Source Intelligence
Sweep 28 Aug 2026 ยท 00:00Z Build v2.1.250 478 read Stable v2.1.236 Latest v2.1.250 Next v2.1.250 Feeds RSS JSON llms.txt

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

Capture

One read of Claude Documentation

16 pages moved out of 216 read.

corpus-hash claude-docs-20260822T160705Z

claude-tag/admins/connections/google Changed · +2 / -14 lines

from line 21
 | **OAuth (Connect button)**  | Fastest path. An admin signs in with a Google account that has access to the content Claude needs.                                  |
 | **GCP service-account key** | When you want a dedicated non-human identity in Google with auditable access, or need domain-wide delegation across your Workspace. |
 
-Both routes create a credential and an allowed-websites rule path-scoped to that Google service (the Drive API path for Drive, the Calendar API path for Calendar, the Gmail API path for Gmail).
+Both routes create a credential and an allowed-websites rule for the Google hosts the connection uses.
 
 ## Add the connection with OAuth
 
 <Warning>Use a dedicated Google account for this connection (for example, `[email protected]`), not your own. The connection is shared: anyone in a channel under the bundle's scope can ask Claude to read whatever this account can see in Drive, Calendar, and Gmail. A dedicated account starts with no access until you share the specific folders and calendars Claude needs, and keeps its activity under a separate identity in Google's audit log.</Warning>
 
-In the bundle, click **Connect** next to **Google Drive**, **Google Calendar**, or **Google Gmail**. A scope checklist appears with read-only scopes selected by default. Each scope grants a specific permission:
-
-| Scope                      | What it lets Claude do                               |
-| :------------------------- | :--------------------------------------------------- |
-| `openid`, `userinfo.email` | Identify the connected account (selected by default) |
-| `calendar.readonly`        | Read events and calendars                            |
-| `calendar.events.readonly` | Read events only (narrower than `calendar.readonly`) |
-| `calendar`                 | Create, edit, and delete events                      |
-| `drive.readonly`           | Read files and folders                               |
-| `drive.file`               | Create and edit files Claude itself created          |
-| `gmail.readonly`           | Read email                                           |
-
-Check write scopes only if Claude should create or edit. Click **Sign in with Google Calendar** (or **Sign in with Google Drive**, or **Sign in with Google Gmail**), approve the Google consent screen, and the credential is saved.
+In the bundle, click **Connect** next to **Google Drive**, **Google Calendar**, or **Gmail**. The dialog lists the Google hosts the connection can reach; there are no scopes to choose. Click **Sign in with Google Drive** (or **Sign in with Google Calendar**, or **Sign in with Gmail**), approve the Google consent screen, and the credential is saved.
 
 The connection's reach is whatever the signed-in Google account can see. Share the relevant folders and calendars with that account in Google before testing.
 

claude-tag/admins/restrict-access Changed · +20 / -20 lines

from line 8
 
 In channels, Claude Tag responds only where it's been added and addressed, and the controls on this page narrow that further. DMs are a separate surface that runs on the user's own account; see [how DMs differ from channels](/docs/claude-tag/concepts/agent-identity#direct-message-channels).
 
-<Note>Most controls on this page require the Owner role in your Claude organization; the [permissions table](#permissions-by-role) below lists which actions an Admin or a channel member can take.</Note>
+<Note>Most controls on this page require the Owner role in your Claude organization; the [permissions table](#permissions-by-role) below lists which actions a channel manager or a channel member can take.</Note>
 
 ## Control who can invoke Claude Tag
 
from line 121
 | **Channel only**       | Replies, but while a guest is present it runs with channel-only access. Bundles, connectors, and instructions from the workspace or from **Default Slack access** don't reach the channel, and neither do repositories, memory, or skills. The channel's own instructions and any access bundle attached directly to the channel still apply. |
 | **Allow**              | Replies with the full access the scope gives it, as in any other channel.                                                                                                                                                                                                                                                                     |
 
-A channel without its own value shows **Inherit** and takes the value from its workspace, or from **Default Slack access**. An Admin can set a scope to **Restrict** or **Channel only**. Changing it to **Allow** or back to **Inherit** requires an organization owner, because either can widen what guests see. The setting applies to every guest channel the scope covers; to open one channel rather than a whole workspace, set it on the channel's own scope.
+A channel without its own value shows **Inherit** and takes the value from its workspace, or from **Default Slack access**. Changing this setting requires an organization owner. The setting applies to every guest channel the scope covers; to open one channel rather than a whole workspace, set it on the channel's own scope.
 
