Generate configuration tokens.
These workspace-level tokens let Agent Barn prepare a new Slack app. Generate both values and keep them ready for the next steps.
- 01.1
Open Slack API → Your Apps.
Go to api.slack.com/apps ↗, sign in, and confirm that you are working in the workspace where this agent should operate.
- 01.2
- 01.3
- 01.4
Store both values securely.
The access token authorizes app creation and expires after 12 hours. The refresh token rotates that access. Never place either value in chat, logs, prompts, or URLs.
- 01.5
Submit the token pair in Agent Barn.
Paste the configuration access token and
xoxe-refresh token into their matching fields, then continue while the access token is still valid.
Define the bot identity.
Use recognizable, role-oriented metadata. These values are visible to teammates and can be changed later.
- 02.1
Choose the display name.
This name appears in Slack messages, mentions, and the app directory. Avoid secrets, environment names, or workspace-specific data.
RECOMMENDEDAgentBarn_General_Purpose - 02.2
Write a one-sentence description.
Describe the outcome teammates can expect rather than the implementation behind it.
SUGGESTEDA flexible starting template for a broad range of configured Slack tasks.
- 02.3
Choose the icon background color.
Pick a readable color that follows your workspace convention. Agent Barn orange is the recommended default.
Aubergine#511152A familiar Slack-adjacent choice.
Blue#1264A3Calm and conventional for utility bots.
Green#2EB67DUseful for workflow or status-oriented agents.
Amber#ECB22EHigh visibility for reminders and alerts.
Agent Barn orange#CC4400Recommended for a consistent Agent Barn identity.
- 02.4
Review the public metadata.
Confirm that the name states the role, the description states the result, the color remains legible at small sizes, and no sensitive information is exposed.
- 02.5
Create the app and confirm it appears in Slack.
Save the identity in Agent Barn, complete app creation, then confirm the new app appears under Your Apps in the intended workspace before continuing.
Connect the new Slack app.
Create the app-level token, install the bot, and store the two resulting credentials that Agent Barn needs.
- 03.1
Select the new app and verify its connection settings.
Return to Your Apps ↗, open the app created for this recipe, verify the workspace, and confirm Socket Mode and the recipe's event subscriptions are enabled.
- 03.2
- 03.3
- 03.4
- 03.5
Install the app to the workspace.
Open Install App, then choose Install to [your workspace]. Review the requested permissions, make sure the workspace selector is correct, and choose Allow.

Install App → Install to your workspace. 
1 // Confirm the workspace. 2 // Approve only after reviewing permissions. - 03.6
Find the Bot User OAuth Token after installation.
After installation, Slack shows an OAuth Tokens section containing the Bot User OAuth Token. Click Copy and keep the
xoxb-value ready for Agent Barn. The token is blurred in this reference.
Installed App Settings → OAuth Tokens → Bot User OAuth Token → Copy. - 03.7
Enter both tokens in Agent Barn.
Paste the
xapp-value into App-level token and thexoxb-value into Bot token. - 03.8
Save and verify the connected app.
Save both fields and confirm Agent Barn resolves the expected Slack app and workspace. Stop if either identity is wrong.
Enter Slack tokens only in their matching Agent Barn fields. Do not include them in messages or screenshots.
Configure how the teammate operates.
Work through these settings in order. Each controls a different part of the agent’s behavior or access.
- 04.1IDENTITY
Name the teammate for its role.
The operational name appears in dashboards and audit history. A short human name makes conversations and mentions easier.
OPERATIONAL NAME AgentBarn_General
Clear in dashboards and logs.
SUGGESTED HUMAN NAME Aria
Easy to mention and remember.
- 04.2MODEL
Choose the model that performs the work.
The model affects capability, speed, and cost. The supplied configuration shows DeepSeek: DeepSeek V4 Flash 0731. Confirm it is available and appropriate for this recipe’s complexity and data sensitivity.
How to decideUse a fast model for structured, repeatable work. Use a more capable model for ambiguous context or nuanced reasoning. Evaluate representative tasks before granting broader access.
- 04.3COMMAND APPROVAL
Decide when a human must approve commands.
Start with the most restrictive mode that still makes the workflow useful.

