Streamlining Security Investigations with Agents
Not a pilot. Slack deployed AI agents across its security operations handling billions of events per day.

Why it matters
Slack is moving beyond chatbots to deploy AI agents for real infrastructure work—specifically automating security incident triage at scale. This is a concrete example of agents-as-productivity-tool shipping in enterprise infrastructure, not just research.
The key facts
9 to knowSlack Security Engineering uses AI agents for alert review automation
Pipeline handles billions of security events per day
Deployed in on-call workflows for production infrastructure
Published Dec 1 2025 — recent production deployment case study
Slack Security Engineering using AI agents for alert investigation
Security event ingestion pipeline processes billions of events per day
Use case: autonomous security investigation during on-call shifts
Deployment: core infrastructure protection (not experimental)
Published: Slack Engineering blog (official product/capability announcement)
Go to the source
Slack Engineeringslack.engineering
Publisher excerpt: Slack’s Security Engineering team is responsible for protecting Slack’s core infrastructure and services. Our security event ingestion pipeline handles billions of events per day from a diverse array of data sources. Reviewing alerts produced by our security detection system is our primary…