 Under every value, guests in the channel can read what Claude posts there. In any channel that includes a guest, even under **Allow**, Claude won't search the workspace, look up people or channels, or read channels other than the one it's in, because the results could include content the guests can't see in Slack. That is the same reason Claude doesn't search private channels. To do any of that, ask from a channel without guests.
 
from line 166
 
 The **Allow direct messages** toggle controls whether members can message Claude directly. When it's off, Claude is reachable only in channels. The default is on, and you must be an Owner of your Claude organization to change it.
 
-On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), the toggle appears in one of two places: directly on the Claude Tag settings page, or in the **Manage** dialog on the Slack entry under **Where Claude Tag works**, where the toggle is labeled **Allow direct messages with Claude**. It's the same setting in both places, so change it wherever it appears for your organization.
+On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), the toggle appears in one of two places: directly on the Claude Tag settings page, or in the **Manage** dialog on the Slack entry under **Where Claude Tag works**. It's the same setting in both places, so change it wherever it appears for your organization.
 
 ### Set spend limits
 
from line 189
 
 A channel manager is a member of your Claude organization who can set up Claude in specific channels without the Owner role. Channel managers are available on the Enterprise plan, and you must be an Owner to add or remove them.
 
-You name channel managers one channel at a time. For that channel, a channel manager adds repositories and credentials, sets the default model, and edits channel instructions. Every other setting at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) stays with Owners and Admins.
+You name channel managers one channel at a time. For that channel, a channel manager adds repositories and credentials, sets the default model, and edits channel instructions. Every other setting at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) stays with Owners.
 
 ### What a channel manager can do on the Configure page
 
from line 229
   </Step>
 </Steps>
 
-Owners and Admins can already configure every channel, so you see them as **Already has full access** and can't add them.
+Owners can already configure every channel, so you see them as **Already has full access** and can't add them.
 
 Leave the role as it was created: assigned to its channel, with **Claude Tag channel setup** as its only permission. If the role's permissions are changed on the Roles page, the channel's **Channel managers** section stops recognizing the role, shows no managers, and refuses to add or remove any, with an error that points you to the Roles page. To recover, set the role's permissions back to exactly **Claude Tag channel setup**; the group and its members are kept. To give channel managers any other permission, create a separate role for it.
 
from line 253
 
 ## Permissions by role
 
-Creating bundles, binding them to scopes, and pairing workspaces need an Owner; an Admin can edit a bundle's Credentials and Domains tabs but not its other tabs. A [channel manager](#delegate-channel-setup-to-channel-managers) configures only the channels assigned to them. Everything else happens inside the channel and is open to its members. The table lists each action and who can take it.
+Creating bundles, binding them to scopes, and pairing workspaces need an Owner. A [channel manager](#delegate-channel-setup-to-channel-managers) configures only the channels assigned to them. Everything else happens inside the channel and is open to its members. The table lists each action and who can take it.
 
-| Action                                                                | Owner               | Admin               | Channel manager                                                   | Channel member                                                                                                                                 |
-| :-------------------------------------------------------------------- | :------------------ | :------------------ | :---------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------- |
-| Pair a workspace                                                      | Yes                 | No                  | No                                                                | No                                                                                                                                             |
-| Create, rename, delete, or bind an Access bundle                      | Yes                 | No (view only)      | Only to create a bundle for an assigned channel                   | No                                                                                                                                             |
-| Edit a bundle's Repositories, Plugins, or Instructions tab            | Yes                 | No (view only)      | No                                                                | No                                                                                                                                             |
-| Edit a bundle's Credentials or Domains tab                            | Yes                 | Yes                 | Credentials tab only, in a bundle created for an assigned channel | No                                                                                                                                             |
-| Add a channel manager                                                 | Yes                 | No                  | No                                                                | No                                                                                                                                             |
-| Set a channel's default model or repositories from the Configure page | Yes                 | Yes                 | Yes, in assigned channels                                         | No                                                                                                                                             |
-| Write channel memory                                                  | Yes, in the channel | Yes, in the channel | Yes, in the channel                                               | Yes                                                                                                                                            |
-| Set channel instructions from the Configure link                      | Yes                 | Yes                 | Yes, in assigned channels                                         | Yes, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting blocks it |
-| Create, list, or disable a scheduled job in the channel               | Yes, in the channel | Yes, in the channel | Yes, in the channel                                               | Yes                                                                                                                                            |
-| Remove Claude from a channel                                          | Yes                 | Yes                 | Yes, with `/remove`, unless your Slack admin restricts it         | Yes, with `/remove`, unless your Slack admin restricts it                                                                                      |
+| Action                                                                | Owner               | Channel manager                                                   | Channel member                                                                                                                                 |
+| :-------------------------------------------------------------------- | :------------------ | :---------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------- |
+| Pair a workspace                                                      | Yes                 | No                                                                | No                                                                                                                                             |
+| Create, rename, delete, or bind an Access bundle                      | Yes                 | Only to create a bundle for an assigned channel                   | No                                                                                                                                             |
+| Edit a bundle's Repositories, Plugins, or Instructions tab            | Yes                 | No                                                                | No                                                                                                                                             |
+| Edit a bundle's Credentials or Domains tab                            | Yes                 | Credentials tab only, in a bundle created for an assigned channel | No                                                                                                                                             |
+| Add a channel manager                                                 | Yes                 | No                                                                | No                                                                                                                                             |
+| Set a channel's default model or repositories from the Configure page | Yes                 | Yes, in assigned channels                                         | No                                                                                                                                             |
+| Write channel memory                                                  | Yes, in the channel | Yes, in the channel                                               | Yes                                                                                                                                            |
+| Set channel instructions from the Configure link                      | Yes                 | Yes, in assigned channels                                         | Yes, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting blocks it |
+| Create, list, or disable a scheduled job in the channel               | Yes, in the channel | Yes, in the channel                                               | Yes                                                                                                                                            |
+| Remove Claude from a channel                                          | Yes                 | Yes, with `/remove`, unless your Slack admin restricts it         | Yes, with `/remove`, unless your Slack admin restricts it                                                                                      |
 
