Capture
One read of Claude Documentation
9 pages moved out of 216 read.
claude-tag/admins/customize Changed · +6 / -0 lines
## Where to change a scope's environment
from line 77
A change to the allowed list applies to new sessions, like a change to the **Default model**; a thread already underway keeps its model until someone in it asks Claude to switch. +## Where to change a scope's environment + +The environment is the sandboxed compute configuration a scope's sessions run in. You create environments in one place and pin one per scope in another. An Owner or admin creates environments on the **Cloud environments** page in [admin settings](https://claude.ai/admin-settings), as [organization-shared environments](https://code.claude.com/docs/en/cloud-environments#organization-shared-environments). You then pin one per scope, in the **Environment** picker in the scope's **Advanced** section on [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), for **Default Slack access**, a workspace, or a channel. A channel with no pin of its own inherits the nearest pin above it; with nothing pinned anywhere, sessions use the **Organization default**. + +A change applies to new sessions; after you pin an environment, start a fresh thread to pick it up. To give a channel broader network access through its environment, see [broad web access through the environment](/docs/claude-tag/admins/add-connections#broad-web-access-through-the-environment). If sessions don't pick up the environment you pinned, see [channel sessions use the wrong environment](/docs/claude-tag/admins/troubleshooting#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one). + ## Auto mode allow rules Sessions run in [auto mode](https://code.claude.com/docs/en/permission-modes#eliminate-prompts-with-auto-mode), where Claude's permission checker reviews each action Claude is about to take and can flag or stop it. When you add an auto mode allow rule to a scope, you pre-approve one action in that scope's sessions, so Claude runs it there without the checker stopping it. The checker keeps reviewing every other action.
claude-tag/admins/migrate-from-earlier Changed · +5 / -3 lines
## Two versions of the same Slack app
from line 58
The **Claude Tag version** setting on each scope lets you pin a channel or workspace to **Off**, **Legacy**, or **New**, or **Inherit** the organization default. Use it to hold specific channels on the Legacy behavior while you finish provisioning, then switch them when ready. Access bundles only apply where the New version answers. See [the version setting](/docs/claude-tag/admins/restrict-access#migrate-from-the-earlier-claude-in-slack) for the control. -Both versions answer through the same @Claude app, so setting a scope to **Off** turns off the earlier version there too. To opt out of Claude Tag while keeping the earlier behavior, set the scope to **Legacy**, not **Off**. +## Two versions of the same Slack app +The earlier Claude in Slack and Claude Tag are two versions of the same `@Claude` Slack app, not two apps, so there is nothing to uninstall. You choose which version answers per scope with the **Claude Tag version** setting (**Off**, **Legacy**, **New**, or **Inherit**), so one workspace can run both during a phased switch. Setting a scope to **Off** turns off both versions there; to keep the earlier behavior in a scope, set it to **Legacy**. + +To tell which version answered in a channel, look at who authored the work. The New version authors code as the Claude GitHub App and keeps work in the channel's thread; if `@Claude` still opens pull requests under the asker's name, that channel is answering with the Legacy version. + ## What existing users notice after the switch In channels, the visible difference is that work belongs to the channel, not to whoever asked. Anyone can reply in a thread to steer it, and the result stays where the team can see and pick it up. Code work is authored by the Claude GitHub App rather than as the requesting user. A user who never linked a claude.ai account can now hand Claude work in channels, by default. Whether that stays open or narrows to organization members is the admin's [access restriction](/docs/claude-tag/admins/restrict-access#members) setting. - -If `@Claude` in a channel still opens pull requests under the asker's name, that channel is answering with the Legacy version; check the scope's Claude Tag version setting. ## Related resources
claude-tag/admins/restrict-access Changed · +12 / -8 lines
### Usage analytics
from line 20
Open **Manage** on the Slack entry under **Where Claude Tag works** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). The dialog shows a toggle that controls who in your Slack workspace can use Claude at all; its label depends on your plan. You must be an Owner of your Claude organization to change it. -| Plan | Toggle | Off (default) | On | -| :--------- | :----------------------------------------- | :------------------------------------------------------------------------------------ | :----------------------------------------------------------------------------------- | -| Enterprise | **Restrict in your organization via RBAC** | Anyone in the connected Slack workspace can use Claude, even without a Claude account | Only members whose role grants the **Claude Tag in Slack** capability can use Claude | -| Team | **Restrict to your organization** | Anyone in the connected Slack workspace can use Claude, even without a Claude account | Only Slack users with a Claude account in your organization can use Claude | +| Plan | Toggle | Off (default) | On | +| :--------- | :------------------------------------------- | :------------------------------------------------------------------------------------ | :----------------------------------------------------------------------------------- | +| Enterprise | **Restrict to roles with Claude Tag access** | Anyone in the connected Slack workspace can use Claude, even without a Claude account | Only members whose role grants the **Claude Tag in Slack** capability can use Claude | +| Team | **Restrict to your organization** | Anyone in the connected Slack workspace can use Claude, even without a Claude account | Only Slack users with a Claude account in your organization can use Claude | The toggle applies to channels and DMs alike.
