[
  {
    "title": "Architecture",
    "slug": "architecture.html",
    "module": "ROOT",
    "source": "docs-Oct2026/src/asciidoc/modules/ROOT/pages/architecture.adoc",
    "text": "= Architecture\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators, developers\n:page-tags: slack-kb-agent, architecture, security\n:page-last-updated: 2026-10-02\n\n== Runtime flow\n\n[source,text]\n----\nSlack -> HTTP callbacks (/slack/events and /slack/interactions) OR Socket Mode\n      -> command parser -> Slack thread fetch -> secret redaction\n      -> OpenAI directly OR Galileo/Portkey gateway -> DraftStore\n      -> Slack preview -> Approve / Edit / Cancel\n      -> GitHub draft PR OR Confluence page; optional Jira issue follows a GitHub PR\n----\n\nThe active application is Python 3.11+ and FastAPI. `app.main:app` exposes `/health`, the two Slack HTTP endpoints, and `/auth/github/start` and `/auth/github/callback`. The alternative `python -m app.slack_socket_app` receives commands and interactions over Slack Socket Mode. Socket Mode does not require public Slack callback endpoints; HTTP mode verifies request signatures unless explicitly disabled.\n\nThe parser accepts one to five thread links by default. Slack messages are normalized and likely Slack, GitHub, OpenAI, and AWS access-key patterns are replaced with `[REDACTED]` before model input. The model returns a structured draft. No destination is written until its creator approves it.\n\n== Publishing and integrations\n\nFor GitHub, authorization is evaluated against `KB_ALLOWED_REPOS` and the selected authorization mode. Approval creates a timestamped `knowledge-assistant/...` branch, writes one Markdown or MDX file, and opens a draft pull request. Confluence approval calls the configured MCP `create_page` tool with MuleSoft service credentials and the approving user's stored PAT. Jira is compatible with GitHub publishing only and is attempted after PR creation.\n\n== State and audit\n\nDrafts use SQLite when `DRAFT_DATABASE_PATH` is set; otherwise they are process-local and lost at restart. OAuth authorizations and single-use, expiring OAuth state use SQLite when `AUTHORIZATION_DATABASE_PATH` is set. Confluence PATs are encrypted files under `CONFLUENCE_TOKEN_DIRECTORY`. The Helm chart mounts a single persistent volume for both SQLite databases.\n\nAudit records contain request/user identifiers, target repository, source URLs, action, approver, and outcome; they do not contain Slack message bodies or tokens. The current audit repository is in-memory, so audit durability is `TO_BE_CONFIRMED`.\n\nSee xref:security:authentication.adoc[Authentication], xref:security:session-persistence.adoc[Session persistence], and xref:reference:configuration.adoc[Configuration].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators, developers",
    "tags": [
      "slack-kb-agent",
      "architecture",
      "security"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Compatibility",
    "slug": "compatibility.html",
    "module": "ROOT",
    "source": "docs-Oct2026/src/asciidoc/modules/ROOT/pages/compatibility.adoc",
    "text": "= Compatibility\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators, developers\n:page-tags: slack-kb-agent, compatibility, python, node\n:page-last-updated: 2026-10-02\n\n== Application runtime\n\n[cols=\"1,2\"]\n|===\n|Component |Supported version\n\n|Python\n|3.11 or later\n\n|FastAPI\n|0.111.0 or later\n\n|Uvicorn\n|0.30.0 or later\n|===\n\n== Documentation build\n\nThe OneDoc documentation build uses Node.js 22 in GitHub Actions.",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators, developers",
    "tags": [
      "slack-kb-agent",
      "compatibility",
      "python",
      "node"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Deprecations",
    "slug": "deprecations.html",
    "module": "ROOT",
    "source": "docs-Oct2026/src/asciidoc/modules/ROOT/pages/deprecations.adoc",
    "text": "= Deprecations\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators, developers\n:page-tags: slack-kb-agent, deprecations\n:page-last-updated: 2026-10-02\n\nThere are currently no documented deprecations for Slack KB Agent.",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators, developers",
    "tags": [
      "slack-kb-agent",
      "deprecations"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Slack KB Agent",
    "slug": "index.html",
    "module": "ROOT",
    "source": "docs-Oct2026/src/asciidoc/modules/ROOT/pages/index.adoc",
    "text": "= Slack KB Agent\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, slack, github, confluence, knowledge\n:page-last-updated: 2026-10-02\n\nSlack KB Agent converts useful Slack conversations into reusable documentation.\n\nIt enables users to create documentation drafts from Slack threads, review the\ngenerated content, and publish approved documentation to GitHub or Confluence.\n\n== Key capabilities\n\n* Generate documentation from Slack threads.\n* Authenticate users individually with GitHub.\n* Review, edit, approve, or cancel drafts.\n* Create GitHub pull requests using the authenticated user's identity.\n* Connect to Confluence using per-user authentication.\n* Prepare for Confluence publishing through the implemented MuleSoft MCP integration (page creation is currently blocked pending Confluence write access).\n* Persist pending drafts across application restarts.\n\n== Get started\n\nxref:getting-started:quickstart.adoc[Start using Slack KB Agent]\n\n== Common tasks\n\nxref:user:github-connect.adoc[Connect your GitHub account]\n\nxref:user:create-draft.adoc[Create a knowledge draft]\n\nxref:user:create-github-pr.adoc[Publish to GitHub]\n\nxref:user:create-confluence-page.adoc[Publish to Confluence]\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "slack",
      "github",
      "confluence",
      "knowledge"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Overview",
    "slug": "overview.html",
    "module": "ROOT",
    "source": "docs-Oct2026/src/asciidoc/modules/ROOT/pages/overview.adoc",
    "text": "= Overview\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, overview\n:page-last-updated: 2026-10-02\n\nSlack KB Agent turns one or more Slack thread links into a structured knowledge article. It fetches the threads with the Slack bot, redacts recognizable credentials, asks the configured model for a factual draft, and returns an interactive Slack preview.\n\nThe requesting Slack user owns the draft. That user can edit it, cancel it, or approve publication. Approval targets either a GitHub draft pull request or a Confluence page. A Jira issue can optionally be created after a GitHub PR.\n\nThe service supports signed HTTP callbacks and Socket Mode, three GitHub authorization modes, per-user encrypted GitHub OAuth tokens, per-user encrypted Confluence PATs, repository allowlisting, and in-memory or SQLite draft storage.\n\nContinue with xref:getting-started:quickstart.adoc[Quickstart], xref:user:create-draft.adoc[Create a draft], or xref:architecture.adoc[Architecture].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "overview"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Release Notes",
