What this read moved
1–7 of 7claude-tag/admins/restrict-access Changed · +12 / -37 lines
#### What access Claude has in a Slack Connect channel #### Who can use Claude in a Slack Connect channel #### Replies, earlier threads, and installs in a Slack Connect channel
from line 121
121121
122122* **DMs.** The version setting doesn't cover them. To close those off too, turn off the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle.
123123* **Guest channels.** By default Claude is off in any channel that includes a Slack guest. If a chosen channel has guests, also set [Allow Claude to work in channels with guests](#restrict-guest-channels) to **Allow** or **Channel only** on its scope.
124* **Shared channels.** A [channel shared across workspaces in your Enterprise Grid](#channels-shared-across-workspaces-in-your-enterprise-grid) takes its settings from **Default Slack access** only and can't serve as a chosen channel. In a [Slack Connect channel](#slack-connect-channels), one shared with another company, the **Allow Claude to work in channels with guests** setting also decides whether Claude replies.
124* **Shared channels.** A [channel shared across workspaces in your Enterprise Grid](#channels-shared-across-workspaces-in-your-enterprise-grid) takes its settings from **Default Slack access** only and can't serve as a chosen channel. Claude doesn't work in a [Slack Connect channel](#slack-connect-channels), one shared with another company.
125125
126126To control who can use Claude in the allowed channels, turn on the [restriction toggle](#restrict-who-can-use-claude); to cap what a channel spends, [set a per-channel spend limit](#set-spend-limits).
127127
from line 140
140140
141141By default, Claude is disabled in any channel that includes a Slack guest. You can change this default per scope with the **Allow Claude to work in channels with guests** setting, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope → the collapsed **Advanced** section. The setting has three values:
142142
143| Value | What Claude does in a channel that includes a guest |
144| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
145| **Restrict** (default) | Doesn't reply. When someone mentions it, Claude posts a short notice that it doesn't respond in channels that include guests, with a link to this setting. |
146| **Channel only** | Replies, but while a guest is present it runs with [channel-only access](#how-channel-only-works). The channel's own instructions still apply, and so do access bundles an Owner has turned on for channels with guests. |
147| **Allow** | Replies with the full access the scope gives it. Bundles, connections, and instructions from the workspace and from **Default Slack access** apply, along with repositories, memory, and skills. |
143| Value | What Claude does in a channel that includes a guest |
144| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
145| **Restrict** (default) | Doesn't reply. When someone mentions it, Claude posts a short notice that it doesn't respond in channels that include guests, with a link to this setting. |
146| **Channel only** | Replies, but while a guest is present it runs with [channel-only access](#how-channel-only-works). The channel's own instructions still apply. |
147| **Allow** | Replies with the full access the scope gives it. Bundles, connections, and instructions from the workspace and from **Default Slack access** apply, along with repositories, memory, and skills. |
148148
149149A channel without its own value shows **Inherit** and takes the value from its workspace, or from **Default Slack access**. Only an organization Owner can choose **Allow** or set a scope back to **Inherit**. The setting applies to every guest channel the scope covers. To open one channel rather than a whole workspace, set it on the channel's own scope.
150150
from line 156
156156
157157Use **Channel only** to keep Claude available in a channel shared with contractors, clients, or agency partners without exposing the rest of the organization's setup to that conversation. While a guest is in the channel, Claude has:
158158
159* No [access bundles](/docs/claude-tag/admins/attach-to-scope) by default, including bundles attached directly to this channel. To give Claude a bundle while a guest is present, an organization Owner opens the scope the bundle is attached to, finds the bundle's row under **Access bundles**, clicks the chip at the end of the row (it reads **Channels with only members (default)** until changed), and turns on **For channels with members and guests**. On a workspace or on **Default Slack access**, that checkbox attaches the bundle in every guest channel the scope covers. Turn it on only for bundles you're comfortable with Claude using in a conversation guests can read.
159* No [access bundles](/docs/claude-tag/admins/attach-to-scope), including bundles attached directly to this channel.
160160* No connections set directly on the channel.
161* No repositories, including any in a bundle turned on for channels with guests.
161* No repositories.
162162* No instructions set on the workspace or the organization. Instructions set on the channel itself still apply.
163163* No memory, including this channel's own, and no skills.
164164* No [environment set on the scope](/docs/claude-tag/admins/customize#configure-the-environment-for-a-scope). The session runs on the standard environment, so the setup script, environment variables, and network access level of the environment you chose don't apply while a guest is present.
from line 171
171171
172172A guest can talk to Claude by mentioning `@Claude` or by replying in a thread Claude is part of, and Claude answers them. A guest can't approve a tool or permission request, and can't restart, mute, fork, or stop the session. If a guest clicks approve, nothing is granted.