from line 37
Restricting by role spans three console pages. -1. On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), turn on **Restrict in your organization via RBAC**. +1. On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), turn on **Restrict to roles with Claude Tag access**. 2. On [`claude.ai/admin-settings/groups`](https://claude.ai/admin-settings/groups), create groups and add the relevant members. 3. On [`claude.ai/admin-settings/roles`](https://claude.ai/admin-settings/roles), create a custom role with the **Claude Tag in Slack** capability turned on or off, and choose which groups hold the role in the role editor. Three rules govern how role restrictions resolve. -* **The toggle gates the capability.** The **Claude Tag in Slack** capability on a role has no effect until **Restrict in your organization via RBAC** is on. While the toggle is off, every member can use Claude regardless of what their role grants. +* **The toggle gates the capability.** The **Claude Tag in Slack** capability on a role has no effect until **Restrict to roles with Claude Tag access** is on. While the toggle is off, every member can use Claude regardless of what their role grants. * **Built-in roles always grant access.** Every built-in role, including User, Owner, and Primary owner, grants **Claude Tag in Slack** automatically, so the restriction only blocks members on a custom role that doesn't grant it. * **Any grant wins.** A member in more than one group keeps access if any of their roles grants it.
from line 170
### Set spend limits -Spend limits and usage analytics live at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag), a different page than the main Claude Tag settings. +Spend limits live at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag), a different page than the main Claude Tag settings. Spend trends and per-channel reports live on a separate analytics page; see [Usage analytics](#usage-analytics) below. A spend limit is a cap on how much of your organization's usage balance Claude Tag can draw each billing period. Setting a limit doesn't fund the balance; on a Team plan, [fund the usage balance first](/docs/claude-tag/admins/set-spend-limit) or Claude won't respond in channels regardless of the limit.
from line 177
* **Organization-wide limit.** Caps total Claude Tag spend across every channel. * **Default spend limit.** A default limit applied to each channel that doesn't have its own. * **Per-channel limits.** Set on any channel from its row in the per-channel spend table, in addition to the organization limit. A channel doesn't need its own scope to take a limit. -* **Usage analytics.** Per-channel spend breakdown on the same page. +* **Per-channel spend.** How much each channel has spent against its limit in the current billing period, at list price, on the same page. Work that would exceed a limit is declined rather than silently truncated. A user blocked by a limit can request more usage from their admin in Slack, and the admin notification names whether the usage balance or the limit caused the block. + +### Usage analytics + +Spend trends live at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag), the Claude Tag section of the Analytics dashboard. It shows total and projected month-end spend for the period you pick, spend by channel with a CSV export, DM versus channel spend, [spend by kind of work](/docs/claude-tag/admins/set-spend-limit#see-spend-by-kind-of-work), and any promotional credit, as billed after your discount. Anyone with permission to view your organization's Analytics dashboard can open it; it has no controls, so use the usage page to change a limit. The two pages link to each other. ## Delegate channel setup to channel managers
claude-tag/concepts/agent-identity Changed · +4 / -0 lines
### How a host gets allowed
from line 71
Nothing is installed inside your network. Your systems see only requests authenticated with the credentials Agent Proxy attached. For the endpoints and addresses your network team may need to allowlist, see [Network requirements](/docs/claude-tag/admins/network-requirements). +### How a host gets allowed + +Agent Proxy allows a host when any one of three layers allows it: a [Domains entry](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) on the bundle attached to the scope, a [connection's allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) (which also attaches that connection's credential), or the network access level of the [environment](/docs/claude-tag/concepts/glossary#environment) the scope's sessions run on. A host that none of them allows is blocked, and Claude names the blocked host in the thread so an admin can add it; see [Give Claude access to your tools](/docs/claude-tag/admins/add-connections). + ### Web search vs. network requests Claude can search the web from a channel without any Domains entry. Web search is [Anthropic's built-in web search tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-search-tool), which runs on Anthropic's servers, not code running in the channel's sandbox.
