Slack
Answered in the channel where the question came up.
One channel is bound to one space. The bot answers the people who belong to it, and every write is a button press in the same audit trail as the web.
Chats come with the cheapest paid plan, not two tiers up.
Three steps
Connect the workspace, bind yourself, bind a channel.
Each binding is a code minted in Orla and pasted into Slack. A code burns on any attempt, right or wrong.
The three steps
- One, the workspace
- Slack's own install screen lists what the app may do before anyone approves it: post, take commands, read mentions and the threads they sit in, read a file that is sent to it. Once per workspace.
- Two, yourself
- Mint a code in Orla, send /orla link CODE in a direct message with the app. Your Slack identity becomes the identity every later press is checked against. Once per person.
- Three, a channel
- A space owner or admin sends /orla linkspace CODE in the channel. From then on that channel answers about that space and no other one, until /orla unlinkspace detaches it again.
- A channel shared with a client
- /orla linkclient CODE binds a Slack Connect channel to one contact. The client sees their own invoices and can say they paid, and the space's own numbers never appear in that channel.
What it answers
The commands, and who sees the answer.
Space figures come back only to the person who typed the command. Slack's own "also send to channel" is one click away when they mean to share it.
Reads
Answered for the caller alone: an account restricted to some members stays invisible to everyone else, in the chat exactly as it is inside the app.
- /orla balance, /orla balances
- The accounts and what is on them.
- /orla cashflow
- In and out this month, and what is waiting to be paid.
- /orla invoices
- Open invoices, overdue first.
- /orla cards, /orla goals
- The cards and their limits, the goals and where they stand.
Writes
A viewer of the space reads and never writes; nothing here is open to a stranger in the room.
- /orla add, /orla income
- A line in the ledger, from a sentence with an amount in it.
- /orla split, /orla whosin
- An equal split across the group, or one that people join by raising a hand.
- A file dropped in the channel
- A receipt or a bill comes back as a draft with two buttons; an unknown file is offered to Documents. Nothing is written until a press.
- An approval card
- A payment waiting for a signature arrives as a card. The press is checked against the presser's role, the same rule as the approve button on the web.
Asks
The same assistant as the web, under the same monthly AI allowance of the space, twenty asks an hour per person.
- /orla ask, or @Orla in a thread
- A question in words, answered from the space's own figures. A mention is answered in its thread.
- /orla mute
- What this channel receives: payments, billing, approvals, cards, budgets, connections, social, discussions. Each group toggles on its own.
- Direct message with the app
- Your personal surface. Personal commands never answer in a channel and channel commands never answer in a direct message.
Boundaries
It reads the thread it was asked in, never the workspace.
The thread is the whole memory: nothing from Slack is stored on our side, so the context is what everyone in the room can scroll up and see.
What it does
- Answers about the bound space
- Balances, invoices, cards, goals, splits.
- Approves a payment
- With the same rule as the web, by the person who pressed.
- Reads a file you send it
- And comes back with a draft, never a record.
- Posts what the space decides to send
- Approvals, receipts, card events, budget lines: every group the channel has not muted with /orla mute.
What it never does
- Index the channel history
- It reads the thread it was asked in, and only when asked.
- Answer somebody outside the space
- A stranger gets a nudge to link an account, never a number.
- Believe another bot's words are its own
- Only the messages it stamped itself count as its earlier turns; anything else posted in the thread is someone else's text.
- Start a bank payment or trade on a key
- Bank links are read only, and an exchange key that can trade or withdraw is refused the moment it is connected.
- Serve a space behind an IP allowlist
- A Slack request carries no client address, so an allowlisted space refuses the bot rather than guessing.
Disconnecting the workspace stops it that moment. What it wrote stays, with the name of the person who pressed.
See it on your own books.
Thirty minutes: we connect an account, drop a real bill in, and close a month together.