Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
One capture · claude-docs

One read of Claude Documentation

14 pages moved out of 222 read.

claude-docs-20260901T010706Z

Pages moved 14 significant first
Pages read 222 in this capture
Captured 01:07 UTC
Corpus hash abe60375906a corpus-hash

What this read moved

1–14 of 14

claude-science/admin-controls Changed · +221 / -78 lines

## Organization settings ### Defaults by plan ### How changes reach members ### Featured connectors and skills ### Custom connectors ### Custom skills ### Network allowlist ### Organization package mirror ### SSH hosts ### Modal ### Scientific model endpoints ### Memory ## How other admin settings apply to Claude Science ### Identity and access ### Capability toggles ### Connectors ### Data and privacy ### Audit and compliance ### Usage, models, and billing ### Offboarding and local data ## Identity and access ## Capability toggles ## Connectors ## Data and privacy ## Audit and compliance ## Usage, models, and billing ## Offboarding and local data

from line 1
11# Admin controls
22 
3> Members sign in to Claude Science with their Claude account, so your identity and billing controls apply automatically.
3> Organization settings for Claude Science on Team and Enterprise plans (Featured connectors and skills, custom connectors and skills, the network allowlist, package mirror, SSH hosts, Modal, scientific model endpoints, and memory) and which other claude.ai admin controls apply to the app.
44 
5Members sign in to Claude Science with their Claude account, so your identity and billing controls apply automatically. Because the app stores conversations on each member's computer, most of the data-handling controls Anthropic provides don't reach that data today. The tables show, for each admin setting, whether it governs Claude Science in beta. Status values describe Claude Science specifically; other Claude products may differ.
5Members sign in to Claude Science with their Claude account, so your identity and billing controls apply automatically. Because the app stores conversations on each member's computer, most of the data-handling controls Anthropic provides don't reach that data today. [Organization settings](#organization-settings) describes the controls on the claude.ai **Organization settings** > **Claude Science** page itself, which govern the connectors, skills, compute, network access, and memory that members can use in the Claude Science app. [How other admin settings apply to Claude Science](#how-other-admin-settings-apply-to-claude-science) lists every other claude.ai admin setting and whether it applies to Claude Science today. Status values describe Claude Science specifically; other Claude products may differ.
66 
7Legend: Supported / Partial / Not available / Not applicable
7## Organization settings
88 
9## Identity and access
9The [**Organization settings** > **Claude Science**](https://claude.ai/admin-settings/claude-science) page in claude.ai holds the controls that apply to every member of your Team or Enterprise organization who uses the app. An Owner or Primary Owner turns Claude Science on there (see [Enable Claude Science](/docs/claude-science/enable-claude-science)), and the other controls unlock once Claude Science is on. Each section below covers one control: what it governs, its default, and what changes for members when you turn it off.
1010 
11| Admin setting | Status in Claude Science beta | Note |
12| --------------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
13| SSO (SAML / OIDC) | Supported | Sign-in goes through claude.ai, so your SSO policy applies automatically. |
14| SCIM / Directory Sync | Supported | Deprovisioning a member revokes their access. |
15| Domain capture | Supported | Inherited from claude.ai account creation. |
16| Members management | Supported | Adding or removing org members controls who can sign in. |
17| Built-in roles | Supported | All built-in roles get access once the product is enabled for the org. |
18| Custom roles | Supported | Custom roles can grant or deny access to the app. |
19| Groups | Supported | Roles assigned through groups carry through. |
20| IP allowlisting | Partial | Claude inference is IP-gated. Gating remote compute (running code on the member's own SSH hosts or cloud accounts) is on the roadmap. Custom connectors and local operation are outside this setting's scope. |
21| Session duration | Partial | Limits the browser sign-in step only; the app stays signed in after that. |
11### Defaults by plan
2212 
23## Capability toggles
13Each control starts at a default that depends on your plan and on whether HIPAA compliance is enabled for your organization. The page always shows the value in force for your organization.
2414 
25| Admin setting | Status in Claude Science beta | Note |
26| -------------------------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
27| Org enable toggle | Supported | Off by default for Team and Enterprise; an Owner or Primary Owner turns it on under Organization settings > Claude Science. Assigning seats doesn't turn it on. |
28| Completion feedback (thumbs) | Supported | The org toggle hides the feedback buttons, same as Chat. |
29| Organization custom instructions | Supported | The org's custom instructions are applied to the app's model calls, the same as Chat. |
30| Skills allowlist | Partial | Org-published skills appear, but members can also install local skills without restriction. Adding admin control is on the roadmap. |
31| Web search | Not available | The app offers web search regardless of this setting. Adding admin control is on the roadmap. |
32| Code execution | Not available | This setting controls Chat's hosted code sandbox only. Claude Science runs code locally regardless of this setting; that's core to the product. |
33| Code execution network allowlist | Not available | This setting controls Chat's hosted code sandbox only and is not yet available for Claude Science in Organization settings. Claude Science's local sandbox keeps its own allowlist, which members manage in the app and administrators can extend per device with the sandbox network keys in the [configuration file reference](/docs/claude-science/configuration-file-reference). |
34| Location metadata | Not applicable | The app doesn't derive, store, or send any geolocation data. |
35| Memory | Not applicable | The claude.ai Memory setting doesn't control memory in Claude Science. The app keeps its own memory locally on the member's device. |
36| Projects | Not applicable | No Projects integration; the app uses local workspaces instead. |
15| Control | Default for Team | Default for Enterprise¹ |
16| ----------------------------------------------------------- | ------------------------------ | ------------------------------ |
17| Featured connectors and Featured skills | All on | All on |
18| Allow custom connectors | On | Off |
19| Allow custom skills | On | On |
20| Manage network allowlist | Off (members manage their own) | Off (members manage their own) |
21| Organization package mirror | Not set | Not set |
22| Allow members to connect SSH hosts | On | On |
23| Allow members to connect to Modal | On | Off |
24| Show scientific model endpoint providers on the Compute tab | On | On |
25| Turn on memory for your team | On | On |
3726 
38## Connectors
27¹ For HIPAA-eligible organizations, note that Claude Science (beta) is not covered under your Business Associate Agreement (BAA) and should not be used with protected health information (PHI). Administrators who enable Claude Science are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. Featured and custom connectors, SSH hosts, Modal, scientific model endpoints, and memory are all off by default for HIPAA-eligible organizations.
3928 
40| Admin setting | Status in Claude Science beta | Note |
41| ---------------------------------- | ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
42| Org-published Directory connectors | Supported | Connectors the admin publishes are available in the app. |
43| Per-role connector restrictions | Partial | Enforced for Directory connectors, not for connectors members add locally. |
44| Org plugin allowlist | Partial | Org-published plugins appear automatically; members can still add their own local skills and connectors. Adding admin control to restrict local skills and connectors is on the roadmap. |
45| Connector tunnels | Partial | Directory connectors the admin publishes reach the app through tunnels. Local connectors the member adds run on their own computer, so tunnels don't apply. Custom remote connectors the member adds don't route through tunnels. |
46| Custom connector restrictions | Not available | Members can add their own custom connectors regardless of the organization allowlist. Adding admin control is on the roadmap. |
47| Desktop Extension allowlist | Not applicable | Desktop Extension directory isn't available in the app. |
29### How changes reach members
4830 
49## Data and privacy
31Changes you save reach each member's running app within a few minutes and apply on the member's next turn or request. An app that is closed picks up your changes when it next starts, and an app that can't reach claude.ai keeps applying the last settings it received.
5032 
51| Admin setting | Status in Claude Science beta | Note |
52| ------------------------- | ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
53| CMEK | Supported | Applies to the product's model traffic the same as Chat. Compliance API session transcripts are also encrypted under your key. |
54| Data processing geography | Partial | Covers Anthropic-hosted processing, not remote compute you configure (code the member runs on their own SSH hosts or cloud accounts) or the member's computer (same as Claude Code). |
55| HIPAA | Partial | Organizations with HIPAA compliance enabled can turn on the Claude Science beta, but usage isn't covered under the BAA. |
56| Custom Data Retention | Partial | The auto-delete window doesn't cover data on members' computers or the model-call logs Anthropic keeps for this product. For Enterprise organizations with the Compliance API enabled, the window does apply to the session transcripts it returns. |
33The settings apply to members running version 0.1.41 or later of the Claude Science app. A member still on an earlier version isn't governed by these settings until the member updates (see [Required updates](/docs/claude-science/manage-on-devices#required-updates)). For Team and Enterprise organizations, Claude Science enforces a minimum version of 0.1.41. A member on an older version sees a notice that the version is no longer supported, with an **Update now** button. If the update doesn't complete after a second try, the member can install the current version from the [Claude Science download page](https://claude.com/product/claude-science) (on Linux, rerun the install command in [Get started](/docs/claude-science/get-started#install)); projects and settings on the computer are kept.
5734 
58## Audit and compliance
35Each member's app also has to reach claude.ai regularly to confirm these settings. If an app can't reach claude.ai for 72 hours, it pauses memory, custom connectors, SSH hosts, Modal, model endpoints, and adding custom skills until it reconnects, and keeps applying the network allowlist, package mirror, and Featured connector and skill choices it last received.
5936 
60| Admin setting | Status in Claude Science beta | Note |
61| --------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
62| Audit log | Not available | Claude Science doesn't write events to the audit log. For Enterprise organizations with the Compliance API enabled, changes to your Claude Science organization settings are recorded in its Activity Feed instead. |
63| Compliance API | Partial | Enterprise plans only. The [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) returns read-only transcripts of members' Claude Science sessions (this coverage is in beta) and records changes to your Claude Science organization settings in its Activity Feed. Sessions in organizations with HIPAA compliance enabled aren't captured. See [Compliance API coverage](/docs/claude-science/how-claude-science-works-with-your-data#compliance-api-coverage). |
64| Org data export | Not available | The export doesn't include data stored on members' computers (same as Claude Code). |
37Turning a control off doesn't delete anything on the members' computers. What members set up under that control (custom connectors, SSH hosts, their Modal connection, saved memories, and their own choices) stays on their computer, and that feature cannot be used inside the Claude Science app while the control is off. The setting shows grayed out in the app with a note that an admin turned it off, and everything works again as before if you turn the control back on. A control that is off by your plan's default instead shows a note that an admin can turn it on. When the **Allow custom skills** switch is off, skills a member added earlier keep working (see [Custom skills](#custom-skills)).
6538 
66## Usage, models, and billing
39### Featured connectors and skills
6740 
68| Admin setting | Status in Claude Science beta | Note |
69| --------------------- | ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
70| Usage limits | Supported | Usage counts toward the same 5-hour and weekly limits as Claude Code and Cowork. |
71| Billing and seats | Supported | Uses the same seat as the rest of claude.ai. |
72| Model access controls | Supported | Uses the standard model API, so the org's allowed-model list and model access grants apply to both the model picker and the calls themselves. |
73| Usage analytics | Supported | Open Analytics from the user menu; the Claude Science tab shows usage, and spend is filterable by product on the Overview tab. |
41Featured connectors and Featured skills come with Claude Science, and admins can control whether they are enabled or disabled for your members (see [Connectors and skills](/docs/claude-science/connectors-and-skills)). The **Featured connectors** and **Featured skills** sections list them with one switch per item, so you can choose which ones members can use. Every item is on by default for Team and Enterprise organizations. In an organization with HIPAA compliance enabled, every Featured connector and skill starts disabled; turn on the ones you have reviewed.
7442 
75## Offboarding and local data
43Each section shows how many items are enabled. Expand it to see the list, and select an item to see its tools or instructions, author, license, and third-party terms.
7644 
77| Admin setting | Status in Claude Science beta | Note |
78| ------------------------ | ----------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
79| Offboarding (local data) | Not available | Removing a member doesn't wipe data already on their computer. |
80| Local deletion signal | Not available | Deleting local data doesn't notify Anthropic to drop the matching server-side model-call logs early; this is on the roadmap. Compliance API session transcripts, where captured, remain until their retention period ends. |
45Besides switching every current item in that list, **Enable all** and **Disable all** set how items added in later versions of Claude Science start: on after **Enable all**, off after **Disable all**. If you use neither, new items start on (off in an organization with HIPAA compliance enabled). The individual switches affect only that item, so to keep today's items on while new ones start off, choose **Disable all** and then turn on the items you want.
46 
