Sweep 22 Sep 2026 · 15:52Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Reading a new release v2.1.280 Building the pages · 4/6 1043 findings $36.88 so far
One capture · claude-docs

One read of Claude Documentation

24 pages moved out of 233 read.

claude-docs-20260910T213726Z

Pages moved 24 significant first
Pages read 233 in this capture
Captured 21:37 UTC
Corpus hash 228b8a2956f4 corpus-hash

What this read moved

1–24 of 24

claude-science/admin-controls Changed · +7 / -7 lines

from line 176
176176| Setting in claude.ai | Status for Claude Science | Note |
177177| -------------------------------------------------------------------------------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
178178| Claude Science > Enable for your organization | Supported in Claude Science | Off by default for Team and Enterprise. An Owner or Primary Owner turns it on under **Organization settings** > **Claude Science** (see [Enable Claude Science](/docs/claude-science/enable-claude-science)). Assigning seats doesn't turn it on. |
179| Data and privacy > Rate chats | Supported in Claude Science | When you turn this off, the app hides its response rating buttons and feedback form, as claude.ai does. |
179| Data and privacy > Rate chats | Supported in Claude Science | When you turn this off, the app hides its response rating buttons and feedback form, as claude.ai does. If your organization uses customer-managed encryption keys (CMEK), you can't turn this setting on and the app doesn't show these controls. |
180180| Organization and access > Organization instructions | Supported in Claude Science | Anthropic adds your organization instructions to the app's requests to Claude, as it does for claude.ai chat, so members don't need to update the app for a change to apply. |
181181| Skills > Organization skills and Policy | Supported in Claude Science | Skills you add under **Organization skills**, and members' own claude.ai skills, appear in Claude Science while **Skills** is on, and **User-created skills** decides whether a member can save a skill from the app to their own claude.ai account. The skills that come with the app and the skills members add in it are controlled on the **Claude Science** page: one switch per Featured skill, and **Allow custom skills** for skills members add themselves (see [Featured connectors and skills](#featured-connectors-and-skills) and [Custom skills](#custom-skills)). |
182182| Capabilities > Web search | Not applicable in Claude Science | This setting governs claude.ai chat. Claude Science can search the web regardless of it, and the **Claude Science** page has no switch for web search. |
from line 199
199199 
200200### Data and privacy
201201 
202| Setting in claude.ai | Status for Claude Science | Note |
203| -------------------------------------------------------------------------------------------------------- | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
204| Data and privacy > Encryption keys (customer-managed keys) | Supported in Claude Science | Anthropic handles Claude Science requests to Claude under your key the same way it handles claude.ai chat requests. Compliance API session transcripts are also encrypted under your key. |
205| Data and privacy > Data residency (US-only inference), or the regional processing terms in your contract | Supported in Claude Science | Governs where Anthropic processes Claude Science requests to Claude, as for your other Claude products. It doesn't cover code that runs on the member's computer, SSH hosts, or Modal account (the same boundary as Claude Code). |
206| Data and privacy > HIPAA Compliance | Not applicable in Claude Science | Organizations with HIPAA compliance enabled can turn Claude Science on, but its use isn't covered under your BAA and members must keep protected health information out of it. These organizations start from stricter defaults, listed under [Defaults by plan](#defaults-by-plan). |
207| Data and privacy > Retention period for chats and projects | Partially supported in Claude Science | The auto-delete window doesn't cover data on members' computers or the model-call logs Anthropic keeps for this product. For Enterprise organizations with the Compliance API enabled, the window does apply to the session transcripts it returns. |
202| Setting in claude.ai | Status for Claude Science | Note |
203| -------------------------------------------------------------------------------------------------------- | ------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
204| Data and privacy > Encryption keys (customer-managed keys) | Supported in Claude Science | The content Anthropic stores from Claude Science (model-call logs, skills members publish, and, where the Compliance API is enabled, session transcripts) is encrypted under your key. Data stored on the member's computer isn't hosted by Anthropic, and work members send to their own SSH hosts, Modal account, or scientific model endpoints doesn't pass through Anthropic, so neither is under your key. In organizations that use customer-managed encryption keys, the app also hides its response rating buttons and feedback form, as claude.ai does. See [Customer-managed encryption keys](/docs/claude-science/how-claude-science-works-with-your-data#customer-managed-encryption-keys). |
205| Data and privacy > Data residency (US-only inference), or the regional processing terms in your contract | Supported in Claude Science | Governs where Anthropic processes Claude Science requests to Claude, as for your other Claude products. It doesn't cover code that runs on the member's computer, SSH hosts, or Modal account (the same boundary as Claude Code). |
206| Data and privacy > HIPAA Compliance | Not applicable in Claude Science | Organizations with HIPAA compliance enabled can turn Claude Science on, but its use isn't covered under your BAA and members must keep protected health information out of it. These organizations start from stricter defaults, listed under [Defaults by plan](#defaults-by-plan). |
207| Data and privacy > Retention period for chats and projects | Partially supported in Claude Science | The auto-delete window doesn't cover data on members' computers or the model-call logs Anthropic keeps for this product. For Enterprise organizations with the Compliance API enabled, the window does apply to the session transcripts it returns. |
208208 
209209### Audit and compliance
210210 

claude-science/how-claude-science-works-with-your-data Changed · +12 / -4 lines

## Customer-managed encryption keys

from line 2
22 
33> What Anthropic receives from Claude Science, what stays on members' computers, and what Enterprise organizations can retrieve through the Compliance API.
44 
5Claude Science is a local-first application. Conversation history and artifacts are stored on the member's computer, and Anthropic doesn't sync them to the member's Claude account or to other devices. Anthropic does receive the prompts and responses the app exchanges with Claude, and handles them under its standard retention and Trust & Safety policies. For Enterprise organizations with the Compliance API enabled, Anthropic also retains those exchanges as session transcripts that the organization can retrieve; [Compliance API coverage](#compliance-api-coverage) explains what they contain. The following sections cover each of these, plus remote compute and connectors.
5Claude Science is a local-first application. Conversation history and artifacts are stored on the member's computer, and Anthropic doesn't sync them to the member's Claude account or to other devices. Anthropic does receive the prompts and responses the app exchanges with Claude, and handles them under its standard retention and Trust & Safety policies. For Enterprise organizations with the Compliance API enabled, Anthropic also retains those exchanges as session transcripts that the organization can retrieve; [Compliance API coverage](#compliance-api-coverage) explains what they contain. The following sections cover each of these, plus remote compute, connectors, and customer-managed encryption keys.
66 
77## What Anthropic receives
88 
9Each time the app calls Claude, the prompt and Claude's response travel to Anthropic's servers and are logged under Anthropic's standard retention policy for model traffic (see How long do you store my organization's data in the Privacy Center), the same policy that applies to other Claude products. If your organization has CMEK enabled, model-call logging follows the same CMEK handling as your other Claude products. Your organization's Custom Data Retention setting doesn't change how long these model-call logs are kept. It does apply to the session transcripts that Anthropic keeps for Enterprise organizations with the Compliance API enabled, described in [Compliance API coverage](#compliance-api-coverage). The app also sends product-usage telemetry (event counts and timings, not conversation content) and, when it runs into an error, a redacted error report (the error type and its location in Claude Science's own code, not conversation content or research data). Both are turned off by the same [device configuration](/docs/claude-science/manage-on-devices#telemetry) setting.
9Each time the app calls Claude, the prompt and Claude's response travel to Anthropic's servers and are logged under Anthropic's standard retention policy for model traffic (see How long do you store my organization's data in the Privacy Center), the same policy that applies to other Claude products. If your organization uses [customer-managed encryption keys (CMEK)](https://platform.claude.com/docs/en/manage-claude/cmek), these model-call logs are encrypted under your key (see [Customer-managed encryption keys](#customer-managed-encryption-keys) below). Your organization's Custom Data Retention setting doesn't change how long these model-call logs are kept. It does apply to the session transcripts that Anthropic keeps for Enterprise organizations with the Compliance API enabled, described in [Compliance API coverage](#compliance-api-coverage). The app also sends product-usage telemetry (event counts and timings, not conversation content) and, when it runs into an error, a redacted error report (the error type and its location in Claude Science's own code, not conversation content or research data). Both are turned off by the same [device configuration](/docs/claude-science/manage-on-devices#telemetry) setting.
1010 
1111## Compliance API coverage
1212 
from line 16
1616 
1717A transcript is reconstructed from what the app exchanged with Claude during the session: the member's prompts, Claude's responses, tool calls (including code and file content Claude wrote through them), and the text portions of tool results, including text from files that Claude read, subject to the size limits the Compliance API applies. Claude's extended thinking and the app's system prompt aren't included (a placeholder marks where the system prompt was), tool definitions and connector (MCP server) configuration are omitted, and images, PDFs, and other non-text content appear as placeholders. Content that never reached the Claude API, such as a local file the session never sent, isn't in the transcript.
1818 
19Anthropic keeps these transcripts for six years from capture by default. If your organization has set a Custom Data Retention period (in claude.ai under Organization settings > Data and privacy), that period applies to the transcripts instead, and when more than one retention period is set, the shortest applies. If your organization uses CMEK, the transcripts are encrypted under your key. The session endpoints are read-only, so transcripts can't be deleted through the API before they expire; see [Retention and deletion](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retention-and-deletion) for the current terms.
19Anthropic keeps these transcripts for six years from capture by default. If your organization has set a Custom Data Retention period (in claude.ai under Organization settings > Data and privacy), that period applies to the transcripts instead, and when more than one retention period is set, the shortest applies. If your organization uses [customer-managed encryption keys (CMEK)](https://platform.claude.com/docs/en/manage-claude/cmek), the transcripts are encrypted under your key. The session endpoints are read-only, so transcripts can't be deleted through the API before they expire; see [Retention and deletion](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retention-and-deletion) for the current terms.
2020 
2121The Compliance API's [Activity Feed](https://platform.claude.com/docs/en/manage-claude/compliance-activity-feed) also records changes to your Claude Science organization settings, such as turning the product on or off. The [Compliance API reference](https://platform.claude.com/docs/en/api/compliance/activities/list) describes these events.
2222 
2323## Remote compute
2424 
25When a member chooses to connect the app to remote compute (an owned server or cloud account they control), the app sends code and data directly to that destination. That traffic doesn't pass through Anthropic. You can turn SSH hosts, Modal, and scientific model endpoints off for the organization under **Organization settings** > **Claude Science** (see [SSH hosts](/docs/claude-science/admin-controls#ssh-hosts), [Modal](/docs/claude-science/admin-controls#modal), and [Scientific model endpoints](/docs/claude-science/admin-controls#scientific-model-endpoints)). For setup details, see [Remote compute clusters](/docs/claude-science/remote-compute-clusters) and [Compute providers](/docs/claude-science/compute-providers) in the user documentation.
25When a member chooses to connect the app to remote compute (an owned server or cloud account they control), the app sends code and data directly to that destination. That traffic doesn't pass through Anthropic, and Anthropic doesn't store it. For organizations that use customer-managed encryption keys, see [Customer-managed encryption keys](#customer-managed-encryption-keys). You can turn SSH hosts, Modal, and scientific model endpoints off for the organization under **Organization settings** > **Claude Science** (see [SSH hosts](/docs/claude-science/admin-controls#ssh-hosts), [Modal](/docs/claude-science/admin-controls#modal), and [Scientific model endpoints](/docs/claude-science/admin-controls#scientific-model-endpoints)). For setup details, see [Remote compute clusters](/docs/claude-science/remote-compute-clusters) and [Compute providers](/docs/claude-science/compute-providers) in the user documentation.
2626 
2727## Connectors
2828 
2929Directory connectors you publish as an admin are reached through Anthropic's hosted connector service, so your directory connector permissions and tunnels apply. Connectors a member adds locally (either running on their own computer or pointing at a custom URL) talk to their app directly, without routing through Anthropic. You can turn custom connectors off for the organization (see [Custom connectors](/docs/claude-science/admin-controls#custom-connectors)).
30 
31## Customer-managed encryption keys
32 
33Organizations that use [customer-managed encryption keys (CMEK)](https://platform.claude.com/docs/en/manage-claude/cmek) can turn on Claude Science. The content Anthropic stores from the app is encrypted under your key, including the model-call logs of members' conversations with Claude, skills members publish, and, for Enterprise organizations with the Compliance API enabled, session transcripts.
34 
35The app's conversation history, files, artifacts, and memory are stored on the member's computer and aren't hosted by Anthropic; of these, only what the app sends to Claude reaches Anthropic, where your key covers it as this section describes. Work members send to their own SSH hosts, Modal account, or scientific model endpoints goes directly there, not through Anthropic, and isn't under your key or any Anthropic-managed key, so review those providers' data handling. You can turn these connections off under **Organization settings** > **Claude Science**.
36 
37In organizations with CMEK enabled, the app hides its response rating buttons and feedback form, as claude.ai does.
3038 
3139## What this means for you as an admin
3240 