Current default shown: Auto. RECOMMENDED START Auto
Low-risk commands run automatically; higher-risk commands still require approval.
MAXIMUM OVERSIGHT Manual
The agent asks before every command. Best for pilots and sensitive systems.
NO APPROVAL GATE Off
All prompts are skipped. Use only with tightly sandboxed, narrowly scoped, reversible tools.
- 04.4CHANNEL ACCESS
Choose which channels the agent may answer in.
Slack controls which channels the app can see; this policy controls where the agent may respond.

Current default shown: Allowlist. RECOMMENDED START Allowlist
Respond only in approved channels. Best for pilots and team-specific workflows.
BROAD AVAILABILITY Open
Respond in any reachable channel. Use only for intentionally workspace-wide roles.
- 04.5DIRECT MESSAGES
Control who can start private conversations.
Direct messages remove shared-channel context and oversight. Enable them only when private interaction is genuinely needed.

Current default shown: Off. RECOMMENDED START Off
Ignore direct messages and keep work visible in approved channels.
LIMITED PRIVATE ACCESS Allowlist
Only designated operators and reviewers may send direct messages.
WORKSPACE-WIDE DMS Open
Anyone who can reach the app may DM it. Use only with strong identity and tool controls.
- 04.6VERBOSITY
Choose how much work the agent narrates.
This changes what teammates see while the agent works; it does not change capabilities or approvals.

Current default shown: Concise. VISIBLE EXECUTION Verbose
Announces each step. Useful during onboarding, debugging, and supervised pilots.
RECOMMENDED STEADY STATE Concise
Provides final answers without narrating every intermediate step.
- 04.7
Add the intended Slack destinations.
Invite the app to each permitted channel. When Allowlist is selected, add the same channels and approved direct-message users in Agent Barn before testing.
- 04.8
Configure the recipe trigger and workflow.
Trigger: A request arrives in an allowed Slack channel or direct message.
- 04.9
Apply the recipe requirements and review rule.
TemplateThe selected model, role, restrictions, and instructions.
SkillsOnly the capabilities needed for the intended workflow.
PoliciesExplicit channel allowlists and direct-message behavior.
Auto command approval · Channel allowlist · Direct messages off · Concise responses. Expand access only after representative tests and review of the agent’s tools and data boundaries.
Assign the skills this recipe needs.
Skills connect the agent to external platforms. Select only the integrations required for the workflow, then connect each one with a dedicated or approved shared credential.
Selected skills only
Add only the platforms required by the role you define for this agent.
- Credential
- A dedicated, least-privilege credential for each selected platform.
- Permissions
- No default integrations · Grant read before write where possible · Add one capability at a time and test it
- Write the role and success criteria before selecting tools.
- Connect the minimum useful skill set.
- Re-run representative tests whenever a new integration is added.
Select the skills this agent can use.
Select one or more skills to show their connection instructions.
Connect Jira.
- Copy the Atlassian site URL.
Use the site origin through
.atlassian.net. Do not include a project path.
Copy the site origin. - Open the API token manager.
Open Profile → Account settings → Security → Create and manage API tokens.

Account settings 
API token manager - Create the matching token type.
Choose standard or scoped, then select the same Authentication Type in Agent Barn. For a scoped token, include only the Jira API scopes required by the role.

Choose standard or scoped. - Complete the Jira credential.SITE URL
Atlassian site origin.
AUTHENTICATION TYPEMatch the token type.
EMAILAtlassian account email.
API TOKENCopied token value.
Grant only the Jira project and issue actions required by the general-purpose role.
- Validate the Jira boundary.
Test one permitted project and confirm a project outside the configured boundary remains unavailable.
Connect Confluence.
- Copy the Atlassian site URL.
Use the site origin through
.atlassian.net. Do not include a space or page path.
Copy the site origin. - Open Atlassian API tokens.
Open Profile → Account settings → Security → Create and manage API tokens.