47In the **Featured connectors** list, the rows marked **Web** (PubMed, Clinical Trials, ChEMBL, and bioRxiv) are connectors Anthropic hosts in the Claude connector directory rather than locally as part of the app. The switches for those four add or remove the connector for your whole organization on **Organization settings** > **Connectors**, need a role that can manage your organization's connectors, and aren't changed by **Enable all** or **Disable all**. For organizations with HIPAA compliance enabled, manage those four on the **Connectors** page instead.
48 
49When you turn a connector or skill off, Claude can no longer use it for any member. A connector is no longer offered to Claude, and a skill is left out of the skills Claude can load, from the member's next turn. The item stays listed in the member's settings, grayed, with a note that it's disabled by your admin.
50 
51Members can still turn off, in their own app, any item you leave on. The app remembers each member's choice, so it applies again if you turn an item off and later back on. Turning a Featured skill off doesn't stop a member from writing a skill of their own; whether members can add their own skills is governed by [Custom skills](#custom-skills).
52 
53When you turn Claude Science on, the [**Turn on Claude Science** dialog](/docs/claude-science/enable-claude-science#turn-on-claude-science) notes: "By continuing, you authorize your team to let Claude use the optional enabled resources on their behalf. These resources and content they reach may be subject to third-party terms (viewable in Settings), and your users are solely responsible for compliance."
54 
55### Custom connectors
56 
57Custom connectors are Model Context Protocol (MCP) servers a member adds under **Settings** > **Connectors** in the Claude Science app, either a remote server at an HTTPS URL or a local command on their computer (see [Custom connectors](/docs/claude-science/custom-connectors)). The **Allow custom connectors** switch decides whether members can add and use them. It's on by default for Team organizations and off by default for Enterprise organizations. Organizations with HIPAA compliance enabled can't turn it on.
58 
59When the switch is off, members can't add, change, or authorize custom connectors, and Claude no longer sees the custom connectors members may have added earlier. Those connectors stay listed in the member's settings, grayed, with a note that custom connectors are disabled by your admin. Featured connectors and the Directory connectors you publish from **Organization settings** > **Connectors** aren't affected by this switch.
60 
61### Custom skills
62 
63Skills are instructions, sometimes with helper code, that Claude loads when a task calls for them (see [Skills](/docs/claude-science/connectors-and-skills#skills)). Members add their own by writing one, uploading one, importing one from a public GitHub repository (or a private repo if a [GitHub credential](/docs/claude-science/connectors-and-skills#skills) is stored), or asking Claude to create one from a session. The **Allow custom skills** switch decides whether members can add skills of their own, including creating one from the Claude Science app so it's also available to them in claude.ai. It's on by default for Team and Enterprise organizations, including those with HIPAA compliance enabled.
64 
65When the switch is off, members can't add new skills of their own or publish them, and the app notes that custom skills are disabled by your admin. Skills a member added earlier still work and can still be edited, and Featured skills aren't affected. Custom skills are how members teach Claude their own workflows and analysis pipelines, so Anthropic recommends leaving this switch on.
66 
67### Network allowlist
68 
69When Claude runs code for a member, that code can reach only the domains on the analysis sandbox's network allowlist: the package hosts, the scientific databases behind the Featured connectors, and hosts the member approved. See [Sandbox](/docs/claude-science/core-concepts#sandbox) and the domain tables in [Network requirements](/docs/claude-science/network-requirements#analysis-sandbox-domains).
70 
71By default, each member manages that list on their own computer. The **Manage network allowlist** switch transfers control of the list from members to you. While it's on, every member's app uses the organization's list instead of the member's own, and members see the list in their **Network** settings read-only, apart from domains they have blocked themselves, with a note that the domain allowlist is controlled by their admin. It's off by default for Team and Enterprise organizations, and on for organizations with HIPAA compliance enabled, which can't turn it off.
72 
73Turning the switch on sets aside what members allowed themselves, including the domains a deployed configuration file adds with its `[sandbox.network]` keys; those settings are kept and apply again when you turn the switch off. Domains the file denies stay denied.
74 
75Your list is enforced by the app's sandbox (see [Sandbox](/docs/claude-science/core-concepts#sandbox)). On a computer where the sandbox is turned off or can't start, the app pauses new sessions and messages and tells the member the computer doesn't meet the organization's security requirements, until the member restarts the app with the sandbox on or you turn the switch off. Turning the switch off keeps your saved list, which applies again the next time you turn it on.
76 
77With the switch on, **Claude Science domains** shows the Featured domains in the same groups as the app, such as **Package management**, **Literature & citations**, and **NCBI / NIH**, with one switch per domain. A group switch turns all of its domains on or off. Below it, **Custom domains** adds your own. The rules for an entry are:
78 
79* An exact name such as `data.example.org`, or a wildcard such as `*.example.org`
80* A wildcard covers subdomains only, so `*.example.org` doesn't cover `example.org` itself; add both if you need both
81* No IP addresses and no single-label names such as `intranet`
82* The list holds up to 600 domains, counting built-in and custom ones together
83* There's no **Save** button: each change is saved as soon as you make it
84 
85Until you change the list, members use Claude Science's Featured list, including domains added in later versions of Claude Science. Once you change it, the list is saved exactly as you left it, so a domain added in a later version stays off until you turn it on. **Reset** returns to the Featured list and removes your custom domains, for all members.
86 
87You can also turn off the **Package management** domains (PyPI, conda, CRAN and Bioconductor, npm, and GitHub), with limits. The PyPI and conda domains can be turned off only while the [organization package mirror](#organization-package-mirror) covers them. Turning the CRAN and Bioconductor, npm, or GitHub domains off means members can't install packages from them, and the page asks you to confirm. The domains the sandbox always blocks (see [Network requirements](/docs/claude-science/network-requirements#domains-the-sandbox-always-blocks)) stay blocked whichever list is in force.
88 
89The allowlist governs the network connections of code Claude runs in the sandbox on the member's computer, the local-command connectors that run inside it, and, while you manage it, the [model endpoints](#scientific-model-endpoints) members connect by host name. Jobs on SSH hosts use the host's own network, so the allowlist doesn't apply to them, and the [**Allow members to connect SSH hosts**](#ssh-hosts) switch is the control for those.
90 
91Modal jobs run in Modal's cloud. While you manage the list, a member's Modal jobs run only if the member has set **Network restrictions** for Modal in the app to **Allowlist** or **No network**. Unrestricted Modal jobs are refused.
92 
93### Organization package mirror
94 
95Analysis environments install Python and conda packages from the public hosts unless a mirror is set. Members or IT can set a mirror per computer under **Settings** > **Network** > **Package mirror** or in the [configuration file](/docs/claude-science/configuration-file-reference#package-download-keys). See [Point package installs at an internal mirror](/docs/claude-science/corporate-networks#point-package-installs-at-an-internal-mirror) for the mirror layout and credentials.
96 
97The **Organization package mirror** section sets the same two addresses once for every member: a **Conda channel URL** and a **Python package index URL (PyPI)**. The section applies whether or not you manage the [network allowlist](#network-allowlist), and there is no organization mirror by default.
98 
99Addresses must start with `https://`, name a host rather than an IP address (an intranet name such as `https://artifactory:8443` works), use the standard port or 8443, and carry no sign-in details. To test an address before you save it, open Claude Science on a computer inside your network, go to **Settings** > **Network** > **Package mirror** > **Configure**, paste the address, and select **Check**. An address that breaks these rules is ignored for that registry, the member's own mirror setting applies instead, and the member's app notes it in its log. An address that passes them but can't be reached isn't ignored, and package installs fail with an error that names the mirror.
100 
101An organization mirror takes precedence over a mirror a member set in Settings or in their configuration file. The member's values are kept but not used, and their Settings show that the package mirror is controlled by their admin. The mirror host is allowed automatically and the public hosts it replaces are removed from the allowlist, as for a member-set mirror. While you manage the network allowlist, those hosts stay removed even if they are switched on in your list.
102 
103Mirror credentials stay with each member. A member signs in to your mirror once per mirror host under **Settings** > **Network** > **Package mirror** > **Mirror credentials**, and the organization settings never store a credential.
104 
105### SSH hosts
106 
107Members can register a machine they reach over SSH, such as a lab workstation or an HPC login node, so Claude can run jobs on it (see [Remote compute clusters](/docs/claude-science/remote-compute-clusters)). The **Allow members to connect SSH hosts** switch decides whether they can. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
108 
109When the switch is off, members can't add SSH hosts, and hosts they added earlier are kept but refuse new commands and file transfers; the app shows that SSH host setup is disabled by your admin. A job that is already running can still be stopped and its results collected.
110 
111Jobs on an SSH host run outside the sandbox, as the member's own user on that machine, with access to everything that account can read and write there. The app uses the member's existing SSH configuration and keys and installs nothing on the host. Job scripts and inputs travel directly from the member's computer to the host, and outputs come back the same way, without passing through Anthropic. Code on the host uses the host's network, so the [network allowlist](#network-allowlist) doesn't apply to it.
112 
113### Modal
114 
115[Modal](https://modal.com/) is a third-party cloud computing service. Members can connect a Modal account they own so Claude can run jobs that need a GPU or more memory than their computer has. Modal bills that account directly, and Anthropic never sees a payment method (see [Compute providers](/docs/claude-science/compute-providers#connecting-modal)). The **Allow members to connect to Modal** switch decides whether members can connect Modal in the Claude Science app in **Settings** > **Compute**. It's on by default for Team organizations, off by default for Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
116 
117When the switch is off, members can't set up Modal or start new Modal jobs, and the app shows that Modal setup is disabled by your admin. A job that is already running can still be stopped, and the member's Modal settings are kept.
118 
119With the switch on, **Modal workspaces** lets you limit which Modal workspaces members can connect to. By default members can connect to any workspace. Select **Restrict to a workspace** and enter each workspace name as Modal shows it; capitalization doesn't matter.
120 
121The app checks the workspace that Modal reports for the member's token when the member uses it, and a member on another workspace sees that their Modal workspace is not allowed by their admin. Turning the **Allow members to connect to Modal** switch off hides the workspace list, which is kept and applies again when you turn Modal back on.
122 
123Modal jobs run in Modal's cloud, not on the member's computer. There is no spend ceiling in Claude Science; to limit spend, use the controls in your Modal account (see [Modal's documentation](https://modal.com/docs/guide/budgets)). Members approve jobs on a card that shows the machine and the maximum billable time, per job or for a whole conversation or project, and a job keeps running and billing after the app closes.
124 
125### Scientific model endpoints
126 
127Members can connect a scientific model server, such as NVIDIA BioNeMo NIM, that Claude calls directly from analyses (see [Scientific model endpoints](/docs/claude-science/compute-providers#scientific-model-endpoints)). The **Show scientific model endpoint providers on the Compute tab** switch decides whether members can connect the providers listed on the app's **Compute** tab. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
128 
129When the switch is off, members can't connect these providers or use the endpoints they set up earlier, and the app shows that scientific model endpoint setup is disabled by your admin; the settings they entered are kept. The switch governs third-party model endpoints only and has no effect on which Claude models members can use.
130 
131While members manage their own network allowlist, an endpoint a member connected is reachable without being on that list. While you manage the [network allowlist](#network-allowlist), an endpoint at a public or internal host name works only if your network allowlist also includes that host, so add `health.api.nvidia.com` (NVIDIA's hosted endpoint) or your own server's name under **Custom domains** on the **Organization settings** > **Claude Science** page. Endpoints at a private IP address or on localhost aren't affected.
132 
133### Memory
134 
135Memory lets Claude save short facts about a member, their projects, and their files across sessions, stored in the app's local database on the member's computer (see [Memory](/docs/claude-science/core-concepts#memory)). Each member chooses whether their own memory is on, during first-time setup or later in **Settings** > **Memory**. The **Turn on memory for your team** switch decides whether members can use memory at all. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
136 
137When the switch is off, memory is off for every member, whatever they chose in their own settings; Claude neither recalls nor saves facts, first-time setup skips its memory step, and the **Memory** setting shows that memory is disabled by your admin. Facts a member saved earlier stay on their computer, the member can still review and delete them, and Claude uses them again if you turn the switch back on.
138 