claude-tag/admins/add-connections Changed · +6 / -4 lines

from line 10
1010 
1111## Your first Access bundle
1212 
13An [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of credentials, repository grants, and instructions that Claude uses in the channels the bundle covers. A connection is one service credential inside a bundle, like a Datadog API key or a warehouse service account, that Claude uses to act in that service from any channel under the bundle's [scope](/docs/claude-tag/concepts/glossary#scope).
13An [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of credentials, domain entries, repository grants, plugins, and instructions that Claude uses in the channels the bundle covers. A connection is one service credential inside a bundle, like a Datadog API key or a warehouse service account, that Claude uses to act in that service from any channel under the bundle's [scope](/docs/claude-tag/concepts/glossary#scope).
1414 
1515If you're in [setup](/docs/claude-tag/admins/setup-overview), you add these connections there; skip to [Decide what to connect](#decide-what-to-connect). The steps below are for creating a bundle outside setup, on the admin page directly.
1616 
from line 24
2424 </Step>
2525 
2626 <Step title="Name the bundle">
27 The new bundle is named after its scope, like **Acme bundle** for a workspace named Acme or **#engineering bundle** for that channel. To rename it, click the pencil next to the name (the console uses "profile" and "Access bundle" interchangeably).
27 A bundle created on a workspace or channel scope is named after that scope, like **Acme bundle** for a workspace named Acme or **#engineering bundle** for that channel. A bundle created on **Default Slack** is named **Untitled access bundle** until you rename it. To rename a bundle, click the pencil next to the name (the console uses "profile" and "Access bundle" interchangeably).
2828 </Step>
2929</Steps>
3030 
3131You can also create an unattached bundle by clicking **Create** on the **Access bundles** page in the left navigation, then attach it to scopes afterward. A bundle created there is named **Untitled access bundle** until you rename it.
3232 
33Connections belong to the [agent identity](/docs/claude-tag/concepts/agent-identity), not to any person. Personal claude.ai connectors apply only in DMs.
33Connections belong to the [agent identity](/docs/claude-tag/concepts/agent-identity), not to any person. Personal claude.ai connectors apply in DMs. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use a member's own connectors in a channel for that member's own tasks, after the member allows it.
3434 
3535Name a bundle after what it grants, since the name is what you'll read when deciding which bundles to bind to a channel: `data-readonly`, `github-write`, `monitoring`, `gtm-tools`. A capability name stays meaningful when the same bundle serves several teams; a team name (`devprod-team`) works when one team's full access is the unit you'll reuse.
3636 
from line 113
113113* **Domain**: the hostname to allow; a wildcard is allowed as the leftmost label, like `*.example.com`, and covers subdomains at any depth but not `example.com` itself
114114* **Ports**: needed only when the service listens on something other than 443
115115 
116For example, to let Claude check a vendor's status page at `status.example.org`, enter `status.example.org` in the **Domain** field and leave the **Ports** field empty.
117 
116118You don't have to predict the full list up front. When a request is blocked, Claude says so in the thread and names the host, with wording like "blocked by the network egress proxy" (that is, by Agent Proxy); add that host here and retry. If the host is listed and Claude still reports it blocked, check these in order:
117119 
118120* **The bundle is attached to the channel's scope.** Claude can use a Domains entry only in channels whose scope, or an ancestor scope, has this bundle attached; see [Attach bundles to scopes](/docs/claude-tag/admins/attach-to-scope).
from line 167
165167| Bearer | API keys and OAuth bearer tokens. Most SaaS REST APIs. |
166168| Basic | HTTP Basic authentication. |
167169| Body parameter | A token the API expects in the request body or query string instead of a header. |
168| AWS SigV4 | Signed requests to AWS APIs with an access key pair. |
170| AWS SigV4 | Signed requests to AWS service endpoints with an access key pair. |
169171| GCP access token (with Service Account Key) | Google Cloud APIs via a service-account JSON key. Google Workspace services like Drive and Calendar also use this; see [the Google guide](/docs/claude-tag/admins/connections/google). |
170172| GCP IAP (with Service Account Key) | Google Cloud services behind Identity-Aware Proxy. |
171173| OAuth 2.0 JWT bearer | Server-to-server OAuth. |

claude-tag/admins/attach-to-scope Changed · +9 / -3 lines

from line 53
5353A channel that doesn't appear in the list yet needs a scope created for it:
5454 
55551. On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), find the workspace on the **Slack** tab under **Claude Tag's access** and select **Add channel**.
562. Paste the channel's ID into the **Channel ID** field. Channel IDs start with `C`, or with `G` for some older private channels. Copy the ID from the channel's details in Slack.
562. Pick the channel in the **Channel** field. Type a name to search public channels, or paste a channel ID or channel link copied from Slack. Private channels don't appear in the search results, so for a private channel, paste its ID from the channel's details in Slack. Channel IDs start with `C`, or with `G` for some older private channels.
57573. Save, then bind bundles in the new scope's **Access bundles** section, the same as for a workspace.
5858 
5959In a channel shared across more than one workspace in your Enterprise Grid, bundles bound to the channel or its workspace don't apply. See [Channels shared across workspaces in your Enterprise Grid](/docs/claude-tag/admins/restrict-access#channels-shared-across-workspaces-in-your-enterprise-grid) for what Claude does there instead.
from line 73
7373 
7474Select the scope name to open that scope, or the bundle name to open the bundle.
7575 
76The grant still lives in a bundle. The item is added to the bundle that was created for that scope, or to the scope's only bundle when that bundle is bound nowhere else, and otherwise a new bundle is created for the scope. If the bundle created for the scope is now bound to other scopes too, the add is refused with a message telling you to manage that bundle's repositories and connectors in **Access bundles** instead, so adding here never widens another scope's access.
76An item you add with the **+** button is still stored in a bundle, chosen in this order:
7777 
781. The bundle that was created for that scope, if it exists
792. The scope's only bundle, if that bundle is bound nowhere else
803. A new bundle created for the scope
81 
82When the receiving bundle is bound to other scopes too, the picker shows a note that the addition applies in every scope the bundle is bound to.
83 
7884## Precedence when bundles overlap
7985 
8086A channel sees the **union** of every bundle bound at the channel itself, its workspace, and Default Slack access. Narrower scopes don't replace wider ones; they add to them. When two bundles in the resolved set carry rules for the same host, the rule from the narrower scope wins. Within that union, fixed rules decide which credential and which instructions apply.
from line 95
8995 
9096### Repositories and plugins
9197 
92Repository grants and plugins from every bound bundle are combined as a union; a channel gets every repo and plugin from any bundle in its chain. The **Access summary** section, shown when a scope you select on the Slack tab has any resolved connections or repositories, lists them with the bundle each one comes from. Plugins aren't listed there. The scope's **Plugins** section shows only the plugins attached at that scope, and plugins inherited from wider scopes and from bundles apply without appearing in it.
98Repository grants and plugins from every bound bundle are combined as a union; a channel gets every repo and plugin from any bundle in its chain. To see what applies to a channel, select its scope on the **Slack** tab. The scope's panel lists everything that applies there in its **Connectors**, **Repositories**, and **Plugins** sections, inherited items included. Each row's origin line says **Inherited from** the wider scope or **Attached from** the bundle that carries it. Select the scope or bundle name in the origin line to open it.
9399 
94100### Custom instructions
95101 

claude-tag/admins/configure-github Changed · +5 / -3 lines

from line 26
2626 </Step>
2727 
2828 <Step title="Connect Claude to GitHub">
29 Click **Connect Claude to GitHub** (**Connect**, once any account is already linked) and complete the GitHub authorization. After authorizing, the page shows two sections: **Connected GitHub accounts** lists accounts already linked, with a **Type** column of **Organization** or **Personal**, and **Unlinked accounts** lists organizations where the Claude GitHub App is installed but not yet linked. Claude Tag uses **Organization** accounts only; a **Personal** row is someone's own GitHub account and can't be used for your repositories.
29 Click **Connect Claude to GitHub** (**Connect**, once any account is already linked) and complete the GitHub authorization. After authorizing, the **Connected GitHub accounts** table lists the GitHub accounts the Claude GitHub App is installed on. The **Type** column reads **Organization** or **Personal**. An account already linked to your Claude organization shows **Connected**, and one that still needs linking shows **Not linked**. Claude Tag uses **Organization** accounts only; a **Personal** row is someone's own GitHub account and can't be used for your repositories.
3030 </Step>
3131 
3232 <Step title="Link or install">
33 If your organization is under **Unlinked accounts**, click **Link** next to it. If it isn't listed at all, click **Install on another organization** and complete the install on github.com; you're returned to this page with the organization under **Connected GitHub accounts** as **Connected**.
33 If your organization's row reads **Not linked**, select the **Link** button next to it. If it isn't listed at all, click **Install on another organization** and complete the install on github.com; you're returned to this page with the organization under **Connected GitHub accounts** as **Connected**.
3434 
35 An organization can also be missing from the table because single sign-on (SSO) on GitHub hides it. A note under the table counts the organizations hidden that way. To make them appear, authorize the Claude app for those organizations on GitHub.
36 
3537 * A disabled **Link** button means you can't link that account yet; the button's tooltip names the reason, such as not being an owner of that GitHub organization
3638 * A **Needs permissions** status means the installation has a pending request; **Review permissions** takes you to github.com to approve it
3739 * An **Authorize SSO** button in place of **Link** means your GitHub token isn't authorized for that organization's SSO; the button opens github.com to authorize it, and you link after returning
from line 42
4042 
4143## Grant repository access
4244 
43The remaining steps are in the Claude Tag admin page, not GitHub's settings. Repository grants live on the Access bundle; editing a bundle's Repositories tab requires the **Owner** role in your Claude organization. A [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can also add repositories to their own channel, limited to repositories their GitHub account can write to.
45The remaining steps are in the Claude Tag admin page, not GitHub's settings. Repository grants live on the Access bundle; editing a bundle's Repositories tab requires the **Owner** role in your Claude organization. A [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can also add repositories to their own channel, limited to repositories their GitHub account is an admin of.
4446 
4547<Steps>
4648 <Step title="Open the bundle's Repositories tab">

