access.
</Check>

**Complete Slack App Manifest Scopes:**

```json theme={null}
{
  "scopes": {
    "bot": [
      "app_mentions:read",    // Only detect @SAMMY mentions
      "chat:write",           // Send responses in threads
      "files:read",           // Access shared files
      "channels:history"      // Read public channel messages (only where invited)
    ]
  }
}
```

<Warning>
  **What SAMMY Cannot Access:**

  * Private channels (unless explicitly invited)
  * Direct messages or group DMs
  * Channels it has not been added to
  * Workspace user lists or admin functions
  * Ability to delete or modify messages
</Warning>

### Exactly What SAMMY Can Access

<Tabs>
  <Tab title="Read Permissions" icon="eye">
    **What SAMMY will be able to view:**

    * **Messages** in public channels where SAMMY has been explicitly added
    * **@mentions** of SAMMY in conversations
    * **Files** shared in channels and conversations SAMMY has access to

    <Warning>
      SAMMY can only access content in channels where it has been explicitly invited. It cannot see content in channels it hasn't been added to.
    </Warning>
  </Tab>

  <Tab title="Write Permissions" icon="pencil">
    **What SAMMY will be able to do:**

    * **Send messages** as @SAMMY to post analysis results and confirmations
    * **Reply to threads** where it was mentioned or where tickets were created
    * **Post notifications** for policy updates and JIRA ticket confirmations

    <Check>
      SAMMY only processes content when explicitly mentioned or invoked. It never monitors conversations in the background.
    </Check>
  </Tab>
</Tabs>

### Privacy Principles

<Columns cols={2}>
  <Card title="User-Initiated Only" icon="hand-point-up">
    SAMMY only processes content when explicitly invoked by users via @mentions
  </Card>

  <Card title="No Background Monitoring" icon="eye-slash">
    The bot never passively monitors conversations or logs content without explicit request
  </Card>

  <Card title="Explicit Consent" icon="check-circle">
    All processing requires explicit user action (button click or @mention)
  </Card>

  <Card title="Minimum Access" icon="shield">
    Only permissions essential for functionality are requested
  </Card>
</Columns>

### Key Security Guarantees

<Columns cols={2}>
  <Card title="No Auto-Join" icon="ban">
    SAMMY never automatically joins channels. It must be explicitly invited using `/invite @SAMMY`
  </Card>

  <Card title="No Unsolicited Messages" icon="message-slash">
    SAMMY only posts when responding to @mentions or sending requested notifications
  </Card>

  <Card title="User-Triggered Processing" icon="user-check">
    Application logic only processes content when users explicitly invoke SAMMY
  </Card>

  <Card title="Transparent Operations" icon="clipboard-check">
    All SAMMY actions are visible in thread replies and audit logs
  </Card>
</Columns>

<Info>
  **Critical Privacy Note:** While Slack's `channels:history` permission technically allows SAMMY to read messages in channels it's added to, SAMMY's application code is designed to **only process and respond to explicit user interactions** (@mentions, button clicks). SAMMY does not passively monitor, log, or process conversations in the background.
</Info>

### Data Handling & Privacy

<Columns cols={2}>
  <Card title="Encrypted Storage" icon="shield-halved">
    All your data is encrypted at rest using enterprise-grade encryption. Credentials and tokens are stored in secure vaults.
  </Card>

  <Card title="Secure Transmission" icon="lock">
    All communications between Slack and Sammy Labs use HTTPS/TLS encryption to protect data in transit.
  </Card>

  <Card title="Organization Isolation" icon="building-shield">
    Your organization's data is completely isolated. No possibility of access by other organizations.
  </Card>

  <Card title="Temporary Processing" icon="clock">
    Files like videos are processed securely and immediately deleted from temporary storage after processing.
  </Card>
</Columns>

***

## Installation & Setup

### Getting Started

<Note>
  Installation requires Slack workspace administrator permissions and an active Sammy Labs organization account.
</Note>