139When Claude recalls saved facts for a session, those facts are sent to Anthropic as part of that session's conversation and handled like the rest of the conversation (see [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data)). The **Capabilities** > **Memory** setting in claude.ai **Organization settings** doesn't control memory in Claude Science.
140 
141## How other admin settings apply to Claude Science
142 
143In the tables below, each setting is named by its page in claude.ai **Organization settings** and, where it has one, its label there (for example, **Capabilities** > **Web search**). Apart from the **Enable for your organization** toggle, the controls on the **Claude Science** page itself are described under [Organization settings](#organization-settings).
144 
145The status column in each table shows one of four values:
146 
147* **Supported in Claude Science**: you can govern this for Claude Science, through the claude.ai setting itself or through the named control on the **Claude Science** page.
148* **Partially supported in Claude Science**: you can govern only part of this for Claude Science through either place, and the note says which part.
149* **Not available in Claude Science**: the setting doesn't cover Claude Science, and Claude Science has no equivalent control.
150* **Not applicable in Claude Science**: Claude Science has nothing for the setting to govern.
151 
152### Identity and access
153 
154| Setting in claude.ai | Status for Claude Science | Note |
155| ----------------------------------------------------------------------------- | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
156| Organization and access > Single sign-on (SSO) | Supported in Claude Science | Members sign in to Claude Science through claude.ai, so your SSO configuration and the **Require SSO for Claude** setting apply to the app. |
157| Organization and access > User provisioning (SCIM directory sync, Enterprise) | Supported in Claude Science | Provisioning and deprovisioning act on claude.ai membership, which Anthropic checks on every request the app makes, so a deprovisioned member's app stops working. |
158| Organization and access > Domains | Supported in Claude Science | Domain verification, and the **Migrate accounts using your domains** and **Restrict organization creation** settings that build on it, act on claude.ai accounts before anyone reaches the app, so they apply unchanged. |
159| Members | Supported in Claude Science | Adding or removing members controls who can sign in to Claude Science. |
160| Roles (built-in) | Supported in Claude Science | Every built-in role (User, Admin, Owner, and Primary Owner) can use Claude Science once it's turned on for the organization. |
161| Roles > Claude Science permission in custom roles (Enterprise) | Supported in Claude Science | Add the Claude Science permission to a custom role to give the app to that role's members. Members whose custom roles don't include it can't use the app. Team plans don't have custom roles, so everyone gets access when Claude Science is on. |
162| Groups (Enterprise) | Supported in Claude Science | Members get the Claude Science access of the roles their groups assign. |
163| IP allowlist (Enterprise) | Partially supported in Claude Science | The app's sign-in, its requests to Claude, and its Directory connector calls are checked against your allowlist (see [Restrict access to Claude with IP allowlisting](https://support.claude.com/en/articles/13200993-restrict-access-to-claude-with-ip-allowlisting)). Traffic that doesn't go to Anthropic isn't checked, which covers code on the member's computer, SSH hosts, or Modal account, and custom connectors. You can turn SSH hosts, Modal, and custom connectors off under [Organization settings](#organization-settings). |
164| Organization and access > Shortened session length (Enterprise) | Partially supported in Claude Science | Applies to the browser sign-in a member completes to connect the app. It doesn't shorten the app's own sign-in after that, so members aren't asked to sign in again on your schedule. Turning Claude Science off for the organization or removing a member still stops their app within a few minutes. |
165 
166### Capability toggles
167 
168| Setting in claude.ai | Status for Claude Science | Note |
169| -------------------------------------------------------------------------------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
170| Claude Science > Enable for your organization | Supported in Claude Science | Off by default for Team and Enterprise. An Owner or Primary Owner turns it on under **Organization settings** > **Claude Science** (see [Enable Claude Science](/docs/claude-science/enable-claude-science)). Assigning seats doesn't turn it on. |
171| Data and privacy > Rate chats | Supported in Claude Science | When you turn this off, the app hides its response rating buttons and feedback form, as claude.ai does. |
172| Organization and access > Organization instructions | Supported in Claude Science | Anthropic adds your organization instructions to the app's requests to Claude, as it does for claude.ai chat, so members don't need to update the app for a change to apply. |
173| Skills > Organization skills and Policy | Supported in Claude Science | Skills you add under **Organization skills**, and members' own claude.ai skills, appear in Claude Science while **Skills** is on, and **User-created skills** decides whether a member can save a skill from the app to their own claude.ai account. The skills that come with the app and the skills members add in it are controlled on the **Claude Science** page: one switch per Featured skill, and **Allow custom skills** for skills members add themselves (see [Featured connectors and skills](#featured-connectors-and-skills) and [Custom skills](#custom-skills)). |
174| Capabilities > Web search | Not applicable in Claude Science | This setting governs claude.ai chat. Claude Science can search the web regardless of it, and the **Claude Science** page has no switch for web search. |
175| Capabilities > Code execution and file creation | Not applicable in Claude Science | This setting governs the code sandbox Anthropic hosts for claude.ai chat. Running code on the member's computer, or on compute the member connects, is the core of Claude Science and can't be turned off; you govern what that code can reach with the [network allowlist](#network-allowlist), [SSH hosts](#ssh-hosts), and [Modal](#modal) controls. |
176| Capabilities > Allow network egress and Domain allowlist | Supported in Claude Science | These settings govern the hosted sandbox for claude.ai chat. Claude Science's sandbox has its own allowlist: manage it for the whole organization with the **Manage network allowlist** switch on the **Claude Science** page (see [Network allowlist](#network-allowlist)), or leave it off and let members manage their own. Administrators can also extend a member's list per device with the sandbox network keys in the [configuration file reference](/docs/claude-science/configuration-file-reference). |
177| Data and privacy > Location metadata | Not applicable in Claude Science | Claude Science doesn't send location data with requests to Claude, so there is nothing for this setting to govern. |
178| Capabilities > Memory (Enable memory for your team) | Supported in Claude Science | This setting governs memory in claude.ai chat. Claude Science keeps a separate memory on each member's computer, which you turn on or off for everyone with the **Turn on memory for your team** switch on the **Claude Science** page (see [Memory](#memory)). |
179| Settings for claude.ai projects (Public projects, Retention period for projects) | Not applicable in Claude Science | Claude Science doesn't use claude.ai projects. Its projects are folders on the member's computer. |
180 
181### Connectors
182 
183| Setting in claude.ai | Status for Claude Science | Note |
184| ---------------------------------------------------------- | ------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
185| Connectors > Directory connectors you publish | Supported in Claude Science | Directory connectors you publish on the **Connectors** page are available to members in the app, as in claude.ai. The app reaches them through Anthropic's hosted connector service with the member's own account. |
186| Roles > connector permissions in custom roles (Enterprise) | Partially supported in Claude Science | Apply to the connectors on your **Connectors** page, which the app reaches through Anthropic. They don't apply to Featured connectors or custom connectors added via the Claude Science app; the **Claude Science** page controls those for every member rather than per role (see [Organization settings](#organization-settings)). |
187| Plugins > plugins you add for the organization | Partially supported in Claude Science | Plugins you set to **Installed by default** or **Required** are synced to members' Claude Science app, which loads their skills and connectors. Plugins left as **Available to install** aren't offered in the app, and plugin commands don't apply there. Which Featured connectors and skills members can use, and whether they can add their own, are separate controls on the **Claude Science** page (see [Featured connectors and skills](#featured-connectors-and-skills), [Custom connectors](#custom-connectors), and [Custom skills](#custom-skills)). |
188| Connectors > Tunnels API (Enterprise) | Partially supported in Claude Science | A connector your organization serves through a tunnel works in the app the same way it does in claude.ai, because the app reaches Directory connectors through Anthropic's hosted connector service. Custom connectors a member adds in the Claude Science app connect directly from the member's computer and never use a tunnel (admins can restrict this in [Custom connectors](#custom-connectors)). |
189| Connectors > connectors members add themselves | Supported in Claude Science | In claude.ai, members use only the connectors on your **Connectors** page. In Claude Science, members can also add custom connectors (a server URL or a local command) while the **Allow custom connectors** switch is on, which it is by default for Team and not for Enterprise, and the **Connectors** page and its restrictions don't apply to those. Turn off the **Allow custom connectors** switch under **Organization settings** > **Claude Science** to limit members to Featured connectors and the Directory connectors you publish (see [Custom connectors](#custom-connectors)). |
190| Connectors > Desktop extension allowlist | Not applicable in Claude Science | Claude Science doesn't install desktop extensions, so there is nothing for this setting to govern. |
191 
192### Data and privacy
193 
194| Setting in claude.ai | Status for Claude Science | Note |
195| -------------------------------------------------------------------------------------------------------- | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
196| Data and privacy > Encryption keys (customer-managed keys) | Supported in Claude Science | Anthropic handles Claude Science requests to Claude under your key the same way it handles claude.ai chat requests. Compliance API session transcripts are also encrypted under your key. |
197| Data and privacy > Data residency (US-only inference), or the regional processing terms in your contract | Supported in Claude Science | Governs where Anthropic processes Claude Science requests to Claude, as for your other Claude products. It doesn't cover code that runs on the member's computer, SSH hosts, or Modal account (the same boundary as Claude Code). |
198| Data and privacy > HIPAA Compliance | Not applicable in Claude Science | Organizations with HIPAA compliance enabled can turn Claude Science on, but its use isn't covered under your BAA and members must keep protected health information out of it. These organizations start from stricter defaults, listed under [Defaults by plan](#defaults-by-plan). |
199| Data and privacy > Retention period for chats and projects | Partially supported in Claude Science | The auto-delete window doesn't cover data on members' computers or the model-call logs Anthropic keeps for this product. For Enterprise organizations with the Compliance API enabled, the window does apply to the session transcripts it returns. |
200 
201### Audit and compliance
202 
203| Setting in claude.ai | Status for Claude Science | Note |
204| ------------------------------------ | ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
205| Data and privacy > Export audit logs | Not available in Claude Science | Claude Science doesn't write events to the audit log. For Enterprise organizations with the Compliance API enabled, changes to your Claude Science organization settings are recorded in its Activity Feed instead. |
206| Data and privacy > Compliance API | Supported in Claude Science | Enterprise plans only. The [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) returns read-only transcripts of members' Claude Science sessions (this coverage is in beta) and records changes to your Claude Science organization settings in its Activity Feed. Sessions in organizations with HIPAA compliance enabled aren't captured. See [Compliance API coverage](/docs/claude-science/how-claude-science-works-with-your-data#compliance-api-coverage). |
207| Data and privacy > Export data | Not available in Claude Science | The organization export doesn't include Claude Science conversations and files, which are stored on members' computers (the same as Claude Code). |
208 
209### Usage, models, and billing
210 
211| Setting in claude.ai | Status for Claude Science | Note |
212| ---------------------------------------------------- | --------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
213| Usage > Extra usage and Spend limits | Supported in Claude Science | Claude Science usage counts toward each member's 5-hour and weekly usage limits, in the same pool as Claude Code and Cowork. |
214| Billing | Supported in Claude Science | Claude Science uses the same seat as the rest of claude.ai, so there is nothing separate to purchase. |
215| Models > Model access and Default model (Enterprise) | Supported in Claude Science | Turning a model off on the **Models** page, for the whole organization or for a custom role, stops those members from using it in Claude Science because requests for that model are refused. A model you turned off can still appear in the app's model picker, where choosing it returns an error, and the **Default model** setting doesn't set the app's default. Team plans don't have the **Models** page. |
216| Analytics (from the user menu) | Supported in Claude Science | Analytics has a **Claude Science** tab with adoption and session metrics, and the spend charts on the **Overview** tab can be filtered to Claude Science (see [Monitor usage](/docs/claude-science/monitor-usage)). |
217 
218### Offboarding and local data
219 
220| Setting in claude.ai | Status for Claude Science | Note |
221| ------------------------------ | ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
222| Removing a member (local data) | Not available in Claude Science | Removing a member ends their access to Claude Science but doesn't delete data already on their computer. Use your device management software for that (see [Manage on devices](/docs/claude-science/manage-on-devices)). |
223| Deleting local data | Not available in Claude Science | When a member deletes Claude Science data on their computer, Anthropic isn't notified, so the matching server-side model-call logs keep their standard retention period. Compliance API session transcripts, where captured, remain until their retention period ends. |
81224 