claude-tag/admins/connections/custom Changed · +16 / -8 lines

from line 39
3939| **Bearer** | An API key or token sent as `Authorization: Bearer <token>`. Most SaaS REST APIs. |
4040| **Basic** | HTTP Basic authentication (`Authorization: Basic <base64(user:password)>`) |
4141| **Body parameter** | A token the API expects in the request body or query string instead of a header |
42| **AWS SigV4** | AWS services and APIs that require Signature Version 4 signing |
42| **AWS SigV4** | AWS service APIs on `amazonaws.com` endpoints that require Signature Version 4 signing |
4343| **GCP access token (with Service Account Key)** | Google Cloud APIs; the proxy exchanges the SA key for an access token |
4444| **GCP IAP (with Service Account Key)** | Google Cloud services behind Identity-Aware Proxy |
4545| **OAuth 2.0 JWT bearer** | APIs that accept a JWT signed with your private key in exchange for an access token (DocuSign, for example) |
from line 52
5252 
5353### AWS SigV4
5454 
55Use the **AWS SigV4** credential type for AWS service APIs (S3, Lambda, Amazon Bedrock, an API Gateway endpoint with IAM authorization). Agent Proxy reads the AWS service and signing region from the hostname and signs each outbound request with the credential at the boundary, so neither the model nor the sandbox holds the keys. The host must be an `amazonaws.com` endpoint; the proxy can't sign requests to an API Gateway custom domain or to a non-AWS API that uses Signature Version 4.
55Use the **AWS SigV4** credential type for AWS service APIs such as S3, Lambda, and DynamoDB. Agent Proxy reads the AWS service and signing region from the hostname and signs each outbound request with the credential at the boundary, so neither the model nor the sandbox holds the keys.
5656 
57| Field | Value |
58| :---------------- | :---------------------------------------------------------------------------------------------------------------------- |
59| Access key ID | The IAM user or role access key, for example `AKIAIOSFODNN7EXAMPLE` |
60| Secret access key | The matching secret access key |
61| Session token | Optional. Only needed for temporary credentials from AWS STS. |
62| Allowed websites | The AWS service endpoint host, for example `s3.us-east-1.amazonaws.com` or `abc123.execute-api.us-east-1.amazonaws.com` |
57Agent Proxy signs requests to hostnames in these forms:
58 
59* `service.region.amazonaws.com`
60* S3 virtual-hosted-style endpoints, for example `my-bucket.s3.us-east-1.amazonaws.com`
61* The regionless hosts of global AWS services such as IAM, STS, and CloudFront
62 
63Apart from S3 virtual-hosted-style endpoints, Agent Proxy can't read the service from a hostname that has extra parts before the service name, so requests to those hosts fail before reaching AWS. Examples include the host of an API Gateway invoke URL, such as `abc123.execute-api.us-east-1.amazonaws.com`, and the host of an Amazon Managed Workflows for Apache Airflow (MWAA) environment. The proxy also can't sign requests to an API Gateway custom domain or to a non-AWS API that uses Signature Version 4.
64 
65| Field | Value |
66| :---------------- | :---------------------------------------------------------------------------------------------------------- |
67| Access key ID | The IAM user or role access key, for example `AKIAIOSFODNN7EXAMPLE` |
68| Secret access key | The matching secret access key |
69| Session token | Optional. Only needed for temporary credentials from AWS STS. |
70| Allowed websites | The AWS service endpoint host, for example `s3.us-east-1.amazonaws.com` or `lambda.us-east-1.amazonaws.com` |
6371 
6472Use long-lived credentials from a dedicated IAM user where you can. Temporary STS credentials work but expire on their own schedule, and the connection stops working when they do; you re-enter all three values to rotate.
6573 

claude-tag/admins/customize Changed · +13 / -13 lines

from line 21
2121 
2222Access and organization-wide behavior are set at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), per scope (a scope is a channel, a workspace, or your whole organization), so the same agent can work differently in different channels. Most controls below are Owner-only.
2323 
24| Setting | What it does | More |
25| :-------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------- |
26| Custom instructions | Standing guidance read in every session on a scope, like team conventions. Outranks channel memory. | [Add custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
27| Respond automatically | Whether Claude replies to a channel's messages without an @-mention. Channel members can change it too, from Slack or the channel's Configure page. | [Turn automatic replies on or off](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) |
28| Plugins | Bundles of skills that teach Claude how to use a specific tool | [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins) |
29| Connections | Which systems it can reach from each channel | [Add connections](/docs/claude-tag/admins/add-connections) |
30| Default model | Which Claude model handles sessions in a scope | [Choose the model for a scope](#choose-the-model-for-a-scope) |
31| Auto mode allow rules | Actions pre-approved in a scope's sessions that Claude's permission checker would otherwise flag or stop | [Auto mode allow rules](#auto-mode-allow-rules) |
32| Environment | Which cloud environment a scope's sessions run in | [Configure the environment for a scope](#configure-the-environment-for-a-scope) |
33| Claude Tag version | Which generation answers (New, Legacy, or Off) in a scope. On the Team plan, a single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) replaces it. | [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/workspaces#set-the-version-for-a-scope) |
24| Setting | What it does | More |
25| :-------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------- |
26| Custom instructions | Standing guidance read in every session on a scope, like team conventions. Outranks channel memory. | [Add custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
27| Respond automatically | Whether Claude replies to a channel's messages without an @-mention. **Respond automatically** exists only on channels, not on workspaces or your whole organization. Channel members can change it too, from Slack or the channel's Configure page. | [Turn automatic replies on or off](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) |
28| Plugins | Bundles of skills that teach Claude how to use a specific tool | [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins) |
29| Connections | Which systems it can reach from each channel | [Add connections](/docs/claude-tag/admins/add-connections) |
30| Default model | Which Claude model handles sessions in a scope | [Choose the model for a scope](#choose-the-model-for-a-scope) |
31| Auto mode allow rules | Actions pre-approved in a scope's sessions that Claude's permission checker would otherwise flag or stop | [Auto mode allow rules](#auto-mode-allow-rules) |
32| Environment | Which cloud environment a scope's sessions run in | [Configure the environment for a scope](#configure-the-environment-for-a-scope) |
33| Claude Tag version | Which generation answers (New, Legacy, or Off) in a scope. On the Team plan, a single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) replaces it. | [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/workspaces#set-the-version-for-a-scope) |
3434 
3535### Channel connections are separate from personal connectors
3636 
37An Owner configures Claude's connections, plugins, and skills, and they apply per scope. They are separate from the connectors, skills, or MCP servers an individual user has set up in their own claude.ai or Claude Desktop account. A user's personal connectors are not available to Claude in a channel, and the channel's connections are not listed among that user's personal connectors in claude.ai. Projects in claude.ai are separate too. Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project. Put standing guidance for a channel in its [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
37An Owner configures Claude's connections, plugins, and skills, and they apply per scope. They are separate from the connectors, skills, or MCP servers an individual user has set up in their own claude.ai or Claude Desktop account. A user's personal connectors are not part of a channel's configuration, and the channel's connections are not listed among that user's personal connectors in claude.ai. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can use a user's personal connectors in a channel for that user's own tasks, after the user allows it. That work runs with the user's permissions and is recorded under their name. Projects in claude.ai are separate too. Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project. Put standing guidance for a channel in its [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
3838 
3939To give Claude access to a tool that is not in the built-in connection list, including a custom MCP server, see [add a custom connection](/docs/claude-tag/admins/connections/custom).
4040 
from line 56
5656 
5757The Configure page also shows the channel's resolved access. Its **Tools and access** tab lists the channel's resolved connections and any allowed domains. Members can see those lists but not change them there. The same tab's **Plugins** card lists the plugins available to Claude in the channel; members can add plugins there unless an admin has [restricted editing to admins](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions). The card groups plugins **Added by your admin**, which members can't remove, separately from plugins **Added by members**, which members can remove. The Configure page's **Routines** tab lists the channel's [routines](/docs/claude-tag/users/proactivity) with each one's schedule, status, and last run.
5858 
59On the Enterprise plan, an Owner can name [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for a channel. They set the channel's default model, repositories, and connections from the same page.
59On the Enterprise plan, an Owner can name [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for a channel. They set the channel's default model, repositories, connections, and plugins from the same page.
6060 
6161## Choose the model for a scope
6262 
from line 122
1221223. The **Environment** setting on **Default Slack access**
1231234. The [organization's default environment](https://code.claude.com/docs/en/cloud-environments#the-default-environment), which an Owner chooses under **Cloud sessions** at [`claude.ai/admin-settings/claude-code`](https://claude.ai/admin-settings/claude-code)
124124 
125If you haven't chosen an environment on a scope, its picker shows **Organization default**, but sessions there may still run on an environment you chose on the workspace or on **Default Slack access**. If a channel's sessions aren't on the environment you expect, see [channel sessions use the wrong environment](/docs/claude-tag/admins/troubleshooting#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one).
125If you haven't chosen an environment on a scope, its picker shows **Organization default**, but sessions there may still run on an environment you chose on the workspace or on **Default Slack access**. In a channel where Claude runs with [channel-only access](/docs/claude-tag/admins/restrict-access#how-channel-only-works) because a guest is present, sessions run on the standard environment regardless of these settings. If a channel's sessions aren't on the environment you expect, see [channel sessions use the wrong environment](/docs/claude-tag/admins/troubleshooting#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one).
126126 
127127## Auto mode allow rules
128128 