 Scheduled jobs run with the channel's credentials, so a member creating one can't reach anything the channel itself can't.
 
from line 278
 * **Renaming or rebranding the app.** The Claude app's name, @-handle, and avatar in Slack are fixed; there is no per-workspace rename setting.
 * **Per-user spend caps on channel work.** Spend limits apply at the organization and channel level. There's no way to cap what one member can spend in channels; DM usage bills to that member's own seat and follows the seat's usual limits.
 * **Per-channel responder allowlist.** The restriction toggle governs who can invoke Claude across the workspace; you can't narrow it to a list of people for one channel only.
-* **An open-internet switch in Claude Tag settings.** A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner or Admin adds that hostname on a [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential); for broad web access, they pin an [environment](/docs/claude-tag/concepts/glossary#environment) whose network access level is Full access on the scope. [Allow-all egress](/docs/claude-tag/admins/add-connections#allow-all-hosts), a `*` entry on the Domains tab, is off by default and enabled per organization by Anthropic.
+* **An open-internet switch in Claude Tag settings.** A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner adds that hostname on a [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential); for broad web access, they pin an [environment](/docs/claude-tag/concepts/glossary#environment) whose network access level is Full access on the scope. [Allow-all egress](/docs/claude-tag/admins/add-connections#allow-all-hosts), a `*` entry on the Domains tab, is off by default and enabled per organization by Anthropic.
 * **A web search toggle for channels.** No setting turns web search off for channel sessions; the web search capability setting in claude.ai admin settings governs claude.ai chat, not channels. Web search runs on Anthropic's servers rather than from the channel sandbox, so Domains entries and egress settings don't govern it, and a search opens no new path out of the sandbox; search requests travel to Anthropic the same way the session's model traffic already does. See [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests).
 * **Read-scope confinement.** Claude can search public channels by keyword the same way any Slack user can; it can't read a channel's full history unless it's been added there. There's no setting to disable workspace search, and no setting to enable it in [channels that include guests](#restrict-guest-channels), where search is unavailable.
 * **Session length enforcement.** Your organization's Slack session-length policy is not enforced on this surface.