    "slug": "release-notes.html",
    "module": "ROOT",
    "source": "docs-Oct2026/src/asciidoc/modules/ROOT/pages/release-notes.adoc",
    "text": "= Release Notes\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators, developers\n:page-tags: slack-kb-agent, release-notes\n:page-last-updated: 2026-10-02\n\n== Version 0.2.0\n\nCurrent application version defined in `pyproject.toml`.\n\nKey capabilities include:\n\n* Slack `/knowledge` commands.\n* Human approval before publishing.\n* Per-user GitHub OAuth authentication.\n* GitHub PR creation.\n* Optional Jira ticket creation.\n* Confluence publishing through MuleSoft MCP Synapse.\n* Galileo/Portkey gateway support.\n* Slack Socket Mode support.",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators, developers",
    "tags": [
      "slack-kb-agent",
      "release-notes"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Roadmap",
    "slug": "roadmap.html",
    "module": "ROOT",
    "source": "docs-Oct2026/src/asciidoc/modules/ROOT/pages/roadmap.adoc",
    "text": "= Roadmap\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators, developers\n:page-tags: slack-kb-agent, roadmap\n:page-last-updated: 2026-10-02\n\nThe repository does not define an approved product roadmap, delivery dates, or backlog location. These items are `TO_BE_CONFIRMED` by the product owner.\n\nCurrent implemented capabilities are recorded in xref:release-notes.adoc[Release notes].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators, developers",
    "tags": [
      "slack-kb-agent",
      "roadmap"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Support",
    "slug": "support.html",
    "module": "ROOT",
    "source": "docs-Oct2026/src/asciidoc/modules/ROOT/pages/support.adoc",
    "text": "= Support\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators, developers\n:page-tags: slack-kb-agent, support\n:page-last-updated: 2026-10-02\n\nThe repository does not provide a verified support channel, email address, service owner, or response-time commitment. Use your normal internal escalation route; the Slack KB Agent-specific contact is `TO_BE_CONFIRMED`.\n\nBefore escalating, record the command (without credentials), draft or request ID, time, destination, and visible error. Never include OAuth tokens, PATs, Slack message contents, signing secrets, or application private keys.\n\nSee xref:troubleshooting:index.adoc[Troubleshooting] first.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators, developers",
    "tags": [
      "slack-kb-agent",
      "support"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Deployment",
    "slug": "admin/deployment.html",
    "module": "admin",
    "source": "docs-Oct2026/src/asciidoc/modules/admin/pages/deployment.adoc",
    "text": "= Deployment\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators\n:page-tags: slack-kb-agent, deployment\n:page-last-updated: 2026-10-02\n\n== Local HTTP mode\n\n[source,bash]\n----\ncp .env.example .env\n# populate secrets without committing .env\ndocker compose up --build knowledge-assistant\ncurl http://localhost:3000/health\n----\n\nCompose runs `uvicorn app.main:app --host 0.0.0.0 --port 3000`. For Socket Mode run `docker compose --profile socket up --build knowledge-assistant-socket`; the image default is `python -m app.slack_socket_app`. The Python image is based on `python:3.11-slim`, installs the project, changes to an unprivileged `app` user, and exposes port 3000.\n\nFor direct development, install Python 3.11+, run `pip install -e '.[dev]'`, then use Uvicorn or the Socket Mode module. Verify with `pytest` and `ruff check .`.\n\n== Production artifacts\n\nThe Helm chart is under `deployment/`. Environment values exist for sbx, dev, and prod. Their hostnames, ECR repositories, and Vault remote keys are repository configuration, but cluster context and release automation are `TO_BE_CONFIRMED`. See xref:kubernetes.adoc[Kubernetes].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators",
    "tags": [
      "slack-kb-agent",
      "deployment"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "GitHub App Setup",
    "slug": "admin/github-app.html",
    "module": "admin",
    "source": "docs-Oct2026/src/asciidoc/modules/admin/pages/github-app.adoc",
    "text": "= GitHub App Setup\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators\n:page-tags: slack-kb-agent, github, oauth\n:page-last-updated: 2026-10-02\n\nCreate/configure a GitHub App with repository **Contents: read and write** and **Pull requests: read and write**. Install it only on approved repositories. Exact App owner/name and installation approval process are `TO_BE_CONFIRMED`.\n\nFor installation/hybrid mode configure `GITHUB_APP_ID`, `GITHUB_APP_PRIVATE_KEY`, and `GITHUB_APP_INSTALLATION_ID`. For delegated/hybrid mode also configure OAuth `GITHUB_APP_CLIENT_ID`, `GITHUB_APP_CLIENT_SECRET`, the exact public `GITHUB_OAUTH_CALLBACK_URL` ending at `/auth/github/callback`, `TOKEN_ENCRYPTION_KEY`, and preferably persistent `AUTHORIZATION_DATABASE_PATH`.\n\nSet `KB_ALLOWED_REPOS` independently of installation scope. The application requires both allowlist authorization and usable GitHub credentials. In GitHub, configure the callback URL exactly; the service's `/auth/github/start` endpoint validates its own state then redirects to GitHub.\n\nValidate with `/knowledge connect`, `/knowledge status`, a draft approval into a test repository, and `/knowledge disconnect`. See xref:security:github-authorization.adoc[GitHub authorization].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators",
    "tags": [
      "slack-kb-agent",
      "github",
      "oauth"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Kubernetes Deployment",
    "slug": "admin/kubernetes.html",
    "module": "admin",
    "source": "docs-Oct2026/src/asciidoc/modules/admin/pages/kubernetes.adoc",
