AI employees

What AI employees are, and five things to check before you give one access

An AI employee, also sold as an AI teammate or an AI coworker, is an AI agent that works inside a tool your team already uses. It has its own name, accounts, and memory, and it does recurring work instead of only answering questions. Judge it the way you judge any account you hand out.

Key takeaways

  • An AI employee, also called an AI teammate or an AI coworker, is an AI agent with a standing identity, connected accounts, saved instructions, and memory, placed in a shared tool such as Slack, Asana, or a phone line to do recurring work.
  • It differs from a chatbot, which answers and changes nothing; from a copilot, which helps one person inside one app; and from automation, which runs a fixed recipe when a trigger fires.
  • The jobs that stick are narrow and cheap to check: triage, recurring reports, look-ups across several tools, first passes on an alert, and chores that end in a confirmation. Jobs that go wrong are the ones where a mistake is slow to spot or leaves the company.
  • Before giving one access, check five things: whose identity it acts under, what it can reach, what waits for a person, how it is metered, and who holds its memory and your data.
  • Products answer those five differently. Viktor is one shared hosted agent paid in credits, Claude Tag is one @Claude on an Anthropic plan, Asana’s AI Teammates work inside Asana’s own permissions, and Chickpea runs named teammates in your own Cloudflare account on your own model keys.

What an AI employee is

An AI employee is an account, not a hire. Most products in the category give the agent four things.

  • An identity in a shared tool. A name people can address, such as a Slack handle, an Asana assignee, or a phone number.
  • Connected accounts. Credentials for the systems it works in, such as a helpdesk, a CRM, a mailbox, or a code repository.
  • Standing instructions. What its job is, what it may do, and what it must ask about first.
  • Memory. What it has picked up since it started, carried from one conversation to the next.

On top of those, it acts. It writes to the systems it is connected to, sends messages, and runs work on a schedule.

One definition covers products that do unrelated jobs. On September 29, 2026, the first page of Google for “ai employees” sold a recruiting, sales, or support agent from $25 a month, a phone and chat agent that answers your customers’ calls, and, on Slack’s own blog, agents that work inside Slack.

The names vary too. “AI employee” is the advertising term. “AI teammate” is also common, and it is the name of an Asana product. “AI coworker” is what Viktor’s own explainer calls it. “Digital employee” and “digital worker” come from robotic process automation, where Blue Prism still uses them.

I think the word “employee” is where buyers go wrong. As Kuse puts it, “An AI employee is not a legal employee.” It has no judgment you can hold to account and no salary to compare against. Pricing one against a worker at “$50K+/year”, as Teammates.ai’s page does, compares it to the wrong thing. Price it against other software. We call ours teammates, and this page uses “AI employee” only for the category.

AI employee vs chatbot vs copilot vs automation

An AI employee starts work when anyone mentions it or its schedule fires, and it acts under its own identity. A chatbot, a copilot, and automation each miss at least one of those.

Chatbot Copilot Automation AI employee
Who starts the work You, in a private tab You, inside one app A trigger you configured Anyone who mentions it, or its own schedule
Whose identity it uses None, it only answers Yours A service account or yours Its own
Where it lives The vendor’s chat window Your documents, mail, or IDE Between two apps A shared tool such as Slack or Asana
What it remembers The conversation, maybe Your files Nothing What it learned across conversations
What it can change Nothing outside the chat What you accept Exactly what the recipe says Whatever its accounts allow, within its rules
Who checks the result You You Nobody, until it breaks The person who asked, and its approval rules

Every AI employee is an agent. What makes it an employee in the vendors’ sense is a standing identity and a job in a shared tool, which is where Atomicwork draws the line too.

Some products sold as AI teammates answer and do not act. Slack’s Channel Expert, for Agentforce in Slack customers, answers questions from channel history and connected files and hands off to a person. An agent that answers is a different purchase from one that updates your CRM.

What teams hand to one

The jobs that last are narrow, recurring, and cheap to check. They come in five shapes.

🔒 finance
9
Today
M
Marco
@revops which deals slipped this month and why?
👀 1
revopsAPP
Four deals slipped, $184k in total. Three are waiting on legal, one went quiet after the demo. Two of those need a call from someone on the team; I have drafted nudges for the other two.
DealOwnerAmountReason
Halvorsen FreightMarco$72,000Legal review
Bluefin LabsPriya$48,500Legal review
Orchard HealthMarco$39,000Went quiet after demo
Tandem RetailDana$24,500Legal review
revops·Claude Sonnet 5·Configure
BIS
Aa
Example conversations showing two of the job shapes above. They are illustrations, not recordings of anyone’s workspace.

