Slack – Marcus Chat Integration
Install the Marcus Slack app, connect a channel to a Guard account, and ask Marcus questions about your attack surface from Slack.
Marcus is Guard's AI assistant, and the Marcus Slack app lets your team ask Marcus questions from a Slack channel. Every answer is scoped to the Guard account the channel is connected to, and every question runs with the Guard permissions of the person who asked it. This guide walks you through installing the app, adding Marcus to a channel, connecting that channel to a Guard account, and asking your first question.
This article covers the Marcus chat app only. Slack alert notifications use a separate incoming-webhook integration, described in Slack Notifications.
Prerequisites
- A Slack workspace where you have permission to install apps.
- A Guard user with permission to manage integrations, for the install and channel-connect steps.
- A Guard user in the connected account for each person who will ask Marcus questions. Marcus answers only people it can match to a Guard user.
Install the Marcus Slack app
The app installs once per Slack workspace through a standard Slack authorization flow. There is no token or webhook URL to paste.
- In Guard, navigate to Integrations > Workplace Messaging > Slack (Chat Bot).
- Click Add to Slack.
- On the Slack authorization page, choose the workspace and click Allow.
- Confirm that Guard returns you to the Integrations page and shows the message Slack workspace
<workspace name>connected.
If Guard shows Workspace <workspace name> is already connected to another account instead, that workspace is already installed from a different Guard account. One install serves every Guard account you can act in, so continue with the steps below from the account that owns the install, or contact support to move it.
Add Marcus to a channel
Installing the app does not add Marcus to any channel, and connecting a channel to Guard does not add it either. Marcus only sees mentions in channels it is a member of.
- In Slack, open the channel where you want to use Marcus.
- Type
/invite @Marcusand press Enter. - Confirm that Slack posts a message saying Marcus was added to the channel.
This works in public channels, private channels, and Slack Connect channels shared with other organizations. Private channels, including private Slack Connect channels, need the groups:history Slack permission, which the Marcus app requests as of September 2026. Public Slack Connect channels do not need it. If your workspace installed the app before then, a Guard admin must reinstall it from Integrations > Workplace Messaging > Slack (Chat Bot) by clicking Add to Slack again. Until then, Marcus reacts to a mention in a private channel but cannot read the thread, and it tells you so (see Troubleshooting).
Connect the channel to a Guard account
Each channel is connected to exactly one Guard account. You start the connection in Slack and finish it in Guard.
In Slack
- In the channel, type
/marcus connectand press Enter. - Read the reply, which only you can see: Connect #
<channel>to a Guard account: open Guard to finish. The link expires in 15 minutes. - Click open Guard to finish. Guard opens in your browser and prompts you to sign in if you are not already signed in.
In Guard
- In the Connect Chat Channel dialog, choose the Guard account this channel should be connected to and click Connect. If you belong to only one account, Guard skips this step.
- In the Confirm Connection dialog, check the channel name and the account name, then click Confirm. Click Back to choose a different account.
- When the Channel Connected dialog appears, click View account or close the dialog.
Note: Guard does not post a confirmation back to the Slack channel. The Channel Connected dialog in Guard is the only confirmation you will see, so check the account name at the Confirm Connection step before you click Confirm. A channel connected to the wrong account answers questions from that account's data until you disconnect it.
If the link has expired, Guard shows Failed to connect channel. Run /marcus connect in the channel again for a fresh link.
Ask Marcus a question
- In the connected channel, type
@Marcusfollowed by your question, for example@Marcus what are my open critical risks?. - Watch the thread that Marcus opens under your message. Marcus posts a status such as Searching your Guard data… while it works, then posts the answer in the thread.
- Reply in the same thread to ask a follow-up. You do not need to mention Marcus again inside a thread it is already answering.
Marcus answers with the data and permissions of your Guard user in the connected account. If your Guard role cannot see something in the Guard UI, Marcus cannot show it to you either.
Link your Slack identity to your Guard user
Marcus matches you to your Guard user by the email address on your Slack profile. If it cannot make that match, for example because you sign in to Guard with single sign-on or you are an external member of a Slack Connect channel, Marcus asks you to link your identity the first time you mention it.
- Read the reply, which only you can see: Hi! I don't know who you are in Praetorian Guard yet. Connect your Guard account (link expires in 15 minutes), then mention me again.
- Click Connect your Guard account. Guard opens in your browser and prompts you to sign in if you are not already signed in. Sign in to the account the channel is connected to.
- In the Link Slack Account dialog, choose the Guard account to link to and click Link. If you belong to only one account, Guard skips this step.
- In the Confirm Link dialog, click Confirm.
- When the Chat Account Linked dialog appears, return to Slack and mention Marcus again.
You link once per Guard account. If you see this link is for a different Guard account than the one you are signed in to, switch to the account the channel is connected to and click the link again. If the link has expired, mention Marcus again for a fresh one.
Guard does not currently offer a way to remove a link yourself. Completing the link flow again replaces your existing link. Contact support if you need a link removed.
Manage connected channels
Connected channels are listed under notification settings, not on the Integrations page.
- In Guard, navigate to Settings > Notifications.
- Open the Chat Messaging card and find the Connected Chat Channels panel. Each row shows the platform and the channel name. The panel is hidden when the account has no connected channels.
- To disconnect a channel, click the disconnect control on its row and click Disconnect in the Disconnect Channel dialog.
Disconnecting a channel stops Marcus from answering in it. The workspace install stays in place, and you can connect the channel again at any time with /marcus connect.
Working across several Guard accounts
If you manage more than one Guard account, for example as a service provider, keep these rules in mind:
- The Slack app is installed once per workspace, from any one of your Guard accounts. You do not reinstall it for each account.
- Each channel is connected to exactly one Guard account. To serve several accounts from one workspace, use a separate channel for each account and connect each channel to its own account.
- A channel that is already connected to a different account cannot be connected again until it is disconnected from the first one. Guard shows this channel is already connected to a different Guard account if you try.
- Members of a Slack Connect channel from another organization link their Slack identity to a Guard user in the account the channel is connected to. They need a Guard user in that account.
Notifications
Marcus does not send alert notifications to Slack. To receive Guard alerts in a Slack channel, set up the incoming-webhook integration described in Slack Notifications. The two integrations are independent, and you can use either or both.
Troubleshooting
If you run into any issues during the integration process or have questions about maximizing the value of this integration, our support team is ready to help. You can reach us at support@praetorian.com, and we'll be happy to guide you through any challenges you encounter.