    "text": "= Kubernetes Deployment\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators\n:page-tags: slack-kb-agent, kubernetes, helm\n:page-last-updated: 2026-10-02\n\nThe chart `slack-kb-agent` is version/appVersion 0.2.0. It creates a Deployment, ClusterIP Service, optional Ingress, ExternalSecret, and optional PVC in namespace `slack-kb-agent`. Defaults request 100m CPU/128Mi and limit 250m/256Mi; one replica is configured.\n\n[source,bash]\n----\nhelm upgrade --install slack-kb-agent deployment   --namespace slack-kb-agent --create-namespace   -f deployment/values.yaml -f deployment/values-sbx.yaml\n----\n\nReplace the final values file for dev or prod only after selecting the correct cluster context. `agent.runtimeMode: socket` uses the image command; `http` overrides it with Uvicorn and enables health probes. The service/ingress can remain enabled in Socket Mode for OAuth callbacks, though Slack commands use the socket.\n\nThe PVC is `ReadWriteOnce` by default and backs `/data/authorizations.sqlite` and `/data/drafts.sqlite`. This SQLite design and one replica must be reviewed before scaling. The sbx override says `Recreate` as an access mode, which is not a valid Kubernetes PVC access mode and requires correction before rendering/applying that override.\n\nRun `helm lint deployment -f deployment/values.yaml -f deployment/values-<environment>.yaml` and inspect `helm template` before upgrade. Cluster name, deployment controller, rollback owner, and namespace permissions are `TO_BE_CONFIRMED`.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators",
    "tags": [
      "slack-kb-agent",
      "kubernetes",
      "helm"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Slack App Setup",
    "slug": "admin/slack-app.html",
    "module": "admin",
    "source": "docs-Oct2026/src/asciidoc/modules/admin/pages/slack-app.adoc",
    "text": "= Slack App Setup\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators\n:page-tags: slack-kb-agent, slack, socket-mode\n:page-last-updated: 2026-10-02\n\nConfigure a `/knowledge` slash command. In HTTP mode, set its request URL to the public `/slack/events` endpoint and enable Interactivity with `/slack/interactions`. In Socket Mode, enable Socket Mode, create an app-level token with the connection permission required by Slack, and retain Interactivity so block actions and modal submissions are delivered over the socket.\n\nThe bot calls `conversations.replies`, posts via response URLs/Web API, and opens modals. Configure bot scopes sufficient for commands, reading replies in intended public/private channels, posting responses, and opening views. The repository does not contain a Slack manifest, so exact scope names and workspace installation owner are `TO_BE_CONFIRMED`; apply least privilege and verify against Slack's current scope requirements.\n\nStore the bot token in `SLACK_BOT_TOKEN`, signing secret in `SLACK_SIGNING_SECRET`, and Socket Mode app token in `SLACK_APP_TOKEN`. Do not enable unsigned HTTP requests. Test `/knowledge help`, a thread fetch, preview buttons, modal submission, and OAuth callback notification.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators",
    "tags": [
      "slack-kb-agent",
      "slack",
      "socket-mode"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Vault Configuration",
    "slug": "admin/vault.html",
    "module": "admin",
    "source": "docs-Oct2026/src/asciidoc/modules/admin/pages/vault.adoc",
    "text": "= Vault Configuration\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators\n:page-tags: slack-kb-agent, vault, secrets\n:page-last-updated: 2026-10-02\n\nThe chart uses External Secrets Operator, not direct Vault API calls. Configure an existing `SecretStore`/`ClusterSecretStore`, `externalSecrets.remoteKey`, and refresh interval. The checked-in overrides use store name `slack-kb-agent-secretstore`; remote keys are environment-specific.\n\nThe ExternalSecret maps named properties to an opaque Kubernetes Secret. Required properties vary by runtime and enabled integrations; use xref:reference:environment-variables.adoc[Environment variables] and the template as the definitive list. Never put values in Helm files or documentation.\n\nBefore deployment, confirm the operator can read the remote key and that the generated Secret contains the expected keys. The Vault authentication method, policies, administrators, rotation cadence, and recovery process are `TO_BE_CONFIRMED`. Rotating `TOKEN_ENCRYPTION_KEY` requires migration or reconnection of stored user credentials.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators",
    "tags": [
      "slack-kb-agent",
      "vault",
      "secrets"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Docs Style Guide",
    "slug": "contributing/docs-style-guide.html",
    "module": "contributing",
    "source": "docs-Oct2026/src/asciidoc/modules/contributing/pages/docs-style-guide.adoc",
    "text": "= Docs Style Guide\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: developers\n:page-tags: slack-kb-agent, documentation\n:page-last-updated: 2026-10-02\n\nUse the Python application, tests, deployment files, configuration, then existing technical docs as the evidence order. Do not infer behavior from the retained TypeScript MVP. Use `TO_BE_CONFIRMED` rather than inventing owners, contacts, URLs, controls, or dates.\n\nEvery page needs title, owner, SME, audience, tags, and last-updated metadata. Use sentence-case headings, one topic per page, Antora `xref:` links, source blocks for commands, and admonitions only for meaningful risk. Never publish credentials or Slack message content.\n\nBefore review, run `npm ci` and `npm run build` from `docs`, check xrefs, and search for template markers. When parsing, rendering, or redaction behavior changes, update the relevant documentation and application tests.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "developers",
    "tags": [
      "slack-kb-agent",
      "documentation"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Onboarding",
    "slug": "getting-started/onboarding.html",
    "module": "getting-started",
    "source": "docs-Oct2026/src/asciidoc/modules/getting-started/pages/onboarding.adoc",
    "text": "= Onboarding\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, onboarding\n:page-last-updated: 2026-10-02\n\n== Prerequisites\n\n* Slack KB Agent is installed and `/knowledge` is available.\n* The bot can read every source thread.\n* The target repository is allowlisted, or a Confluence space is available.\n\n== Set up\n\n. Run `/knowledge help`.\n. For delegated or hybrid GitHub access, run `/knowledge connect`, complete the browser authorization, then run `/knowledge status`.\n. For Confluence, run `/knowledge confluence-connect` and submit the PAT only in the modal.\n. Follow xref:quickstart.adoc[Quickstart].\n\nInstallation ownership and user eligibility are `TO_BE_CONFIRMED`; see xref:requesting-access.adoc[Requesting access].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "onboarding"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Quickstart",
    "slug": "getting-started/quickstart.html",
    "module": "getting-started",
    "source": "docs-Oct2026/src/asciidoc/modules/getting-started/pages/quickstart.adoc",