In a Reddit thread on what survived six months of OpenClaw, one user kept email triage and killed a PR review bot after 4 days. A founder who ran an OpenClaw “AI employee” for a week got useful overnight research and reports, watched it invent $150 of freelancing revenue in marketing copy, and summed it up as “a very capable junior employee, not a senior one.”

An agent you have to remember to summon can go unused. A team that tried the assistant-you-call model in Slack gave it up because “nobody remembered to call it”. And agents fail quietly. A commenter who watched an invoice-review agent miss edge cases for a month wrote, “Traditional employees signal when they’re struggling. These don’t.”

The Chickpea docs describe one narrow first job, a documented setup rather than a customer. Someone asks for a support teammate with one message in #billing, which grants it that channel only. Zendesk and Stripe are connected to that teammate alone, as shared team accounts. Its memory holds one rule, “Refunds over 500 dollars need a manager to sign off in #billing first.” Sending, deleting, publishing, and bulk changes wait for a person.

Five things to check before you give one access

Before one of these products gets a single login, I want five answers: whose identity it uses, what it can reach, what waits for a person, how it is metered, and who holds its memory and your data. The table shows how five products answer them, as of the dates in the sources. We build one of them, Chickpea, and it sits in each check next to the others.

CheckChickpeaViktorClaude TagAsana AI TeammatesCustomer-service AI employees
Whose identity it acts underEach teammate has its own handle, instructions, memory, and model.One shared @Viktor per workspace.One @Claude under the organization's identity.Prebuilt role agents inside Asana, more than 30 of them.A named persona that talks to your customers.
What it can reach37 connector presets plus HTTP APIs and MCP servers, connected to one teammate each.Accounts are connected to the one Viktor, per workspace.Tools are connected once by an admin, for the one Claude.The projects you choose, under the Asana permissions you already set.Phone, chat, email, and the CRM it is connected to.
What waits for a personSending, deleting, publishing, and bulk changes wait for a person.Sensitive actions pause for a person.Not built in. It can act, and jump in, unprompted.Not stated on the product page.A hand-off to a person when it cannot resolve the case.
How it is meteredNo seats, no credits. You pay the provider and Cloudflare directly.Credits: $50 for 20,000, up a ladder. A quick task is 100 to 300 credits.Needs Team (from 2 seats) or Enterprise, then tokens on top.No price on the product page.Per agent, from $25 a month at Teammates.ai and $99 at AIEmployee.com and Nextiva.
Where it runs and keeps dataYour Cloudflare account, or Node on your own host.Runs on Viktor's private cloud.Runs on Anthropic's infrastructure.Inside Asana. Asana says customer data is not used to train models.The vendor's cloud.

1. Whose identity does it act under?

Prefer an agent that posts under its own name. The alternatives are one shared bot name or yours, and each choice changes who is accountable for what it does. This is the question the word “employee” hides. A small-business owner on r/smallbusinessUS wrote: “a human still owns the outcome”. That only works if you can tell which agent did what.

Watch for one person’s account becoming everyone’s. When we set up Viktor on August 2, 2026, its Google Sheets connection asked who could use it and defaulted to Team-only, with a warning that this makes the files accessible to the whole team. That suits a shared agent. It also means a member who connects a personal account shares those files unless they change the setting. Good answers keep a personal account personal. In Chickpea, a personal account can be used only when the member who owns it is the one asking, and each teammate posts under its own name and avatar.

2. What can it reach, and who decided?

Ask what it reads without being asked, then ask for the list of channels and accounts and who can change it. The best answers are narrow and name the agent, the channels, the accounts, and the scopes.

On the same Viktor install, its first message said it was reading through the workspace history. About two minutes later, unprompted, it named three internal channels and proposed three automations based on what it found.

Asana reuses permissions you already maintain, and you choose what projects and work it can see. Chickpea stores a grant per channel, and a teammate mentioned in a channel it has no grant for gets no reply. Asking in Slack to give it a new channel or account returns a proposal that applies only when you reply “approve”. It drops a message that mentions no one before any model sees it. And credentials never enter the model’s context. You can narrow reach further. The Supabase connector asks at setup whether a teammate gets read-only or read and write access, and an API connection lists the HTTP methods it may use.

