Podcast episode
How to Build Team Agents
agents build-vs-buy orchestration security tool-use
Nathaniel Whittemore and Nufar Gaspar lay out a framework for "team agents": instead of every employee building their own AI helper, a team shares one, with one owner and one curated knowledge base. Gaspar walks through four archetypes, from a searchable internal wiki to a "bridge agent" spanning sales-to-support handoffs. She's honest that the bridge version doesn't really work yet and most orgs should start with the boring one.
Buried inside the framework is the part worth acting on now. When Claude runs inside a shared Slack channel and you approve a connector (a link letting Claude read your docs, email, or CRM), the data Claude fetches is visible to everyone in the channel, regardless of their actual access rights. A salary sheet you're authorized to see lands in front of people who aren't. Gaspar flags it; Whittemore largely concedes the "easy win" is just a chatbot on a wiki.
The portability point is real: build your knowledge base tool-agnostic and you can move it when better native tools ship. But audit your Claude-in-Slack channels first. That's the only thing here with a cost if you wait.
Full analysis
The news here is a playbook, not a product. Nathaniel Whittemore and Nufar Gaspar spend an episode arguing that 2026 is when companies stop letting every employee build their own AI helper and start building shared "team agents": one AI, one owner, one shared knowledge base, used by a whole team. Useful framework. But the one piece of hard, checkable news buried in it is a live security gap in Anthropic's Claude-in-Slack integration. That's the part worth acting on this week.
How hard is this to undo? Easy. Nothing here demands a big commitment. You can pilot a team agent and kill it Friday. The only thing that's expensive to undo is a data leak, and that's the Slack issue.
What sets the deadline? Nothing external. No shutdown, no price change. If you run Claude in Slack, the deadline is self-imposed: audit your channels before someone pulls sensitive data into one.
What's actually being decided: whether to front-load the boring work. Writing down what one expert knows, deciding who can touch what, before the vendors ship native tools that do half of it for you.
The Skeptic
Most of this is a repackaging of "write good documentation and manage permissions," dressed in agent vocabulary. The four archetypes are a consultant's slide, not a discovery. Gaspar herself admits the most attractive one, the bridge agent that spans sales-to-support handoffs, is the hardest and not where anyone should start. Translation: the exciting version doesn't work yet. What survives contact with a real org is the dull version. A chatbot sitting on top of a company wiki. Whittemore basically concedes this: his "easy early win" is a searchable knowledge hub. That's SharePoint with a chat box. Fine. Just don't call it a breakthrough.
The Builder
The one thing I'd act on Tuesday is the Claude-in-Slack gap. Here's the mechanics: when you approve your own connectors (the links that let Claude read your email, docs, or CRM) inside a shared Slack channel, the data Claude fetches lands in the channel for everyone to see. Your access rights don't travel with the answer. So a person who can't see a salary sheet sees it anyway because you asked. That's not a config nuance, that's a leak waiting for a careless prompt. Audit every shared channel running Claude now. Route anything sensitive to a direct message. Don't wait for Anthropic to fix it.
The Enterprise Buyer
This is where the episode earns its keep. Gaspar's real advice: do the knowledge curation and permission mapping yourself, because "the config work transfers; the vendor lock-in doesn't." She's right, and it's the buying lesson. The instructions and approved-knowledge base you build are portable across Claude team spaces, ChatGPT Workspace, and Microsoft Copilot. The moment a vendor's native permissions tool ships, you lift your work onto it. What you never want is an agent wired to touch systems using one employee's personal login. Gaspar calls that out and she's dead right. When that person leaves, or their password rotates, your agent breaks and nobody can trace what it did.
The Open-Source Advocate
The episode names OpenClo and Hermes as self-hosted agent options for teams that want to run this on their own servers. Honest framing from Gaspar: most flexible, most technically demanding. For 90% of readers, that's a trap this year. You'd be hand-building the identity and permission plumbing that Anthropic and Microsoft are about to ship for free. The open-source case only holds if your data genuinely cannot leave your walls: regulated health, defense, some finance. Everyone else should let the vendors carry the infrastructure and keep their moat in the curated knowledge, exactly as Gaspar says.
Where they part ways
The Skeptic and the Enterprise Buyer disagree on what this episode is worth. The Skeptic says it's documentation with a new hat. The Buyer says the portability point (build your knowledge base tool-agnostic, move it when native tools mature) is a genuine hedge against lock-in and worth the effort now. Both are right about different things: the framework is thin, the sequencing advice is not.
The Builder and the vendors disagree on the Slack gap. Gaspar frames it as a design gap operators must work around by hand. Anthropic would call it expected behavior in a shared channel. That difference decides whether you trust the default or override it. Trust the default and you're one prompt away from a leak.
What it hinges on
Two things. One, is the "team agent" consolidation real or a vendor talking point? The Shopify and Sierra examples are real but they're the AI-forward outliers, not proof most companies are consolidating. Two, does the Slack permission gap actually get closed by the vendor, or does it stay the buyer's problem? That's the checkable one, and it tells you how seriously Anthropic treats permissions inside collaboration tools versus inside its own API.
De-risk it cheaply: run one expert agent on a wiki you already trust, keep the knowledge base in plain files you own, and never let an agent authenticate as a human. That's the whole playbook that matters.
Prediction: Anthropic will change the default behavior of Claude's Slack integration so that connector-fetched data respects each channel member's individual access rights, rather than surfacing one user's authorized pull to everyone in the channel, by 2027-04-04.
Confidence: Medium. The security gap is clear, but timing depends on Anthropic's enterprise roadmap.
Why: Gaspar has publicly described a specific, reproducible flaw: an authorized user's connector pull becomes visible to everyone in a shared Slack channel regardless of their own permissions, which means Claude can expose data a channel member has no right to see. Anthropic sells Claude to enterprises on the promise of permission-aware behavior, so a leak that fires on ordinary use directly threatens the deals it wants to close, and enterprise security teams block tools over exactly this. The pattern with cloud vendors is that a named, reproducible permission bug in a flagship integration gets patched within a couple of quarters once it's circulating publicly, because the reputational and sales cost of leaving it open exceeds the engineering cost of scoping the fetch. The less likely outcome is that Anthropic leaves it as documented "expected behavior," because that hands every rival Copilot and ChatGPT Workspace a security talking point in every enterprise bake-off.
Revisit by 2027-04-04: We're right if Anthropic ships a change (documented in release notes or its Slack integration docs) making connector data respect individual channel-member access. We're wrong if the current behavior, where one user's authorized pull is visible to the whole channel, is still the default on that date.
Comments