All posts
Product

Agent-Native Messaging: AI Teammates Join the Chat

Ando raised $20M to rebuild team chat so AI agents are members with identities, permissions and shared context. Why that beats bolting a bot onto Slack.

Younes Alturkey
Younes Alturkey
September 28, 2026·today
Agent-Native Messaging: AI Teammates Join the Chat

Ando came out of stealth on 24 September 2026 with $20 million in pre-seed and seed funding and a blunt thesis: team chat was built for a world where the only participants were people. In Ando, agents are members of the workspace — with their own identities, inboxes, permissions and shared context — rather than apps you install into a channel.

The reason it matters is not the product. It is the pattern the whole industry is about to copy.

The problem she is actually solving

Sara Du founded Ando after building MCP servers for companies in 2025 and watching the same thing happen everywhere: people wanted to run agents inside Slack, got them working, and then became the relay.

She has a name for it — the "meat proxy." The human ends up as the messenger between the agent and the rest of the company. The agent does the work, the person copies the output into the right thread, and the context dies in a DM.

That is a real and under-discussed cost. Every hand-off through a person loses information: the reasoning, the caveats, the thing the agent found but did not think was important. It also means the agent's work is invisible to everyone except the one person who asked.

What Ando shipped

In its current form, Ando is a standalone messaging platform — channels, DMs, group conversations and live calls that can be transcribed and read by an agent. The agent-specific parts are where it departs from the incumbents:

  • Agents have identities and inboxes. Not a shared bot token — a participant, so its messages, mentions and history are attributable.
  • They can join conversations without being tagged. An agent can browse channels and decide a conversation is relevant to it.
  • They can message first. If an agent judges that a person needs to know something, it can start that conversation rather than waiting for approval.
  • They can bring in a human. In Du's own example, an agent noticed two channels discussing the same problem, opened a group chat, explained the context, and suggested a decision.

Teams can bring agents they already run, including Codex, Claude and Grokbot. Ando says it is working with customers in software, real estate and finance across 15 countries, though most teams on it are still small.

Why the incumbents are in an awkward spot

Slack has turned its native bot into an agent. Microsoft has done serious work wiring Copilot through Teams and the rest of Microsoft 365. Just months ago, Jack Dorsey launched Buzz, which mixes people and agents in one messaging app, aimed more at developers.

So Ando is not first. But it is attacking from a position the incumbents structurally cannot occupy: Slack and Teams are priced, permissioned and designed around human seats, with agents as second-class integrations grafted onto a human-first data model. Du's own framing is that incumbents have to figure out "how to pivot their existing software."

That is the part worth watching. A workspace where an agent is a first-class participant needs different primitives — per-agent rate limits, agent-visible audit trails, channel-level agent permissions, and a way to tell a generated message from a typed one. Retrofitting those onto a product with hundreds of millions of human users is genuinely hard.

Bot in a channel vs. agent as a member

Bot bolted onto Slack/TeamsAgent as a first-class member
IdentityOne shared app tokenIts own account and presence
ContextOnly what it is tagged intoThe channels it has joined
InitiativeResponds when invokedCan notice, raise and act
Attribution"The bot said…"Named participant in the thread
PermissionsWhatever the install grantedScoped per agent, per channel
RiskSilent failureOver-participation and noise

Read that last row again. The same design that lets an agent bring two teams together is the design that lets it speak in a thread where it was not wanted. Every argument for agent autonomy is also an argument for agent volume control — and none of these platforms has published a convincing answer to "what stops fifty agents from filling a channel with polite agreement?"

The unsolved parts

Three things no vendor has nailed yet, and all three are your problem regardless of which platform you pick:

  1. Identity. An agent with write access to team conversation needs its own credentials, not yours — so that its actions are attributable and revocable. This is the same reason we argued agents need their own identity months before this launch.
  2. Permission drift. Agents accumulate access quietly. If you have ever granted a bot "read messages" and later given it write, review the scopes — the platform will not.
  3. The audit question. When an agent makes a decision that costs money, what did it know? If channel history is the evidence, agents being participants means agents are also part of the record.

What to do this quarter

You do not need to migrate your company chat. You do need to fix the relay problem:

  • Give each agent you run its own name and account rather than a shared credential.
  • Create one channel per agent, not one channel for all of them, so context does not collide.
  • Pin a short brief in that channel: what the agent is for, what it may do unattended, and who owns it. Teams that do this report far less "why did the bot do that?"
  • Log everything. If your agent's work cannot be reconstructed later, it is not ready for shared space.
  • Where it matters most, keep a human on the irreversible step. Shared context should not mean shared authority.

Takeaway

Ando is a $20M bet that the messaging app, not the model, is the bottleneck for agent adoption at work — that agents fail in teams not because they are incapable but because they have nowhere to be. Whether Ando wins or Slack absorbs the idea, the direction is set: agents get identities, channels and permissions, and the days of the human meat proxy are numbered.

Read next: AI Agents Are Now a Daily Habit at Work for the adoption numbers, or Shadow AI Agents at Work if you suspect your team is already running them unofficially.

One-page takeaway: the relay problem, the five agent-member rules, and what to fix this quarter