One read of Claude Documentationclaude-docs-20260923T213705Z
3 pages moved out of 243 read.
Pages moved
3
significant first
Pages read
243
in this capture
Captured
21:37 UTC
Corpus hash
26bcde8015fa
corpus-hash
What this read moved
1-3 of 3claude-tag/admins/customize Changed · +6 / -4 lines
from line 70
7070
7171### Models your organization allows
7272
73Claude Tag's model lists come from the models your organization makes available for Claude Code, set in the Claude admin console, leaving out any that Claude Tag doesn't support. A model you see in Claude Code can be absent in Slack for that reason. The allowed list applies in two places.
73On the Team plan, Claude Tag doesn't apply the [`availableModels` allowlist](https://code.claude.com/docs/en/model-config#restrict-model-selection) from your Claude Code [server-managed settings](https://code.claude.com/docs/en/server-managed-settings), and on the Enterprise plan it applies the allowlist in only some organizations.
7474
75* **Model lists in Slack.** The models Claude offers when someone asks it to switch, and the model selector for direct messages, show only allowed models. Claude declines a request to switch to a model outside the list.
76* **Configured defaults.** If your organization also enforces the policy on defaults and a workspace or channel's **Default model** isn't allowed by your organization's Claude Code model policy, Claude declines to start the session and posts a notice in the thread asking the requester to contact an admin. A model excluded by your organization's plan entitlements works differently. Claude starts the session on a fallback model the plan includes, and declines only when the plan excludes every fallback. The footer of the first reply names the model that served it, so check there to see which model the session started on.
75* **Where the allowlist doesn't apply**: Claude offers your organization's full Claude Tag model list, both when someone asks it to switch and in the model selector for direct messages. It starts sessions on a scope's **Default model** without checking that model against the allowlist. The **Default model** picker in admin settings still lists only allowed models.
76* **Where the allowlist applies**: sessions in a channel run as the [agent identity](/docs/claude-tag/concepts/agent-identity) you provisioned and without your server-managed settings. When someone in a channel asks Claude to switch models, Claude may decline a model outside the allowlist, though that check doesn't always run. In direct messages from a member whose linked Claude account belongs to your organization, Claude runs on that member's own account, which receives your allowlist; see [Restrict model selection](https://code.claude.com/docs/en/model-config#restrict-model-selection) for what happens to a model the allowlist blocks.
7777
78A change to the allowed list applies to new sessions, like a change to the **Default model**; a thread already underway keeps its model until someone in it asks Claude to switch.
78In either case, Claude Tag offers only the models it supports, so a model your allowlist includes can be absent in Slack.
79
80On the Enterprise plan, turning a model off for the whole organization on your **Models** page removes it from the lists in Slack, and Claude declines requests to switch to it. If you turn off the model a scope's **Default model** is set to, Claude still starts sessions there on a fallback model that's still on, and declines only when every fallback is off too. The footer of the first reply names the model that served it.
7981
8082## Configure the environment for a scope
8183
claude-tag/admins/connections/custom Changed · +2 / -0 lines
from line 46
4646| **OAuth 2.0 client credentials** | Machine-to-machine OAuth with a client ID and secret |
4747| **MCP Connector** | OAuth sign-in. Sign in once as an admin; the agent acts as that account. |
4848
49<Note>The **MCP Connector** type signs in to a connector from your organization's connector library. If you register a new connector from this form with **Add custom connector…**, that connector is added to the library on the **Connectors** page at [`claude.ai/admin-settings/connectors`](https://claude.ai/admin-settings/connectors), not only to the bundle. Removing the connection from the bundle later leaves the library entry in place.</Note>
50
4951For GitHub repositories, use the GitHub connection at [Configure GitHub access](/docs/claude-tag/admins/configure-github) rather than a credential from this table.
5052
5153If you're unsure which type, check the service's API authentication docs for which header or flow it expects.
claude-tag/admins/restrict-access Changed · +1 / -1 lines
from line 171
171171
172172A conversation that was underway before the first guest joined doesn't keep its full access. The next message from a workspace member in that thread starts the conversation over with channel-only access. A guest who writes there before a member does gets the same notice as under **Restrict**.
173173
174While a guest is present, Claude replies only to mentions and to threads it's already part of. It doesn't act on other messages in the channel on its own, even where [**Respond automatically**](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) is on.
174The channel's [**Respond automatically**](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) setting works the same while a guest is present, and it's on by default. While it's on, messages from workspace members that don't mention Claude still reach it, and Claude may reply to some of them on its own. Outside the threads Claude is part of, a guest's messages that don't mention Claude reach it only as context, not as requests. To have Claude reply only to @-mentions and in threads it's already part of, turn **Respond automatically** off for that channel.
175175
176176A guest can talk to Claude by mentioning `@Claude` or by replying in a thread Claude is part of, and Claude answers them. A guest can't approve a tool or permission request, and can't restart, mute, fork, or stop the session. If a guest clicks approve, nothing is granted.
177177