One read of Claude Documentationclaude-docs-20260926T003708Z
11 pages moved out of 255 read.
Pages moved
11
significant first
Pages read
255
in this capture
Captured
00:37 UTC
Corpus hash
7744fc0da769
corpus-hash
What this read moved
1-11 of 11claude-tag/admins/healthcare Changed · +5 / -1 lines
from line 67
6767* Treat email and calendar as PHI-bearing unless your compliance team has confirmed otherwise, and leave them unconnected until then
6868* Attach each bundle to the approved channels that need it, not to **Default Slack** (the entry whose settings apply to every channel in every connected workspace), so a connection never reaches a channel it wasn't reviewed for
6969
70Members' own claude.ai connectors, such as their email or calendar, are a separate path to tools outside Slack. In a direct message, Claude works on the member's own Claude account and can use those connectors, so keep the **Allow direct messages** toggle off as described in [Limit Claude to PHI-free channels](#limit-claude-to-phi-free-channels). In channels, Claude can also use a member's own connectors for that member's requests after the member allows it, through [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), and no organization setting turns that off. Include members' claude.ai connectors in the tools that must stay PHI-free, and on the Enterprise plan turn on **Require human review of every message** in the **Personal connectors** section at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) so a member reviews every result before it posts to the channel.
70Members' own claude.ai connectors, such as their email or calendar, are a separate path to tools outside Slack. In a direct message, Claude works on the member's own Claude account and can use those connectors, so keep the **Allow direct messages** toggle off as described in [Limit Claude to PHI-free channels](#limit-claude-to-phi-free-channels). In channels, Claude can [use a member's own connectors for that member's requests](/docs/claude-tag/concepts/personal-connectors) after the member allows it, and no organization setting turns off personal connectors in channels entirely. These controls apply:
71
72* **Block a connector for everyone.** A connector you restrict for your organization on the [**Connectors** admin page](https://claude.ai/admin-settings/connectors) stays restricted when Claude uses a member's connectors in a channel.
73* **Require human review.** On the Enterprise plan, turn on **Require human review of every message** in the **Personal connectors** section at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), so a member reviews every result before it posts to the channel.
74* **Treat the rest as PHI-bearing.** Include members' remaining claude.ai connectors in the tools that must stay PHI-free.
7175
7276## Train your workspace and monitor approved channels
7377
claude-tag/concepts/settings-map Changed · +8 / -8 lines
from line 8
88
99Claude Tag's settings live on claude.ai, split across a few pages that each own a different kind of setting. Which page you need depends on what you're changing. The table maps each surface to what it controls.
1010
11| Surface | Who changes it | What it controls |
12| :--------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
13| [Claude Tag admin page](https://claude.ai/admin-settings/claude-tag) | An Owner in your Claude organization | Access, behavior, and restrictions for channels, per [scope](/docs/claude-tag/concepts/glossary#scope) |
14| [Usage page](https://claude.ai/admin-settings/usage/claude-tag) | An admin | Spend limits and each channel's spend against them |
15| [Analytics page](https://claude.ai/analytics/claude-tag) | Anyone who can view the Analytics dashboard | Spend trends, projections, and per-channel reports; read-only |
16| The **Configure** link in the footer of any Claude reply in a channel | Channel members (unless an admin restricts editing) and [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | One channel's instructions and whether Claude replies there without an @-mention. Channel managers also set the channel's default model, repositories, connections, and plugins |
17| [Customize > Connectors](https://claude.ai/customize/connectors) on your own claude.ai account | You | Which of your personal tools apply in [DMs](/docs/claude-tag/concepts/agent-identity#direct-message-channels) and, where available, for [your own tasks in a channel](/docs/claude-tag/concepts/personal-connectors) |
11| Surface | Who changes it | What it controls |
12| :--------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
13| [Claude Tag admin page](https://claude.ai/admin-settings/claude-tag) | An Owner in your Claude organization | Access, behavior, and restrictions for channels, per [scope](/docs/claude-tag/concepts/glossary#scope) |
14| [Usage page](https://claude.ai/admin-settings/usage/claude-tag) | An admin | Spend limits and each channel's spend against them |
15| [Analytics page](https://claude.ai/analytics/claude-tag) | Anyone who can view the Analytics dashboard | Spend trends, projections, and per-channel reports; read-only |
16| The **Configure** link in the footer of any Claude reply in a channel | Channel members (unless an admin restricts editing) and [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | One channel's instructions and whether Claude replies there without an @-mention. Channel managers also set the channel's default model, repositories, connections, and plugins |
17| [Customize > Connectors](https://claude.ai/customize/connectors) on your own claude.ai account | You | Which of your personal tools apply in [DMs](/docs/claude-tag/concepts/agent-identity#direct-message-channels) and for [your own tasks in a channel](/docs/claude-tag/concepts/personal-connectors) |
1818
1919Channel memory and routines aren't in the table because you change them by talking to Claude in the channel; see [what anyone can change from the channel](/docs/claude-tag/admins/customize#change-behavior-from-the-channel). Owners can review both, as each scope's memory files and scheduled work, from [the Audit page](/docs/claude-tag/admins/audit), labeled **Activity** in the console.
