Prompt
How do I build an AI agent that can take actions in Slack and Gmail?
Latest observation
To build an AI agent that can take actions in Slack and Gmail, you generally want this architecture:
- LLM / reasoning layer — decides what to do.
- Tool layer — functions the agent can call, like “send Slack message” or “draft Gmail reply.”
- Permissions + auth — OAuth for Slack/Gmail, scoped minimally.
- Safety / approval layer — especially for sending messages or emails.
- Event loop / orchestration — listens for triggers, runs the agent, executes actions.
1) Define the agent’s job
Be explicit about what actions it can take, for example:
- Slack:
- read channel messages
- post messages
- reply in threads
- mention users
- Gmail:
- read inbox summaries
- draft replies
- send emails
- label/archive messages
Start with draft-only actions for Gmail if you want to reduce risk.
2) Connect Slack and Gmail APIs
Slack
Use the Slack API with a Slack app.
Typical OAuth scopes:
chat:writechannels:historygroups:historyif neededim:historyif neededusers:readchannels:readreactions:writeif you want reactions
Use:
- Events API or Socket Mode to receive messages/events
chat.postMessageto send messagesconversations.repliesto fetch thread context
Gmail
Use the Gmail API with Google OAuth.
Typical scopes:
gmail.readonlyfor readinggmail.composefor draftsgmail.sendfor sendinggmail.modifyfor labels/archive actions
Use:
- Gmail API to list messages
- create drafts
- send messages
- modify labels
3) Wrap each capability as a tool/function
Your LLM shouldn’t directly talk to Slack/Gmail APIs. Instead, expose safe functions like:
def send_slack_message(channel_id: str, text: str) -> str:
...
def reply_to_slack_thread(channel_id: str, thread_ts: str, text: str) -> str:
...
def create_gmail_draft(to: str, subject: str, body: str) -> str:
...
def send_gmail_email(to: str, subject: str, body: str) -> str:
...
Then give the LLM a tool-calling interface. The agent can decide:
- “This message needs a Slack reply”
- “This email should be drafted”
- “This task needs human approval before sending”
4) Add an approval workflow
Best practice: don’t let the agent send emails or post to Slack without guardrails.
Common pattern:
- Agent proposes action
- System shows draft to human
- Human approves/edits
- System executes
For example:
- If confidence is low, create a draft
- If action is high impact, require approval
- If content includes sensitive info, block or escalate
5) Build the orchestration loop
You need a process that:
- receives an event from Slack or Gmail
- fetches context
- passes context to the agent
- the agent decides what tool to call
- execute tool
- log outcome
Example flow:
- Slack message comes in
- Agent sees: “Can you summarize the latest customer feedback?”
- Agent fetches thread and maybe recent emails
- Agent posts a summary back to Slack
6) Recommended stack
A simple practical stack:
- Python or Node.js
- Slack Bolt for Slack app handling
- Google Gmail API client
- OpenAI API or another LLM provider with tool calling
- A backend framework:
- FastAPI / Flask
- Express / NestJS
- Database for state:
- Postgres / SQLite
- Queue/background jobs:
- Celery / RQ / BullMQ
- Secrets storage:
- environment variables for development
- secret manager in production
7) Minimal architecture
Slack/Gmail event
↓
Webhook / polling service
↓
Context fetcher
↓
LLM agent with tools
↓
Approval check
↓
Slack/Gmail API action
↓
Log + audit trail
8) Example agent behavior
Example 1: Slack
User in Slack says:
“Please send a status update to #team about the release delay.”
Agent:
- drafts a message
- asks for approval
- posts to channel after approval
Example 2: Gmail
New email arrives from a customer
“Can you reschedule our meeting?”
Agent:
- reads email
- drafts reply with available times
- sends only if approved
9) Important safety considerations
- Use least-privilege OAuth scopes
- Maintain an audit log
- Keep a human-in-the-loop for send/post actions
- Prevent prompt injection from email/Slack content:
- don’t let message content override system instructions
- treat all external text as untrusted
- Rate limit actions
- Make actions idempotent to avoid duplicate sends
10) A good first MVP
I’d recommend this MVP:
- Slack bot that:
- responds to mentions
- summarizes threads
- drafts suggested replies
- Gmail agent that:
- monitors inbox
- drafts replies
- never sends automatically
Then later:
- add auto-send for low-risk cases
- add calendar actions
- add CRM actions
11) If you want to implement it with tool calling
A typical pattern is:
- system prompt defines behavior
- tools represent Slack/Gmail actions
- model chooses a tool
- backend executes it
- backend returns result to model
Example pseudo-flow:
messages = [
{"role": "system", "content": "You are an assistant that can draft Slack and Gmail actions safely."},
{"role": "user", "content": "Reply to this email saying I can meet Friday at 3."}
]
response = llm.chat(messages, tools=[create_gmail_draft, send_gmail_email])
The model may choose create_gmail_draft first.
12) If you want, I can give you:
- a Python starter project for Slack + Gmail agent
- a Node.js version
- a tool-calling example with OpenAI
- a secure architecture diagram and deployment plan
If you want, I can generate a working Python FastAPI example that connects to Slack and Gmail and lets the model draft actions.