3. What waits for a person?

Ask for the list, in writing. The actions that should wait are the ones you cannot take back: sending a message or an email, deleting, publishing, and bulk changes. Viktor pauses sensitive actions for a person. Claude Tag, per our comparison, has no approval step built in.

Then ask two follow-ups. First, can instructions hidden in a page or file the agent reads talk it past the list? OWASP ranks prompt injection first among LLM risks. Second, will people actually read the prompts? A thread on agent permissions describes approving 20 small actions a day until the clicks become blind, and suggests a better line: “Gate on ‘does this leave the building’”.

# billing
42
Today
D
Dana
@support can we refund order 4821? The customer says the card was charged twice.
👀 1
supportAPP
Order 4821 was captured twice on Sep 1, at 14:02 and 14:03, same card, same amount. Zendesk ticket #5518 is open for it. I can refund the duplicate capture in Stripe.
Approve refundDecline
support·Claude Sonnet 5·Configure
BIS
Aa
Example. The teammate finds the duplicate charge, then asks before it refunds anything.

In Chickpea, sending, deleting, publishing, and bulk changes need a yes in Slack unless the saved instructions allow that kind of action, and a gate outside the model refuses any write that the current Slack request did not ask for. Retrieved content, Slack history, and memory cannot authorize one.

4. How is it metered?

Seats scale with people, per-agent plans with agents, credits with tasks, and direct model usage with tokens.

Ask what one ordinary task costs, who can see the meter, and what happens when it runs out. Credits deserve a closer look, because the price of a task is a credit count, not a dollar figure. On our August 2, 2026 run, Viktor’s dashboard led with the credit balance, and in a one-person workspace the starter credits needed a card before the Slack handoff, although the offer said no card was required.

UseRequests a monthViktor, in creditsChickpea, model usage only
Light, 5 a person a week541$325$32
Medium, 20 a person a week2,165$1,300$130

A team of 25. Viktor at 250 credits a request on its published ladder. Chickpea at $0.06 a request on a mid-tier model, paid to the provider, on Cloudflare's free plan. Neither column counts the time someone spends checking the work.

The comparison pages show the full chart, a heavy-use level, and every assumption.

5. Who holds its memory and your data, and what happens when you leave?

An AI employee accumulates what it learns about your customers, your pipeline, and your incidents. Ask where that lives, whether you can read and delete it, whether it trains anyone’s model, and what you take with you if you cancel. In a Hacker News thread on the biggest risks of a full-AI employee, one commenter led with lock-in: “Single point of failure, single vendor.”

Hosted products keep memory in the vendor’s cloud. Viktor keeps it on its side, and its SOC 2 Type 1 report covers its controls at one point in time, not where your data lives. Asana says customer data is not used to train models. In Chickpea, each teammate has one memory body stored in your own deployment, editable and deletable in Admin, and memory can shape an answer but never grant a permission.

What else to know about Chickpea

Chickpea is an open source Slack app, licensed Apache 2.0, that you deploy to your own Cloudflare account or a Node host, so state, memory, and credentials stay in your deployment.

Chickpea is Slack only. You deploy and update it yourself. Named handles need a paid Slack plan and a workspace setting that lets members create user groups. It answers in Slack with text, tables, and task lists rather than producing finished decks or web apps.

When another product is the better choice

  • You want an AI employee that talks to your customers on the phone or in web chat. Look at Teammates.ai, Nextiva, or AIEmployee.com. Chickpea does not answer customers or phones.
  • Your team’s work lives in Asana. Asana’s AI Teammates work inside the projects and permissions you already have there. Chickpea reaches Asana only through a connector, from Slack.
  • You run on Microsoft 365 or Teams. Microsoft 365 Copilot for one person’s work, or Viktor, which works in Teams as well as Slack, for a shared agent.
  • You want no infrastructure at all, a marketplace install, and finished PDFs, decks, and small web apps. Viktor is ahead on all three.
  • You already pay for Claude Team or Enterprise and want one @Claude in Slack. Claude Tag.
  • You have an existing process-automation estate. Blue Prism and similar platforms are built for that governance model.

FAQ

What is an AI employee?