claude-tag/admins/restrict-access Changed · +60 / -27 lines

#### How Channel only works

from line 120
120120DMs, guest channels, and shared channels sit outside the version setting:
121121 
122122* **DMs.** The version setting doesn't cover them. To close those off too, turn off the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle.
123* **Guest channels.** By default Claude is off in any channel that includes a Slack guest. If a chosen channel has guests, also set [Allow Claude to work in channels with guests](#restrict-guest-channels) to **Allow** on its scope.
123* **Guest channels.** By default Claude is off in any channel that includes a Slack guest. If a chosen channel has guests, also set [Allow Claude to work in channels with guests](#restrict-guest-channels) to **Allow** or **Channel only** on its scope.
124124* **Shared channels.** A [channel shared across workspaces in your Enterprise Grid](#channels-shared-across-workspaces-in-your-enterprise-grid) takes its settings from **Default Slack access** only, and Claude [doesn't operate in Slack Connect channels](#externally-shared-channels) at all; neither can serve as a chosen channel.
125125 
126126To control who can use Claude in the allowed channels, turn on the [restriction toggle](#restrict-who-can-use-claude); to cap what a channel spends, [set a per-channel spend limit](#set-spend-limits).
from line 138
138138 
139139### Restrict guest channels
140140 
141By default, Claude is disabled in any channel that includes a Slack guest. To allow it there, set **Allow Claude to work in channels with guests** to **Allow** for the scope covering the channel; **Restrict** (the default) keeps it off wherever a guest is present. The setting is at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the **Slack** tab under **Claude Tag's access**, in the scope's collapsed **Advanced** section.
141By default, Claude is disabled in any channel that includes a Slack guest. You can change this default per scope with the **Allow Claude to work in channels with guests** setting, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) **Claude Tag's access** **Slack** the scope the collapsed **Advanced** section. The setting has three values:
142142 
143**Allow** applies to every guest channel the scope covers, and guests in those channels can see Claude's replies and interact with it. To open one channel rather than a whole workspace, set it on the channel's own scope.
143| Value | What Claude does in a channel that includes a guest |
144| ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
145| **Restrict** (default) | Doesn't reply. When someone mentions it, Claude posts a short notice that it doesn't respond in channels that include guests, with a link to this setting. |
146| **Channel only** | Replies, but while a guest is present it runs with [channel-only access](#how-channel-only-works). The channel's own instructions and any access bundle attached directly to the channel still apply. |
147| **Allow** | Replies with the full access the scope gives it. Bundles, connections, and instructions from the workspace and from **Default Slack access** apply, along with repositories, memory, and skills. |
144148 
145**Allow** controls whether Claude replies, not what it can search. Workspace search is unavailable in any channel that includes a guest, even when the setting is **Allow**. Search results could include content from channels the guests can't see, the same reason Claude doesn't search private channels. To run a search that covers the workspace, ask from a channel without guests.
149A channel without its own value shows **Inherit** and takes the value from its workspace, or from **Default Slack access**. Only an organization Owner can choose **Allow** or set a scope back to **Inherit**. The setting applies to every guest channel the scope covers. To open one channel rather than a whole workspace, set it on the channel's own scope.
146150 
151Under every value, guests in the channel can read what Claude posts there.
152 
153In any channel that includes a guest, even under **Allow**, Claude won't search the workspace, look up people or channels, or read channels other than the one it's in. The results could include content the guests can't see in Slack, which is also why Claude doesn't search private channels. To have Claude search, look someone up, or read another channel, ask from a channel without guests.
154 
155#### How Channel only works
156 
157Use **Channel only** to keep Claude available in a channel shared with contractors, clients, or agency partners without exposing the rest of the organization's setup to that conversation. While a guest is in the channel, Claude has:
158 
159* No [access bundles](/docs/claude-tag/admins/attach-to-scope) from the workspace or from **Default Slack access**. A bundle attached directly to this channel's scope still applies, with its connections, instructions, and plugins. Attach to a guest channel only what you're comfortable with Claude using in a conversation guests can read.
160* No connections set directly on the channel.
161* No repositories, including any in a bundle attached to the channel.
162* No instructions set on the workspace or the organization. Instructions set on the channel itself still apply.
163* No memory, including this channel's own, and no skills.
164* No [environment set on the scope](/docs/claude-tag/admins/customize#configure-the-environment-for-a-scope). The session runs on the standard environment, so the setup script, environment variables, and network access level of the environment you chose don't apply while a guest is present.
165 
166Claude decides which access applies when a conversation starts. When no guest is in the channel, new conversations get full access, as under **Allow**.
167 
168A conversation that was underway before the first guest joined doesn't keep its full access. The next message from a workspace member in that thread starts the conversation over with channel-only access. A guest who writes there before a member does gets the same notice as under **Restrict**.
169 
170While a guest is present, Claude replies only to mentions and to threads it's already part of. It doesn't act on other messages in the channel on its own, even where [**Respond automatically**](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) is on.
171 
172A guest can talk to Claude by mentioning `@Claude` or by replying in a thread Claude is part of, and Claude answers them. A guest can't approve a tool or permission request, and can't restart, mute, fork, or stop the session. If a guest clicks approve, nothing is granted.
173 
174Treat a channel's instructions, and the instructions in any bundle attached to the channel, as visible to everyone in that channel, including guests. Under **Channel only**, Claude follows them in replies that guests can read and respond to.
175 
176**Channel only** takes effect where the **New** [Claude Tag version](/docs/claude-tag/admins/workspaces#set-the-version-for-a-scope) answers. On a scope where **Legacy** answers, a channel that includes a guest is treated as **Restrict**.
177 
147178### Externally shared channels
148179 
149180Claude doesn't operate in Slack Connect channels, the ones shared with another company. It's off in those channels regardless of scope or bundle, and this isn't configurable.
from line 208
177208* **Organization-wide limit.** Caps total Claude Tag spend across every channel.
178209* **Default spend limit.** A default limit applied to each channel that doesn't have its own.
179210* **Per-channel limits.** Set on any channel from its row in the per-channel spend table, in addition to the organization limit. A channel doesn't need its own scope to take a limit.
180* **Per-channel spend.** How much each channel has spent against its limit in the current billing period, at list price, on the same page.
211* **Per-channel spend.** How much each channel has spent against its limit in the current billing period, at list price, on the same page. Usage covered by a promotional credit isn't counted here and shows as \$0.00. The **Spend by channel** table at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag) shows list-price spend including covered usage.
181212 
182213Work that would exceed a limit is declined rather than silently truncated. A user blocked by a limit can request more usage from their admin in Slack, and the admin notification names whether the usage balance or the limit caused the block.
183214 
184215### Usage analytics
185216 
186Spend trends live at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag), the Claude Tag section of the Analytics dashboard, refreshed once a day. It shows total and projected month-end spend for the period you pick, spend by channel with a CSV export, DM versus channel spend, [spend by kind of work](/docs/claude-tag/admins/set-spend-limit#see-spend-by-kind-of-work), and any promotional credit, as billed after your discount. Anyone with permission to view your organization's Analytics dashboard can open it; it has no controls, so use the usage page to change a limit. The two pages link to each other.
217Spend trends live at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag), the Claude Tag section of the Analytics dashboard, refreshed once a day. It shows total and projected month-end spend for the period you pick, spend by channel with a CSV export, DM versus channel spend, [spend by kind of work](/docs/claude-tag/admins/set-spend-limit#see-spend-by-kind-of-work), and any promotional credit. Billed figures are shown after your discount. Anyone with permission to view your organization's Analytics dashboard can open it; it has no controls, so use the usage page to change a limit. The two pages link to each other.
187218 
219When the period you pick falls within the current month, the **Spend by channel** table shows a **Billed** column and a **List price** column. Usage covered by a promotional credit shows as \$0.00 under **Billed** and at its list price under **List price**.
220 
188221## Delegate channel setup to channel managers
189222 
190223A channel manager is a member of your Claude organization who can set up Claude in specific channels without the Owner role. Channel managers are available on the Enterprise plan, and you must be an Owner to add or remove them.
191224 
192You name channel managers one channel at a time. For that channel, a channel manager adds repositories and credentials, sets the default model, and edits channel instructions. Every other setting at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) stays with Owners.
225You name channel managers one channel at a time. For that channel, a channel manager sets the default model, adds repositories, manages credentials and plugins in the channel's bundle, and edits channel instructions. Every other setting at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) stays with Owners.
193226 
194227### What a channel manager can do on the Configure page
195228 
196229A channel manager has to be a member of the channel in Slack. The channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel), reached from the **Configure** link in any Claude reply, is split into tabs. In a channel you assigned to them, a channel manager sees the **Default model** card on the **General** tab and the repository and access bundle cards on the **Tools and access** tab. Members without the role don't see those cards. Owners and Admins also see an **Admin** tab, whose **Channel settings** card holds some of the channel scope's settings from admin settings.
197230 
198| Setting | What a channel manager can do |
199| :----------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
200| **Default model** | Choose the model new threads in the channel start on, from the models your organization allows. **Inherit** keeps the workspace or organization default |
201| **Repositories** | Add repositories beyond the ones your bundles already grant the channel. They can add only repositories their own GitHub account can write to |
202| **Access bundles** | Add, rotate, test, and remove credentials in the bundle Claude created for the channel and in any bundle they created for it. If the channel has no bundle yet, they can create one. They can't edit a bundle you created or a bundle that other channels share |
231| Setting | What a channel manager can do |
232| :----------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
233| **Default model** | Choose the model new threads in the channel start on, from the models your organization allows. **Inherit** keeps the workspace or organization default |
234| **Repositories** | Add repositories beyond the ones your bundles already grant the channel. They can add only repositories their own GitHub account is an admin of |
235| **Access bundles** | Add, rotate, test, and remove credentials, and turn [plugins](/docs/claude-tag/admins/add-connections#attach-plugins) on or off, in the bundle Claude created for the channel and in any bundle they created for it. If the channel has no bundle yet, they can create one. They can't edit a bundle you created or a bundle that other channels share |
203236 
204237When a channel manager adds a credential, Claude also allows the host that credential uses. Channel managers can't change the bundle's domains or rules in any other way. Credentials that use Claude's own identity (mutual TLS, AWS or GCP service identity, and IAP) stay Owner-only: a channel manager can't add, change, or rotate one, but can delete one from the channel's bundle, including one an Owner added. If that happens, Claude loses access to that service until an Owner adds the credential back.
205238 
from line 288
255288 
256289Creating bundles, binding them to scopes, and pairing workspaces need an Owner. A [channel manager](#delegate-channel-setup-to-channel-managers) configures only the channels assigned to them. Everything else happens inside the channel and is open to its members. The table lists each action and who can take it.
257290 
258| Action | Owner | Channel manager | Channel member |
259| :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------ | :---------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------- |
260| Pair a workspace | Yes | No | No |
261| Create, rename, delete, or bind an Access bundle | Yes | Only to create a bundle for an assigned channel | No |
262| Edit a bundle's Repositories, Plugins, or Instructions tab | Yes | No | No |
263| Edit a bundle's Credentials or Domains tab | Yes | Credentials tab only, in a bundle created for an assigned channel | No |
264| Add a channel manager | Yes | No | No |
265| Set a channel's default model or repositories from the Configure page | Yes | Yes, in assigned channels | No |
266| Set a channel's default model by asking Claude in a thread, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block** | Yes | Yes | Yes |
267| Write channel memory | Yes, in the channel | Yes, in the channel | Yes |
268| Set channel instructions from the Configure link | Yes | Yes, in assigned channels | Yes, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting blocks it |
269| Create, list, or disable a scheduled job in the channel | Yes, in the channel | Yes, in the channel | Yes |
270| Remove Claude from a channel | Yes | Yes, with `/remove`, unless your Slack admin restricts it | Yes, with `/remove`, unless your Slack admin restricts it |
291| Action | Owner | Channel manager | Channel member |
292| :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------ | :-------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------- |
293| Pair a workspace | Yes | No | No |
294| Create, rename, delete, or bind an Access bundle | Yes | Only to create a bundle for an assigned channel | No |
295| Edit a bundle's Repositories, Domains, or Instructions tab | Yes | No | No |
296| Edit a bundle's Credentials or Plugins tab | Yes | Yes, in a bundle created for an assigned channel | No |
297| Add a channel manager | Yes | No | No |
298| Set a channel's default model or repositories from the Configure page | Yes | Yes, in assigned channels | No |
299| Set a channel's default model by asking Claude in a thread, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block** | Yes | Yes | Yes |
300| Write channel memory | Yes, in the channel | Yes, in the channel | Yes |
301| Set channel instructions from the Configure link | Yes | Yes, in assigned channels | Yes, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting blocks it |
302| Create, list, or disable a scheduled job in the channel | Yes, in the channel | Yes, in the channel | Yes |
303| Remove Claude from a channel | Yes | Yes, with `/remove`, unless your Slack admin restricts it | Yes, with `/remove`, unless your Slack admin restricts it |
271304 
272305Scheduled jobs run with the channel's credentials, so a member creating one can't reach anything the channel itself can't.
273306 

claude-tag/admins/set-spend-limit Changed · +6 / -4 lines

from line 6
66 
77<BetaNote />
88 
9Work Claude does in channels bills to your **organization's usage balance**, not to individual seats. The **spend limit** is a cap you set on how much of that balance Claude Tag can use each billing period.
9Work Claude does in channels bills to your **organization's usage balance**, not to individual seats. The **spend limit** is a cap you set on how much of that balance Claude Tag can use each month.
1010 
1111| Work | Bills to | Capped by |
1212| :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------- | :---------------------------------------------------------------------------------------------------- |
from line 31
3131 </Step>
3232 
3333 <Step title="Enter an amount">
34 Enter an amount in your organization's billing currency. The spend limit resets at the start of each billing period and applies across every paired workspace. You can change it any time.
34 Enter an amount in your organization's billing currency. The spend limit resets at the start of each month and applies across every paired workspace. You can change it any time.
3535 </Step>
3636</Steps>
3737 
38There's no published per-task cost guidance. For a pilot, set a spend limit you're comfortable with for the first billing period, then watch the per-channel usage breakdown on the same page and adjust.
38There's no published per-task cost guidance. For a pilot, set a spend limit you're comfortable with for the first month, then watch the per-channel usage breakdown on the same page and adjust. If a promotional credit covers the pilot's usage, that breakdown shows \$0.00. In that case, watch the **List price** column of the **Spend by channel** table at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag) instead.
3939 
4040## What happens when the spend limit is reached
4141 
from line 60
6060 
6161## Attribute costs by channel
6262 
63In claude.ai you see spend per channel, not per user. The usage page at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag) shows each channel's spend. Channel work bills to your organization's usage balance, not to any user's seat.
63In claude.ai you see spend per channel, not per user. Channel work bills to your organization's usage balance, not to any user's seat.
64 
65The usage page at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag) shows spend broken down by channel, at list price. Usage covered by a promotional credit isn't counted there and shows as \$0.00. To see each channel's list-price spend for the current month including covered usage, use the **List price** column of the **Spend by channel** table at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag).
6466 
6567To attribute spend to teams or departments for showback or chargeback reporting, structure channels so each maps to one team or department, and give those channels [their own scopes](/docs/claude-tag/admins/attach-to-scope). The per-channel breakdown then reads as your per-team report, and per-channel spend limits act as team-level budgets.
6668 