claude-tag/admins/setup-overview Changed · +10 / -10 lines

from line 22
 
 ## Before you start
 
-| Prerequisite                                                              | Why you need it                                                                                                                                                                                       | If you don't have it                                                                                                                                                                                                                                                                                                              |
-| :------------------------------------------------------------------------ | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-| A **Team or Enterprise plan** on claude.ai                                | Claude Tag is available on Team and Enterprise plans, on Anthropic's first-party service. It isn't available on individual plans (Free, Pro, or Max), or for third-party deployments.                 | Start a Team or Enterprise plan at [claude.com/pricing](https://claude.com/pricing)                                                                                                                                                                                                                                               |
-| A Claude organization **without Zero Data Retention (ZDR)**               | Claude Tag stores channel memory and session transcripts, which ZDR doesn't permit.                                                                                                                   | Claude Tag isn't available to ZDR organizations                                                                                                                                                                                                                                                                                   |
-| **Routines** enabled for your Claude organization                         | Claude Tag requires Routines to be enabled for your organization. Until it is, Claude answers every mention and DM with a reply that it's unavailable and does no work.                               | An admin enables Routines at [`claude.ai/admin-settings/claude-code`](https://claude.ai/admin-settings/claude-code)                                                                                                                                                                                                               |
-| **Owner** role in the Claude organization you're setting up               | Pairing a workspace and creating Access bundles are Owner-only writes; an Admin can view settings but not complete setup. Roles are per organization, so being an Owner elsewhere doesn't carry over. | Ask an Owner to run setup, or have one promote you at [`claude.ai/admin-settings/members`](https://claude.ai/admin-settings/members)                                                                                                                                                                                              |
-| A **Slack workspace admin**                                               | Running `@Claude connect` requires a Slack workspace admin; installing the app usually does too (most workspaces require admin approval for new apps)                                                 | If that's someone else, [send them the install request](/docs/claude-tag/admins/pair-workspace#send-the-install-request-to-your-slack-admin) early (app approval can take time), and plan to be online together when you [pair your Slack workspace](#pair-your-slack-workspace); pairing codes expire 15 minutes after they're issued |
-| **Usage credits** (Team plans)                                            | Channel work draws from your organization's usage balance; on a Team plan nothing runs until credits are loaded                                                                                       | Check whether your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise) before buying; otherwise, buy credits at [`claude.ai/admin-settings/usage`](https://claude.ai/admin-settings/usage)                                           |
-| *(Optional)* The **Claude GitHub App** linked to your Claude organization | Linking GitHub before you start turns setup's GitHub step into repository selection, so you can grant repositories there instead of installing the app mid-setup                                      | [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) first, or grant repository access after setup                                                                                                                                                                                  |
-| *(Optional)* A **channel to test in**                                     | You'll invite Claude to a channel to [test](#test-that-setup-worked) that setup worked                                                                                                                | Create a private Slack channel for the pilot, or pick any existing one                                                                                                                                                                                                                                                            |
+| Prerequisite                                                              | Why you need it                                                                                                                                                                       | If you don't have it                                                                                                                                                                                                                                                                                                              |
+| :------------------------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
+| A **Team or Enterprise plan** on claude.ai                                | Claude Tag is available on Team and Enterprise plans, on Anthropic's first-party service. It isn't available on individual plans (Free, Pro, or Max), or for third-party deployments. | Start a Team or Enterprise plan at [claude.com/pricing](https://claude.com/pricing)                                                                                                                                                                                                                                               |
+| A Claude organization **without Zero Data Retention (ZDR)**               | Claude Tag stores channel memory and session transcripts, which ZDR doesn't permit.                                                                                                   | Claude Tag isn't available to ZDR organizations                                                                                                                                                                                                                                                                                   |
+| **Routines** enabled for your Claude organization                         | Claude Tag requires Routines to be enabled for your organization. Until it is, Claude answers every mention and DM with a reply that it's unavailable and does no work.               | An admin enables Routines at [`claude.ai/admin-settings/claude-code`](https://claude.ai/admin-settings/claude-code)                                                                                                                                                                                                               |
+| **Owner** role in the Claude organization you're setting up               | Pairing a workspace and creating Access bundles are Owner-only writes. Roles are per organization, so being an Owner elsewhere doesn't carry over.                                    | Ask an Owner to run setup, or have one promote you at [`claude.ai/admin-settings/members`](https://claude.ai/admin-settings/members)                                                                                                                                                                                              |
+| A **Slack workspace admin**                                               | Running `@Claude connect` requires a Slack workspace admin; installing the app usually does too (most workspaces require admin approval for new apps)                                 | If that's someone else, [send them the install request](/docs/claude-tag/admins/pair-workspace#send-the-install-request-to-your-slack-admin) early (app approval can take time), and plan to be online together when you [pair your Slack workspace](#pair-your-slack-workspace); pairing codes expire 15 minutes after they're issued |
+| **Usage credits** (Team plans)                                            | Channel work draws from your organization's usage balance; on a Team plan nothing runs until credits are loaded                                                                       | Check whether your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise) before buying; otherwise, buy credits at [`claude.ai/admin-settings/usage`](https://claude.ai/admin-settings/usage)                                           |
+| *(Optional)* The **Claude GitHub App** linked to your Claude organization | Linking GitHub before you start turns setup's GitHub step into repository selection, so you can grant repositories there instead of installing the app mid-setup                      | [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) first, or grant repository access after setup                                                                                                                                                                                  |
+| *(Optional)* A **channel to test in**                                     | You'll invite Claude to a channel to [test](#test-that-setup-worked) that setup worked                                                                                                | Create a private Slack channel for the pilot, or pick any existing one                                                                                                                                                                                                                                                            |
 
 If any of your services restrict traffic by IP, file the [network requirements](/docs/claude-tag/admins/network-requirements) request with your network team early; in many organizations, IP allowlist changes take days to approve.
 

