Introduction
How Tandem mirrors Slack and lets a workplace govern what its future agent can use.
Tandem is a workplace control plane built around a simple idea: useful automation needs organizational context, but context must never outrun the boundaries people already rely on.
#What this repository does today
The current product installs into Slack, mirrors tenant data into an isolated Slack database, and stores skills, MCP servers, model providers, and capability policy in one common control-plane database.
- One Slack mirror per tenant.
- One shared database for configuration and capability policy.
- Workspace defaults with channel-level overrides.
- No agent execution path in the current milestone.
Security boundary
Slack login proves identity. The API checks tenant role and channel access again before returning configuration or an effective composition.
#The configuration shape
Slack installation → tenant workspace
Workspace capabilities → channel overrides
Stored resources + policy → effective composition