2020
from line 51
5151
5252## Personal connectors on claude.ai
5353
54Connectors you add to your own claude.ai account, under **Customize > Connectors**, apply in DMs with Claude, because [a DM runs on your own account](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A channel session uses the connections an admin attached to it. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use your personal connectors there for your own tasks, after you allow it. Slack has no connector settings of its own.
54Connectors you add to your own claude.ai account, under **Customize > Connectors**, apply in DMs with Claude, because [a DM runs on your own account](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A channel session uses the connections an admin attached to it. Claude can also [use your personal connectors there](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it. Slack has no connector settings of its own.
5555
5656See [connectors on claude.ai](/docs/connectors/getting-started) for setting one up, and [the troubleshooting entry](/docs/claude-tag/users/troubleshooting#a-connector-works-on-claude-ai-but-not-in-slack) if a connector you use on claude.ai is missing in Slack.
5757
claude-tag/admins/add-connections Changed · +1 / -1 lines
from line 30
3030
3131You can also create an unattached bundle by clicking **Create** on the **Access bundles** page in the left navigation, then attach it to scopes afterward. A bundle created there is named **Untitled access bundle** until you rename it.
3232
33Connections belong to the [agent identity](/docs/claude-tag/concepts/agent-identity), not to any person. Personal claude.ai connectors apply in DMs. With [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), Claude can also use a member's own connectors in a channel for that member's own tasks, after the member allows it.
33Connections belong to the [agent identity](/docs/claude-tag/concepts/agent-identity), not to any person. Personal claude.ai connectors apply in DMs. Claude can also [use a member's own connectors in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
3434
3535Name a bundle after what it grants, since the name is what you'll read when deciding which bundles to bind to a channel: `data-readonly`, `github-write`, `monitoring`, `gtm-tools`. A capability name stays meaningful when the same bundle serves several teams; a team name (`devprod-team`) works when one team's full access is the unit you'll reuse.
3636
claude-tag/admins/connections/amplitude Changed · +1 / -1 lines
from line 12
1212
1313You can connect with a project API key and secret key, which you can limit to read requests, or by signing in as an Amplitude user, which gives Claude Amplitude's MCP tools for creating and editing content as well as reading it.
1414
15For the API key route, pair the connection with a plugin that covers Amplitude so Claude knows how to call the REST API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). A member's own Amplitude connector on claude.ai is separate from this connection and applies in DMs. With [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), Claude can also use that connector in a channel for that member's own tasks, after the member allows it.
15For the API key route, pair the connection with a plugin that covers Amplitude so Claude knows how to call the REST API; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins). A member's own Amplitude connector on claude.ai is separate from this connection and applies in DMs. Claude can also [use that connector in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
1616
1717## Choose an API key or Amplitude sign-in
1818
claude-tag/admins/connections/google Changed · +1 / -1 lines
from line 10
1010
1111Connecting Google Drive, Calendar, and Gmail lets Claude read documents, spreadsheets, calendar events, and email from any channel under the bundle's scope. You add it as a connection inside an [Access bundle](/docs/claude-tag/admins/add-connections); the credential belongs to the agent, not to any person.
1212
13This is an HTTP API connection, not a personal claude.ai connector. A member's own Google connector applies in DMs. With [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), Claude can also use it in a channel for that member's own tasks, after the member allows it.
13This is an HTTP API connection, not a personal claude.ai connector. A member's own Google connector applies in DMs. Claude can also [use it in a channel](/docs/claude-tag/concepts/personal-connectors) for that member's own tasks, after the member allows it.