claude-tag/admins/setup-overview Changed · +29 / -27 lines

from line 19
1919The console saves your progress, so you can leave and come back to where you stopped. When you've launched, [verify your setup](#verify-your-setup).
2020 
2121<Accordion title="Before you start: check that you have what setup needs">
22 | Prerequisite | Why you need it | If you don't have it |
23 | :------------------------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
24 | A **Team or Enterprise plan** on claude.ai | Claude Tag is available on Team and Enterprise plans, on Anthropic's first-party service. It isn't available on individual plans (Free, Pro, or Max), or for third-party deployments. | Start a Team or Enterprise plan at [claude.com/pricing](https://claude.com/pricing) |
25 | A Claude organization **without Zero Data Retention (ZDR)** | Claude Tag stores channel memory and session transcripts, which ZDR doesn't permit. | Claude Tag isn't available to ZDR organizations |
26 | **Routines** enabled for your Claude organization | Until it is, Claude answers every mention and DM with a reply that it's unavailable and does no work. | An admin enables Routines at [`claude.ai/admin-settings/claude-code`](https://claude.ai/admin-settings/claude-code) |
27 | **Owner** role in the Claude organization you're setting up | Pairing a workspace and creating Access bundles are Owner-only writes. Roles are per organization, so being an Owner elsewhere doesn't carry over. | Ask an Owner to run setup, or have one promote you at [`claude.ai/admin-settings/members`](https://claude.ai/admin-settings/members) |
28 | A **Slack workspace admin** | Running `@Claude connect` requires a Slack workspace admin; installing the app usually does too. | If that's someone else, [send them the install request](#if-you-re-not-the-slack-workspace-admin) early (app approval can take time), and plan to be online together when you pair; pairing codes expire 15 minutes after they're issued |
29 | **Usage credits** (Team plans) | Channel work draws from your organization's usage balance; on a Team plan nothing runs until credits are loaded. | Check whether your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise) before buying; otherwise, buy credits at [`claude.ai/admin-settings/usage`](https://claude.ai/admin-settings/usage) |
30 | *(Optional)* The **Claude GitHub App** linked to your Claude organization | Linking GitHub first turns setup's GitHub step into repository selection instead of an app install. | [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) first, or grant repository access after setup |
31 | *(Optional)* A **channel to test in** | You'll invite Claude to a channel to [verify your setup](#verify-your-setup). | Create a private Slack channel for the pilot, or pick any existing one |
22 | Prerequisite | Why you need it | If you don't have it |
23 | :------------------------------------------------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
24 | A **Team or Enterprise plan** on claude.ai | Claude Tag is available on Team and Enterprise plans, on Anthropic's first-party service. It isn't available on individual plans (Free, Pro, or Max), or for third-party deployments. | Start a Team or Enterprise plan at [claude.com/pricing](https://claude.com/pricing) |
25 | A Claude organization **without Zero Data Retention (ZDR) or customer-managed encryption (CMEK)** | Claude Tag stores channel memory and session transcripts, which ZDR doesn't permit. A CMEK policy doesn't allow Claude Tag either. | Claude Tag isn't available to organizations with a ZDR or CMEK policy |
26 | **Routines** enabled for your Claude organization | Until it is, Claude answers every mention and DM with a reply that it's unavailable and does no work. | An admin enables Routines at [`claude.ai/admin-settings/claude-code`](https://claude.ai/admin-settings/claude-code) |
27 | **Owner** role in the Claude organization you're setting up | Pairing a workspace and creating Access bundles are Owner-only writes. Roles are per organization, so being an Owner elsewhere doesn't carry over. | Ask an Owner to run setup, or have one promote you at [`claude.ai/admin-settings/members`](https://claude.ai/admin-settings/members) |
28 | A **Slack workspace admin** | Running `@Claude connect` requires a Slack workspace admin; installing the app usually does too. | If that's someone else, [send them the install request](#if-you-re-not-the-slack-workspace-admin) early (app approval can take time), and plan to be online together when you pair; pairing codes expire 15 minutes after they're issued |
29 | **Usage credits** (Team plans) | Channel work draws from your organization's usage balance; on a Team plan nothing runs until credits are loaded. | Check whether your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise) before buying; otherwise, buy credits at [`claude.ai/admin-settings/usage`](https://claude.ai/admin-settings/usage) |
30 | *(Optional)* The **Claude GitHub App** linked to your Claude organization | Linking GitHub first turns setup's GitHub step into repository selection instead of an app install. | [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) first, or grant repository access after setup |
31 | *(Optional)* A **channel to test in** | You'll invite Claude to a channel to [verify your setup](#verify-your-setup). | Create a private Slack channel for the pilot, or pick any existing one |
3232 
3333 If any of your services restrict traffic by IP, file the [network requirements](/docs/claude-tag/admins/network-requirements) request with your network team early; in many organizations, IP allowlist changes take days to approve.
3434 
from line 109
109109 
110110## Connect GitHub
111111 
112**Where:** the Claude Tag setup page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). If the app isn't installed yet, the step sends you to github.com to install it.
112**Where:** the Claude Tag setup page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). If the app isn't installed yet, select **Start setup** on the step to open your [Claude GitHub settings](/docs/claude-tag/admins/configure-github), where you sign in with GitHub, authorize your organization, and install the app.
113113 
114114Claude reaches GitHub through the [Claude GitHub App](/docs/claude-tag/admins/configure-github) rather than an account and credential, so GitHub has its own step. The setup page shows one of three things, depending on where the Claude GitHub App is installed:
115115 
116* **Install the Claude GitHub App**, when the app isn't linked to your Claude organization yet. Only an owner of your GitHub organization can install it. If that's you, follow the steps shown. If not, send the message the step shows to a GitHub organization owner, skip this step, and continue with setup. After they install the app, [grant repositories](/docs/claude-tag/admins/configure-github#grant-repository-access) from the admin page.
116* **Connect GitHub**, when the app isn't linked to your Claude organization yet. Only an owner of your GitHub organization can install the app. If that's you, follow the steps shown. If not, send the message the step shows to a GitHub organization owner, skip this step, and continue with setup. After they install the app, [grant repositories](/docs/claude-tag/admins/configure-github#grant-repository-access) from the admin page.
117117* **Choose your GitHub repos**, when the app is already linked. Grant every repository or pick specific ones.
118118* **The Claude app is installed on \[username], a personal account**, when the app was installed on someone's personal GitHub account rather than an organization. Claude Tag connects to a GitHub organization only. A GitHub organization owner installs the app on the organization that owns your repositories (see [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization)). You can skip the step and continue with setup while that happens, then [grant repositories](/docs/claude-tag/admins/configure-github#grant-repository-access) from the admin page afterward.
119119 
from line 153
153153 
154154**Where:** the Claude Tag setup page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
155155 
156Channel work draws from your organization's usage balance, not from individual seats; the spend limit caps how much of that balance Claude Tag can use each billing period. DMs run on the user's own claude.ai account and aren't capped by this limit. If your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise), the launch screen shows the amount and the date it runs through, and after launch the admin page shows it under **Included usage** with how much is used. You're billed for usage beyond it, up to the spend limit.
156Channel work draws from your organization's usage balance, not from individual seats; the spend limit caps how much of that balance Claude Tag can use each month. DMs run on the user's own claude.ai account and aren't capped by this limit. If your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise), the launch screen shows the amount and the date it runs through, and after launch the admin page shows it under **Included usage** with how much is used. You're billed for usage beyond it, up to the spend limit.
157157 
158158If the setup page shows a **Buy usage credits** step before Launch, buy credits on that step to continue. The launch screen then doesn't include **Set monthly spend limits**, so set a limit after launch at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag).
159159 
from line 163
163163 </Step>
164164 
165165 <Step title="Let members know they can now tag Claude">
166 The toggle is on by default: after launch, Claude DMs each member of the workspace to help them get started. Those DMs don't count toward your usage. Turn the toggle off to skip them. The same setting appears on the admin page afterward as **Let people know they can talk to Claude**, marked **Members notified** once the DMs have gone out.
166 The toggle is on by default: after launch, Claude DMs each member of the workspace to help them get started. Those DMs don't count toward your usage. Turn the toggle off to skip them.
167 
168 The admin page has a matching row, **Let people know they can talk to Claude**. To send the DMs from the admin page, select **Notify members now** on that row and confirm. The row reads **Members notified** once the DMs have gone out.
167169 </Step>
168170 
169171 <Step title="Click Launch Claude Tag">
from line 243
241243 
242244Every entry has the same sections: **Connectors**, **Repositories**, **Plugins**, **Custom instructions**, **Access bundles**, and, under **Advanced**, the **Default model**. An [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of connections, repositories, plugins, and instructions that you can attach to more than one place. Setup created one on your workspace's entry, named after the workspace (for example, **Tag Test default**), holding the tools you connected.
243245 
244| To do this | Go to | Learn more |
245| :---------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------------- |
246| Change the model Claude replies with | The entry's **Advanced** section, **Default model**. Set it on **Default Slack** to change it everywhere, or on one channel. | [Choose the model for a scope](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope) |
247| Give Claude standing instructions | The **Custom instructions** field on **Default Slack** for every channel, or on one channel's entry for that channel only. | [Customize](/docs/claude-tag/admins/customize) |
248| Connect another tool, or one you skipped | **Connectors** on the entry, or the bundle named after your workspace under **Access bundles**. | [Give Claude access](/docs/claude-tag/admins/add-connections) |
249| Let Claude reach a site or API that has no credential | The **Domains** list of the Access bundle, under **Access bundles**. | [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) |
250| Grant more repositories | **Repositories** on the entry. | [Configure GitHub access](/docs/claude-tag/admins/configure-github) |
251| Give one channel more than the default | Select the channel and add to it. | [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope) |
252| Limit where Claude works or who can use it | | [Restrict where Claude operates](/docs/claude-tag/admins/restrict-access) |
253| Pair another workspace, or disconnect one | The Slack row's **⋮** menu under **Where Claude Tag works**. | [Manage workspaces](/docs/claude-tag/admins/workspaces) |
254| Change the spend limit | [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag). | [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) |
255| Turn Claude Tag off | The **Enable Claude Tag for your organization** toggle at the top of the admin page. | |
256| Bring in the first users | | [Getting started for users](/docs/claude-tag/users/getting-started) |
246| To do this | Go to | Learn more |
247| :---------------------------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------------- |
248| Change the model Claude replies with | The entry's **Advanced** section, **Default model**. Set it on **Default Slack** to change it everywhere, or on one channel. | [Choose the model for a scope](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope) |
249| Give Claude standing instructions | The **Custom instructions** field on **Default Slack** for every channel, or on one channel's entry for that channel only. | [Customize](/docs/claude-tag/admins/customize) |
250| Connect another tool, or one you skipped | **Connectors** on the entry, or the bundle named after your workspace under **Access bundles**. | [Give Claude access](/docs/claude-tag/admins/add-connections) |
251| Let Claude reach a site or API that has no credential | The **Domains** list of the Access bundle, under **Access bundles**. | [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) |
252| Grant more repositories | **Repositories** on the entry. | [Configure GitHub access](/docs/claude-tag/admins/configure-github) |
253| Give one channel more than the default | Select the channel and add to it. | [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope) |
254| Limit where Claude works or who can use it | | [Restrict where Claude operates](/docs/claude-tag/admins/restrict-access) |
255| Pair another workspace, or disconnect one | The Slack row's **⋮** menu under **Where Claude Tag works**. Disconnecting permanently deletes the workspace's Claude data. See [Data lifecycle and deletion](/docs/claude-tag/concepts/data-lifecycle). | [Manage workspaces](/docs/claude-tag/admins/workspaces) |
256| Change the spend limit | [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag). | [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) |
257| Turn Claude Tag off | The **Enable Claude Tag for your organization** toggle at the top of the admin page. | |
258| Bring in the first users | | [Getting started for users](/docs/claude-tag/users/getting-started) |
257259 
258260## Common setup issues
259261 

