AI answers in Slack: who sees what, and why private channels stay private
How an AI assistant in Slack should scope answers to private channels, the visibility rule Biddle uses, and a checklist of questions to ask any tool first.
On this page
A Slack AI tool keeps private channels private only if it scopes each answer to two things: who asked, and where the answer will appear. Biddle's rule is this: an answer in a channel uses only that channel and the public channels the asker can see, and an answer in a DM can use everything the asker can see. Private-channel content never reaches a public answer.
That rule is the thing to look for in any tool. "Respects Slack permissions" is a claim. A stated rule you can test is evidence.
Why does scoping by the asker and the place matter?
AI-native teams create context faster than anyone can sync, manage or remember it. Agents open PRs all day, decisions land in threads, and plans change mid-week. So people stop searching and start asking: "what did we decide about the export format?" The assistant answers by pulling from many places at once.
That is where the risk sits. A search box shows you results and you decide what to do with them. An assistant composes an answer, and the answer is posted somewhere. If the place is a channel with forty people in it, everyone reads it. If the assistant drew on a private channel to write it, it has just republished that channel to people who were never invited.
Two things have to be checked, not one:
- Who asked. The assistant should never know more on your behalf than you could look up yourself.
- Where the answer lands. Even if you can see a private channel, an answer posted in a public one is readable by people who cannot.
A tool that checks only the first leaks through the second. You can be a member of a private leadership channel and still not want its contents summarized into a thread the whole company can read.
What is the visibility rule, in plain words?
Biddle answers questions in Slack when someone asks in a DM or mentions it in a thread. The rule has three parts:
- An answer in a channel uses only that channel and the public channels the asker can see.
- An answer in a DM can use everything the asker can see.
- Private-channel content never reaches a public answer.
One limit applies before any of this: Biddle can only draw on Slack channels it has been invited to, plus DMs sent to it. The rule narrows what it can use. It never widens it.
Three examples
An illustration with sample channel names and sample askers. Say the team has a public channel #product and a private channel #leadership. One teammate is a member of #leadership, and another teammate is not.
1. The #leadership member asks in #product. The teammate mentions Biddle in a thread in #product: "where did we land on the export format?" The answer can use that thread, #product, and public channels the asker can see. It cannot use #leadership, even though the asker is a member. The answer is posted where everyone in #product can read it, so only content that was already open to them is eligible.
2. The same teammate asks in a DM. They send the same question to Biddle directly. Now the answer can also use #leadership, if Biddle was invited there, because the asker can see it. This is why the same question can get a fuller answer in a DM than in a channel. The difference is where the answer lands, not who asked.
3. A teammate outside #leadership asks in a DM. This person is not in #leadership. Their DM answer can use what they can see, and #leadership is not in that set.
In all three, the same two inputs decide what the answer may draw on: the asker and the place.
What does Biddle read and keep?
Scoping answers is one half of trust. The other half is what the tool holds in the first place. This is what Biddle reads and keeps today:
- GitHub: a GitHub App with read-only permissions (contents, pull requests, issues, checks, actions, metadata). It never comments on PRs or writes code.
- Slack: only the channels it is invited to, plus DMs sent to it. It posts only in DMs, its own #askbiddle channel, and threads where someone asks it.
- Retention: raw events are kept 90 days. Derived notes are kept until the org is removed. Everything is deleted when the org is removed.
- Models: model calls go through Anthropic's API under Anthropic's commercial terms.
GitHub and Slack are the only sources today. Linear and Notion are not integrated. The questions section of the home page covers who sees what in short form.
What should you ask any Slack AI tool before installing it?
These questions work for any vendor, including us. A tool that answers all of them in specific terms is easier to trust than one that says "enterprise-grade security". Copy the list into your evaluation doc.
- Scope of reading. Does it read every channel by default, or only channels someone invites it to? Can you see the list of channels it has access to?
- DMs. Does it read DMs between people, or only messages sent to it?
- Asker check. Does the answer set depend on what the person asking can see, or on what the tool can see?
- Place check. Does the answer set change depending on whether the reply lands in a DM, a private channel or a public channel?
- Private to public. Can content from a private channel ever appear in an answer posted in a public one? Ask for the rule in one sentence.
- Where it posts. Can it post unprompted in channels, or only in DMs and threads where someone asked?
- Citations. Does each claim link back to the message or PR it came from, so a reader can check it and see where it was sourced?
- Retention. How long are raw messages kept, how long are derived summaries kept, and what is deleted when you remove the workspace or org?
- Models. Which model provider handles your data, under which terms, and what does the vendor say (and not say) about training?
- Permissions on other tools. For GitHub or other connected sources, are the permissions read-only? Can it write, comment or merge?
- Removal. What happens to stored data when you uninstall?
- Setup. Who configures channels and repos, and can you change the list later?
Test the answers, don't just collect them. Make a throwaway private channel with a fake secret in it. Ask the tool about the secret from a public channel with an account that is a member, then from a DM, then from an account that is not a member. The three results should match the rule the vendor gave you.
Where do the rules stop?
A scoping rule is not a promise about everything. It does not stop a person from pasting private content into a public channel, and it does not replace deciding which channels a tool should be invited to in the first place. The cleanest control is still the invite: if a channel holds material you would not want summarized anywhere, do not add the tool to it.
A few habits make the rule easier to live with:
- Invite the tool to channels where decisions are made in the open, and leave out channels that hold HR, legal or compensation talk.
- Ask sensitive questions in a DM, where the audience is one person.
- Re-read the channel list when a project changes hands.
Where Biddle fits
Biddle is in early access and runs every weekday for Liouville Labs' own team, including Q&A in Slack under the rule above. We set it up with each team during early access, with you picking which repos and channels it reads. If you are weighing Slack AI and private channels, read what Biddle reads and keeps.
Common questions
Can an AI answer in a public channel use a private channel I belong to?
Under Biddle's rule, no. A channel answer uses only that channel and the public channels the asker can see, so private-channel content never reaches a public answer, even if the asker is a member of the private channel.
Why does a DM answer sometimes know more than a channel answer?
A DM answer can use everything the asker can see, while a channel answer is limited to that channel and the public channels the asker can see. The place the answer lands sets the limit.
Does Biddle read every Slack channel and DM?
No. It reads only the channels it is invited to, plus DMs sent to it.
Read next
- What is an AI chief of staff for product teams?: what Biddle is for, and how it differs from assistants and dashboards.
- GitHub Slack digest: events, digests and briefings compared: how to route GitHub updates in Slack by audience.
- Decisions lost in Slack threads: a decision log template: capture the decisions your team makes in threads.
Want this in your Slack?
Biddle reads your GitHub and Slack and sends you a briefing each weekday morning, with every claim linked to the PR or thread behind it. We’re onboarding a few product teams now, and we set each one up with you.
Request early accessRelated posts
Plan drift: when a merged PR quietly undoes a team decision
Decision drift is when merged code quietly contradicts a team decision. See how it happens and run a three-step drift check this week, no tooling needed.
Too many PRs to review? What to track when agents ship 200+ in two weeks
When agents open more PRs than anyone can read, stop tracking diffs. Track decisions, open questions and needs-a-human in a 15-minute routine.
What is an AI chief of staff for product teams?
What an AI chief of staff for product teams does, how it differs from email assistants and exec dashboards, and how to tell whether your team needs one.