    "text": "= Quickstart\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, quickstart\n:page-last-updated: 2026-10-02\n\n== Create a first draft\n\n. In Slack, copy a thread link that the bot can read.\n. Run `/knowledge draft <slack-thread-url>`.\n. Wait for the private preview and check title, summary, root cause, resolution steps, tags, and source links.\n. Select *Edit*, *Cancel*, or *Approve*.\n\nApproval creates a GitHub branch, file, and **draft** PR by default. In delegated mode, first complete xref:user:github-connect.adoc[GitHub connection]. The Confluence workflow is implemented but cannot currently create pages because the deployment is awaiting Confluence write access; see xref:user:create-confluence-page.adoc[Create a Confluence page] for its status and configuration.\n\nIf no preview appears, see xref:troubleshooting:slack.adoc[Slack issues].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "quickstart"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Requesting Access",
    "slug": "getting-started/requesting-access.html",
    "module": "getting-started",
    "source": "docs-Oct2026/src/asciidoc/modules/getting-started/pages/requesting-access.adoc",
    "text": "= Requesting Access\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, access\n:page-last-updated: 2026-10-02\n\nThe repository does not define who may request access, the approval route, or provisioning time. These are `TO_BE_CONFIRMED`.\n\nA user needs access to the installed Slack app and its `/knowledge` command, access to every source channel, and destination access. In delegated GitHub mode the user must be able to authorize the GitHub App and write to the target repository. Confluence publishing requires a PAT accepted by the configured MCP environment.\n\nAsk the application owner (`TO_BE_CONFIRMED`) to confirm Slack workspace availability and destination allowlisting. Never send credentials in a request. Continue with xref:onboarding.adoc[Onboarding].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "access"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Command Reference",
    "slug": "reference/commands.html",
    "module": "reference",
    "source": "docs-Oct2026/src/asciidoc/modules/reference/pages/commands.adoc",
    "text": "= Command Reference\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, commands, reference\n:page-last-updated: 2026-10-02\n\n[cols=\"2,3,3\"]\n|===\n|Syntax |Purpose |Requirements/side effects\n|`/knowledge` or `/knowledge help` |Show help |None\n|`/knowledge connect` |Start GitHub OAuth |Delegated/hybrid OAuth configuration; stores encrypted user tokens\n|`/knowledge status` |Show GitHub binding |Authorization service configured\n|`/knowledge disconnect` |Revoke binding |Attempts GitHub token revocation and marks/removes local authorization\n|`/knowledge confluence-connect` |Open PAT modal |Interactivity and `TOKEN_ENCRYPTION_KEY`\n|`/knowledge draft <links...> [options]` |Generate a pending preview |Valid thread URLs; does not publish\n|`/knowledge create-pr <links...> [options]` |Legacy alias through the same draft/approval flow |Does not bypass approval\n|`/knowledge approve <draft-id>` |Publish owned pending draft |Creator only; writes selected destination\n|`/knowledge edit <draft-id>` |Direct user to preview Edit button |Creator only; modal requires a button trigger\n|`/knowledge cancel <draft-id>` |Cancel owned pending draft |No destination write\n|===\n\nDraft options are `--repo owner/repo`, `--path docs-relative-path`, `--jira`, `--jira-project VALUE`, `--jira-issue-type VALUE`, `--confluence`, `--confluence-space SPACE`, and `--confluence-parent PAGE_ID`. Values with spaces must be quoted. Unknown flags and missing values are rejected. `--confluence` and `--jira` are mutually exclusive. See xref:user:create-draft.adoc[Create a draft].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "commands",
      "reference"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Configuration",
    "slug": "reference/configuration.html",
    "module": "reference",
    "source": "docs-Oct2026/src/asciidoc/modules/reference/pages/configuration.adoc",
    "text": "= Configuration\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators, developers\n:page-tags: slack-kb-agent, configuration, reference\n:page-last-updated: 2026-10-02\n\n== Categories\n\n* **Slack:** choose signed HTTP callbacks or Socket Mode and configure the matching signing/app credentials.\n* **Model:** direct OpenAI uses `OPENAI_API_KEY`; Galileo routing uses `GALILEO_API_KEY` (falling back to the OpenAI key), its gateway URL, and Portkey application metadata.\n* **GitHub:** choose installation, delegated, or hybrid auth; set target defaults and a required repository allowlist.\n* **Persistence:** set both SQLite paths for restart-safe drafts, authorizations, and OAuth state. Mount the Confluence token directory separately.\n* **Jira:** select auth type, API version, description format, defaults, SSL verification, and optional Cloudflare Access credentials.\n* **Confluence:** configure MCP URL/tool, MuleSoft credentials, optional default space/parent, and encrypted PAT directory.\n* **Runtime:** `PORT` is used by startup; the Helm `runtimeMode` selects Socket Mode or Uvicorn HTTP.\n\nApplication defaults in code can differ from deployment choices. For example, code defaults GitHub to `installation` and Galileo off, while `.env.example` selects delegated/Galileo and the Helm values select Socket Mode/Galileo. Treat deployed environment values as authoritative for an environment.\n\nSee xref:environment-variables.adoc[Environment variables].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators, developers",
    "tags": [
      "slack-kb-agent",
      "configuration",
      "reference"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Environment Variables",
    "slug": "reference/environment-variables.html",
    "module": "reference",
    "source": "docs-Oct2026/src/asciidoc/modules/reference/pages/environment-variables.adoc",
