REVIEWS / DEVELOPER TOOLS / OWNER INSIGHTS
🦉 WE READ 90 OWNER COMMENTS
Slack Data Agent: what owners actually say
Owners appreciate the convenience of data answers in Slack but raise serious concerns about security, pricing clarity, and whether the agent can handle real-world data complexity.
What owners complain about
- Security vulnerabilities COMMON
Multiple owners and commenters call AI agents in Slack a 'ridiculously massive security vulnerability,' warning that unlike traditional systems where attackers must probe for bugs, AI agents can be tricked via prompts. Defaults are described as not secure, and most users are expected to stick with defaults.
- Clunky pricing model SOME
The $20/200 actions pricing is called a 'clunky statement.' Owners suggest a simple per-action rate ($0.10/action) with volume discounts instead. Production users expect to blow past 200 actions quickly and want higher-volume tiers.
- Data privacy in shared channels SOME
Owners ask whether charts generated using individual RLS permissions are visible to the entire Slack channel or can stay private. This is an unresolved concern about sensitive data leaking into shared threads.
- Hallucination risk with real data SOME
Commenters question how the agent handles complex or messy database schemas to ensure it doesn't pull wrong metrics or hallucinate answers when translating natural language to SQL.
- Limited knowledge scope FEW
Users want the agent to search full Slack history, threads, mentions, and external sources like Jira and Confluence, but report it currently responds only from pre-written knowledge bases.
What owners love
- Meets users where they work
Owners consistently praise that the agent lives in Slack — the place teams already spend their day — eliminating the need to switch between dashboards and analytics tools for quick questions.
- Fast answers to ad-hoc questions
Commenters highlight it as a 'massive time-saver' for answering executive questions on the fly, getting charts directly in threads without chasing down analysts.
- Scheduled queries
The scheduled query feature is called out as genuinely useful for recurring reporting needs without manual effort.
- Human-in-the-loop concept
The approval-based workflow is praised as addressing a real problem — owners note that clicking approve 90 times and hand-editing 10 is far better than manually copying data between apps.
Surprising patterns
- A user reported getting a real discount from a mattress chatbot by simply asking for a better deal — roughly 25% below the advertised sale price — suggesting AI agents can be socially engineered in commercial contexts.
- Startup owners openly say they'd have an intern build a quick-and-dirty internal copy rather than pay for the SaaS, indicating the perceived moat is thin for technically capable teams.
- Multiple commenters frame AI agent security as fundamentally different from traditional software security — attackers don't need to find a code vulnerability, they just need to trick the model, which 'computers will finally catch up to humans in their ability to be tricked.'
WHO SHOULD SKIP IT
Teams handling sensitive or regulated data in shared Slack channels, or those without the technical resources to override default security settings, should skip this given unresolved concerns about data visibility and prompt-injection vulnerabilities.
Synthesised from 90 real owner comments across 5 platforms. Every point is grounded in the comments — no marketing, no AI guessing. How we do it →