claude-tag/concepts/how-it-works Changed · +3 / -3 lines

from line 105
 
 Editing or deleting an earlier message doesn't steer the session the way a reply does:
 
-* **Editing a message**: Claude receives a note each time you edit, showing what the message said before the edit and what it says now. It reads the note but doesn't act on it, so it won't reply, redo finished work, or treat words you added as a new request.
+* **Editing a message**: Claude receives a note each time you edit, showing what the message said before the edit and what it says now. An edit doesn't start a new task or re-address Claude, even if you add `@Claude` to it.
 * **Deleting a reply**: Claude gets no notification and keeps the version it already read.
 * **Deleting the thread's first message**: if the thread already has replies, Claude keeps working and the session stays open. If you delete it before anyone has replied, the session closes. Anything Claude already pushed or posted persists, per [what survives between replies](#what-survives-between-replies), and you start a new thread to pick the task back up.
-* **Correcting course**: Claude acts on replies, not on edits or deletions. Say the change in a new reply; the reply is also how you walk back a message it already read.
+* **Correcting course**: Claude responds to replies; edits reach it only as notes, and a deleted reply not at all. Say the change in a new reply; the reply is also how you walk back a message it already read.
 
 ## Team channels and personal DMs
 
from line 215
 
 ### Conversation context
 
-A session reads its own thread and its channel. Mentioning `@Claude` partway into an existing thread gives it up to 50 messages from the start of the thread (the root plus the oldest replies, with other bots' replies filtered out). In long threads, the most recent messages before your mention can fall outside that window, so restate anything critical.
+A session reads its own thread and its channel. Mentioning `@Claude` partway into an existing thread gives it a window of the thread's messages, not the whole thread, with other bots' replies filtered out. In long threads, restate anything critical.
 
 Claude works in channels it has been added to, but workspace search can still find messages by keyword from public channels it's not a member of (the same search any Slack user has). Workspace search is unavailable in [channels that include guests](/docs/claude-tag/admins/restrict-access#restrict-guest-channels). Finding something is broader than being able to act somewhere; to have it participate in a channel directly, invite it with `/invite @Claude`.
 

claude-tag/users/getting-started Changed · +3 / -3 lines

from line 6
 
 <BetaNote />
 
-Claude Tag is Claude working in your Slack workspace. You hand it work by writing a message where Claude is, and Claude carries it out in that thread. An `@Claude` mention guarantees a response in a channel, but it isn't required everywhere. DMs and threads Claude is already in reach it without one. There's nothing for you to install or configure; if `@Claude` is in your channel, you can use it (unless your admin has [restricted who can invoke Claude](/docs/claude-tag/admins/restrict-access#members)).
+Claude Tag is Claude working in your Slack workspace. You hand it work by writing a message where Claude is, and Claude carries it out in that thread. An `@Claude` mention guarantees a response in a channel, but it isn't required everywhere. DMs and threads Claude is already in reach it without one. There's nothing for you to install or configure; if `@Claude` is in your channel, you can use it (unless your admin has [restricted who can invoke Claude](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude)).
 
 ## When to tag Claude in a channel versus a DM
 
 Where you tag Claude decides whose tools it uses and who sees the result.
 
-* **Channel** for shared team work. The work happens in the open, so anything Claude does in the thread, including its checklist and results, is visible to everyone in the channel, and anyone can reply to steer the work. An admin sets what Claude can reach in each channel, and everyone who asks there gets the same access. By default you don't need a Claude account to tag Claude in a channel; the work bills to the organization. An admin can [restrict who can invoke Claude](/docs/claude-tag/admins/restrict-access#members).
+* **Channel** for shared team work. The work happens in the open, so anything Claude does in the thread, including its checklist and results, is visible to everyone in the channel, and anyone can reply to steer the work. An admin sets what Claude can reach in each channel, and everyone who asks there gets the same access. By default you don't need a Claude account to tag Claude in a channel; the work bills to the organization. An admin can [restrict who can invoke Claude](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude).
   * Example: `@Claude where are we on the launch checklist? Pull what's still open from this channel and #design-review.`
 * **DM** for personal tasks. A DM runs on your own claude.ai account with [your own connectors](/docs/connectors/overview). Every DM message reaches Claude without an @-mention. You can also DM Claude questions about getting started, like how to word a task or what to try first. DMs are one-to-one only; group DMs aren't supported.
   * Example: `Pull my afternoon meetings from my calendar and draft a one-line prep note for each.`
from line 85
 | Private channels and DMs                                    | Only from inside them. Adding Claude to a private channel lets it work there, but the channel stays unreadable from any other channel or DM.                                                                                                                           |
 | A link you paste, like a Google Doc or a webpage            | Only if your admin allowed that site for this channel. If not, Claude tells you it can't reach it. For files in your personal Drive or Google account, DM Claude instead; [a DM uses your own connectors](/docs/claude-tag/concepts/agent-identity#direct-message-channels) |
 | A Slack canvas                                              | No                                                                                                                                                                                                                                                                     |
-| A message you edited after sending                          | Yes. Each edit sends Claude a note showing the text before and after the edit. Claude reads the note but doesn't act on it, so say a correction in a new reply. Deleting a message doesn't notify Claude                                                               |
+| A message you edited after sending                          | Yes. Each edit sends Claude a note showing the text before and after the edit. An edit never starts a new task on its own, so to be sure a correction is picked up, say it in a new reply. Deleting a message doesn't notify Claude                                    |
 