1414
1515## Choose OAuth or a service account
1616
claude-tag/admins/customize Changed · +1 / -1 lines
from line 35
3535
3636### Channel connections are separate from personal connectors
3737
38An Owner configures Claude's connections, plugins, and skills, and they apply per scope. They are separate from the connectors, skills, or MCP servers an individual user has set up in their own claude.ai or Claude Desktop account. A user's personal connectors are not part of a channel's configuration, and the channel's connections are not listed among that user's personal connectors in claude.ai. With [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), Claude can use a user's personal connectors in a channel for that user's own tasks, after the user allows it. That work runs with the user's permissions and is recorded under their name. Projects in claude.ai are separate too. Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project. Put standing guidance for a channel in its [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
38An Owner configures Claude's connections, plugins, and skills, and they apply per scope. They are separate from the connectors, skills, or MCP servers an individual user has set up in their own claude.ai or Claude Desktop account. A user's personal connectors are not part of a channel's configuration, and the channel's connections are not listed among that user's personal connectors in claude.ai. Claude can [use a user's personal connectors in a channel](/docs/claude-tag/concepts/personal-connectors) for that user's own tasks, after the user allows it. That work runs with the user's permissions and is recorded under their name. Projects in claude.ai are separate too. Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project. Put standing guidance for a channel in its [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
3939
4040To give Claude access to a tool that is not in the built-in connection list, including a custom MCP server, see [add a custom connection](/docs/claude-tag/admins/connections/custom).
4141
claude-tag/concepts/agent-identity Changed · +2 / -2 lines
from line 8
88
99Claude Tag's identity depends on where you message it.
1010
11In Slack channels, Claude acts with its own service accounts, rather than as a specific user. An organization Owner [provisions this identity during setup](/docs/claude-tag/admins/setup-overview), so it arrives with its own account in each system it works in: the Claude app in Slack, the Claude GitHub App on GitHub, and a service account in every other connected tool. Actions it takes are attributed to those accounts; for example, posts come from the Claude app and pull requests show the Claude GitHub App as the author. In organizations where personal connectors in channels is available, Claude can also use your own claude.ai connectors for a task you hand it in a channel, after you allow it. See [Personal connectors in a channel](#personal-connectors-in-a-channel).
11In Slack channels, Claude acts with its own service accounts, rather than as a specific user. An organization Owner [provisions this identity during setup](/docs/claude-tag/admins/setup-overview), so it arrives with its own account in each system it works in: the Claude app in Slack, the Claude GitHub App on GitHub, and a service account in every other connected tool. Actions it takes are attributed to those accounts; for example, posts come from the Claude app and pull requests show the Claude GitHub App as the author. Claude can also use your own claude.ai connectors for a task you hand it in a channel, after you allow it. See [Personal connectors in a channel](#personal-connectors-in-a-channel).
1212
1313In direct messages (DMs) between a user and `@Claude`, the provisioned identity does not apply. DMs are one-to-one only; group DMs aren't supported. A DM has no channel to scope it to, so a DM session runs on [the individual's own claude.ai account](#direct-message-channels) instead, with their personal connectors. GitHub is the exception in attribution: a pull request opened from a DM is authored by the Claude GitHub App, the same as in channels, though the session can only work with repositories connected on that user's own account. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
1414
from line 93
9393
9494* **Configure once.** Everyone in the scope can use it immediately.
9595* **Predictability.** What Claude can do never changes based on who asked.
96* **Personal connectors are separate.** A shared channel session uses only the service-account connections an admin attached. With [personal connectors in channels](#personal-connectors-in-a-channel), Claude uses the connectors on your own claude.ai account only for your own tasks, after you allow it.
96* **Personal connectors are separate.** A shared channel session uses only the service-account connections an admin attached. Claude [uses the connectors on your own claude.ai account](#personal-connectors-in-a-channel) only for your own tasks, after you allow it.
9797* **Clean audit.** Actions the channel session takes in connected tools show up under a service account your security team already knows how to reason about.
9898
9999That service-account identity is also how Claude appears wherever it acts. In Slack, it posts as the Claude app. On GitHub, commits and pull requests show the Claude GitHub App, and pull requests link back to the Slack thread they came from. In every other connected service, actions appear under the service account an admin provisioned, in that service's audit log.
claude-tag/concepts/glossary Changed · +2 / -2 lines
from line 43
4343
4444A credential for one external service that Claude uses on the channel's behalf, like a Datadog API key or a GitHub App installation. Connections belong to the agent identity, not to any user, and are grouped into [Access bundles](#access-bundle) by an admin.
4545
46A connection is not a connector. A connector belongs to your personal claude.ai account. A channel session uses the channel's connections. With [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), Claude can also use your connectors there for your own tasks, after you allow it. A DM uses your own account instead, as [how DMs work in this model](/docs/claude-tag/concepts/agent-identity#direct-message-channels) describes.