173173
174Treat a channel's instructions, and the instructions in any bundle turned on for channels with guests, as visible to everyone in that channel, including guests. Under **Channel only**, Claude follows them in replies that guests can read and respond to.
174Treat a channel's instructions as visible to everyone in that channel, including guests. Under **Channel only**, Claude follows them in replies that guests can read and respond to.
175175
176176**Channel only** takes effect where the **New** [Claude Tag version](/docs/claude-tag/admins/workspaces#set-the-version-for-a-scope) answers. On a scope where **Legacy** answers, a channel that includes a guest is treated as **Restrict**.
177177
from line 179
179179
180180### Slack Connect channels
181181
182A Slack Connect channel is a channel your Slack workspace shares with another company. By default, Claude is off in Slack Connect channels. When someone mentions `@Claude` there, Claude doesn't reply and doesn't post a message explaining why.
182A Slack Connect channel is a channel your Slack workspace shares with another company. Claude doesn't work in Slack Connect channels, and no setting at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) turns it on there. When someone mentions `@Claude` in one, Claude posts a notice that it isn't turned on for Slack Connect channels and doesn't answer.
183183
184Claude treats everyone from the other company as a guest, so the [**Allow Claude to work in channels with guests**](#restrict-guest-channels) setting decides whether Claude replies in a Slack Connect channel. To let Claude answer, an organization Owner sets **Allow Claude to work in channels with guests** to **Channel only** or **Allow** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the workspace the channel belongs to → the collapsed **Advanced** section. You set the value on the workspace because a Slack Connect channel can't get a scope of its own after it's shared. If the channel had its own scope before it was shared, it keeps that scope, and you can set **Allow Claude to work in channels with guests** on the channel's scope instead of the workspace's.
185
186Claude answers in Slack Connect channels only on scopes set to the **New** [Claude Tag version](/docs/claude-tag/admins/workspaces#set-the-version-for-a-scope). On a scope set to **Legacy**, Claude stays silent in Slack Connect channels under every value of the guest setting.
187
188#### What access Claude has in a Slack Connect channel
189
190Claude runs with [channel-only access](#how-channel-only-works) in a Slack Connect channel, whether **Allow Claude to work in channels with guests** is set to **Allow** or to **Channel only**. Connections, instructions, and the environment set on the workspace or on **Default Slack access** don't apply, and Claude runs with no memory, no skills, no repositories, and no connections set directly on the channel. The channel's own instructions still apply, so treat them as visible to the other company. Claude also doesn't search your workspace, look up people or channels, or read channels other than the one it's in.
191
192No [access bundle](/docs/claude-tag/admins/attach-to-scope) reaches a Slack Connect channel by default, wherever the bundle is attached. To give Claude a bundle there, an organization Owner goes to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope the bundle is attached to → **Access bundles**, clicks the chip at the end of the bundle's row (it reads **Channels with only members (default)** until changed), and turns on **For Slack Connect channels**. On a workspace or on **Default Slack access**, that checkbox attaches the bundle in every Slack Connect channel the scope covers. People from the other company can then have Claude use whatever the bundle grants, so turn it on only for a bundle you would hand to that company.
193
194#### Who can use Claude in a Slack Connect channel
195
196People from the other company can talk to Claude by mentioning `@Claude` or by replying in a thread Claude is part of, and Claude answers them. To keep Claude from answering the other company's people, turn on your plan's member restriction toggle, described in [Restrict who can use Claude](#restrict-who-can-use-claude).
197
198No one from the other company can approve a tool or permission request. If they click approve, nothing is granted.
199
200Of the [commands](/docs/claude-tag/users/commands), your organization's members can run only `!help`, `!mute`, `!unmute`, and `!restart` in a Slack Connect channel. `!fork` and [routines](/docs/claude-tag/users/proactivity) aren't available there.
201
202Everyone in the channel, including the other company's people, can read what Claude posts.
203
204#### Replies, earlier threads, and installs in a Slack Connect channel
205
206* **Automatic replies.** Claude replies only to mentions and to threads it's already part of, even where [**Respond automatically**](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) is on. Claude reads the other messages in the channel as context, including messages from the other company's people and apps, and never replies to their apps or bots.
207* **Threads from before the channel was shared.** Claude stops replying in a thread that started before the channel was shared. The next mention in that thread gets a notice asking you to mention `@Claude` in a new thread.
208* **The other company's Claude.** If the other company also uses Claude Tag, their organization's settings decide whether their Claude answers in the channel, and your settings decide only whether your Claude answers. Claude never replies to the other company's Claude.
