Chaser, a Toronto-based task-management platform built to operate inside Slack, formally launched out of beta on June 25 with a Model Context Protocol connection for Anthropic’s Claude. The integration allows Claude to read Chaser task data and, after user approval, create, assign, edit and complete tasks that Chaser then tracks in Slack. [1]
The significance is less about another chatbot connection than about the handoff between an AI-produced output and the person responsible for acting on it. Claude can research a topic or draft a document, then create a task for a teammate to review, approve or discuss that work. Chaser supplies the persistent ownership, deadlines, status tracking and follow-up reminders that a one-off AI response does not. [1]
How the Claude MCP connection works
Chaser runs an MCP server at https://api.trychaser.com/mcp. A user can add it as a custom connector in Claude’s connector settings, giving Claude a structured way to call Chaser’s task-management tools rather than treating task details as unstructured text. [2]
According to Chaser, those tools can read and write task records; create and assign tasks to the user or coworkers; change dates and assignees; mark work complete; and generate reports from current and historical task data, including previously overdue tasks. The connector can also turn meeting notes and other supplied context into assigned Slack tasks. [2]
In practice, that means a user could ask Claude to identify action items from a meeting summary, propose owners and deadlines, and send those items to Chaser. The resulting tasks appear as normal Chaser tasks in Slack, where Chaser handles reminders and visibility into unfinished work. Chaser says its core product uses Slack authentication, does not require a separate project-management login, and does not need access to Slack messages for its basic task-management operation. [1]
The underlying protocol is not exclusive to Claude. Chaser says its MCP endpoint can also be connected to compatible products including ChatGPT, Perplexity and Cursor. MCP is therefore the interoperability layer; Claude is the first prominent assistant highlighted in Chaser’s launch announcement. [2]

From AI output to accountable human work
General-purpose AI assistants increasingly search, summarize, draft and perform work across connected systems. Their weak point in organizational workflows is often the next step: ensuring that a named person takes responsibility for reviewing or acting on the result. Chaser is positioning its integration around that gap.
For example, Claude could finish preliminary research and create a follow-up task assigning a manager to validate the findings. Or it could convert a document review into tasks for legal approval, product feedback and a final decision. The agent is not simply being assigned a task; it can initiate a human task assignment, subject to the requesting user’s approval. [1]
That distinction matters in Slack-based teams, where commitments are often buried in channels, direct messages and meeting follow-ups. A task manager that maintains assignees, due dates, completion states and automated nudges can make those commitments more durable than a chat summary alone.
Chaser said its beta reached more than 500,000 users across over 1,000 companies after it entered open beta in 2024. The company also reported a 98.7% task-completion rate and thousands of completed tasks each day. Those figures are company-reported and have not been independently audited; as of July 12, there was no neutral benchmark of Chaser’s Claude integration or public revenue and retention data. [1]
Permissions and approval gates remain central
Chaser says Claude has read-only access by default. Actions that change task data, including creating, editing or completing tasks, require explicit user approval. It also says the connector inherits the requesting user’s Slack permissions, so Claude should not be able to access channels or perform actions beyond what that user could access or do. [1]
These controls address a core concern with agentic systems: a useful connection needs enough authority to complete work, but every additional write permission increases the cost of a mistaken or manipulated instruction. Chaser says it is SOC 2 Type 2 compliant and monitored through Vanta, although that compliance claim does not independently establish the security of every customer’s connector configuration. [1]
The approval model is particularly important when tasks are created from ambiguous or externally sourced material. Slack warns that large-language-model responses can hallucinate people, channels, files or links and advises users to verify generated information before relying on it. A fabricated or misinterpreted detail may not bypass permissions, but it could still yield an incorrect assignee, deadline or task description if a user approves it without review. [5]
Teams deploying the connector should use least-privilege access, limit who can authorize write actions, review generated assignments and monitor tool activity. Those operational safeguards remain necessary even where Slack permissions and Chaser’s approval prompts work as designed.