claude-tag/admins/troubleshooting Changed · +16 / -6 lines

from line 12
1212 
1313If someone reports that Claude can't reach a service you connected, check two things before anything else:
1414 
15* The connection is in a [bundle attached to that channel's scope](/docs/claude-tag/admins/attach-to-scope).
15* The connection reaches that channel through an attached bundle. To check, go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Claude Tag's access** > **Slack** > the channel's scope (or its workspace's scope, if the channel isn't listed) > **Access summary**, which includes access [inherited from wider scopes](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit). If there's no **Access summary** section, or the connection isn't in it, [attach the bundle](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) to the channel's scope; if the channel has no scope yet, select **Add channel** on its workspace to [create the scope](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) first.
1616* The test ran in a new thread; an existing thread isn't told about a connection added after it started, though the connection works there if the request names the service.
1717 
1818## Setup errors
from line 126
126126 
127127**What it means**
128128 
129**Allow Claude to work in channels with guests** is set to **Restrict** for this channel's [scope](/docs/claude-tag/concepts/glossary#scope), so Claude checks the channel for guests before replying, and this install predates the `users:read` permission that check needs.
129**Allow Claude to work in channels with guests** is set to **Restrict** or **Channel only** for this channel's [scope](/docs/claude-tag/concepts/glossary#scope), so Claude checks the channel for guests before replying, and this install predates the `users:read` permission that check needs.
130130 
131131**How to resolve**
132132 
from line 173
173173Either fix works:
174174 
175175* Remove the guests from the channel, or move the conversation to a channel with no guests; this changes no settings, so no other channel is affected.
176* Or set **Allow Claude to work in channels with guests** to **Allow** for the scope covering this channel. The setting is at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the **Slack** tab under **Claude Tag's access**, in the scope's collapsed **Advanced** section. **Allow** applies to every guest channel that scope covers, and guests there can see Claude's replies and interact with it. To limit it to one channel, set it on the channel's own scope. See [restrict guest channels](/docs/claude-tag/admins/restrict-access#restrict-guest-channels) for the full exposure picture.
176* Change **Allow Claude to work in channels with guests** for the scope covering this channel, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) **Claude Tag's access** **Slack** the scope the collapsed **Advanced** section. **Channel only** restores replies with [channel-only access](/docs/claude-tag/admins/restrict-access#how-channel-only-works). **Allow** restores replies with the scope's full access, and only an organization Owner can choose it. See [restrict guest channels](/docs/claude-tag/admins/restrict-access#restrict-guest-channels) for what each value exposes.
177177 
178**Allow** restores replies, not workspace search. Claude can't search the workspace from a channel that includes guests, even when the setting is **Allow**. Removing the guests restores search as well.
178Either value applies to every guest channel that scope covers. To limit the change to one channel, set the value on the channel's own scope.
179179 
180Either value restores replies, not workspace search. Claude can't search the workspace from a channel that includes guests, even under **Allow**. Removing the guests restores search as well.
181 
180182If the fix worked, a mention in the channel gets a reply.
181183 
182184### Couldn't check this channel just now
from line 338
3363382. Have an Owner in that organization [disconnect the workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing) from their **Connected workspaces** list.
3373393. Send `@Claude connect` again for a fresh code and redeem it here.
338340 
341<Warning>
342 Disconnecting deletes the workspace's Claude data, including its memory, channel configurations, sessions, and the routines set up in its channels. The deletion can't be undone. See [Data lifecycle and deletion](/docs/claude-tag/concepts/data-lifecycle) for the full list of what's deleted.
343</Warning>
344 
339345<a id="claim-code-invalid" />
340346 
341347### Claim code is invalid, expired, or already used
from line 464
4584642. If the message persists, check which Claude organization the workspace is paired to. If your company has more than one (a trial organization alongside the main one, for example), an Owner in the wrong organization can [revoke the pairing](/docs/claude-tag/admins/workspaces#revoke-a-pairing) so you can pair the workspace to the right one.
4594653. If the right organization has the toggle on and the message persists, contact your account team to confirm Claude Tag is enabled for it.
460466 
467<Warning>
468 Revoking the pairing deletes the workspace's Claude data, including its memory, channel configurations, sessions, and the routines set up in its channels. The deletion can't be undone. See [Data lifecycle and deletion](/docs/claude-tag/concepts/data-lifecycle) for the full list of what's deleted.
469</Warning>
470 
461471### Claude Tag is unavailable because Routines are not enabled
462472 
463473**What you see**
from line 590
5805902. **A bundle with GitHub access on this channel's scope**: bundles attach per scope, so the bundle that carries GitHub access must be attached to a scope that covers this channel; [Attach the bundle to a scope](/docs/claude-tag/admins/attach-to-scope) covers attachment and inheritance. If the bundle is attached, asking `@Claude what can you access from this channel?` in a new thread lists GitHub.
5815913. **A fresh thread**: a new thread picks up every configuration change, so test in one before checking anything further.
5825924. **The repository granted in the bundle**: the repository must be listed in the bundle's **Repositories** tab, per [Grant repository access](/docs/claude-tag/admins/configure-github#grant-repository-access). If the repository is granted, asking Claude to read a file from it works in a new thread. Granting makes the repository available to clone, but the code doesn't enter a session until a request names it.
5835. **The GitHub App installation covers the repository**: if Claude reports a repository isn't available, isn't configured, or returned a 403, check the installation, since the app's repository selection is upstream of the bundle grant. At [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github), the organization that owns the repository should show **Connected** under **Connected GitHub accounts**. If it appears under **Unlinked accounts** with a **Needs permissions** status instead, the install is waiting on a GitHub organization owner. Click **Review permissions** to approve it on github.com. If you aren't a GitHub organization owner, use **Copy message** under **Not a GitHub account owner?** on that settings page to send the request to someone who is. If the organization isn't listed at all, install the app with **Install on another organization**; [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) covers both.
5935. **The GitHub App installation covers the repository**: if Claude reports a repository isn't available, isn't configured, or returned a 403, check the installation, since the app's repository selection is upstream of the bundle grant. At [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github), the organization that owns the repository should show **Connected** under **Connected GitHub accounts**. If its row shows a **Needs permissions** status instead, the install is waiting on a GitHub organization owner. Click **Review permissions** to approve it on github.com. If you aren't a GitHub organization owner, use **Copy message** under **Not a GitHub account owner?** on that settings page to send the request to someone who is. If the organization isn't listed at all, install the app with **Install on another organization**; [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) covers both.
584594 
585595For GitHub Enterprise Server repositories, confirm [the GHE host is registered](/docs/claude-tag/admins/configure-github#github-enterprise-server) instead. The github.com App install doesn't cover them.
586596 

claude-tag/concepts/agent-identity Changed · +10 / -4 lines

### Personal connectors in a channel

from line 1
11# How agent identity works
22 
3> Claude Tag acts under its own service accounts in Slack channels, not as you. See how channel access is bounded, how credentials reach it, and why DMs differ.
3> Claude Tag acts under its own service accounts in Slack channels, not as you. See how channel access is bounded, how credentials reach it, how Claude uses your personal connectors for your own tasks in a channel, and why DMs differ.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
from line 8
88 
99Claude Tag's identity depends on where you message it.
1010 
11In Slack channels, Claude acts with its own service accounts, rather than as a specific user. An organization Owner [provisions this identity during setup](/docs/claude-tag/admins/setup-overview), so it arrives with its own account in each system it works in: the Claude app in Slack, the Claude GitHub App on GitHub, and a service account in every other connected tool. Actions it takes are attributed to those accounts; for example, posts come from the Claude app and pull requests show the Claude GitHub App as the author.
11In Slack channels, Claude acts with its own service accounts, rather than as a specific user. An organization Owner [provisions this identity during setup](/docs/claude-tag/admins/setup-overview), so it arrives with its own account in each system it works in: the Claude app in Slack, the Claude GitHub App on GitHub, and a service account in every other connected tool. Actions it takes are attributed to those accounts; for example, posts come from the Claude app and pull requests show the Claude GitHub App as the author. In organizations where personal connectors in channels is available, Claude can also use your own claude.ai connectors for a task you hand it in a channel, after you allow it. See [Personal connectors in a channel](#personal-connectors-in-a-channel).
1212 
1313In direct messages (DMs) between a user and `@Claude`, the provisioned identity does not apply. DMs are one-to-one only; group DMs aren't supported. A DM has no channel to scope it to, so a DM session runs on [the individual's own claude.ai account](#direct-message-channels) instead, with their personal connectors. GitHub is the exception in attribution: a pull request opened from a DM is authored by the Claude GitHub App, the same as in channels, though the session can only work with repositories connected on that user's own account. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
1414 
from line 93
9393 
9494* **Configure once.** Everyone in the scope can use it immediately.
9595* **Predictability.** What Claude can do never changes based on who asked.
96* **Personal connectors apply in DMs.** A shared channel uses only the service-account connections an admin attached, not connectors on anyone's claude.ai account.
97* **Clean audit.** Actions in connected tools show up under a service account your security team already knows how to reason about.
96* **Personal connectors are separate.** A shared channel session uses only the service-account connections an admin attached. Where [personal connectors in channels](#personal-connectors-in-a-channel) is available, Claude uses the connectors on your own claude.ai account only for your own tasks, after you allow it.
97* **Clean audit.** Actions the channel session takes in connected tools show up under a service account your security team already knows how to reason about.
9898 
9999That service-account identity is also how Claude appears wherever it acts. In Slack, it posts as the Claude app. On GitHub, commits and pull requests show the Claude GitHub App, and pull requests link back to the Slack thread they came from. In every other connected service, actions appear under the service account an admin provisioned, in that service's audit log.
100 
101### Personal connectors in a channel
102 
103A channel session works with the channel's Access bundles, so the [connectors on your own claude.ai account](/docs/connectors/overview) are not part of it. Personal connectors in channels is available to a limited number of organizations. Where it is available and a task you hand Claude needs something only your connectors can reach, Claude can use your connector for that part of the work, and it asks you before it starts. The work runs with your permissions and is recorded under your name. Requests other people make to Claude in the task's thread run with the channel's own access, not with your connectors. Claude is designed to take direction from you, treating what other people post in the thread as information for the task rather than as instructions.
104 
105[Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) covers how you approve connector use, when Claude holds a result for your review before posting, what other people in the channel see, and how to stop a task.
100106 
101107## Direct message channels
102108 

claude-tag/concepts/glossary Changed · +3 / -3 lines

from line 20
2020 
2121## Channel manager
2222 
23A member of your Claude organization whom an Owner has named to set up specific channels. For each channel assigned to them, a channel manager sets the default model, adds repositories their own GitHub account can write to, and manages credentials in the channel's own bundle, without holding the Owner role. See [Delegate channel setup to channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers).
23A member of your Claude organization whom an Owner has named to set up specific channels. For each channel assigned to them, a channel manager sets the default model, adds repositories their own GitHub account is an admin of, and manages credentials and plugins in the channel's own bundle, without holding the Owner role. See [Delegate channel setup to channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers).
2424 
2525## Channel memory
2626 
from line 43
4343 
4444A credential for one external service that Claude uses on the channel's behalf, like a Datadog API key or a GitHub App installation. Connections belong to the agent identity, not to any user, and are grouped into [Access bundles](#access-bundle) by an admin.
4545 
46A connection is not a connector. A connector belongs to your personal claude.ai account. Claude cannot use your connectors in channels; it uses the channel's connections. The one exception is a DM, where it uses your own account instead; see [how DMs work in this model](/docs/claude-tag/concepts/agent-identity#direct-message-channels).
46A connection is not a connector. A connector belongs to your personal claude.ai account. A channel session uses the channel's connections. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use your connectors there for your own tasks, after you allow it. A DM uses your own account instead, as [how DMs work in this model](/docs/claude-tag/concepts/agent-identity#direct-message-channels) describes.
4747 
4848## Connector
4949 
50A tool you add to your own claude.ai account, like Gmail, Google Drive, or a custom MCP server, listed under [Customize > Connectors](https://claude.ai/customize/connectors). Connectors are personal; in Slack they apply only in DMs. For the agent-side equivalent that works in channels, see [Connection](#connection).
50A tool you add to your own claude.ai account, like Gmail, Google Drive, or a custom MCP server, listed under [Customize > Connectors](https://claude.ai/customize/connectors). Connectors are personal. In Slack they apply in DMs. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use them in a channel for your own tasks, after you allow it. For the agent-side equivalent that works in channels, see [Connection](#connection).
5151 
5252## Environment
5353 

claude-tag/concepts/personal-connectors New page · 61 lines, new page

# Personal connectors in channels ## Where your connectors apply ## Control connector use ### Approve connector use ### Review results before posting ### Stop connector use ## What other people in the channel see ## Related resources

A whole new page. There's nothing to diff it against, so here is what it says.