An AI employee is an AI agent with its own identity in a shared tool, such as a Slack handle, plus connected accounts, saved instructions, and memory. It does recurring work, such as triage or weekly reports, and can act in the systems it is connected to. Vendors also call it an AI teammate, an AI coworker, or a digital employee.

Is an AI employee the same as an AI agent?

Every AI employee is an AI agent, but not every agent is an AI employee. The difference is a standing identity and a job inside a team’s shared tool. An agent that runs once in a script is an agent; one with a handle, a job, and its own accounts is what vendors sell as an employee.

How is an AI employee different from a chatbot or from Zapier?

A chatbot answers in a private window and changes nothing. Zapier-style automation runs a fixed recipe when a trigger fires. An AI employee takes a request in plain language from anyone on the team, decides which tools to use, and acts through its own accounts, within the rules it was given.

What is a good first job for an AI employee?

A narrow, recurring job where a wrong answer is cheap: morning triage of tickets or email, a weekly report, or a first read of an alert. Avoid starting with anything that leaves the company, such as customer emails or published copy.

How much does an AI employee cost?

It depends on the billing model. Per-agent products start at $25 to $99 a month, Microsoft 365 Copilot is $30 a user a month paid yearly, Viktor sells credits at $50 for 20,000, and Chickpea, which runs teammates on your own keys, costs the model provider’s list price plus hosting. Ask what one ordinary task costs.

Will AI employees replace my team?

No. They take narrow, recurring tasks off a team, and a person still checks the result.

Is it safe to give an AI employee access to our tools?

It is as safe as its identity, reach, and approval rules. Check whose account it acts under, which channels and accounts it can reach, which actions wait for a person, whether text it reads can override those rules, and where its memory is stored.

Can an AI employee work in Slack?

Yes. Viktor and Claude Tag work in Slack, and so do Chickpea’s teammates. Slack’s own Agentforce agents answer questions there too. They differ on whether you get one shared agent or several named ones, how they are billed, and where they run.

How to start with one

Pick one recurring job that is cheap to check, such as a morning triage or a weekly report. Give the agent one channel and the fewest accounts that job needs, read-only where the product allows it. Write down what must wait for a person, using the “does this leave the building” line. Read everything it produces for a week. Then widen one thing at a time.

If you want to try that on Chickpea, the Cloudflare setup guide takes you from deploy to the first reply in Slack.

Sources

Every fact on this page traces to one of these, checked on the date shown.

Chickpea, checked September 29, 2026: What Chickpea is, How Chickpea works, Handles and channel grants, Connections, Connect a service, Authority and confirmation, Memory, Data and storage, Requirements and costs, Manage from Slack, Schedules.

Viktor, checked September 29, 2026: Viktor pricing, and Chickpea vs Viktor for the identity, approval, and hosting facts. Our own Viktor setup ran on August 2 and 3, 2026; the notes are private.

Claude Tag, checked September 29, 2026: Claude plans, and Chickpea vs Claude Tag for the identity, approval, and billing facts, checked September 8, 2026.

Other products, checked September 29, 2026: Asana AI Teammates, Microsoft 365 Copilot pricing, Teammates.ai AI employees, AIEmployee.com, Nextiva on AI employees, CellCog AI employees, Slack on AI employees, Salesforce Ben on Slack’s Channel Expert, Kuse on AI employees, Blue Prism on AI workers, Atomicwork on AI agents and AI coworkers.

Security, checked September 29, 2026: OWASP LLM01:2025 Prompt injection.

People who run them, threads read in full September 29, 2026: r/smallbusinessUS, AI as an employee or a tool, Hacker News, a week with an OpenClaw AI employee, r/AI_Agents, six months of OpenClaw, r/AI_Agents, agent permissions, r/LLMDevs, AI agents in Slack, r/AI_Agents, the closest thing to an AI employee, Hacker News, problems with a full-AI employee.

Try it

Your first teammate, this afternoon.

One deploy into your own Cloudflare account, connect Slack, pick a model, and ask for a teammate in a sentence. Apache 2.0, no seats, no credits.

Star on GitHub7

Or read how it works first.

Related

About this page

Facts on this page were checked against the sources listed at the end on September 29, 2026. Products in this category change monthly; if something is out of date, open an issue and it will be fixed. A plain-text copy of this page is at /ai-employees.md, and the site index for agents is at /llms.txt. Chickpea's source is on GitHub. Product names belong to their owners, none of whom is affiliated with Chickpea.