 The fastest way to find out for your channel is to ask: `@Claude can you read the doc I just linked?` gets you a yes or a "that site isn't allowed here."
 

claude-tag/users/troubleshooting Changed · +2 / -2 lines

from line 40
 
 **What it means**
 
-Mentioning Claude in a channel doesn't require the sender to have a Claude account or seat, so by default anyone in the workspace can use it. Your organization can restrict that with the [member access setting](/docs/claude-tag/admins/restrict-access#members), in which case members outside the restriction are declined.
+Mentioning Claude in a channel doesn't require the sender to have a Claude account or seat, so by default anyone in the workspace can use it. Your organization can restrict that with the [member access setting](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude), in which case members outside the restriction are declined.
 
 **How to resolve**
 
from line 48
 
 * No reaction and no reply at all: unusual when it works for you in the same channel; send your admin the exact channel and person.
 * A message about guests: see [the guest entry below](#claude-doesn%E2%80%99t-respond-in-channels-that-include-guests).
-* A message about permissions or access: your organization restricts who can use Claude; send your admin [the member access setting](/docs/claude-tag/admins/restrict-access#members).
+* A message about permissions or access: your organization restricts who can use Claude; send your admin [the member access setting](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude).
 
 ### Claude reacted or started thinking, then never replied
 

claude-tag/admins/configure-github Changed · +7 / -8 lines

from line 17
 ## Link your GitHub organization
 
 <Note>
-  The person who completes the link must be both an **owner of the GitHub organization** and an **Admin in your Claude organization**. If you aren't a GitHub organization owner, use **Copy message** under **Not a GitHub account owner?** on the GitHub settings page to send the link to someone who is.
+  The person who completes the link must be both an **owner of the GitHub organization** and an **Owner in your Claude organization**. If you aren't a GitHub organization owner, use **Copy message** under **Not a GitHub account owner?** on the GitHub settings page to send the link to someone who is.
 </Note>
 
 <Steps>
from line 68
 
 Repository grants apply to new threads. After changing the **Repositories** tab, start a fresh thread in the channel and name the repository in the first message.
 
-The message "GitHub Actions writes are not permitted for this session type." is a different `403`. It says nothing about repository access; see [What Claude can do with GitHub Actions](#what-claude-can-do-with-github-actions).
+A `403` that names a GitHub Actions operation, such as "repository\_dispatch is not permitted for this session type.", is a different error. It says nothing about repository access; see [What Claude can do with GitHub Actions](#what-claude-can-do-with-github-actions).
 
 ## How granted repositories reach a session
 
from line 101
 Claude can:
 
 * Read workflow runs, jobs, logs, and artifacts, so it follows a pull request's CI and reports the result
-* Re-run a workflow run or its failed jobs, and cancel a run in progress
-* Trigger `push` and `pull_request` workflows by pushing a branch or opening a pull request, the same way any other author does. To let Claude start automation on demand, put the workflow behind one of these triggers instead of `workflow_dispatch`
+* Re-run a workflow run or its failed jobs, cancel a run in progress, and dispatch a `workflow_dispatch` workflow
+* Delete runs, logs, or artifacts, and enable or disable a workflow
+* Trigger `push` and `pull_request` workflows by pushing a branch or opening a pull request, the same way any other author does
 * Edit files under `.github/workflows/` and open a pull request with the change, like any other file
 
 Claude can't:
 
-* Dispatch a workflow (`workflow_dispatch` or `repository_dispatch`)
+* Send a `repository_dispatch` event
 * Approve a workflow run that's waiting on approval, or its pending deployments
-* Delete runs, logs, or artifacts
-* Enable or disable a workflow
 
-A request for any of those is refused with a `403`. A `repository_dispatch` request returns "repository\_dispatch is not permitted for this session type." The others return "GitHub Actions writes are not permitted for this session type." Dispatching a workflow or approving a held run starts new code running with the repository's Actions secrets, so it needs a person; do it from the repository's **Actions** tab on github.com.
+A request for either is refused with a `403`; a `repository_dispatch` request returns "repository\_dispatch is not permitted for this session type." Approving a held run or a pending deployment releases a checkpoint GitHub inserted for a person, so do it from the repository's **Actions** tab on github.com.
 