    "text": "= Environment Variables\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators, developers\n:page-tags: slack-kb-agent, environment, configuration\n:page-last-updated: 2026-10-02\n\n“Required” is contextual: startup validation requires Slack/model/default GitHub values plus credentials for the selected runtime and GitHub mode. Integration-specific values are required only when that integration is used. Never put real credentials in documentation.\n\n[cols=\"2,1,1,3,1,1\",options=\"header\"]\n|===\n|Name |Default |Requirement |Purpose |Sensitivity |Area\n|`SLACK_BOT_TOKEN`\n|empty\n|Runtime required\n|Slack Web API credential\n|Secret\n|Slack\n|`SLACK_SIGNING_SECRET`\n|empty\n|Required in HTTP mode\n|HTTP request verification\n|Secret\n|Slack\n|`SLACK_APP_TOKEN`\n|empty\n|Required in Socket Mode\n|Socket authentication\n|Secret\n|Slack\n|`SLACK_ALLOW_UNSIGNED_REQUESTS`\n|false\n|Optional\n|Development-only signature bypass\n|Sensitive control\n|Slack\n|`OPENAI_API_KEY`\n|empty\n|Required when Galileo key absent\n|Direct/fallback model credential\n|Secret\n|Model\n|`OPENAI_MODEL`\n|configured Roche model name\n|Optional\n|Model identifier\n|No\n|Model\n|`GALILEO_ENABLED`\n|false in code; true in example/Helm\n|Optional\n|Select gateway routing\n|No\n|Model\n|`GALILEO_API_KEY`\n|empty\n|Required for gateway unless OpenAI key used\n|Gateway credential\n|Secret\n|Model\n|`GALILEO_GATEWAY_URL`\n|Roche US gateway shown in example\n|Optional\n|OpenAI-compatible gateway URL\n|Internal endpoint\n|Model\n|`PORTKEY_APPLICATION_NAME`\n|slack-kb-agent\n|Optional\n|Portkey metadata application\n|No\n|Model\n|`GITHUB_TOKEN`\n|empty\n|Legacy/optional\n|Pipeline token when no authorization service credential is supplied\n|Secret\n|GitHub\n|`GITHUB_AUTH_MODE`\n|installation\n|Optional\n|installation, delegated, or hybrid\n|No\n|GitHub\n|`GITHUB_HYBRID_INSTALLATION_FALLBACK`\n|true\n|Hybrid only\n|Allow installation fallback\n|Sensitive control\n|GitHub\n|`GITHUB_APP_ID`\n|empty\n|Installation/hybrid required\n|GitHub App identity\n|Sensitive\n|GitHub\n|`GITHUB_APP_CLIENT_ID`\n|empty\n|Delegated/hybrid required\n|OAuth client identity\n|Sensitive\n|GitHub\n|`GITHUB_APP_CLIENT_SECRET`\n|empty\n|Delegated/hybrid required\n|OAuth exchange credential\n|Secret\n|GitHub\n|`GITHUB_APP_PRIVATE_KEY`\n|empty\n|Installation/hybrid required\n|Signs App JWTs\n|Secret\n|GitHub\n|`GITHUB_APP_INSTALLATION_ID`\n|empty\n|Installation/hybrid required\n|Installation selection\n|Sensitive\n|GitHub\n|`GITHUB_OAUTH_CALLBACK_URL`\n|empty\n|Delegated/hybrid required\n|OAuth callback URL\n|Internal URL\n|GitHub\n|`TOKEN_ENCRYPTION_KEY`\n|empty\n|Delegated/hybrid and Confluence storage required\n|Encrypt stored tokens\n|Secret\n|GitHub/Confluence\n|`OAUTH_STATE_TTL_SECONDS`\n|600\n|Optional\n|OAuth state lifetime\n|No\n|GitHub\n|`AUTHORIZATION_DATABASE_PATH`\n|empty\n|Optional\n|SQLite authorizations/state; empty is memory\n|Filesystem path\n|Persistence\n|`DRAFT_DATABASE_PATH`\n|empty\n|Optional\n|SQLite drafts; empty is memory\n|Filesystem path\n|Persistence\n|`DEFAULT_KB_GITHUB_OWNER`\n|empty\n|Runtime required\n|Default target owner\n|No\n|GitHub\n|`DEFAULT_KB_GITHUB_REPO`\n|empty\n|Runtime required\n|Default target repository\n|No\n|GitHub\n|`DEFAULT_KB_BASE_BRANCH`\n|main\n|Optional\n|PR base branch\n|No\n|GitHub\n|`DEFAULT_KB_DOCS_PATH`\n|docs/pages\n|Optional\n|Target content root\n|No\n|GitHub\n|`DEFAULT_KB_SUBDIR`\n|generated\n|Optional\n|Generated-content subdirectory\n|No\n|GitHub\n|`KB_ALLOWED_REPOS`\n|empty (deny all)\n|Operationally required\n|Comma-separated exact or owner wildcard targets\n|Authorization control\n|GitHub\n|`KB_FILE_EXTENSION`\n|mdx\n|Optional\n|md or mdx\n|No\n|GitHub\n|`MAX_THREAD_LINKS`\n|5\n|Optional\n|Parser link limit\n|No\n|Runtime\n|`DRAFT_TTL_SECONDS`\n|86400\n|Optional\n|Draft expiry timestamp\n|No\n|Persistence\n|`PORT`\n|3000\n|Optional\n|HTTP listen port\n|No\n|Runtime\n|`JIRA_BASE_URL`\n|empty\n|Jira required\n|Jira site root\n|Internal URL\n|Jira\n|`JIRA_EMAIL`\n|empty\n|Required for basic auth\n|Jira account identity\n|Personal/sensitive\n|Jira\n|`JIRA_API_TOKEN`\n|empty\n|Jira required\n|Jira credential\n|Secret\n|Jira\n|`JIRA_DEFAULT_PROJECT_KEY`\n|empty\n|Required unless flag supplied\n|Default project\n|No\n|Jira\n|`JIRA_DEFAULT_ISSUE_TYPE`\n|Task\n|Optional\n|Default issue type\n|No\n|Jira\n|`JIRA_CREATE_BY_DEFAULT`\n|false\n|Optional\n|Create Jira unless command overrides\n|No\n|Jira\n|`JIRA_AUTH_TYPE`\n|basic\n|Optional\n|basic or bearer\n|No\n|Jira\n|`JIRA_API_VERSION`\n|3\n|Optional\n|2 or 3\n|No\n|Jira\n|`JIRA_DESCRIPTION_FORMAT`\n|adf\n|Optional\n|adf or text\n|No\n|Jira\n|`JIRA_VERIFY_SSL`\n|true\n|Optional\n|TLS certificate verification\n|Security control\n|Jira\n|`JIRA_CLOUDFLARE_ACCESS_CLIENT_ID`\n|empty\n|Optional pair\n|Access service identity\n|Sensitive\n|Jira\n|`JIRA_CLOUDFLARE_ACCESS_CLIENT_SECRET`\n|empty\n|Optional pair\n|Access service credential\n|Secret\n|Jira\n|`CONFLUENCE_MCP_URL`\n|empty\n|Confluence required\n|MCP endpoint\n|Internal URL\n|Confluence\n|`MULESOFT_CLIENT_ID`\n|empty\n|Confluence required\n|Gateway identity\n|Sensitive\n|Confluence\n|`MULESOFT_CLIENT_SECRET`\n|empty\n|Confluence required\n|Gateway credential\n|Secret\n|Confluence\n|`CONFLUENCE_MCP_TOOL`\n|create_page\n|Optional\n|MCP tool name\n|No\n|Confluence\n|`CONFLUENCE_SPACE_KEY`\n|empty\n|Required unless command flag\n|Default space\n|No\n|Confluence\n|`CONFLUENCE_PARENT_PAGE_ID`\n|empty\n|Optional\n|Default parent page\n|No\n|Confluence\n|`CONFLUENCE_TOKEN_DIRECTORY`\n|/tmp/knowledge-assistant/confluence\n|Optional\n|Encrypted per-user PAT files\n|Sensitive path\n|Confluence\n|===\n\nNOTE: `.env.example` also lists `MAX_THREAD_MESSAGES`, but the Python `Settings` model does not define or use it. It currently has no application effect.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators, developers",
    "tags": [
      "slack-kb-agent",
      "environment",
      "configuration"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Authentication",
    "slug": "security/authentication.html",
    "module": "security",
    "source": "docs-Oct2026/src/asciidoc/modules/security/pages/authentication.adoc",
    "text": "= Authentication\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, authentication, security\n:page-last-updated: 2026-10-02\n\n== Slack\n\nHTTP command and interaction handlers validate Slack's timestamped HMAC signature using `SLACK_SIGNING_SECRET`. Keep `SLACK_ALLOW_UNSIGNED_REQUESTS=false`; enabling it bypasses this control for development. Socket Mode authenticates with `SLACK_APP_TOKEN`, while Slack Web API calls use `SLACK_BOT_TOKEN`.\n\n== GitHub and Confluence\n\nGitHub installation mode uses short-lived installation tokens minted from the App ID, installation ID, and private key. Delegated mode binds GitHub OAuth tokens to a Slack user. Hybrid prefers a connected user's credential and can fall back to installation credentials. Confluence combines an encrypted, per-Slack-user PAT with administrator-managed MuleSoft credentials.\n\n== Security assessment\n\nApplication: Slack KB Agent. SRA status: Approved. Reference: `RI0038086`. Last approved: 2026-06-18. Next review, reviewer, data classification, AMR link, ACT link, and ServiceNow application link: `TO_BE_CONFIRMED`.\n\nSee xref:github-authorization.adoc[GitHub authorization] and xref:confluence-authentication.adoc[Confluence authentication].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "authentication",
      "security"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Confluence Authentication",
    "slug": "security/confluence-authentication.html",
    "module": "security",
    "source": "docs-Oct2026/src/asciidoc/modules/security/pages/confluence-authentication.adoc",