209* **Enterprise Grid organization-level installs.** When Claude is installed for your whole Enterprise Grid organization rather than per workspace, Claude replies only in Slack Connect channels that one of your own workspaces created. In a Slack Connect channel the other company created, Claude stays silent and posts no notice.
184If a channel Claude already works in becomes a Slack Connect channel, Claude stops answering there, including in threads it was already part of. You also can't add a Slack Connect channel as a scope. The **Add channel** drawer reports that Claude can't be added to it yet.
210185
211186### Channels shared across workspaces in your Enterprise Grid
212187
claude-tag/users/troubleshooting Changed · +7 / -15 lines
from line 108
108108
109109**What you see**
110110
111Mentions in a Slack Connect channel, one shared with another company, get no answer and no notice, or get a notice saying the thread's earlier session can't continue.
111A mention in a Slack Connect channel, one shared with another company, gets a notice that Claude isn't turned on for Slack Connect channels, and no answer.
112112
113113**What it means**
114114
115By default, Claude is off in Slack Connect channels, and it posts no notice there. A Claude organization Owner can [turn Claude on for Slack Connect channels](/docs/claude-tag/admins/restrict-access#slack-connect-channels) by changing the **Allow Claude to work in channels with guests** setting, because Claude treats the other company's people as guests. Claude then replies using only the channel's own instructions and the tools an admin has turned on for Slack Connect channels.
115Claude doesn't work in [Slack Connect channels](/docs/claude-tag/admins/restrict-access#slack-connect-channels), and no admin setting turns it on there. If the channel became a Slack Connect channel after Claude was added, Claude stops answering from then on, including in threads it was already part of.
116116
117If **Allow Claude to work in channels with guests** is already **Channel only** or **Allow** and Claude still doesn't answer, one of these three causes is likely:
118
119* The organization that runs Claude has limited Claude to that organization's own members, and you're from the other company in the channel.
120* The scope that covers the channel is set to the **Legacy** Claude Tag version.
121* The organization that runs Claude installed it across its whole Slack Enterprise Grid, and a workspace outside that Grid created the channel.
122
123If the mention gets the notice "This channel is now shared with another organization through Slack Connect, so this thread's earlier session can't continue here," the thread started before the channel was shared. Mention `@Claude` in a new thread.
124
125A channel shared across workspaces inside your Enterprise Grid isn't silent; what happens there depends on how those workspaces connect to Claude. When every workspace in the channel belongs to your one Claude organization, Claude answers, but with only your organization's default access and settings, so a repository or an instruction set up for that channel doesn't apply. A notice in the thread points this out from time to time. When the workspaces are connected to different Claude organizations, you see "This channel is shared among several Claude workspaces, so Claude cannot respond here" instead of an answer.
117A channel shared across workspaces inside your Enterprise Grid is different. When every workspace in the channel belongs to your one Claude organization, Claude answers, but with only your organization's default access and settings, so a repository or an instruction set up for that channel doesn't apply. A notice in the thread points this out from time to time. When the workspaces are connected to different Claude organizations, you see "This channel is shared among several Claude workspaces, so Claude cannot respond here" instead of an answer.
126118
127119Where guest access is restricted, you may first see "This channel is shared across multiple workspaces, and Claude can't verify whether it includes guests, so Claude can't respond here." If you ask Claude from another conversation to act in one of these channels, such as posting a message there, you see a reply that ends "Claude isn't available in channels shared across your Enterprise Grid".
128120
claude-tag/admins/for-slack-admins Changed · +1 / -1 lines
from line 23
2323
2424Reading a channel's full history requires being added there. Workspace search can surface public-channel content, the same as any app with the search scope.
2525
26In a Slack Connect channel (shared with another company), Claude is off by default. A Claude organization Owner can turn Claude on there. Claude then works without the instructions and memory your organization gave it for the workspace, and with only the tools a Claude admin has explicitly turned on for Slack Connect channels. See [Slack Connect channels](/docs/claude-tag/admins/restrict-access#slack-connect-channels).
26In a Slack Connect channel (shared with another company), Claude doesn't answer, and a mention there gets a notice saying so. See [Slack Connect channels](/docs/claude-tag/admins/restrict-access#slack-connect-channels).
2727
2828## Requested scopes
2929
claude-tag/admins/healthcare Changed · +1 / -1 lines
from line 18
1818* Search every public channel by keyword, including public channels it hasn't been added to. [No admin setting turns this search off](/docs/claude-tag/admins/restrict-access#controls-that-aren%E2%80%99t-available)
1919* Read a private channel only after someone in that channel invites it
2020
21Claude never searches private channels, and it doesn't operate in Slack Connect channels shared with another company.