# Personal connectors in channels

> Claude can use your own claude.ai connectors, called personal connectors, for your tasks in a Slack channel. See how you approve connector use, when Claude asks you to review a result before posting it, and what other people in the channel can reach.

export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;

<BetaNote />

Personal connectors are the tools you add to your own claude.ai account, like your calendar or your email. When a task you ask for in a Slack channel needs one of your own tools, Claude can offer to use your connector for it.

Connector use in channels is available to a limited number of organizations. If Claude never offers to use your connectors in a channel, connector use in channels may not be available to your organization, and the channel works with admin-attached connections as described in [how agent identity works](/docs/claude-tag/concepts/agent-identity).

## Where your connectors apply

In a channel, an admin decides the shared access. The channel uses the connections an admin attached to it, and everyone who asks there gets the same access. In organizations where connector use in channels is available, Claude can also use the connectors on your own claude.ai account in that channel. When you ask Claude there for something that needs one of your own tools, it can use your connector for your task.

In a direct message (DM), your connectors apply on their own, because a DM runs on [your own claude.ai account](/docs/claude-tag/concepts/agent-identity#direct-message-channels).

[Routines](/docs/claude-tag/users/proactivity) and other work Claude starts on its own in a channel use the channel's connections, never your connectors. Claude uses your connectors only while working on a request you made yourself.

Your connectors serve only you. When someone else in the channel asks Claude for something, their request doesn't control or use your connectors, even in a shared channel. Claude works with your permissions, reaches only what your account can reach, and records what it does under your name.

To add or remove connectors on your account, open the **Customize > Connectors** page on claude.ai; see [connectors on claude.ai](/docs/connectors/overview) for setup.

## Control connector use

### Approve connector use

By design, Claude asks before it starts using your connectors in a channel. The first time a task calls for one of your connectors, Claude shows you a prompt in the thread that only you can see, with three choices:

* **Allow** starts the work in auto mode. Claude uses your connectors as the task needs them and checks with you before posting anything that looks sensitive.
* **Allow with review** starts the work and shows you every result to approve before it posts to the channel.
* **Don't allow** declines this request, and Claude doesn't use your connectors. A later request can prompt you again.

To save **Allow** or **Allow with review** for future tasks in every channel, select the **Use this choice for future requests** checkbox on the prompt before you choose. Once you've saved a choice, Claude starts a task you @-mention it for without showing the prompt.

To change a saved answer, open the Claude app in Slack and select its **Home** tab. The **Home** tab offers **Auto mode**, **Ask every time**, and **Allow with review**. **Ask every time** is the setting before you save a choice.

### Review results before posting

Claude can hold a result and show it to you before anything posts to the channel. When you chose **Allow with review**, Claude holds every result. When you chose **Allow**, Claude holds a result when the content looks sensitive and posts the rest directly. Once you approve a held result, Claude posts it in the thread where you asked.

On the Enterprise plan, an Owner can set the review rule for a scope with the **Delegated task results** setting, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope → **Advanced** → **Delegated task results**. **Require review** removes **Allow** from the prompt and **Auto mode** from the **Home** tab, so Claude holds every result for your review. **Share without review** removes **Allow with review** from both.

### Stop connector use

To stop a task that's using your connectors, select **Stop** under the message in the task's thread where Claude says it's going to use your connectors. Only you can see the **Stop** button.

## What other people in the channel see

Results stay visible in the channel. What Claude posts back to a channel thread is readable by everyone there, like any other work Claude does in a channel. Claude's detailed work on a task you approved lives in a session only you can open. The work runs with your permissions and is recorded under your name.

Other people can't use your connectors. Requests other people make to Claude in your task's thread run with the channel's own access, not with yours.

While Claude works on your connector task, it is designed to take direction from you and to treat what other people post in the thread as information for the task rather than as instructions.

## Related resources

* [How agent identity works](/docs/claude-tag/concepts/agent-identity): whose identity and access Claude uses in channels and DMs
* [Connectors](/docs/connectors/overview): set up and manage connectors on your claude.ai account
* [Get started](/docs/claude-tag/users/getting-started): hand Claude your first task in a channel

claude-tag/concepts/security-and-data Changed · +5 / -3 lines

from line 35
3535* **Persists:** The thread, its visible work, and anything pushed to a branch, opened as a pull request, or posted into Slack.
3636* **Does not persist:** Files that existed only inside the sandbox. To keep generated files, ask Claude to push them to a branch or post them in the thread.
3737 
38Claude Tag retains channel memory and session transcripts. Because of that retention, Claude Tag isn't available to organizations with Zero Data Retention (ZDR) enabled.
38Claude Tag retains channel memory and session transcripts. Because of that retention, Claude Tag isn't available to organizations with Zero Data Retention (ZDR) enabled. Claude Tag also isn't available to organizations with a customer-managed encryption (CMEK) policy.
3939 
4040### Credential storage
4141 
from line 65
6565 
6666A connection belongs to that agent identity and is shared by everyone the bundle's scope covers. Anyone in a channel under that scope can ask Claude to act with the credential, so whatever the connected account can read or write is available to every member of those channels. Connect a dedicated identity you control for each service, such as a `[email protected]` seat or a native service account, rather than a personal login. A dedicated account keeps the agent's actions separately auditable in each tool's logs and lets you revoke its access without affecting a person; see [Create a dedicated account per service](/docs/claude-tag/admins/add-connections#create-a-dedicated-account-per-service).
6767 
68DMs with `@Claude` run on the user's own claude.ai account instead, with that user's personal connectors, and work there is attributed to them, except pull requests, which the Claude GitHub App authors from DMs as well. Personal connectors apply only in DMs, never in channels. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
68DMs with `@Claude` run on the user's own claude.ai account instead, with that user's personal connectors, and work there is attributed to them, except pull requests, which the Claude GitHub App authors from DMs as well. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
6969 
70Personal connectors in channels is available to a limited number of organizations. Where it is available, Claude uses a user's personal connectors in a channel only for that user's own tasks, after the user allows it. The work runs with that user's permissions and is recorded under their name. Requests other people make to Claude in the task's thread run with the channel's own access, not with that user's connectors. Claude is designed to take direction from the connector's owner, treating what other people post in the thread as information for the task rather than as instructions, and the owner can tell Claude in the task's thread to stop. See [Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors).
71 
7072### Isolate credentials between channels
7173 
7274A channel session can use only the [Access bundles](/docs/claude-tag/admins/add-connections) attached in one of three places:
from line 85
8385 
84861. Attach its bundle to that channel and nowhere broader.
85872. Keep the channel private. A bundle on a public channel [grants its access to anyone who joins](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel).
863. Check the channel's **Access summary** on the [Slack tab in admin settings](/docs/claude-tag/admins/attach-to-scope). It shows the access the channel actually gets, including what it inherits from the workspace and Default Slack access.
883. Check the channel's **Connectors**, **Repositories**, and **Plugins** sections on the [Slack tab in admin settings](/docs/claude-tag/admins/attach-to-scope). They list the access the channel gets, including rows inherited from the workspace or from Default Slack access, each with an origin line naming where it comes from.
8789 
8890Claude [doesn't operate in externally shared channels](/docs/claude-tag/admins/restrict-access#externally-shared-channels), so a channel shared with another company never has a session to isolate.
8991 

claude-tag/concepts/settings-map Changed · +11 / -9 lines

from line 1
11# Claude Tag settings map
22 
3> Claude Tag settings map: the admin page for access and behavior, the usage page for spend limits, the in-Slack Configure link for channel instructions, and personal connectors for DMs. Claude Managed Agents is configured separately on the Claude Platform.
3> Claude Tag settings map: the admin page for access and behavior, the usage page for spend limits, the in-Slack Configure link for channel instructions, and personal connectors for DMs and your own tasks in channels. Claude Managed Agents is configured separately on the Claude Platform.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
from line 8
88 
99Claude Tag's settings live on claude.ai, split across a few pages that each own a different kind of setting. Which page you need depends on what you're changing. The table maps each surface to what it controls.
1010 
11| Surface | Who changes it | What it controls |
12| :--------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
13| [Claude Tag admin page](https://claude.ai/admin-settings/claude-tag) | An Owner in your Claude organization | Access, behavior, and restrictions for channels, per [scope](/docs/claude-tag/concepts/glossary#scope) |
14| [Usage page](https://claude.ai/admin-settings/usage/claude-tag) | An admin | Spend limits and each channel's spend against them |
15| [Analytics page](https://claude.ai/analytics/claude-tag) | Anyone who can view the Analytics dashboard | Spend trends, projections, and per-channel reports; read-only |
16| The **Configure** link in the footer of any Claude reply in a channel | Channel members (unless an admin restricts editing) and [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | One channel's instructions and whether Claude replies there without an @-mention. Channel managers also set the channel's default model, repositories, and connections |
17| [Customize > Connectors](https://claude.ai/customize/connectors) on your own claude.ai account | You | Which of your personal tools apply in [DMs](/docs/claude-tag/concepts/agent-identity#direct-message-channels) |
11| Surface | Who changes it | What it controls |
12| :--------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
13| [Claude Tag admin page](https://claude.ai/admin-settings/claude-tag) | An Owner in your Claude organization | Access, behavior, and restrictions for channels, per [scope](/docs/claude-tag/concepts/glossary#scope) |
14| [Usage page](https://claude.ai/admin-settings/usage/claude-tag) | An admin | Spend limits and each channel's spend against them |
15| [Analytics page](https://claude.ai/analytics/claude-tag) | Anyone who can view the Analytics dashboard | Spend trends, projections, and per-channel reports; read-only |
16| The **Configure** link in the footer of any Claude reply in a channel | Channel members (unless an admin restricts editing) and [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | One channel's instructions and whether Claude replies there without an @-mention. Channel managers also set the channel's default model, repositories, connections, and plugins |
17| [Customize > Connectors](https://claude.ai/customize/connectors) on your own claude.ai account | You | Which of your personal tools apply in [DMs](/docs/claude-tag/concepts/agent-identity#direct-message-channels) and, where available, for [your own tasks in a channel](/docs/claude-tag/concepts/personal-connectors) |
1818 
1919Channel memory and routines aren't in the table because you change them by talking to Claude in the channel; see [what anyone can change from the channel](/docs/claude-tag/admins/customize#change-behavior-from-the-channel). Owners can review both, as each scope's memory files and scheduled work, from [the Audit page](/docs/claude-tag/admins/audit), labeled **Activity** in the console.
2020 
from line 33
3333 
3434Spend limits live at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag), a different page than the Claude Tag admin page. It holds the organization-wide spend limit, the default spend limit for channels, per-channel limits, and each channel's spend against its limit. If your organization bills through a reseller, this page is not available. See [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) for funding the usage balance and what users see when a limit is reached.
3535 
36Usage covered by a promotional credit isn't counted on the usage page and shows as \$0.00 there. To see each channel's list-price spend for the current month including covered usage, use the **List price** column of the **Spend by channel** table at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag).
37 
3638Spend trends live at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag), the Claude Tag section of the Analytics dashboard. It shows total and projected spend, spend by channel, and [spend by kind of work](/docs/claude-tag/admins/set-spend-limit#see-spend-by-kind-of-work) for the period you pick, and anyone with permission to view the Analytics dashboard can open it. It has no controls; see [Usage analytics](/docs/claude-tag/admins/restrict-access#usage-analytics).
3739 
3840## The Configure page
from line 51
4951 
5052## Personal connectors on claude.ai
5153 
52Connectors you add to your own claude.ai account, under **Customize > Connectors**, apply only in DMs with Claude, because [a DM runs on your own account](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A channel uses only the connections an admin attached to it, and personal connectors never apply there. Slack has no connector settings of its own.
54Connectors you add to your own claude.ai account, under **Customize > Connectors**, apply in DMs with Claude, because [a DM runs on your own account](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A channel session uses the connections an admin attached to it. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use your personal connectors there for your own tasks, after you allow it. Slack has no connector settings of its own.
5355 
5456See [connectors on claude.ai](/docs/connectors/overview) for setting one up, and [the troubleshooting entry](/docs/claude-tag/users/troubleshooting#a-connector-works-on-claude-ai-but-not-in-slack) if a connector you use on claude.ai is missing in Slack.
5557 