    "text": "= Confluence Authentication\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, confluence, security\n:page-last-updated: 2026-10-02\n\ninclude::ROOT:partial$confluence-publishing-unavailable.adoc[]\n\nConfluence publishing uses two credential layers: `MULESOFT_CLIENT_ID` and `MULESOFT_CLIENT_SECRET` identify the service to the gateway, while a per-user PAT authorizes Confluence. `/knowledge confluence-connect` captures the PAT in a private Slack modal.\n\nThe PAT is encrypted with the same `TOKEN_ENCRYPTION_KEY` boundary used for GitHub OAuth. Its filename is a digest of the Slack user ID; plaintext is never persisted. The token directory must be persistent if connections must survive restarts. Publishing retrieves the PAT for the draft creator and sends it to the configured MCP endpoint; logs and audit events omit it.\n\nPAT issuance, expiry, rotation, and deletion processes are `TO_BE_CONFIRMED`. See xref:user:confluence-connect.adoc[Connect Confluence].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "confluence",
      "security"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "GitHub Authorization",
    "slug": "security/github-authorization.html",
    "module": "security",
    "source": "docs-Oct2026/src/asciidoc/modules/security/pages/github-authorization.adoc",
    "text": "= GitHub Authorization\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators, developers\n:page-tags: slack-kb-agent, github, authorization\n:page-last-updated: 2026-10-02\n\n`GITHUB_AUTH_MODE` supports:\n\n* `installation`: no user connection is required; the GitHub App installation supplies a short-lived token.\n* `delegated`: `/knowledge connect` is required and the user's push permission is checked.\n* `hybrid`: uses delegated credentials when present; if absent, installation fallback occurs only when `GITHUB_HYBRID_INSTALLATION_FALLBACK=true`.\n\nEvery mode first requires a non-empty `KB_ALLOWED_REPOS` match (exact `owner/repo` or configured owner wildcard). An empty allowlist denies every repository. Delegated access and refresh tokens are authenticated-encrypted before SQLite or memory storage. OAuth state is random, hashed at rest, expires after `OAUTH_STATE_TTL_SECONDS`, binds the Slack user and response URL, and is consumed once.\n\nA draft's creator is also its only permitted approver/editor/canceller. Human approval is mandatory before GitHub is called. See xref:user:github-connect.adoc[Connect GitHub].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators, developers",
    "tags": [
      "slack-kb-agent",
      "github",
      "authorization"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Secrets Management",
    "slug": "security/secrets.html",
    "module": "security",
    "source": "docs-Oct2026/src/asciidoc/modules/security/pages/secrets.adoc",
    "text": "= Secrets Management\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators\n:page-tags: slack-kb-agent, secrets, security\n:page-last-updated: 2026-10-02\n\nNever commit or log secret values. `.env.example` contains names and non-secret defaults only. Kubernetes uses External Secrets Operator to copy properties from a configured SecretStore/Vault remote key into a Kubernetes Secret.\n\nSensitive values include Slack bot/app tokens and signing secret; OpenAI/Galileo keys; GitHub App private key, OAuth client secret, and legacy token; `TOKEN_ENCRYPTION_KEY`; Jira token, email, and Cloudflare Access secret; MuleSoft credentials; and user PAT/OAuth tokens.\n\nUse `SLACK_ALLOW_UNSIGNED_REQUESTS=false`. Rotate a compromised credential at its issuer and update the external secret. Rotating `TOKEN_ENCRYPTION_KEY` without migrating ciphertext makes stored GitHub and Confluence tokens unreadable. Exact Vault access policy, rotation cadence, and break-glass process are `TO_BE_CONFIRMED`.\n\nBefore model generation, the application redacts patterns for Slack tokens, GitHub tokens, OpenAI-style keys, and AWS access-key IDs. This is a limited pattern set, not a substitute for users removing confidential material. Audit events exclude Slack message bodies and credentials.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators",
    "tags": [
      "slack-kb-agent",
      "secrets",
      "security"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Session Persistence",
    "slug": "security/session-persistence.html",
    "module": "security",
    "source": "docs-Oct2026/src/asciidoc/modules/security/pages/session-persistence.adoc",
    "text": "= Session Persistence\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: administrators, developers\n:page-tags: slack-kb-agent, persistence, sqlite\n:page-last-updated: 2026-10-02\n\nThere is no browser session. Identity comes from Slack request payloads and OAuth state binds a browser callback to a Slack user.\n\n* `DRAFT_DATABASE_PATH` selects SQLite draft storage. Empty uses an in-memory singleton and loses drafts at process restart.\n* `AUTHORIZATION_DATABASE_PATH` selects SQLite for encrypted GitHub authorizations and OAuth state. Empty uses memory and loses connections/state at restart.\n* `CONFLUENCE_TOKEN_DIRECTORY` stores encrypted PAT files; the default is `/tmp/knowledge-assistant/confluence` and is ephemeral unless mounted.\n\nThe SQLite implementation is documented for a single-process deployment. The Helm chart uses one replica and maps the two database paths to `/data`; it does not currently set `CONFLUENCE_TOKEN_DIRECTORY` to that persistent volume. Confluence PAT persistence in Kubernetes therefore requires an explicit deployment change.\n\n`DRAFT_TTL_SECONDS` is configured and placed on draft records, but the repository contains no background purge job. Retention/deletion schedules are `TO_BE_CONFIRMED`.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "administrators, developers",
    "tags": [
      "slack-kb-agent",
      "persistence",
      "sqlite"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Confluence Issues",
    "slug": "troubleshooting/confluence.html",
    "module": "troubleshooting",
    "source": "docs-Oct2026/src/asciidoc/modules/troubleshooting/pages/confluence.adoc",
    "text": "= Confluence Issues\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, troubleshooting, confluence\n:page-last-updated: 2026-10-02\n\ninclude::ROOT:partial$confluence-publishing-unavailable.adoc[]\n\n== PAT missing\n\nRun `/knowledge confluence-connect` as the same Slack user who created the draft. A PAT is stored per Slack user; another user's token is not used.\n\n== MCP 401\n\nReconnect the PAT. Administrators must verify `MULESOFT_CLIENT_ID`, `MULESOFT_CLIENT_SECRET`, and `CONFLUENCE_MCP_URL`. A PAT issued for another environment may be rejected; ensure PAT and MCP URL refer to the same environment.\n\n== Space missing or invalid\n\nSupply `--confluence-space SPACE` or set `CONFLUENCE_SPACE_KEY`. Verify the PAT can create pages there. Check `--confluence-parent PAGE_ID` or the configured parent exists in that space.\n\n== Connection disappears after restart\n\nThe default token directory is under `/tmp`. Mount persistent storage and set `CONFLUENCE_TOKEN_DIRECTORY`; the current Helm deployment does not set it. Never inspect or copy plaintext PATs—the stored files are encrypted.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "troubleshooting",