 ## Scheduled work uses the same connection
 

claude-tag/admins/troubleshooting Changed · +1 / -1 lines

from line 149
 Either fix works:
 
 * Remove the guests from the channel, or move the conversation to a channel with no guests; this changes no settings, so no other channel is affected.
-* Or change **Allow Claude to respond to guests** for the scope covering this channel. **Channel only** restores replies while keeping Claude to the channel's own instructions and access, and an Admin can set it. **Allow** gives guests the full access the scope has and needs an organization owner. The setting is at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the **Slack** tab under **Claude Tag's access**, in the scope's collapsed **Advanced** section. Either value applies to every guest channel that scope covers; to limit it to one channel, set it on the channel's own scope. See [restrict guest channels](/docs/claude-tag/admins/restrict-access#restrict-guest-channels) for what each value exposes.
+* Or change **Allow Claude to respond to guests** for the scope covering this channel; changing it needs an organization owner. **Channel only** restores replies while keeping Claude to the channel's own instructions and access. **Allow** gives guests the full access the scope has. The setting is at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the **Slack** tab under **Claude Tag's access**, in the scope's collapsed **Advanced** section. Either value applies to every guest channel that scope covers; to limit it to one channel, set it on the channel's own scope. See [restrict guest channels](/docs/claude-tag/admins/restrict-access#restrict-guest-channels) for what each value exposes.
 
 Either value restores replies, not workspace search. Claude can't search the workspace from a channel that includes guests, even under **Allow**. Removing the guests restores search as well.
 

claude-tag/concepts/security-and-data Changed · +1 / -1 lines

from line 99
 
 ## Member access
 
-By default, anyone in a connected Slack workspace can invoke Claude in channels, with or without a Claude account. An Owner can turn on a restriction toggle to narrow that: on Team plans it limits Claude to people with a Claude account in your organization, and on Enterprise plans it limits Claude to members whose role grants the **Claude Tag in Slack** capability. See [Restrict who can use Claude](/docs/claude-tag/admins/restrict-access#members). The toggle governs DMs as well as channels.
+By default, anyone in a connected Slack workspace can invoke Claude in channels, with or without a Claude account. An Owner can turn on a restriction toggle to narrow that: on Team plans it limits Claude to people with a Claude account in your organization, and on Enterprise plans it limits Claude to members whose role grants the **Claude Tag in Slack** capability. See [Restrict who can use Claude](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude). The toggle governs DMs as well as channels.
 
 ## Related resources
 

claude-tag/admins/pair-workspace Changed · +1 / -1 lines

from line 94
 
 ## After pairing: where Claude is enabled
 
-Once a workspace is paired, where Claude responds depends on what you chose when pairing (entire workspace or specific channels), the **Enable Claude Tag for your organization** toggle, and your [access restriction](/docs/claude-tag/admins/restrict-access#members) setting.
+Once a workspace is paired, where Claude responds depends on what you chose when pairing (entire workspace or specific channels), the **Enable Claude Tag for your organization** toggle, and your [access restriction](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude) setting.
 
 * **What Claude can reach** in each channel depends on which Access bundles you bind; see [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope).
 * **Nothing runs until usage is funded** on Team plans; see [Set a spend limit](/docs/claude-tag/admins/set-spend-limit).

claude-tag/admins/skills-repo Changed · +2 / -2 lines

from line 14
 
 <Steps>
   <Step title="Create the repository">
-    A new GitHub repository in your organization, with one folder per plugin. Each plugin bundles one or more skills.
+    A private or internal GitHub repository, laid out as a [Claude Code plugin marketplace](https://code.claude.com/docs/en/plugin-marketplaces): a `.claude-plugin/marketplace.json` file at the root that lists each plugin, and one folder per plugin. Each plugin bundles one or more skills. A public repository can't be selected in the next step; fork it into a private one first.
   </Step>
 
   <Step title="Register the repository as a plugin marketplace">
-    On the **Plugins** page at [`claude.ai/admin-settings/plugins`](https://claude.ai/admin-settings/plugins), click **Add plugins** and choose **Sync from GitHub**. Select the repository, leave **Sync automatically** on (the default), and click **Create**.
+    For a github.com repository, the GitHub connector must be enabled for your organization. On the **Plugins** page at [`claude.ai/admin-settings/plugins`](https://claude.ai/admin-settings/plugins), click **Add plugins** and choose **Sync from GitHub**. Select the repository, leave **Sync automatically** on (the default), and click **Create**.
   </Step>
 
   <Step title="Grant Claude write access to the repository">

claude-tag/admins/migrate-from-earlier Changed · +1 / -1 lines

from line 68
 
 In channels, the visible difference is that work belongs to the channel, not to whoever asked. Anyone can reply in a thread to steer it, and the result stays where the team can see and pick it up. Code work is authored by the Claude GitHub App rather than as the requesting user.
 