claude-science/compute-providers Changed · +9 / -1 lines

### Workspace restrictions set by your organization ## Scientific model endpoints ## Model endpoints

from line 8
88 
99In Settings > Compute > **Cloud providers**, click Connect on the Modal card. If you've signed in with the Modal CLI (`modal token new`), the app reads `~/.modal.toml` automatically; click Check again after the file exists. Alternatively, paste a **Token ID** and **Token secret** in Settings > Credentials, under Modal. Tokens are stored encrypted on your computer and never shown to Claude.
1010 
11### Workspace restrictions set by your organization
12 
13On Team and Enterprise plans, your organization's admin can limit Modal to specific workspaces. When Claude uses your Modal token, the app checks the workspace that Modal reports for that token, not the label in your `~/.modal.toml`. If that workspace isn't on your organization's list, the app tells you that this Modal workspace is not allowed by your admin, and Claude can't run jobs there until you connect a token from an allowed workspace. Your admin can also turn Modal off for the organization (see [Modal](/docs/claude-science/admin-controls#modal)).
14 
15If your organization manages the network allowlist, set **Network restrictions** on the Modal page under **Settings** > **Compute** to **Allowlist** or **No network** before you run jobs. Jobs from a Modal setup with unrestricted network access are refused while your organization manages the list (see [Network allowlist](/docs/claude-science/admin-controls#network-allowlist)).
16 
1117## Running cloud jobs
1218 
1319When work needs a GPU or more memory than your machine has, Claude proposes a job and a **Start a Modal job?** card appears. The card shows the Modal profile, exact machine spec (for example, H100, 8 CPUs, 32 GiB), a note that billing is per-second, and the maximum billable time. It links to Modal's pricing page. Approve per job, or for the conversation or project.
from line 34
2834 
2935Claude derives a container image from the environment a job needs and builds it once on Modal's build servers, then reuses that image for later jobs until the environment changes. Claude tracks built images in the Details document on the Modal page under Settings > Compute.
3036 
31## Model endpoints
37## Scientific model endpoints
3238 
3339Claude Science can connect to a model server (hosted, or a container you run) that serves a scientific model over HTTP, and call it directly from analyses.
40 
41On Team and Enterprise plans, your organization's admin can turn off scientific model endpoints for the organization. When your admin turns them off, you can't connect these providers or use endpoints you set up earlier, and the settings you entered are kept. Turning them off doesn't change which Claude models you can use (see [Scientific model endpoints](/docs/claude-science/admin-controls#scientific-model-endpoints)). If your organization manages the network allowlist, an endpoint at a public or internal host name works only while that list includes the host.
3442 
3543### NVIDIA BioNeMo NIM
3644 