claude-tag/users/troubleshooting Changed · +23 / -19 lines

from line 156
156156 
157157* Remove the guests from the channel. In Slack, open **Channel details** → **Members** and filter by "guests"; guests show a **guest** badge on their Slack profile.
158158* Move the conversation to a channel with no guests.
159* Ask a claude.ai organization owner to allow Claude to respond in channels that include guests, and send them [the guest access setting](/docs/claude-tag/admins/restrict-access#restrict-guest-channels). If you don't know who your organization's owners are, ask whoever set Claude up in your workspace.
159* Ask a claude.ai organization owner to change the guest setting for this channel, and send them [the guest access setting](/docs/claude-tag/admins/restrict-access#restrict-guest-channels). They can let Claude reply with only the channel's own setup, or with full access. If you don't know who your organization's owners are, ask whoever set Claude up in your workspace.
160160 
161161The guest access setting restores replies, not workspace search. Claude can't search the workspace from a channel that includes guests, even when it's allowed to respond there. Removing the guests or moving the conversation to a channel with no guests restores search as well.
162162 
from line 228
228228 
229229## Claude stopped mid-task
230230 
231The messages in this section mean a session started and then stopped partway through. In most cases the work isn't lost, and the same thread picks up where it stopped. Each entry says whether anything needs redoing.
231The messages in this section mean a session started and then stopped partway through. For most of them the work is still there, and the same thread picks up where it stopped. For a disconnect, work that existed only on the machine running the session can be lost. Each entry says whether anything needs redoing.
232232 
233233### I hit repeated API server errors
234234 
from line 306
306306 
307307**What you see**
308308 
309Claude posts in the thread:
309In the thread, Claude posts a message that begins "I got disconnected partway through and may not have finished" or "I lost my connection". The rest of the message either says that Claude is recovering on its own and how long to wait before mentioning it, or asks you to mention it so it can start again.
310310 
311> I got disconnected partway through and may not have finished. Reconnecting and resuming automatically usually within a few minutes, though a slow recovery can take much longer. Mention me if I don't follow up.
311A disconnect message appears in a thread where you're working with Claude, including a direct-message thread; Claude doesn't post one in a channel it's only watching or from a routine.
312312 
313When Claude reconnects, it edits that message to "I reconnected and I'm carrying on where I left off. No need to mention me." When automatic recovery isn't armed, the message is "I got disconnected partway through and may not have finished. Mention me to pick up where I left off." instead.
313If the machine running the session comes back, Claude removes the disconnect message from the thread, and there's nothing for you to do. If Claude restarts on a fresh machine instead, it edits the disconnect message to:
314314 
315You can see it in a thread where you're working with Claude, including a direct-message thread; Claude doesn't post it in a channel it's only watching or from a routine.
315> I've restarted on a fresh machine. Uncommitted changes from before the restart may not have carried over, so I'll re-check my work before continuing. No need to mention me.
316316 
317317**What it means**
318318 
319The sandbox running this thread's session stopped partway through a turn, so the step Claude was on may not have finished. The thread's conversation is intact.
319The machine running this thread's session, the sandbox Claude works in, stopped partway through a turn, so the step Claude was on may not have finished. The thread's conversation is intact, and so is work Claude pushed to a branch, opened as a pull request, or posted into the thread. Files and drafts that existed only on the machine that stopped may not carry over to a fresh one. The entry [Claude lost work it created earlier](#claude-lost-work-it-created-earlier) describes the same kind of loss.
320320 
321321**How to resolve**
322322 
323Wait for the reconnect message, or mention Claude in the same thread when the message asks you to. Claude resumes there and continues from the conversation; ask it to check on the step it was working on and redo anything that didn't finish. If the same notice comes back, the underlying problem hasn't cleared yet. Wait a few minutes and mention Claude again.
323If the message says how long to wait, wait that long. If Claude hasn't posted in the thread by then, or if the message asks you to mention Claude, mention `@Claude` in the same thread. Claude runs the interrupted step again, so check the files and drafts from before the disconnect and ask Claude to redo anything that's missing.
324324 
325If the message says there's no need to mention Claude, wait for Claude to post in the thread. Claude re-checks its earlier work, then continues.
326 
327If a disconnect message comes back after you mention Claude, the problem hasn't cleared yet. Wait a few minutes, then mention Claude in the thread again.
328 
325329### Something went wrong and I couldn't finish this turn
326330 
327331**What you see**
from line 478
474478 
475479**What it means**
476480 
477Where you message Claude determines which connectors apply. A channel uses only the connections an admin attached to it, and personal connectors never apply there. A DM runs on your own claude.ai account and uses that account's connectors.
481Where you message Claude determines which connectors apply. A channel session uses the connections an admin attached to it. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use your personal connectors there for your own tasks, after you allow it. A DM runs on your own claude.ai account and uses that account's connectors.
478482 
479483You set up and authenticate connectors on claude.ai under **Customize > Connectors**; Slack has no connector settings of its own. The [settings map](/docs/claude-tag/concepts/settings-map) covers every settings surface.
480484 
481485**How to resolve**
482486 
483For a channel, ask your admin to [add a connection](/docs/claude-tag/admins/add-connections) for the service.
487For a channel, ask your admin to [add a connection](/docs/claude-tag/admins/add-connections) for the service. If [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available to your organization, Claude can also use your personal connectors for your own tasks, after you allow it.
484488 
485489For a DM, work through these in order:
486490 

skills/how-to Changed · +1 / -5 lines

from line 45
4545 
4646**name**: Lowercase letters, numbers, and hyphens only. Maximum 64 characters. Must match the directory name.
4747 
48**description**: Explains what the skill does and when to use it. Claude uses this to determine when to invoke your skill.
49 
50<Warning>
51 Claude.ai limits descriptions to **200 characters**. The [Agent Skills specification](https://agentskills.io/specification) allows up to 1024 characters, but skills uploaded to Claude.ai must use the shorter limit.
52</Warning>
48**description**: Explains what the skill does and when to use it. Claude uses this to determine when to invoke your skill. Maximum 1,024 characters, the same limit as the [Agent Skills specification](https://agentskills.io/specification).
5349 
5450### Markdown body
5551 

claude-tag/admins/connections/google Changed · +1 / -1 lines

from line 10
1010 
1111Connecting Google Drive, Calendar, and Gmail lets Claude read documents, spreadsheets, calendar events, and email from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
1212 
13This is an HTTP API connection, not a personal claude.ai connector. A member's own Google connector applies only in DMs.
13This is an HTTP API connection, not a personal claude.ai connector. A member's own Google connector applies in DMs. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use it in a channel for that member's own tasks, after the member allows it.
1414 
1515## Choose OAuth or a service account
1616 

claude-tag/admins/workspaces Changed · +1 / -1 lines

from line 85
8585| :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
8686| "These settings aren't applied while Claude Tag is disabled. They're saved and will take effect once it's enabled." | Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag** and turn the switch on |
8787| "These settings aren't applied while Claude Tag is turned off for this workspace or channel; the org-wide Enable Claude Tag setting doesn't override that. They're saved and will take effect once it's turned back on." | The workspace, or the channel's workspace, is set to **Off** on its own, and the switch doesn't override it. While you have the switch, the admin page has no control for that setting |
88| "These settings aren’t applied while Claude Tag setup is incomplete for this workspace or channel." | Select **Resume** beside the notice and finish that workspace's setup |
88| "These settings aren’t applied while Claude Tag setup is incomplete for this workspace or channel." | Select the **Resume** *workspace* **setup** button beside the notice and finish that workspace's setup. On a channel's entry, the button's label names the channel's workspace |
8989 
9090## Revoke a pairing
9191 

claude-tag/concepts/data-lifecycle Changed · +1 / -1 lines

from line 86
8686 
8787* **Disconnect a workspace or an Enterprise Grid** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), or uninstall the app from the workspace in Slack. Deletes all of that workspace's data. See [Revoke a pairing](/docs/claude-tag/admins/workspaces#revoke-a-pairing)
8888* **Remove a channel's scope** in the **Claude Tag's access** section. Deletes that channel's data recorded so far
89* **Delete a scope's memory files**, from the scope's options menu, or tell Claude in the channel to forget an entry. See [Check and correct what Claude Tag remembers](/docs/claude-tag/users/memory#check-and-correct-what-claude-tag-remembers)
89* **Delete a scope's memory files**: select **View memory files** in the scope's options menu, choose a file, then select **Delete**. You can also tell Claude in the channel to forget an entry. See [Check and correct what Claude Tag remembers](/docs/claude-tag/users/memory#check-and-correct-what-claude-tag-remembers)
9090* **Delete a routine** from the **Scheduled work** tab, or ask Claude to delete it in the channel or direct message where it was set up. See [Audit Claude Tag activity](/docs/claude-tag/admins/audit)
9191 
9292There is no control in Slack or in your Claude admin settings that deletes a single thread's transcript on its own. During the beta, Claude Tag session transcripts and memory aren't included in your organization's data exports, and the Compliance API doesn't list or delete Claude Tag sessions. For a deletion request these controls don't cover, contact your account team or [[email protected]](mailto:[email protected]).

claude-tag/concepts/how-it-works Changed · +2 / -2 lines

from line 134
134134| Who sees the work | Everyone in the channel | Just you | Just you |
135135| Best for | Shared work the team should see and steer | Personal research and drafting | Hands-on coding in your own checkout |
136136 
137The short version: **team work → Claude Tag; personal work → Cowork or Claude Code.** Claude Tag's connections authenticate the agent itself with service accounts, not any person. Personal connectors apply in a Claude Tag DM, which runs on your own claude.ai account, the same way Cowork does.
137The short version: **team work → Claude Tag; personal work → Cowork or Claude Code.** Claude Tag's connections authenticate the agent itself with service accounts, not any person. Personal connectors apply in a Claude Tag DM, which runs on your own claude.ai account, the same way Cowork does. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use your personal connectors in a channel for your own tasks, after you allow it.
138138 
139139## Key concepts
140140 
from line 205
205205 
206206* **Ask what Claude can reach.** In any channel, `@Claude what can you access from this channel?` lists its current reach.
207207* **If Claude cannot reach something, the channel was not granted access.** Another channel may have the access, and an organization Owner can add it. [How agent identity works](/docs/claude-tag/concepts/agent-identity) covers the model.
208* **Personal connectors apply only in DMs.** A connection an admin attaches to a channel is separate from a connector on your personal claude.ai account; anything on your own account works in your DMs, not here.
208* **Personal connectors are separate from channel connections.** A connection an admin attaches to a channel is separate from a connector on your personal claude.ai account. Your own connectors work in your DMs. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use them in a channel for your own tasks, after you allow it.
209209 
210210### One-off and scheduled tasks
211211 

claude-tag/overview Changed · +2 / -0 lines

from line 166
166166 
167167To learn what your team's usage costs, run a pilot with a spend limit set and watch the per-channel breakdown on the [usage page in your admin settings](https://claude.ai/admin-settings/usage/claude-tag). Your organization may already have a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise) to run that pilot against before it funds the balance itself.
168168 
169The usage page doesn't count usage that a credit covers, so that usage shows as \$0.00 there. While the credit covers your pilot, watch the **List price** column of the **Spend by channel** table at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag) instead. That column shows each channel's list-price spend for the current month, including covered usage.
170 
169171[Set a spend limit](/docs/claude-tag/admins/set-spend-limit) covers how to fund the balance on each plan, set the limit, and what happens when usage reaches it.
170172 
171173<div className="tm-eyebrow"><span className="tm-swatch tm-swatch-users" />For end users</div>

claude-tag/users/getting-started Changed · +1 / -0 lines

from line 126
126126* [Good habits](/docs/claude-tag/users/good-habits): how to write tasks that finish
127127* [Set up routines](/docs/claude-tag/users/proactivity): once a task works, have Claude run it on its own schedule
128128* [Commands](/docs/claude-tag/users/commands): exact words starting with `!` that run a fixed action, like `!restart` for a stuck session
129* [Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors): how Claude can use your own claude.ai connectors for a task you hand it in a channel
129130