Part of Slack’s broader agent platform push
Chaser’s launch follows Slack’s own expansion of MCP-based infrastructure. On February 17, Slack said its MCP server and Real-Time Search API had reached general availability. The company said more than 50 partners, including Anthropic, Google, OpenAI and Perplexity, were building context-aware agents with the platform, and reported a 25-fold increase in Real-Time Search queries and MCP tool calls since its limited release. Those adoption figures were supplied by Slack. [4]
Slack’s MCP connection and Chaser’s MCP server serve different functions. Slack’s infrastructure provides permission-aware access to Slack context and actions inside Slack. Chaser’s server provides task-specific operations: creating, assigning and managing the work record. When both are connected, Claude can use context from Slack conversations, meeting transcripts or other approved systems to suggest follow-up work, then place the approved items into Chaser for tracking. [2][4]
Anthropic also introduced Claude Tag for Slack in beta on June 23 for Claude Team and Enterprise customers. The feature lets people mention Claude in channels, grant it access to selected tools and data, and delegate multistep or asynchronous work. Chaser complements that model by giving Claude a dedicated mechanism for recording the human follow-through after a delegated workflow produces an answer. [3]
MCP’s expanding reach also brings security questions
The Chaser announcement does not involve a reported Chaser-specific security incident. But it arrives amid broader scrutiny of MCP-based agent connections. A January paper by Narek Maloyan and Dmitry Namiot identified potential architectural weaknesses involving capability attestation, server-originated sampling and implicit trust among multiple MCP servers. Across 847 attack scenarios, the researchers reported attack-success increases of 23% to 41% for MCP integrations compared with equivalent non-MCP setups. The research should not be read as evidence that Chaser’s implementation is vulnerable, but it illustrates why tool permissions and untrusted inputs need careful handling. [6]
A June Internet-Draft by Anas Mohiuddin Syed similarly catalogued MCP risks such as excessive tool permissions, prompt-injection exposure, information leakage and authentication gaps. The document is an individual IETF Internet-Draft rather than a formal standard, but it reflects an unresolved reality of fast-moving agent ecosystems: the technical capability to act across systems is advancing faster than common security practice. [7]
For Chaser, the practical test will be whether its approval controls and Slack-native task workflow help teams gain useful automation without making assignments feel opaque or unreliable. Its core proposition is straightforward: AI can generate work products, but teams still need a dependable way to make sure the right human owns the next action.
Editor’s Take
I like the narrowness of this integration. The valuable step is not having Claude produce another polished meeting summary; it is turning a proposed next action into a durable commitment with an owner, due date and reminder loop. For Slack-centric teams, that can eliminate a surprising amount of task-loss between “we should do this” and someone actually doing it.
The approval gate is the feature I would evaluate most aggressively. AI can suggest sensible work, but it is still error-prone around ownership, urgency and context. Chaser’s claims on adoption and completion rates are encouraging but not independently validated; the next proof point is whether teams can safely approve high volumes of AI-created tasks without creating noisy, misassigned work. MCP makes the connection easier, but operational discipline—not the protocol—is what will determine the outcome.
References
- PR Newswire – https://www.prnewswire.com/news-releases/claude-can-finally-assign-you-tasks—chaser-launches-in-slack-with-claude-mcp-302810174.html
- Chaser MCP – https://www.trychaser.com/mcp
- Anthropic, Introducing Claude Tag – https://www.anthropic.com/news/introducing-claude-tag
- Slack, MCP and Real-Time Search API – https://slack.com/blog/news/mcp-real-time-search-api-now-available
- Slack Help Center, Identify hallucinations in Slackbot responses – https://slack.com/help/articles/49426254285203-Identify-hallucinations-in-Slackbot-responses
- Maloyan and Namiot, MCP security research – https://arxiv.org/abs/2601.17549
- Syed, MCP Security Considerations Internet-Draft – https://datatracker.ietf.org/doc/html/draft-mohiuddin-mcp-security-considerations-00
