Wire

Ask it in Slack, and only you see the answer.

One slash command, an answer built only from your own team’s facts with a numbered citation behind every claim, and it goes to you and nobody else. Harbor holds no Slack permission that would let it speak to anyone unprompted.

The door for people who do not open a terminal

Most of what a company knows is needed by people who will never run a command. /harbor is one slash command in Slack that answers from the same brain, under the same access rules, with the same citations as the Ask page in the web app.

The same, not similar. There is one answering engine and Slack calls it with a label saying where the question came from. If a Slack answer ever differed from a web answer for the same person and the same question, that is a bug rather than a feature, and the service that renders it says so in its own header.

Turn it on

  1. Connect Slack once, in the web app

    Sources, then add a source, then Slack. One grant covers both halves: the channels Harbor may read, and this command. If your workspace already connected Slack as a source, the command is already there and there is nothing to install.

  2. Type the command with no question

    slack
    /harbor

    You get the usage line back, privately. It costs nothing, reads nothing and answers in well under a second, which makes it the cheapest way to prove the command is really installed before you trust an answer from it.

  3. Ask something

    slack
    /harbor what is our deploy window?

    A placeholder appears immediately, then the answer replaces it. Questions are capped at a thousand characters, and a shorter one ranks better anyway.

  4. Link your account, if it asks you to

    Harbor has to know whose access to answer under before it will answer at all. It matches the confirmed email on your Slack profile to a Harbor member. If that fails you get a Connect my Harbor account button: click it while signed in to Harbor, confirm, and every later question answers as you. The link lasts fifteen minutes and it lands on your own profile page, because saying which Harbor member you are is a fact about you rather than an administrative act on a connector.

Why it refuses rather than guessing

Harbor resolves your identity two ways and neither of them is a resemblance: a mapping you confirmed by hand, or an email Slack itself has verified. It will not match you by name. The reason is the worst case rather than the common one: one Dan Cohen reading another Dan Cohen’s filtered answer is not a misattributed sentence, it is an authentication bypass, and a name match is a guess.

An unverified Slack email is not a credential either. Some Slack workspaces let a member set their own address without confirming it, so accepting one would let anybody who can join the Slack team claim any Harbor account by typing its address into their profile.

The two usual causes of a refusal are dull and worth knowing: a different address on your two profiles, or you are not a member of the workspace this Slack is connected to. The button settles both.

What comes back

The reply has four parts, and three of them are there so you can check the fourth.

  • The answer, in prose, with a [#1] marker immediately after every claim it rests on. A sentence resting on two facts carries both.
  • One line per cited fact, reading [#1] convention · Engineering: what kind of thing it is, then the scope it lives at. Eight get their own line and the rest are summarised.
  • The footer, which says what was searched and what was withheld. This is the instrument.
  • A 👎 button, because the answer being wrong is a thing you should be able to do something about from where you are standing.

The model is given the numbered facts and nothing else. It is told never to fill a gap from general knowledge, never to invent a number that is not in the list, and to answer with a refusal rather than a hedge when the facts do not cover the question, because a confident wrong answer about your own company is worse than silence.

Narrowing it to one Space

Put a bracket at the front of the question and the answer comes from that Space alone.

slack
/harbor [in Engineering] what is our deploy window?

It is a typed literal rather than something inferred from your wording, and that is deliberate: Slack has no picker, so the bracket is the picker. Writing in the Engineering space, what is our deploy window asks a question about Engineering rather than scoping one to it, and the scope has to be a thing you chose rather than a thing a model read out of your sentence.

Name a Space that does not exist, or one you are not on, and you get a refusal listing the Spaces you are actually on. It never falls back to searching everything. Answering the wider question after you narrowed it on purpose would be a scope lie, and the only place it would show is the footer you were not looking at.

Every way it declines

None of these is an error page. Slack kills a slash command at three seconds, so the answer arrives on a second delivery, and anything that escapes on the way is a command that silently never replies: the worst failure this surface has, because it is indistinguishable from the product being broken. So every ending below is a written sentence.

What /harbor says when it will not answer, and what to do.
WhenWhat it saysWhat to do
Slack is not connectedThis Slack workspace is not connected to Harbor yet.An admin connects it once, under Sources. It is the same connection that reads channels.
Harbor cannot tell who you areI could not match your Slack account to a Harbor member, so I don’t know whose access to answer under.Use the Connect my Harbor account button. One click, signed in to Harbor.
You are in more than one workspace behind this SlackWhich brain should answer?Pick one. Nothing is remembered, so the next question asks again.
You named a Space you are not onI could not find a Space called Finance that you are on. Yours: ...Fix the name or drop the bracket. It will not quietly answer the wider question instead.
More than twenty questions in a minuteThat is more than 20 questions in a minute. Give it a moment and ask again.Wait. The web app has exactly the same budget, so Slack is not the cheap way around it.
Nothing is indexed yetI have nothing indexed for Acme yet, so there was nothing to search.Connect a source, or approve something in Review.
Plenty is indexed and none of it matchedI could not answer that from what Acme knows.Press 👎. A question the brain should have answered is the most valuable thing the queue can get.
Billing is unpaidHarbor is paused for Acme while a billing issue is resolved.An admin fixes it in the web app.

The two empty answers are worth telling apart, and the product spends a database read to do it: nothing indexed yet is a setup problem, while plenty indexed and nothing matched is a knowledge gap. Both are true things to say and neither is a blank card.

Correcting a wrong answer

Press 👎 and a form opens asking what is true instead, plus an optional menu naming the facts the answer cited. Two sentences is enough. It files into Review as a proposal for somebody with approval rights, and it is indistinguishable there from a correction filed in the browser: same queue, same pairing, same approval. If an admin can tell which door it came through, that is a bug.

Naming the wrong fact is what makes the correction worth more than a complaint. A named rule is paired with your replacement, so approving yours retires the old one in the same action rather than leaving both in the brain contradicting each other. Leave the menu empty and it lands as a plain proposal, with nothing superseded and the outcome said out loud rather than reported as filed.

Correcting the answer that said nothing is allowed and is often the best one you can file. You should know this, and you did not is exactly the gap the queue exists to close, and it arrives with nothing to retire.

What Harbor cannot do in Slack

The app holds eight scopes. Seven are reads: channel lists and history for public and private channels, the ability to join a public channel it was pointed at, and enough of a profile to tell which person wrote something. The eighth is permission to have a slash command at all.

Three scopes are deliberately absent, and their absence is the claim: chat:write, chat:write.public and im:write. Harbor cannot post in a channel, cannot send you a direct message and cannot announce anything, because it holds no permission that would let it originate a message to a person. That is a property of the grant on the consent screen rather than a policy in our code, which means you can check it instead of believing us.

What lets it answer at all is narrower than a permission. A slash command arrives carrying a single-use reply address, good for half an hour, which Slack hands over precisely because you ran the command; the correction form opens against a trigger that Slack mints when you press a button and which expires in about three seconds. Both are capabilities handed over by something you did, not standing rights over your workspace.

And the answer is always private. It is computed under your access and it reports how much was withheld from you, so posting it to a channel whose members have different permissions would be a data leak with a one-word diff. The word is not a parameter anywhere in the code.

Next, the half of Slack this page deliberately left alone: what Harbor reads, which channels you pick, and what it refuses to take even from those. Sources.