21Claude never searches private channels, and it doesn't reply in [Slack Connect channels](/docs/claude-tag/admins/restrict-access#slack-connect-channels), the channels your workspace shares with another company.
2222
2323For a healthcare organization, the rule that follows is to keep PHI out of every public channel in the connected workspace, not only the channels where Claude responds, because Claude's keyword search reaches all of them. Keep PHI out of any private channel Claude has been invited to as well.
2424
claude-tag/concepts/security-and-data Changed · +1 / -1 lines
from line 87
87872. Keep the channel private. A bundle on a public channel [grants its access to anyone who joins](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel).
88883. Check the channel's **Connectors**, **Repositories**, and **Plugins** sections on the [Slack tab in admin settings](/docs/claude-tag/admins/attach-to-scope). They list the access the channel gets, including rows inherited from the workspace or from Default Slack access, each with an origin line naming where it comes from.
8989
90In a channel shared with another company through Slack Connect, Claude is off by default. If an Owner turns it on, Claude runs there with [channel-only access](/docs/claude-tag/admins/restrict-access#slack-connect-channels), and a bundle's credentials reach that channel only if an Owner has also turned the bundle on for Slack Connect channels.
90Claude doesn't work in a channel shared with another company through [Slack Connect](/docs/claude-tag/admins/restrict-access#slack-connect-channels), so no access bundle's credentials reach one.
9191
9292Isolating a credential doesn't isolate what Claude knows. What it learns in a public channel becomes [workspace memory](/docs/claude-tag/users/memory) that sessions in the workspace's other channels can read, and it can [search public channels by keyword](/docs/claude-tag/admins/restrict-access#controls-that-aren%E2%80%99t-available) without being added to them, the same way any workspace member can.
9393
claude-tag/users/good-habits Changed · +1 / -1 lines
from line 138
138138
139139A private channel is readable only from inside it. Inviting Claude lets it work in that channel, but Claude can't read the private channel's messages from any other channel or DM. To ask about a private channel, ask in that channel.
140140
141Channels in a different workspace stay out of reach. In a Slack Connect channel, one shared with another company, Claude answers only if your admin has [turned Claude on there](/docs/claude-tag/admins/restrict-access#slack-connect-channels). When Claude does answer, it works without your organization's memory or workspace instructions, and with only the tools your admin turned on for Slack Connect channels.
141Channels in a different workspace stay out of reach. Claude also doesn't answer in a [Slack Connect channel](/docs/claude-tag/admins/restrict-access#slack-connect-channels), one shared with another company.
142142
143143When more than one surface would work, prefer a channel. Work that happens there compounds, because Claude can draw on it in later threads and teammates can find it, redirect it, or build on it.
144144
claude-tag/users/when-claude-responds Changed · +1 / -1 lines
from line 118
118118* **Editing a message to add the mention.** An edit doesn't trigger a response. Delete the message and send a new one with `@Claude` included.
119119* **Channels with guest accounts.** By default, Claude is off in channels that include guests; your admin can turn it on per scope. Ask whoever runs your Claude plan, or send them [the guest access setting](/docs/claude-tag/admins/restrict-access#restrict-guest-channels).
120120* **Channels shared across workspaces connected to different Claude organizations.** Every workspace where Claude runs is connected to a Claude organization, the account a company sets up for Claude. When a channel is shared across workspaces connected to different Claude organizations, Claude won't reply there and posts a refusal message instead. You can't tell from Slack how a workspace is connected; the refusal message itself is the signal. Use a channel that belongs to one workspace, or send Claude a DM.
121* **Slack Connect channels.** By default, Claude is off in channels shared with another company. A mention there gets no reply and no message explaining why. Your admin can [turn Claude on for Slack Connect channels](/docs/claude-tag/admins/restrict-access#slack-connect-channels). Claude then replies without your organization's memory or workspace instructions, and with only the tools your admin turned on for Slack Connect channels.
121* **Slack Connect channels.** Claude doesn't answer in [channels shared with another company](/docs/claude-tag/admins/restrict-access#slack-connect-channels). A mention there gets a notice saying Claude isn't turned on for Slack Connect channels, and no admin setting changes that.
122122
123123When the workspaces sharing a channel all belong to one Claude organization, Claude replies there, but with only your organization's default access and settings. The repositories, instructions, and memory set up for that channel or its workspaces don't apply, and Claude posts a notice in the thread explaining this from time to time. The guest check above still applies first where guest access is restricted.
124124