claude-science/configuration-file-reference Changed · +12 / -12 lines

from line 6
66 
77## Network configuration
88 
9The network-related keys, grouped by the TOML table each belongs to. For the package-mirror keys (`[conda] channel_mirror`, `pip_index_url`, and `ca_bundle`) and the proxy key (`[network] proxy`), a value set in the file takes precedence over the matching Settings control, which then shows as managed by your organization so a member cannot override it. The `[sandbox.network]` lists are additive instead: they add to the member-managed lists under **Settings** > **Network** and lock nothing. The `[network] ca_bundle`, `no_proxy`, and `mcp_x509_strict` keys and `[conda] allow_insecure_mirror` have no in-app control.
9The network-related keys, grouped by the TOML table each belongs to. For the package-mirror keys (`[conda] channel_mirror`, `pip_index_url`, and `ca_bundle`) and the proxy key (`[network] proxy`), a value set in the file takes precedence over the matching Settings control, which then shows as managed by your organization so a member cannot override it. The `[sandbox.network]` lists are additive instead: they add to the member-managed lists under **Settings** > **Network** and lock nothing. On Team and Enterprise plans, two settings made for the whole organization under **Organization settings** > **Claude Science** sit above both the file and the Settings page. An [organization package mirror](/docs/claude-science/admin-controls#organization-package-mirror) takes precedence over the mirror keys, and while the organization manages the [network allowlist](/docs/claude-science/admin-controls#network-allowlist), the file's `allowed_domains` are set aside and its `denied_domains` still apply. The `[network] ca_bundle`, `no_proxy`, and `mcp_x509_strict` keys and `[conda] allow_insecure_mirror` have no in-app control.
1010 
1111### App connection keys
1212 
from line 23
2323 
2424The `[conda]` table configures where analysis environments fetch packages from and how those downloads verify certificates.
2525 
26| Key | Type | Default | Effect |
27| ----------------------- | ---------------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
28| `channel_mirror` | string (URL) | unset | Base URL of an internal conda mirror. Channel names resolve beneath it, so `<channel_mirror>/conda-forge/noarch/repodata.json` must return the conda-forge index. Setting it removes the public conda hosts from the sandbox allowlist and admits the mirror host, which environment builds contact directly from the workstation, not through an outbound proxy. Must be `https://` on port 443 or 8443 (an `http://` URL is accepted only when `allow_insecure_mirror` is set), by DNS name, with no embedded credentials. A deployed value these rules reject prevents the app from starting. |
29| `pip_index_url` | string (URL) | unset | A PEP 503 simple index for Python packages, for example an Artifactory or Nexus PyPI remote ending in `/simple`. Setting it removes the public Python hosts from the sandbox allowlist. Same URL rules as `channel_mirror`, including the startup failure on an invalid value. |
30| `ca_bundle` | string (absolute path) | unset | A complete PEM bundle (public roots plus your corporate roots) that package downloads verify against, replacing the default trust list; in this release the bundle alone may not be sufficient for pip, which verifies against the operating system's trust store. This key affects package downloads only and never fixes sign-in; behind TLS inspection, set `[network] ca_bundle` as well. When unset, Linux uses your distribution's system certificate bundle. Same path rules as `[network] ca_bundle`. |
31| `allow_insecure_mirror` | boolean | `false` | Allows `http://` mirror URLs in this file (the Settings page accepts `https://` only). Off by default because a plaintext mirror lets an on-path attacker substitute packages. |
26| Key | Type | Default | Effect |
27| ----------------------- | ---------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
28| `channel_mirror` | string (URL) | unset | Base URL of an internal conda mirror. Channel names resolve beneath it, so `<channel_mirror>/conda-forge/noarch/repodata.json` must return the conda-forge index. Setting it removes the public conda hosts from the sandbox allowlist and admits the mirror host, which environment builds contact directly from the workstation, not through an outbound proxy. Must be `https://` on port 443 or 8443 (an `http://` URL is accepted only when `allow_insecure_mirror` is set), by DNS name, with no embedded credentials. A deployed value these rules reject prevents the app from starting. An [organization package mirror](/docs/claude-science/admin-controls#organization-package-mirror) set under **Organization settings** > **Claude Science** takes precedence over this key. |
29| `pip_index_url` | string (URL) | unset | A PEP 503 simple index for Python packages, for example an Artifactory or Nexus PyPI remote ending in `/simple`. Setting it removes the public Python hosts from the sandbox allowlist. Same URL rules as `channel_mirror`, including the startup failure on an invalid value, and the same precedence of an organization package mirror. |
30| `ca_bundle` | string (absolute path) | unset | A complete PEM bundle (public roots plus your corporate roots) that package downloads verify against, replacing the default trust list; in this release the bundle alone may not be sufficient for pip, which verifies against the operating system's trust store. This key affects package downloads only and never fixes sign-in; behind TLS inspection, set `[network] ca_bundle` as well. When unset, Linux uses your distribution's system certificate bundle. Same path rules as `[network] ca_bundle`. |
31| `allow_insecure_mirror` | boolean | `false` | Allows `http://` mirror URLs in this file (the Settings page accepts `https://` only). Off by default because a plaintext mirror lets an on-path attacker substitute packages. |
3232 
3333### Sandbox network keys
3434 
3535The `[sandbox.network]` table adjusts the network allowlist the analysis sandbox enforces. Members see the same allowlist under **Settings** > **Network**.
3636 
37| Key | Type | Default | Effect |
38| ----------------- | ---------------- | ------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
39| `enabled` | boolean | `true` | When `false`, code Claude runs has no network access: package installs and data fetches inside the analysis fail, while the app's own connections are unaffected. This is a no-network mode, not a way to skip the allowlist. |
40| `allowed_domains` | array of strings | `[]` | Domains added to the built-in allowlist, as exact hostnames or wildcards such as `*.example.org`. |
41| `denied_domains` | array of strings | `[]` | Domains added to the built-in denylist. A denied domain is blocked even if it also appears on the allowlist, and the built-in denylist entries cannot be removed. |
37| Key | Type | Default | Effect |
38| ----------------- | ---------------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
39| `enabled` | boolean | `true` | When `false`, code Claude runs has no network access: package installs and data fetches inside the analysis fail, while the app's own connections are unaffected. This is a no-network mode, not a way to skip the allowlist. |
40| `allowed_domains` | array of strings | `[]` | Domains added to the built-in allowlist, as exact hostnames or wildcards such as `*.example.org`. While the organization manages the [network allowlist](/docs/claude-science/admin-controls#network-allowlist) under **Organization settings** > **Claude Science**, these domains are set aside and the organization's list applies. |
41| `denied_domains` | array of strings | `[]` | Domains added to the built-in denylist. A denied domain is blocked even if it also appears on the allowlist, and the built-in denylist entries cannot be removed. |
4242 
4343## Related resources
4444 

claude-science/connectors-and-skills Changed · +4 / -4 lines

from line 6
66 
77## Featured connectors
88 
9Claude Science includes Featured connectors to public life-sciences databases. All are on by default and can be turned off individually in **Settings > Connectors**. Featured connectors are read-only and don't require an account or key. Some underlying databases have non-commercial or attribution terms; review each source's license for your use case.
9Claude Science includes Featured connectors to public life-sciences databases. They're on by default and can be turned off individually in **Settings > Connectors**. On Team and Enterprise plans, your organization can also turn individual Featured connectors off for everyone, and in organizations with HIPAA compliance enabled they start off until an admin turns them on. A connector your organization has off stays listed, grayed, and Claude can't use it (see [Featured connectors and skills](/docs/claude-science/admin-controls#featured-connectors-and-skills)). Featured connectors are read-only and don't require an account or key. Some underlying databases have non-commercial or attribution terms; review each source's license for your use case.
1010 
1111| Connector | Sources |
1212| ------------------------- | ---------------------------------------------------- |
from line 31
3131 
3232Four Directory connectors are available from the [connector directory](https://claude.com/connectors) and are accessible in Claude Science and other Claude products: **PubMed**, **Clinical Trials**, **ChEMBL**, and **bioRxiv**. On Team and Enterprise plans, directory connectors appear only after an admin adds them.
3333 
34By choosing to enable connectors, you authorize Claude to use the optional enabled resources on your behalf and confirm you have the necessary rights and licenses. These resources and content they reach may be subject to third-party terms (viewable in Settings), and you are solely responsible for compliance.
34By choosing to enable connectors, you authorize Claude to use the optional enabled resources on your behalf and confirm you have the necessary rights and licenses. These resources and content they reach may be subject to third-party terms (viewable in Settings), and you are solely responsible for compliance. On Team and Enterprise plans, an admin in your organization gives this authorization for the team when turning Claude Science on and choosing which connectors members can use, and you remain responsible for complying with those terms.
3535 
3636## Using connectors
3737 
from line 43
4343 
4444**Settings > Skills** lists the skills Claude can load. Featured science skills include literature review, indication dossier, and model-specific skills for AlphaFold2, Boltz-2, Chai-1, ESMFold2, OpenFold3, ProteinMPNN (with LigandMPNN and SolubleMPNN), DiffDock, ESM-2, Evo 2, Borzoi, scGPT, and scvi-tools.
4545 
46Claude loads a skill automatically when the work calls for it. Type **/** in the composer to open the skill picker and insert one explicitly.
46Claude loads a skill automatically when the work calls for it. Type **/** in the composer to open the skill picker and insert one explicitly. On Team and Enterprise plans, your organization can turn individual Featured skills off; a skill it has off stays listed, grayed, and Claude doesn't load it.
4747 
48**Add skill** lets you create your own via **Chat with Claude**, **Write from scratch**, **Upload a skill**, or **Import from GitHub**. **Import from GitHub** works with private repositories too, once you add a GitHub token under **Settings > Credentials**. You can also ask Claude to distill a workflow from an existing session into a skill.
48**Add skill** lets you create your own via **Chat with Claude**, **Write from scratch**, **Upload a skill**, or **Import from GitHub**. **Import from GitHub** works with private repositories too, once you add a GitHub token under **Settings > Credentials**. You can also ask Claude to distill a workflow from an existing session into a skill. On Team and Enterprise plans, adding skills of your own is available only if your organization allows custom skills; skills you added earlier keep working either way (see [Custom skills](/docs/claude-science/admin-controls#custom-skills)).
4949 

claude-science/corporate-networks Changed · +4 / -2 lines

from line 39
3939 
4040## Point package installs at an internal mirror
4141 
42When your network blocks the public package hosts (`conda.anaconda.org`, `repo.anaconda.com`, `pypi.org`), point Claude Science at your internal artifact repository instead, and every environment build fetches packages through it. Set the mirror for a fleet with the `[conda] channel_mirror` and `pip_index_url` keys in a [deployed `config.toml`](/docs/claude-science/manage-on-devices#deploy-configuration-with-device-management), or for a single machine under **Settings** > **Network** > **Package mirror**, where the same two settings are called the conda channel mirror and the pip index URL. The steps below use the Settings page, the quickest way to test a mirror URL before you deploy it.
42When your network blocks the public package hosts (`conda.anaconda.org`, `repo.anaconda.com`, `pypi.org`), point Claude Science at your internal artifact repository instead, and every environment build fetches packages through it. You can set the mirror in three places: once for the whole organization under **Organization settings** > **Claude Science** > **Organization package mirror**, for a fleet with the `[conda] channel_mirror` and `pip_index_url` keys in a [deployed `config.toml`](/docs/claude-science/manage-on-devices#deploy-configuration-with-device-management), or for a single machine under **Settings** > **Network** > **Package mirror**, where the same two settings are called the conda channel mirror and the pip index URL. The steps below use the Settings page, the quickest way to test a mirror URL before you deploy it.
4343 
44The organization setting takes a conda channel URL and a Python package index (PyPI) URL, which apply to every member whether or not the organization manages the network allowlist. They take precedence over a mirror set in a member's configuration file or Settings; the member's values are kept but not used, and their Settings show the package mirror as controlled by their admin. The same URL rules apply as below, and an address that breaks those rules is ignored for that registry rather than stopping the app. Members still sign in to the mirror themselves, once for each mirror host (see [Mirror credentials](#mirror-credentials)), and the mirror removes the public hosts it replaces for every member. See [Organization package mirror](/docs/claude-science/admin-controls#organization-package-mirror).
45 
4446Set both a conda channel mirror and a pip index: analysis environments are built from conda packages, so a pip index alone leaves the first build stuck trying to reach the public conda host.
4547 
4648<Steps>
from line 90
8890 
8991### Mirror traffic and your other network controls
9092 
91Configuring a mirror removes the public package hosts from the sandbox's network allowlist and admits the mirror host in their place, so a misconfigured mirror fails with an error that names the mirror rather than falling back to the public hosts. To keep the public hosts reachable alongside the mirror, re-add them under **Settings** > **Network** (`pypi.org`, `*.pypi.org`, `files.pythonhosted.org` for pip, and `conda.anaconda.org`, `repo.anaconda.com`, `anaconda.org`, `*.anaconda.org` for conda).
93Configuring a mirror removes the public package hosts from the sandbox's network allowlist and admits the mirror host in their place, so a misconfigured mirror fails with an error that names the mirror rather than falling back to the public hosts. To keep the public hosts reachable alongside the mirror, re-add them under **Settings** > **Network** (`pypi.org`, `*.pypi.org`, `files.pythonhosted.org` for pip, and `conda.anaconda.org`, `repo.anaconda.com`, `anaconda.org`, `*.anaconda.org` for conda). When the organization manages the network allowlist, **Network** settings are read-only, so a member can't re-add them, and the hosts a mirror replaces stay removed even if they are switched on in the organization's list.
9294 
9395Environment builds connect to the mirror host directly, never through your outbound proxy: the workstation needs a direct route (typically your VPN or internal network), any workstation firewall must allow the mirror host as a direct destination, and a proxy allowlist entry alone does not reach it. A package failure that names the mirror on a proxy-only network therefore means the mirror is unreachable directly, and a SaaS repository such as `yourorg.jfrog.io` works only if the workstation can reach it directly, so on a proxy-only network host the mirror inside your network. On a proxy-configured machine the **Check** button and a real build can take different paths, so treat a test environment build as the authoritative signal (a known limitation).
9496 

claude-science/enable-claude-science Changed · +29 / -26 lines

### Review role access ### Set up connectors ### Reviewing role access ### Setting up connectors for the organization

from line 2
22 
33> Claude Science is a desktop app for scientific research.
44 
5Claude Science is a desktop app for scientific research. It's off by default for Team and Enterprise organizations. Turning it on in Organization settings > Claude Science walks you through a short setup wizard that covers what's not supported yet, which roles get access, and which connectors to publish.
5Claude Science is a desktop app for scientific research. It's off by default for Team and Enterprise organizations. Turning it on in **Organization settings** > **Claude Science** opens a short dialog that covers who gets access and which connectors to turn on. You can change any of it later on the same page, which also holds the other [organization settings](/docs/claude-science/admin-controls#organization-settings) for Claude Science: which connectors, skills, compute, network access, and memory members can use.
66 
77## Availability
88 
99Claude Science is in beta.
1010 
11| Plan | Claude Science app access |
12| ----------- | ------------------------------------- |
13| Team | Off; turn on in Organization settings |
14| Enterprise | Off; turn on in Organization settings |
15| Pro and Max | On; no admin action needed |
16| Free | Not available |
11| Plan | Claude Science app access |
12| ----------- | ----------------------------------------- |
13| Team | Off; turn on in **Organization settings** |
14| Enterprise | Off; turn on in **Organization settings** |
15| Pro and Max | On; no admin action needed |
16| Free | Not available |
1717 
18If your organization has HIPAA compliance enabled, Claude Science app access is also off by default. You can turn it on, but usage isn't covered under your Business Associate Agreement (BAA) and the app shouldn't be used with protected health information (PHI).
18If your organization has HIPAA compliance enabled, Claude Science app access is also off by default. You can turn it on, but usage isn't covered under your Business Associate Agreement (BAA) and the app shouldn't be used with protected health information (PHI). These organizations also start with stricter organization settings (see [HIPAA organizations](#hipaa-organizations)).
1919 
2020## Turn on Claude Science
2121 
22Go to Organization settings > Claude Science.\
23Turn on the Enable for your organization toggle. The setup wizard opens.\
24Complete each step of the wizard, then select Enable Claude Science.\
22Go to **Organization settings** > **Claude Science**.\
23Turn on the **Enable for your organization** toggle. The **Turn on Claude Science** dialog opens.\
24Complete each step of the dialog, described below, then select **Turn on Claude Science**. Nothing is saved until you do.\
25Review the [organization settings](/docs/claude-science/admin-controls#organization-settings) below the toggle, which unlock once Claude Science is on.\
2526Members with access can [download Claude Science](https://claude.com/product/claude-science) and sign in with their claude.ai account.
2627 
2728You need an Owner or Primary Owner role to turn Claude Science on or off. If you have the Admin role, you can add members and assign seats, but you can't turn on Claude Science. Ask an Owner or Primary Owner to turn it on.
2829 
29### Reviewing role access
30### Review role access
3031 
31This step appears only on Enterprise plans. It lists any custom roles that already include the Claude Science capability. Built-in roles get access automatically. To change which custom roles have access, select Configure in role settings, or continue and adjust roles later.
32This step shows who gets access once Claude Science is on. On Team plans, everyone in your organization gets access automatically. On Enterprise plans, members in the built-in roles (User, Admin, Owner, and Primary Owner) get access automatically, and the step lists any custom roles that already include the **Claude Science** capability. To change which custom roles have access, select **Configure in role settings**, or continue and adjust roles later.
3233 
33### Setting up connectors for the organization
34### Set up connectors
3435 
35Enable the data sources your team will use in Claude Science.
36Turn on the tools and data sources your team will use in Claude Science. You can change all of it later.
3637 
37Featured connectors are built by Anthropic and curated for scientific research.\
38Local connectors ship with the app and run on each member's computer. Members can turn individual local connectors off in the app.\
39Directory connectors are additional life sciences connectors from the Claude connector directory. On Team and Enterprise plans, these appear only after an Owner adds them to the organization's connector allowlist.
38Under **Featured connectors**, the **Claude Science local connectors** row covers the connectors that are built by Anthropic, ship with the app, and run on each member's computer. Expand it to turn individual connectors on or off for the whole organization; you can change this later under [Featured connectors and skills](/docs/claude-science/admin-controls#featured-connectors-and-skills), and members can also turn individual local connectors off for themselves in the app. The **PubMed**, **Clinical Trials**, **ChEMBL**, and **bioRxiv** rows are connectors Anthropic hosts. They start selected, and turning Claude Science on adds the selected ones to **Organization settings** > **Connectors** for your organization, which makes them available to members in Claude Science and in claude.ai.
4039 
41This step is shown read-only if your organization has HIPAA compliance enabled. Add connectors from Organization settings > Connectors after enabling.
40Under **From the Claude connector directory**, you can select additional life-sciences connectors, which are added to your organization the same way.
4241 
42The **PubMed**, **Clinical Trials**, **ChEMBL**, and **bioRxiv** rows and the directory list are read-only if your organization has HIPAA compliance enabled or your role can't add connectors for the organization; add those connectors from **Organization settings** > **Connectors** after enabling. The switches for the local connectors still work, and in an organization with HIPAA compliance enabled they start off so you can turn on the ones you have reviewed.
43 
4344By continuing, you authorize your team to let Claude use the optional enabled resources on their behalf. These resources and content they reach may be subject to third-party terms (viewable in Settings), and your users are solely responsible for compliance.
4445 
4546## Who gets access after you enable
4647 
47Turning on the organization toggle controls whether Claude Science is accessible to your organization at all. Adding members or assigning seats doesn't turn it on. Once it's on, roles control which members can use it:
48Turning on the **Enable for your organization** toggle controls whether Claude Science is accessible to your organization at all. Adding members or assigning seats doesn't turn it on. Once it's on, roles control which members can use it:
4849 
4950Built-in roles include the Claude Science entitlement, so those members can download and sign in immediately.\
50Custom roles (Enterprise plans only) need the Claude Science capability added. Members on a custom role without the capability see the app as unavailable even after you enable it for the organization.\
51A custom role whose Capability access setting is All capabilities already includes Claude Science. The All generally available setting excludes beta capabilities such as Claude Science, so for those roles also select the Claude Science capability.
51Custom roles (Enterprise plans only) need the **Claude Science** capability added. Members on a custom role without the capability see the app as unavailable even after you enable it for the organization.\
52A custom role whose **Capability access** setting is **All capabilities** already includes Claude Science. The **All generally available** setting excludes beta capabilities such as Claude Science, so for those roles also select the **Claude Science** capability.
5253 
5354This is the same pattern as other Claude apps you enable per organization.
5455 
from line 57
5657 
5758Once Claude Science is enabled and a member's role includes the entitlement, they can download the app from claude.com/product/claude-science and sign in with their claude.ai account.
5859 
59If the organization toggle is off, claude.ai stops members at sign-in with a message such as "Claude Science has not been enabled for your account. Contact your organization administrator." On Enterprise plans, members whose custom role doesn't include the capability are stopped the same way.
60If the **Enable for your organization** toggle is off, members are stopped at sign-in with a message such as "Your organization hasn't turned on Claude Science yet. Ask your admins for access." They can select **Request access** to send that request to the organization's admins, then sign in again once Claude Science is on. On Enterprise plans, members whose custom role doesn't include the capability are stopped the same way, with a message that Claude Science isn't available for their account yet, and can also request access. These requests appear under **Requests** in **Organization settings** > **Notifications**. Turning Claude Science on resolves them, and for a member whose custom role lacks the capability, you give the role access on the **Roles** page.
6061 
61Members who belong to more than one organization on claude.ai, such as a personal account alongside yours, need to choose your organization when claude.ai asks which one to connect. Before they select Authorize, they can also select Switch organization on the authorization screen to change that choice. A member who connects a Free personal account instead sees "Claude Science requires a Pro or Max subscription." and can select Switch account to sign in again and choose your organization.
62Members who belong to more than one organization on claude.ai, such as a personal account alongside yours, need to choose your organization when claude.ai asks which one to connect. Before they select **Authorize**, they can also select **Switch organization** on the authorization screen to change that choice. A member who connects a Free personal account instead sees "Claude Science requires a Pro or Max subscription." and can select **Switch account** to sign in again and choose your organization.
6263 
6364## HIPAA organizations
6465 
65Organizations with HIPAA compliance enabled can turn on Claude Science during the beta, but usage isn't covered under your BAA. The setup wizard shows this notice on step 1, and the connectors step is read-only because the wizard's quick-enable path doesn't include the per-connector HIPAA attestation. Add connectors from Organization settings > Connectors instead, where the attestation is required.
66Organizations with HIPAA compliance enabled can turn on Claude Science during the beta, but usage isn't covered under your BAA, so keep protected health information out of it. The **Turn on Claude Science** dialog opens with a step that says so. In its connectors step the local connectors start off, and you can turn on the ones you have reviewed. The Anthropic-hosted and directory connectors in that step are read-only because the dialog's quick-enable path doesn't include the per-connector HIPAA attestation, so add those from **Organization settings** > **Connectors** instead, where the attestation is required.
6667 
68These organizations also start with stricter organization settings. Featured connectors and skills, SSH hosts, Modal, model endpoints, and memory are off until you turn them on (including for members who were already using them), custom connectors can't be turned on, and the organization always manages the network allowlist. See [Defaults by plan](/docs/claude-science/admin-controls#defaults-by-plan).
69 
6770## Turn off Claude Science
6871 
69Go to Organization settings > Claude Science and turn off the Enable for your organization toggle. Members can no longer sign in to the app. Data already on members' computers stays there; see [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data) for details.
72Go to **Organization settings** > **Claude Science** and turn off the **Enable for your organization** toggle. Members can no longer sign in to the app, and members who are already signed in lose access within a few minutes. The app stops accepting new messages and shows a notice that Claude Science isn't available for their account. The other settings on the page keep their values and apply again when you turn Claude Science back on. Data already on members' computers stays there; see [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data) for details.
7073 

claude-science/how-claude-science-works-with-your-data Changed · +3 / -3 lines

from line 22
2222 
2323## Remote compute
2424 
25When a member chooses to connect the app to remote compute (an owned server or cloud account they control), the app sends code and data directly to that destination. That traffic doesn't pass through Anthropic. Admins can't yet restrict whether members can connect to remote compute. For setup details, see [Remote compute clusters](/docs/claude-science/remote-compute-clusters) and [Compute providers](/docs/claude-science/compute-providers) in the user documentation.
25When a member chooses to connect the app to remote compute (an owned server or cloud account they control), the app sends code and data directly to that destination. That traffic doesn't pass through Anthropic. You can turn SSH hosts, Modal, and scientific model endpoints off for the organization under **Organization settings** > **Claude Science** (see [SSH hosts](/docs/claude-science/admin-controls#ssh-hosts), [Modal](/docs/claude-science/admin-controls#modal), and [Scientific model endpoints](/docs/claude-science/admin-controls#scientific-model-endpoints)). For setup details, see [Remote compute clusters](/docs/claude-science/remote-compute-clusters) and [Compute providers](/docs/claude-science/compute-providers) in the user documentation.
2626 
2727## Connectors
2828 
29Directory connectors you publish as an admin are reached through Anthropic's hosted connector service, so your directory connector permissions and tunnels apply. Connectors a member adds locally (either running on their own computer or pointing at a custom URL) talk to their app directly, without routing through Anthropic.
29Directory connectors you publish as an admin are reached through Anthropic's hosted connector service, so your directory connector permissions and tunnels apply. Connectors a member adds locally (either running on their own computer or pointing at a custom URL) talk to their app directly, without routing through Anthropic. You can turn custom connectors off for the organization (see [Custom connectors](/docs/claude-science/admin-controls#custom-connectors)).
3030 
3131## What this means for you as an admin
3232 
33Because conversations and artifacts live on members' computers, Custom Data Retention and Org Data Export don't reach that local data. For Enterprise organizations with the Compliance API enabled, Anthropic also keeps session transcripts captured from the app's model calls, which include file text the app sent to Claude, and a record of settings changes (see [Compliance API coverage](#compliance-api-coverage)). Device management is the control you have for local data: your device management software (such as your MDM or EDR) governs the app's local folder the same way it governs any other local application data. Identity controls (SSO, SCIM, roles) apply because sign-in goes through claude.ai. See [Admin controls](/docs/claude-science/admin-controls) for what IP allowlisting and session duration cover.
33Because conversations and artifacts live on members' computers, Custom Data Retention and Org Data Export don't reach that local data. For Enterprise organizations with the Compliance API enabled, Anthropic also keeps session transcripts captured from the app's model calls, which include file text the app sent to Claude, and a record of settings changes (see [Compliance API coverage](#compliance-api-coverage)). Device management is the control you have for local data: your device management software (such as your MDM or EDR) governs the app's local folder the same way it governs any other local application data. Identity controls (SSO, SCIM, roles) apply because sign-in goes through claude.ai. See [Admin controls](/docs/claude-science/admin-controls) for the organization settings that govern what members can connect the app to, and for what IP allowlisting and session duration cover.
3434 

claude-science/network-requirements Changed · +9 / -5 lines

from line 2
22 
33> The domains Claude Science connects to, grouped for a proxy or firewall allowlist: the app's connections to Anthropic, the analysis sandbox's package and research domains, the domains a package mirror adds and removes, and the built-in list of domains it always blocks.
44 
5Claude Science connects to a small, fixed set of domains for sign-in, the Claude API, and the app's own literature search, and to a larger, member-adjustable set of package and research domains when Claude runs analysis code. This page lists them for the team that manages your proxy or firewall allowlist.
5Claude Science connects to a small, fixed set of domains for sign-in, the Claude API, and the app's own literature search, and to a larger set of package and research domains when Claude runs analysis code, which members adjust on their own computers or your organization manages for every member. This page lists them for the team that manages your proxy or firewall allowlist.
66 
7Connections are outbound-only and almost entirely HTTPS on TCP 443 (an internal package mirror may use 8443). The app's own domains are fixed, apart from open-access full-text downloads (covered below); the analysis-sandbox domains are a built-in allowlist whose groups members can adjust during onboarding or under **Settings** > **Network**.
7Connections are outbound-only and almost entirely HTTPS on TCP 443 (an internal package mirror may use 8443). The app's own domains are fixed, apart from open-access full-text downloads (covered below); the analysis-sandbox domains are a built-in allowlist that members adjust during onboarding or under **Settings** > **Network**, or that the organization manages for every member (see [Analysis sandbox domains](#analysis-sandbox-domains)).
88 
99The domains fall into three groups: the app's own connections every member needs, the analysis sandbox's package and research domains, and the domains the member's browser loads. For the proxy and TLS-inspection settings, see [Use Claude Science on a corporate network](/docs/claude-science/corporate-networks).
1010 
from line 38
3838 
3939## Analysis sandbox domains
4040 
41When Claude runs code, its network access passes through a local filtering proxy that allows only the domains on the sandbox's built-in allowlist, grouped by purpose below. These are member-level controls with no organization-level setting: members can turn off any group except package management, during onboarding or under **Settings** > **Network**, and add allowed domains of their own in Settings. An administrator can instead use the per-device configuration file, whose `[sandbox.network]` keys add allowed or denied domains, or disable sandbox networking entirely.
41When Claude runs code, its network access passes through a local filtering proxy that allows only the domains on the sandbox's built-in allowlist, grouped by purpose below. By default, each member manages the list on their own computer. Members can turn off any group except package management, during onboarding or under **Settings** > **Network**, and add allowed domains of their own in Settings. An administrator can also use the per-device configuration file, whose `[sandbox.network]` keys add allowed or denied domains, or disable sandbox networking entirely.
4242 
43An organization can instead manage the list for every member from **Organization settings** > **Claude Science**, with one switch per domain and custom domains of its own. Members then see their **Network** settings read-only, and the domains a member or a configuration file added are set aside while the organization manages the list. See [Network allowlist](/docs/claude-science/admin-controls#network-allowlist) for what the organization's list covers and how changes reach members.
44 
4345### Package management domains
4446 
45These domains are always on the sandbox allowlist and supply Python, R, and system packages when Claude builds an analysis environment.
47These domains supply Python, R, and system packages when Claude builds an analysis environment. Members can't turn them off. An organization that manages the allowlist can turn the CRAN and Bioconductor, npm, and GitHub domains off, and the PyPI and conda domains off once an organization package mirror replaces them.
4648 
4749| Domain | Purpose |
4850| ----------------------------------------------------------------------------------------- | ----------------------------------------------- |
from line 58
5658 
5759When you configure a conda channel mirror, Claude Science removes only the conda hosts (`conda.anaconda.org`, `repo.anaconda.com`, `anaconda.org`, `*.anaconda.org`) from the allowlist, and a Python index mirror removes only `pypi.org`, `*.pypi.org`, and `files.pythonhosted.org`. The `*.conda.io`, CRAN and Bioconductor, npm, and GitHub rows stay. A removed host is reachable again if a member re-adds it under **Settings** > **Network** or an administrator lists it in `[sandbox.network] allowed_domains`, which takes precedence over the removal. Environment builds contact the mirror host directly from the workstation, not through the outbound proxy, so it must be reachable directly (over your VPN or internal network if the mirror is internal, HTTPS on TCP 443 or 8443). A proxy allowlist entry alone does not make the mirror reachable for builds, and build-time mirror traffic will not appear in your proxy logs. See [Point package installs at an internal mirror](/docs/claude-science/corporate-networks#point-package-installs-at-an-internal-mirror).
5860 
61An organization package mirror set under **Organization settings** > **Claude Science** removes the same hosts for every member and is admitted the same way. When the organization manages the allowlist, the removed hosts stay unreachable even if they are switched on in the organization's list, and a member's own mirror host is reachable only if the organization's list includes it.
62 
5963### Research database domains
6064 
61These groups are on by default and can be turned off during onboarding or anytime under **Settings** > **Network**.
65These groups are on by default. Members can turn them off during onboarding or anytime under **Settings** > **Network**. When the organization manages the allowlist, the organization's per-domain switches apply instead.
6266 
6367| Group | Domains |
6468| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

claude-science/whats-not-available-yet Changed · +3 / -3 lines

from line 2
22 
33> Claude Science is in beta, and some admin controls you use with other Claude products don't govern it yet.
44 
5Claude Science is in beta, and some admin controls you use with other Claude products don't govern it yet. The setup wizard lists some of these when you enable the product; this page has the full detail. See [Admin controls](/docs/claude-science/admin-controls) for the complete per-setting table.
5Claude Science is in beta, and some admin controls you use with other Claude products don't govern it yet. This page lists them. See [Admin controls](/docs/claude-science/admin-controls) for the complete per-setting table and for the controls on the **Organization settings** > **Claude Science** page itself.
66 
77## Audit and compliance
88 
from line 16
1616 
1717## Connector and domain allowlists
1818 
19Your organization's connector and domain allowlists apply to Directory connectors you publish, but don't restrict connectors a member adds locally (running on their own computer or pointing at a custom URL). Adding admin control over local and custom connectors is on the roadmap. Skills allowlists work the same way: org-published skills are visible; there's no admin control over which featured skills members can enable.
19Your organization's connector allowlist applies to Directory connectors you publish, and doesn't filter the custom connectors a member adds in the app; you can only turn custom connectors off for the whole organization. The Claude Science controls for connectors, skills, and the sandbox domain allowlist are on the **Organization settings** > **Claude Science** page (see [Organization settings](/docs/claude-science/admin-controls#organization-settings)), separate from the connector allowlist and from the code execution network allowlist for claude.ai chat.
2020 
2121## Session duration
2222 
23Your session-duration setting limits the browser sign-in step only. After a member signs in, the app holds its own token and stays signed in beyond that window.
23Your session-duration setting limits the browser sign-in step only. After a member signs in, the app holds its own token and stays signed in beyond that window. Turning Claude Science off for the organization still stops that member within a few minutes (see [Turn off Claude Science](/docs/claude-science/enable-claude-science#turn-off-claude-science)).
2424 
2525## Offboarding
2626 

claude-science/core-concepts Changed · +2 / -0 lines

from line 50
5050 
5151Saved facts are stored in the app's local database on your computer; they aren't synced to Anthropic. The Memory settings page lists every saved fact. You can edit, delete, add, or clear facts there. A per-session toggle in the session settings menu turns memory off for that session only.
5252 
53Facts Claude recalls for a session are sent to Anthropic as part of that session's conversation, and Anthropic retains them as [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data) describes. On Team and Enterprise plans, your organization's admin can turn memory off for the organization. Memory is then off for you whatever you chose, and your saved facts stay on your computer, where you can still review and delete them (see [Memory](/docs/claude-science/admin-controls#memory) in the admin controls).
54 
5355## Composer shortcuts
5456 
5557* `@` inserts an artifact or uploaded file by name

claude-science/custom-connectors Changed · +3 / -1 lines

from line 2
22 
33> Add any Model Context Protocol (MCP) server as a Remote (HTTPS web server) or Local command (program on your computer).
44 
5In **Settings > Connectors** > **Add connector**, choose Remote or Local command and enter a **Name** (lowercase letters, digits, hyphens). For Remote, enter the server URL; Advanced settings covers transport (**SSE** or **Streamable HTTP**), OAuth client settings, and the **Headers helper command**. For Local command, enter the command; Advanced settings covers arguments and environment variables. **Browse Connectors Directory** opens the public directory.
5In **Settings > Connectors** > **Add connector**, choose **Remote** or **Local command** and enter a **Name** (lowercase letters, digits, hyphens). For **Remote**, enter the server URL; **Advanced settings** covers transport (**SSE** or **Streamable HTTP**), OAuth client settings, and the **Headers helper command**. For **Local command**, enter the command; **Advanced settings** covers arguments and environment variables. **Browse Connectors Directory** opens the public directory.
66 
77Remote servers that need login take you through the provider's sign-in page.
8 
9On Team and Enterprise plans, you can add and use custom connectors only if your organization allows them. When it doesn't, the **Remote** and **Local command** options under **Add connector** are grayed with a note that custom connectors are disabled by your admin. Custom connectors you added earlier stay listed and grayed, Claude can't use them, and they work again if your organization turns custom connectors back on. See [Custom connectors](/docs/claude-science/admin-controls#custom-connectors) in the admin controls.
810 
911Every tool from a custom connector starts at **Ask each time**. On the connector's page, set individual tools to **Always allow** or **Block** under **Tools**, or turn on Skip approvals for the whole connector.
1012 

claude-science/glossary Changed · +1 / -1 lines

from line 26
2626 
2727**Model endpoint**: a scientific domain-specific model server you register under Settings > Compute, that runs locally or connects to a vendor's hosted solution, that Claude sends single prediction requests to.
2828 
29**Network allowlist**: the list under Settings of every outside host that sandboxed code may reach.
29**Network allowlist**: the list of every outside host that sandboxed code may reach, kept under Settings or, on Team and Enterprise plans, managed by your organization.
3030 
3131**Permission card**: the card that replaces the message box when Claude needs your permission for running code, running a job, accessing a network host, a folder, a connector tool, or re-configuring Claude Science; you allow or deny it.
3232 

claude-science/manage-on-devices Changed · +1 / -1 lines

from line 17
1717 
1818## Deploy configuration with device management
1919 
20To set configuration keys organization-wide, deploy \~/.claude-science/config.toml through your MDM or endpoint tool. Claude Science doesn't read a system-level managed-preferences file, so there's no native MDM configuration channel. Deploying the per-member config.toml is the supported approach. The keys most relevant to admins are:
20To set configuration keys organization-wide, deploy \~/.claude-science/config.toml through your MDM or endpoint tool. Claude Science doesn't read a system-level managed-preferences file, so there's no native MDM configuration channel. Deploying the per-member config.toml is the supported approach. The sandbox network allowlist and the package mirror can instead be set once for every member under **Organization settings** > **Claude Science** (see [Organization settings](/docs/claude-science/admin-controls#organization-settings)). The keys most relevant to admins are:
2121 
2222| Key | Effect |
2323| ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |

claude-science/remote-compute-clusters Changed · +2 / -0 lines

from line 4
44 
55Connect a machine you can reach over SSH (a lab workstation or an HPC login node) so Claude can run jobs on it. Use it to connect to a remote workstation with a GPU, or your existing HPC cluster. Claude Science uses your existing `~/.ssh/config`, authenticates with your key or `ssh-agent`, and installs nothing on the host itself.
66 
7On Team and Enterprise plans, your organization can turn SSH hosts off. When it has, **Add SSH host** isn't available, hosts you added earlier stay listed but refuse new commands and file transfers, and a job that's already running can still be stopped and its results collected (see [SSH hosts](/docs/claude-science/admin-controls#ssh-hosts) in the admin controls).
8 
79## Adding a host
810 
911Go to **Settings > Compute** > **SSH hosts** > **Add SSH host**.\