      "confluence"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "GitHub Issues",
    "slug": "troubleshooting/github.html",
    "module": "troubleshooting",
    "source": "docs-Oct2026/src/asciidoc/modules/troubleshooting/pages/github.adoc",
    "text": "= GitHub Issues\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, troubleshooting, github\n:page-last-updated: 2026-10-02\n\n== Not connected\n\nRun `/knowledge status`, then `/knowledge connect`. Delegated mode requires a connection; hybrid may use installation fallback when enabled.\n\n== Repository not allowed\n\nAn empty allowlist denies all repositories. Add an exact `owner/repo` or intended owner wildcard to `KB_ALLOWED_REPOS`; do not broaden it merely to bypass an error.\n\n== Permission denied or GitHub API error\n\nThe connected user needs push permission. In installation mode, verify the App installation covers the target and its ID is correct. Confirm the base branch exists and the App has Contents read/write and Pull requests read/write.\n\n== OAuth callback failure\n\nState expires (600 seconds by default), is single-use, and is bound to the initiating Slack user. Start again from `/knowledge connect`; verify callback URL equality and persistent authorization storage when multiple callbacks/restarts are possible. Do not log or share code/state/token values.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "troubleshooting",
      "github"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Troubleshooting",
    "slug": "troubleshooting/index.html",
    "module": "troubleshooting",
    "source": "docs-Oct2026/src/asciidoc/modules/troubleshooting/pages/index.adoc",
    "text": "= Troubleshooting\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, troubleshooting\n:page-last-updated: 2026-10-02\n\nStart with the exact Slack response and a request/draft ID; do not collect message contents or secrets.\n\n* GitHub connection, permission, allowlist, OAuth state, or installation coverage: xref:github.adoc[GitHub issues].\n* Invalid signatures, missing interactions, or Socket Mode startup: xref:slack.adoc[Slack issues].\n* PAT, MuleSoft, MCP environment, space, or 401 failures: xref:confluence.adoc[Confluence issues].\n\n== Jira\n\n“Jira service is not configured” means required URL/token/default or flag values are absent. Basic auth also needs `JIRA_EMAIL`. A redirect/error can indicate the wrong auth type, API version, SSO restriction, or incomplete Cloudflare Access credential pair. Keep `JIRA_VERIFY_SSL=true`; the Helm default currently overrides it to false and should be reviewed. Jira creation occurs after the PR, so a Jira failure does not remove the successful PR.\n\nEscalation contact and log-retention procedure are `TO_BE_CONFIRMED`. See xref:ROOT:support.adoc[Support].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "troubleshooting"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Slack Issues",
    "slug": "troubleshooting/slack.html",
    "module": "troubleshooting",
    "source": "docs-Oct2026/src/asciidoc/modules/troubleshooting/pages/slack.adoc",
    "text": "= Slack Issues\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users, administrators\n:page-tags: slack-kb-agent, troubleshooting, slack\n:page-last-updated: 2026-10-02\n\n== Invalid Slack signature\n\nVerify `SLACK_SIGNING_SECRET`, the configured request URLs, and that a proxy preserves the raw body and signature headers. Do not set `SLACK_ALLOW_UNSIGNED_REQUESTS=true` outside isolated development.\n\n== Buttons or modal do not work\n\nConfigure Slack Interactivity to POST to `/slack/interactions` in HTTP mode. Socket Mode must deliver `interactive` envelopes. Ensure the bot token can open views. Use approve/cancel fallback commands; edit requires the preview button because Slack supplies the modal trigger there.\n\n== Socket Mode does not start\n\nSet a valid app-level `SLACK_APP_TOKEN` and bot token, enable Socket Mode in Slack, and start `python -m app.slack_socket_app`. The process validates runtime secrets before connecting.\n\n== Thread cannot be fetched\n\nCheck the URL is a Slack archive thread link, the bot belongs to the channel, and the user can access all linked threads. More than `MAX_THREAD_LINKS` is rejected.\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users, administrators",
    "tags": [
      "slack-kb-agent",
      "troubleshooting",
      "slack"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Connect Confluence",
    "slug": "user/confluence-connect.html",
    "module": "user",
    "source": "docs-Oct2026/src/asciidoc/modules/user/pages/confluence-connect.adoc",
    "text": "= Connect Confluence\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, confluence, authentication\n:page-last-updated: 2026-10-02\n\ninclude::ROOT:partial$confluence-publishing-unavailable.adoc[]\n\n. Run `/knowledge confluence-connect`.\n. Enter the Confluence PAT in the Slack modal. Do not paste it into a channel or command.\n. Submit. The service encrypts the PAT with `TOKEN_ENCRYPTION_KEY` and writes it to a file named with a SHA-256 digest of your Slack user ID. The directory and file modes are set to `0700` and `0600`.\n\nThe PAT is retrieved only for the Slack user who owns the approved draft. MuleSoft client ID and secret are separate service credentials configured by administrators. If token storage or encryption is not configured, submission fails with a service-unavailable response.\n\nNo disconnect command is implemented for Confluence. PAT removal/rotation procedure is `TO_BE_CONFIRMED`. See xref:security:confluence-authentication.adoc[Confluence authentication].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "confluence",
      "authentication"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Create a Confluence Page",
    "slug": "user/create-confluence-page.html",
    "module": "user",
    "source": "docs-Oct2026/src/asciidoc/modules/user/pages/create-confluence-page.adoc",