-A user who never linked a claude.ai account can now hand Claude work in channels, by default. Whether that stays open or narrows to organization members is the admin's [access restriction](/docs/claude-tag/admins/restrict-access#members) setting.
+A user who never linked a claude.ai account can now hand Claude work in channels, by default. Whether that stays open or narrows to organization members is the admin's [access restriction](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude) setting.
 
 ## Related resources
 

claude-tag/admins/for-slack-admins Changed · +1 / -1 lines

from line 32
 Two scopes a Slack admin commonly asks about:
 
 * `channels:join` lets Claude add itself to a public channel when a member selects one of its suggested-channel buttons, or when the channel's name matches an [auto-join channel pattern](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name) an admin set. It cannot join private channels this way.
-* `users:read.email` lets Claude match a Slack member to their Claude account by email, so a person who DMs Claude is recognized without a separate linking step.
+* `users:read.email` lets Claude read a member's profile email. Claude uses it for checks such as the email domain when a member connects their Claude account. It does not connect accounts; a member still runs the Connect step in Slack.
 
 ## What installing does not grant
 

claude-tag/admins/configure-gitlab Changed · +1 / -1 lines

from line 12
 
 ## Prerequisites
 
-* The **Owner** role in your Claude organization to create an Access bundle; an Admin can add credentials to a bundle that already exists.
+* The **Owner** role in your Claude organization to create an Access bundle.
 * Permission in GitLab to create a user (or a [service account](https://docs.gitlab.com/user/profile/service_accounts/) on tiers that offer it) and to add that user to the groups or projects Claude should reach.
 * An [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle) to hold the credential. Create one first if you haven't already.
 

claude-tag/admins/audit Changed · +1 / -1 lines

from line 8
 
 Use this page to review what Claude Tag is doing across your organization: which routines are scheduled, what memory it has saved, and where to find a record of each action it took.
 
-<Note>You must be an Admin or Owner in your Claude organization to open the Audit page; the other trails on this page are visible to anyone with access to the underlying surface.</Note>
+<Note>You must be an Owner in your Claude organization to open the Audit page; the other trails on this page are visible to anyone with access to the underlying surface.</Note>
 
 Claude Tag activity is auditable in four places:
 

claude-tag/admins/add-connections Changed · +1 / -3 lines

from line 14
 </div>
 
 <div className="tm-stepmeta">
-  <div className="tm-stepmeta-row"><span className="tm-stepmeta-label">Role you need</span><span>Owner in your Claude organization to create the bundle; an Admin can add credentials to a bundle that already exists. You'll also need a credential for each service, created by you or by that service's admin.</span></div>
+  <div className="tm-stepmeta-row"><span className="tm-stepmeta-label">Role you need</span><span>Owner in your Claude organization. You'll also need a credential for each service, created by you or by that service's admin.</span></div>
   <div className="tm-stepmeta-row"><span className="tm-stepmeta-label">Before this step</span><span>A <a href="/docs/docs/claude-tag/admins/pair-workspace">paired workspace</a></span></div>
   <div className="tm-stepmeta-row"><span className="tm-stepmeta-label">Do I need this?</span><span><span className="tm-meta-pill tm-meta-pill-opt">Optional to start</span>You need a connection only when Claude should act in a system beyond Slack, like querying BigQuery, reading Google Drive, or filing Linear tickets.<br /><br />You can add connections any time after setup (they apply immediately), but adding the systems your team expects before they onboard means their first requests succeed.</span></div>
 </div>
from line 129
 You don't have to predict the full list up front. When a request is blocked, Claude says so in the thread and names the host; add that host here and retry; if it's still blocked, start a fresh thread.
 
 Typical entries are hosts the work calls without a key, such as a docs site or a public API. Common package registries are usually already reachable through the [environment's Trusted access default](#broad-web-access-through-the-environment), and a host that needs a credential belongs in a [connection](#add-a-connection) instead. Entries appear below the form, and each one can be edited or removed from its row.
-
-An Admin can edit the Domains tab on an existing bundle; creating the bundle itself needs an Owner.
 
 <Note>[Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) carries only HTTP and HTTPS. A protocol that isn't HTTP, such as SSH, can't cross the proxy, so listing a host here doesn't make it reachable over SSH.</Note>