Open the API token manager. - Create and copy the token.
Choose the token type used in Agent Barn, add a recognizable name and expiration, create it, and copy the value.

Name · expiration · create 
Copy the value. - Complete the Confluence credential.SITE URL
Atlassian site origin.
AUTHENTICATION TYPEMatch the token type.
EMAILAtlassian account email.
API TOKENCopied token value.
The same saved Atlassian credential can connect Jira and Confluence when the account and token cover both products.
- Validate the Confluence boundary.
Test one permitted space and confirm a space outside the configured boundary remains unavailable.
Connect GitHub with a Classic PAT.
- Open Personal access tokens.
Open github.com/settings/tokens ↗, choose Tokens (classic) → Generate new token, then add a note and expiration.
- Select the scopes.REPO
Repository access.
READ:ORGOrganization membership.
READ:USERUser profile data.
- Generate and copy the token.

The token is blurred; use the copy control. - Complete the GitHub credential.
Copy Owner / Org from the value before the slash and add every repository the agent may use.

Owner / Org appears before the slash. - Validate the GitHub boundary.
Test one permitted repository and confirm a repository outside the configured list remains unavailable.
Connect Bitbucket.
- Record the workspace ID.
Open the workspace. In
bitbucket.org/agentbarn/workspace/overview,agentbarnis the workspace ID. - Create a Bitbucket-scoped API token.
Open Profile → Account settings → Security → Create and manage API tokens. Choose Create API token with scopes, select Bitbucket, and continue to permissions.
- Select access.USER
Read the account.
WORKSPACERead the workspace.
REPOSITORYRead repository content.
PULL REQUESTSRead; add write only when the role posts comments.
- Complete the Bitbucket credential.WORKSPACE
Workspace ID.
REPOSITORIESPermitted repository names.
EMAILAtlassian account email.
API TOKENBitbucket-scoped value.
- Validate the Bitbucket boundary.
Test one permitted repository and confirm a repository outside the configured list remains unavailable.
Connect Gmail with Google OAuth.
- Click Authenticate with Google.
Choose the mailbox that the agent should read.
- Review and approve read-only access.
Approve
gmail.readonly. No manual key is required.
Google OAuth · gmail.readonly - Use a custom Google client only when required.
Keep the optional custom-client fields closed unless the workspace must supply and manage its own Google OAuth application.
- Set mailbox boundaries.
Choose the labels, folders, senders, recipients, and message types this general-purpose agent may inspect.
- Test the connection.
Confirm one included message is available and one excluded message remains outside the agent’s results.
- Define the role before selecting skills.
Write the tasks, inputs, outputs, and prohibited actions first.
- Test one skill at a time.
Connect the minimum access required, run a representative task, and confirm resources outside the selected boundary remain unavailable.
- Review every selected skill.
Confirm each connection uses the intended account and resources, then remove anything the defined role does not need.
Verify the setup before launch.
Run this short review once Slack, Agent Barn, and the required skills are configured.
- Confirm the app is installed in the intended Slack workspace.
- Verify the
xapp-andxoxb-values connect the intended Slack app. - Validate every required skill and confirm its credential has only the intended site, space, project, or repository access.
- Test one representative request in an allowlisted channel.
- Confirm higher-risk commands still trigger the expected approval path.
- Review the agent’s response quality, visibility, and logs before expanding access.
- Run the configured trigger: A request arrives in an allowed Slack channel or direct message.
- Confirm the result follows Receive request → Apply role → Use skills → Return answer.
- Apply the review rule: Start with the narrowest useful scope and add tools only when the workflow genuinely needs them.
General Purpose is ready for a controlled pilot.
Start with a narrow audience and reversible work, then widen access after observing representative tasks.
Return to recipes →