<Steps>
  <Step title="Start Installation" icon="rocket">
    Navigate to your Sammy Labs dashboard, go to Integrations, and click "Add Slack Integration"
  </Step>

  <Step title="Authorize with Slack" icon="key">
    Review the requested permissions on Slack's authorization page and approve the integration
  </Step>

  <Step title="Automatic Configuration" icon="settings">
    The bot is automatically configured with your organization's settings
  </Step>

  <Step title="Invite to Channels" icon="hashtag">
    Add SAMMY to specific channels using `/invite @SAMMY` where you want to use the features
  </Step>

  <Step title="Start Using" icon="check">
    You're ready to go! @mention SAMMY or receive policy notifications immediately
  </Step>
</Steps>

### Configuring Channels

<Tabs>
  <Tab title="Policy Notifications" icon="bell">
    **Set Your Notification Channel**

    Configure which Slack channel receives policy notifications in your Sammy Labs dashboard under Settings > Integrations > Slack > Notification Channel.

    <Tip>
      Choose a channel dedicated to compliance or policy updates for best organization.
    </Tip>
  </Tab>

  <Tab title="JIRA Integration" icon="ticket">
    **Connect Your JIRA Account**

    To enable JIRA ticket creation from Slack, connect your JIRA account in your Sammy Labs dashboard under Settings > Integrations > JIRA.

    You'll need:

    * Your JIRA workspace URL
    * An API token with appropriate permissions

    <Note>
      JIRA integration is optional. Policy notifications work without it.
    </Note>
  </Tab>

  <Tab title="Channel Access" icon="lock">
    **Control Where SAMMY Works**

    SAMMY only works in channels where it's been explicitly invited. To add SAMMY to a channel:

    1. Open the channel in Slack
    2. Type `/invite @SAMMY`
    3. Press Enter

    To remove SAMMY from a channel, simply remove it like any other user.
  </Tab>
</Tabs>

***

## Frequently Asked Questions

<Tabs>
  <Tab title="Privacy & Access" icon="shield">
    **Can SAMMY access all our Slack messages?**

    No. The integration only processes messages in threads where it's explicitly mentioned by users via @mentions. It never passively monitors conversations.

    **How is our data isolated from other organizations?**

    Complete isolation through database-level Row Level Security, separate encryption keys, organization-specific bot tokens, and multi-tenant architecture.

    **Can we control what data is processed?**

    Yes. Processing only occurs when users explicitly mention @sammy or click action buttons. No background monitoring or automatic processing occurs.
  </Tab>

  <Tab title="Management" icon="settings">
    **Can we revoke access?**

    Yes. Access can be revoked instantly through either Slack's app management interface or your Sammy Labs dashboard, immediately stopping all bot functionality.

    **What happens if we uninstall the integration?**

    Extracted memories remain in your knowledge base for continued access. Raw Slack data is never stored, and bot tokens are automatically invalidated.

    **How do we manage user permissions?**

    User access is managed through your existing Sammy Labs organization settings. Slack workspace permissions determine who can install/uninstall the bot.
  </Tab>

  <Tab title="Operation" icon="activity">
    **Is the bot always active in our workspace?**

    The bot only activates when explicitly invoked via @mention. It performs no background processing or monitoring.

    **What if our team uses multiple Slack workspaces?**

    Each Slack workspace requires separate installation, but all integrate with your single Sammy Labs organization account.

    **How are videos processed?**

    Videos are downloaded, uploaded to secure S3 storage, analyzed by Vertex AI, and immediately deleted from temporary storage after processing.
  </Tab>
</Tabs>

***

## Getting Started

Ready to transform your Slack workspace into an intelligent knowledge and policy hub?

<Card title="Install Slack Integration" icon="rocket" href="https://app.sammylabs.com/" cta="Get Started">
  Connect your Slack workspace to Sammy Labs in just a few clicks. Requires Slack admin permissions and an active organization account.
</Card>

<Tip>
  After installation, add the bot to your desired channels using `/invite @SAMMY` and configure your notification channel to start receiving policy updates.
</Tip>