    "text": "= Create a Confluence Page\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, confluence, publishing\n:page-last-updated: 2026-10-02\n\ninclude::ROOT:partial$confluence-publishing-unavailable.adoc[]\n\nConnect a PAT first with xref:confluence-connect.adoc[Connect Confluence]. Then run:\n\n[source,text]\n----\n/knowledge draft <slack-thread-url> --confluence [--confluence-space SPACE] [--confluence-parent PAGE_ID]\n----\n\nAfter write access is granted, review the preview and approve it. The service chooses flag values before `CONFLUENCE_SPACE_KEY` and `CONFLUENCE_PARENT_PAGE_ID`, requires a space, then calls the configured MCP tool with the user's PAT and MuleSoft headers. Slack receives the created page URL. `--confluence` cannot be combined with `--jira`; GitHub repository/path flags have no Confluence publishing effect.\n\nA 401 usually means the PAT is absent/rejected, MuleSoft credentials are wrong, or the PAT belongs to another MCP environment. Reconnect the PAT and have an administrator verify the MCP URL and credentials. See xref:troubleshooting:confluence.adoc[Confluence issues].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "confluence",
      "publishing"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Create a Knowledge Draft",
    "slug": "user/create-draft.html",
    "module": "user",
    "source": "docs-Oct2026/src/asciidoc/modules/user/pages/create-draft.adoc",
    "text": "= Create a Knowledge Draft\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, draft, commands\n:page-last-updated: 2026-10-02\n\n== Syntax\n\n[source,text]\n----\n/knowledge draft <slack-thread-url> [more-thread-urls...] [--repo owner/repo] [--path docs-relative-path] [--jira] [--jira-project KEY_OR_QUOTED_NAME] [--jira-issue-type TYPE] [--confluence] [--confluence-space SPACE] [--confluence-parent PAGE_ID]\n----\n\nOne link is required; the configured `MAX_THREAD_LINKS` limit defaults to 5. Links must be Slack archive thread URLs. `--repo` overrides the configured GitHub target and is still allowlisted. `--path` is a safe repository-relative output path. `--jira` requests an issue after GitHub PR creation. `--confluence` changes the destination; it cannot be combined with `--jira`. Space and parent flags override Confluence defaults.\n\nThe service fetches all messages (up to Slack's configured/default fetch behavior), normalizes them, redacts recognizable secrets, generates structured content, stores a pending draft, and posts a preview. No GitHub or Confluence write occurs yet. `create-pr` accepts the same inputs but also follows this approval workflow despite its legacy name.\n\nSee xref:review-draft.adoc[Review a draft] and xref:reference:commands.adoc[Command reference].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "draft",
      "commands"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Create a GitHub Pull Request",
    "slug": "user/create-github-pr.html",
    "module": "user",
    "source": "docs-Oct2026/src/asciidoc/modules/user/pages/create-github-pr.adoc",
    "text": "= Create a GitHub Pull Request\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, github, publishing\n:page-last-updated: 2026-10-02\n\nThe exact flow is: Slack thread fetch -> redaction -> model-generated draft -> stored preview -> creator approval -> authorization check -> GitHub branch and file -> **draft pull request**.\n\nThe target comes from defaults or `--repo`; `--path` can override the generated file location. The repository must match `KB_ALLOWED_REPOS`. Delegated credentials must have push permission; installation credentials require the configured GitHub App installation to cover the repository.\n\nOn approval the service branches from `DEFAULT_KB_BASE_BRANCH`, names the branch `knowledge-assistant/<slug>-<timestamp>`, commits the rendered Markdown/MDX file, and opens the PR with `draft: true`. The PR body includes source thread URLs and request/approver identifiers. Slack receives the PR link. If `--jira` was selected, Jira creation is attempted afterward; Jira failure does not undo the PR.\n\nSee xref:github-connect.adoc[Connect GitHub] and xref:troubleshooting:github.adoc[GitHub issues].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "github",
      "publishing"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Connect GitHub",
    "slug": "user/github-connect.html",
    "module": "user",
    "source": "docs-Oct2026/src/asciidoc/modules/user/pages/github-connect.adoc",
    "text": "= Connect GitHub\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, github, oauth\n:page-last-updated: 2026-10-02\n\nThis workflow applies when `GITHUB_AUTH_MODE` is `delegated` or `hybrid`.\n\n. Run `/knowledge connect`.\n. Open the returned short-lived authorization link. The service validates its signed random state before redirecting to GitHub.\n. Authorize the GitHub App. The callback consumes the state once, exchanges the code, encrypts the access and refresh tokens, and binds them to your Slack user ID.\n. Close the success page. Slack also receives an ephemeral confirmation when its response URL remains valid.\n. Run `/knowledge status` to see the connected GitHub login.\n\nRun `/knowledge disconnect` to revoke the stored binding and attempt token revocation. Tokens are never displayed in Slack. A missing configuration produces “GitHub authorization is not configured”; expired or reused state produces “Invalid or expired OAuth state.” Repository permission and allowlisting are checked separately when publishing. See xref:security:github-authorization.adoc[GitHub authorization].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "github",
      "oauth"
    ],
    "updated": "2026-10-02"
  },
  {
    "title": "Review a Draft",
    "slug": "user/review-draft.html",
    "module": "user",
    "source": "docs-Oct2026/src/asciidoc/modules/user/pages/review-draft.adoc",
    "text": "= Review a Draft\n:page-owner: CSCoE TSO\n:page-sme: TO_BE_CONFIRMED\n:page-audience: users\n:page-tags: slack-kb-agent, draft, approval\n:page-last-updated: 2026-10-02\n\nOnly the Slack user who created a draft can act on it. The service compares the interacting Slack user ID with `created_by`; another user receives an ownership error.\n\n* **Approve** changes a pending draft to approved and publishes it. A failed destination write returns it to pending approval for retry.\n* **Edit** opens a modal for title, summary, root cause, resolution steps, and tags. Submission updates the stored draft and posts a fresh preview. Editing does not publish.\n* **Cancel** changes the draft to cancelled and creates no PR or page.\n\nButtons require Slack Interactivity. Fallback commands are `/knowledge approve <draft-id>`, `/knowledge edit <draft-id>`, and `/knowledge cancel <draft-id>`. The edit slash command tells the user to use the preview button because a modal requires an interaction trigger. Completed or cancelled drafts cannot be edited, and status transitions prevent duplicate publication.\n\nSee xref:create-github-pr.adoc[GitHub publishing] or xref:create-confluence-page.adoc[Confluence publishing].\n",
    "owner": "CSCoE TSO",
    "sme": "TO_BE_CONFIRMED",
    "audience": "users",
    "tags": [
      "slack-kb-agent",
      "draft",
      "approval"
    ],
    "updated": "2026-10-02"
  }
]