46A connection is not a connector. A connector belongs to your personal claude.ai account. A channel session uses the channel's connections. Claude can also [use your connectors there](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it. A DM uses your own account instead, as [how DMs work in this model](/docs/claude-tag/concepts/agent-identity#direct-message-channels) describes.
4747
4848## Connector
4949
50A tool you add to your own claude.ai account, like Gmail, Google Drive, or a custom MCP server, listed under [Customize > Connectors](https://claude.ai/customize/connectors). Connectors are personal. In Slack they apply in DMs. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use them in a channel for your own tasks, after you allow it. For the agent-side equivalent that works in channels, see [Connection](#connection).
50A tool you add to your own claude.ai account, like Gmail, Google Drive, or a custom MCP server, listed under [Customize > Connectors](https://claude.ai/customize/connectors). Connectors are personal. In Slack they apply in DMs. Claude can also [use them in a channel](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it. For the agent-side equivalent that works in channels, see [Connection](#connection).
5151
5252## Environment
5353
claude-tag/concepts/how-it-works Changed · +2 / -2 lines
from line 134
134134| Who sees the work | Everyone in the channel | Just you | Just you |
135135| Best for | Shared work the team should see and steer | Personal research and drafting | Hands-on coding in your own checkout |
136136
137The short version: **team work → Claude Tag; personal work → Cowork or Claude Code.** Claude Tag's connections authenticate the agent itself with service accounts, not any person. Personal connectors apply in a Claude Tag DM, which runs on your own claude.ai account, the same way Cowork does. In organizations where [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) is available, Claude can also use your personal connectors in a channel for your own tasks, after you allow it.
137The short version: **team work → Claude Tag; personal work → Cowork or Claude Code.** Claude Tag's connections authenticate the agent itself with service accounts, not any person. Personal connectors apply in a Claude Tag DM, which runs on your own claude.ai account, the same way Cowork does.
138138
139139## Key concepts
140140
from line 205
205205
206206* **Ask what Claude can reach.** In any channel, `@Claude what can you access from this channel?` lists its current reach.
207207* **If Claude cannot reach something, the channel was not granted access.** Another channel may have the access, and an organization Owner can add it. [How agent identity works](/docs/claude-tag/concepts/agent-identity) covers the model.
208* **Personal connectors are separate from channel connections.** A connection an admin attaches to a channel is separate from a connector on your personal claude.ai account. Your own connectors work in your DMs. With [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), Claude can also use them in a channel for your own tasks, after you allow it.
208* **Personal connectors are separate from channel connections.** A connection an admin attaches to a channel is separate from a connector on your personal claude.ai account. Your own connectors work in your DMs. Claude can also [use them in a channel](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it.
209209
210210### One-off and scheduled tasks
211211
claude-tag/concepts/security-and-data Changed · +1 / -1 lines
from line 67
6767
6868DMs with `@Claude` run on the user's own claude.ai account instead, with that user's personal connectors, and work there is attributed to them, except pull requests, which the Claude GitHub App authors from DMs as well. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
6969
70With [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), Claude uses a user's personal connectors in a channel only for that user's own tasks, after the user allows it. The work runs with that user's permissions and is recorded under their name. Requests other people make to Claude in the task's thread run with the channel's own access, not with that user's connectors. Claude is designed to take direction from the connector's owner, treating what other people post in the thread as information for the task rather than as instructions, and the owner can tell Claude in the task's thread to stop. See [Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors).
70Claude uses a user's [personal connectors in a channel](/docs/claude-tag/concepts/personal-connectors) only for that user's own tasks, after the user allows it. The work runs with that user's permissions and is recorded under their name. Requests other people make to Claude in the task's thread run with the channel's own access, not with that user's connectors. Claude is designed to take direction from the connector's owner, treating what other people post in the thread as information for the task rather than as instructions, and the owner can tell Claude in the task's thread to stop. See [Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors).
7171
7272### Isolate credentials between channels
7373
claude-tag/users/troubleshooting Changed · +1 / -1 lines
from line 480
480480
481481**What it means**
482482
483Where you message Claude determines which connectors apply. A channel session uses the connections an admin attached to it. With [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors), Claude can also use your personal connectors there for your own tasks, after you allow it. A DM runs on your own claude.ai account and uses that account's connectors.
483Where you message Claude determines which connectors apply. A channel session uses the connections an admin attached to it. Claude can also [use your personal connectors there](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it. A DM runs on your own claude.ai account and uses that account's connectors.
484484
485485You set up and authenticate connectors on claude.ai under **Customize > Connectors**; Slack has no connector settings of its own. The [settings map](/docs/claude-tag/concepts/settings-map) covers every settings surface.
486486