claude-tag/concepts/settings-map Changed · +5 / -2 lines
from line 11
| Surface | Who changes it | What it controls | | :--------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | [Claude Tag admin page](https://claude.ai/admin-settings/claude-tag) | An Owner in your Claude organization | Access, behavior, and restrictions for channels, per [scope](/docs/claude-tag/concepts/glossary#scope) | -| [Usage page](https://claude.ai/admin-settings/usage/claude-tag) | An admin | Spend limits and per-channel usage analytics | +| [Usage page](https://claude.ai/admin-settings/usage/claude-tag) | An admin | Spend limits and each channel's spend against them | +| [Analytics page](https://claude.ai/analytics/claude-tag) | Anyone who can view the Analytics dashboard | Spend trends, projections, and per-channel reports; read-only | | The **Configure** link in the footer of any Claude reply in a channel | Channel members (unless an admin restricts editing) and [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | One channel's instructions and whether Claude replies there without an @-mention. Channel managers also set the channel's default model, repositories, and connections | | [Customize > Connectors](https://claude.ai/customize/connectors) on your own claude.ai account | You | Which of your personal tools apply in [DMs](/docs/claude-tag/concepts/agent-identity#direct-message-channels) |
from line 31
## Spend limits and usage -Spend limits and usage analytics live at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag), a different page than the Claude Tag admin page. It holds the organization-wide spend limit, the default spend limit for channels, per-channel limits, and the per-channel spend breakdown. If your organization bills through a reseller, this page is not available. See [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) for funding the usage balance and what users see when a limit is reached. +Spend limits live at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag), a different page than the Claude Tag admin page. It holds the organization-wide spend limit, the default spend limit for channels, per-channel limits, and each channel's spend against its limit. If your organization bills through a reseller, this page is not available. See [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) for funding the usage balance and what users see when a limit is reached. + +Spend trends live at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag), the Claude Tag section of the Analytics dashboard. It shows total and projected spend, spend by channel, and [spend by kind of work](/docs/claude-tag/admins/set-spend-limit#see-spend-by-kind-of-work) for the period you pick, and anyone with permission to view the Analytics dashboard can open it. It has no controls; see [Usage analytics](/docs/claude-tag/admins/restrict-access#usage-analytics). ## The Configure page
claude-tag/users/use-cases/watch-monitors Changed · +8 / -0 lines
from line 60
<Card title="Set up routines" href="/docs/claude-tag/users/proactivity" horizontal arrow> Schedules and event triggers </Card> + + <Card title="Claude on call" href="https://claude.com/blog/ai-ci-cd-on-call" horizontal arrow> + How Anthropic runs Claude as first responder for CI/CD failures + </Card> + + <Card title="On-call kit" href="https://github.com/anthropics/oncall-kit" horizontal arrow> + Reference playbooks, templates, and guided setup for an on-call channel + </Card> </CardGroup>
claude-tag/users/use-cases/answer-data-questions Changed · +4 / -0 lines
from line 60
<Card title="Set up routines" href="/docs/claude-tag/users/proactivity" horizontal arrow> Recurring reports </Card> + + <Card title="Self-service data analytics" href="https://claude.com/blog/self-service-data-analytics-in-slack-how-anthropic-deploys-claude-tag-for-ad-hoc-questions" horizontal arrow> + How Anthropic answers ad-hoc data questions in Slack with Claude + </Card> </CardGroup>
claude-tag/admins/troubleshooting Changed · +1 / -1 lines
from line 597
**What it means** -Each scope at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the **Slack** tab under **Claude Tag's access**, has an **Environment** picker (in the scope's **Advanced** section) that pins the Claude Code environment or runner pool that sessions in that scope use. With nothing pinned, sessions use the **Organization default**. The picker only lists environments scoped to the organization; an environment created under an individual account doesn't appear, because channel sessions run with no user account attached. +Each scope at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the **Slack** tab under **Claude Tag's access**, has an **Environment** picker (in the scope's **Advanced** section) that pins the Claude Code environment or runner pool that sessions in that scope use. A channel with no pin of its own inherits the nearest pin above it; with nothing pinned anywhere, sessions use the **Organization default**. The picker only lists environments scoped to the organization; an environment created under an individual account doesn't appear, because channel sessions run with no user account attached. **How to resolve**
claude-tag/admins/audit Changed · +1 / -1 lines
from line 19
## What the Audit view lists -The **Audit** page (left-nav label **Audit logs**) at [`claude.ai/admin-settings/claude-tag/audit`](https://claude.ai/admin-settings/claude-tag/audit) has these tabs: +The Audit page, labeled **Activity** in the admin console's left nav and page heading, at [`claude.ai/admin-settings/claude-tag/audit`](https://claude.ai/admin-settings/claude-tag/audit) has these tabs: | Tab | What it shows | | :----------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |