Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260930T160705Z

7 pages moved out of 258 read.

Pages moved 7 significant first
Pages read 258 in this capture
Captured 16:07 UTC
Corpus hash 889461e6aae9 corpus-hash

What this read moved

1-7 of 7

government/account/sessions Changed · +4 / -4 lines

from line 6
66 
77Use this page to see every place you are currently signed in to Claude for Government and to sign out of any of them remotely.
88 
9A session is created each time you sign in, whether that is in a web browser or in the Claude desktop application. This page lists your active sessions so you can confirm that nothing unexpected has access to your account, and clean up after yourself on a computer you no longer have.
9A session is created each time you sign in, whether that is in a web browser or in one of the Claude applications. This page lists your active sessions so you can confirm that nothing unexpected has access to your account, and clean up after yourself on a computer you no longer have.
1010 
1111## What each row shows
1212 
1313Each row is one active sign-in. The one you are using right now is labeled **this session** and always appears at the top of the list; the rest are ordered with the most recent first.
1414 
15* **Client** tells you which kind of application the sign-in is for. It shows **Browser** for a web sign-in, or **Desktop app** for the Claude application installed on a computer.
16* **via …** tells you how that session was established. **Single sign-on** means you authenticated through your agency's identity provider. **Device pairing** means a code shown in the desktop application was entered and approved in a browser, linking that application to your account. **Email link** means a one-time link was sent to your inbox and followed to sign in.
15* **Client** tells you which kind of application the sign-in is for.
16* **via …** tells you how that session was established. **Single sign-on** means you authenticated through your agency's identity provider. **Device pairing** means a user entered a code shown in a Claude application and approved it in a browser, linking that application to your account. **Email link** means a one-time link was sent to your inbox and followed to sign in.
1717* **Signed in** tells you when the session started. The time is shown in your local time zone along with a relative hint such as "2 days ago".
1818 
1919## What is not shown
2020 
21To limit how much information about your devices is held in the system, the list deliberately does not include IP addresses, locations, device names, or browser details. You can tell a browser session from a desktop session and you can see when each one started, but you cannot tell two browser sessions apart by device. When in doubt, sign out anything you cannot positively account for; signing back in is quick.
21To limit how much information about your devices is held in the system, the list deliberately does not include IP addresses, locations, device names, or browser details. You can tell a browser session from an application session and you can see when each one started, but you cannot tell two browser sessions apart by device. When in doubt, sign out anything you cannot positively account for; signing back in is quick.
2222 
2323## How long sessions last
2424 

government/config/settings Changed · +39 / -7 lines

### Claude Code ### Bypass-permissions mode and Auto mode ### Microsoft 365 features ### File access rules (Microsoft 365)

from line 50
5050 
5151### Telemetry endpoint
5252 
53The base address of the collector where Claude Desktop sends usage telemetry using the [OpenTelemetry](https://opentelemetry.io/) protocol (OTLP), for example `https://otel-collector.example.gov:4318`. Claude Desktop appends the OTLP request paths `/v1/logs` and `/v1/metrics` itself, so enter the address without those suffixes. Leaving the value empty disables telemetry.
53The base address of the collector where Claude applications send usage telemetry using the [OpenTelemetry](https://opentelemetry.io/) protocol (OTLP), for example `https://otel-collector.example.gov:4318`. Each application appends the OTLP request paths it uses, such as `/v1/logs` and `/v1/metrics`, so enter the address without those suffixes. Leaving the value empty disables telemetry.
5454 
5555The value must begin with `https://` and may include a port and a path prefix. Its host must be a hostname or a private-network address, and a public IP address is refused.
5656 
from line 70
7070 
7171### Telemetry headers
7272 
73Headers sent with every telemetry request, typically the credential your collector requires. Leave the setting empty if your collector does not require one. Because the value may contain a secret, it is never displayed after you save it; you see only that it is set.
73Headers sent with every telemetry request, typically the credential your collector requires. Each member's app receives these headers and sends its telemetry directly, so use a credential that can only send data to your collector. Leave the setting empty if your collector does not require one. Because the value may contain a secret, it is never displayed after you save it; you see only that it is set.
7474 
7575Click **Add header**, then enter the header's name and value, for example `Authorization` and `Bearer <token>`, and add a row for each additional header. A value can contain spaces and `=` characters, but not a comma. Because saved headers are hidden, the headers you enter later replace all of the saved ones when you save, so enter every header again when you add or change one.
7676 
7777### Telemetry content capture
7878 
79The content that Claude Desktop adds to the telemetry it sends to your collector, chosen from **Prompts**, **Claude's responses**, **Tool inputs**, **Tool results**, and **Full requests and responses**. Nothing is selected by default, so the export records activity such as models, token counts, durations, and tool names without any message or tool text.
79The content that Claude applications add to the telemetry they send to your collector, chosen from **Prompts**, **Claude's responses**, **Tool inputs**, **Tool results**, and **Full requests and responses**. Nothing is selected by default, so the export records activity such as models, token counts, durations, and tool names without any message or tool text.
8080 
8181**Tool results** content is delivered only while **Telemetry traces** is on. Captured content goes only to your collector and is never sent to Anthropic. [Content capture](/docs/third-party/claude-desktop/telemetry#content-capture) in the Claude Desktop telemetry reference shows what each category adds.
8282 
from line 134
134134 
135135A group of separate switches that control which Claude products and features are available to members. Each switch appears as its own row: **Claude Desktop**, **Chat in Claude Desktop**, **Advanced file analysis in Chat**, **Cowork in Claude Desktop**, **Code in Claude Desktop**, **Claude Code**, and **Claude for Microsoft 365**. These switches are on by default, except for **Claude Code** and **Claude for Microsoft 365**.
136136 
137Turning off one of the three product switches (**Claude Desktop**, **Claude Code**, or **Claude for Microsoft 365**) makes Claude for Government stop serving that application your organization's configuration. From then on, Claude Desktop and the Claude for Microsoft 365 add-in are refused the organization's configuration when they request it, and Claude Code that is signed in to Claude for Government exits when it next starts (or right after sign-in) with a message that it couldn't load settings from the cloud gateway. Claude Code that is already running is not cut off and keeps working until it is next started. The product switches are not an access control on the Claude for Government service itself. What a member can reach is governed by their account, their [seat tier](/docs/government/org-admin/seat-tiers), and your agency's device and network management. To cut a member off at once, deactivate their account, after which they cannot sign in and requests from their existing sign-ins are refused (see [Deactivated users](/docs/government/org-admin/users#deactivated-users)). Turning off one of the other four switches removes that feature from Claude Desktop, as described below.
137Turning off **Claude Code** or **Claude for Microsoft 365** stops the members the setting applies to from using that application. Turning off **Claude Desktop** stops the app from receiving your organization's settings. These switches turn applications off, not accounts, and are not a security boundary: to cut one member off from everything at once, deactivate their account (see [Deactivated users](/docs/government/org-admin/users#deactivated-users)). Turning off one of the other four switches removes that feature from Claude Desktop, as described below.
138138 
139The **Chat in Claude Desktop**, **Cowork in Claude Desktop**, and **Code in Claude Desktop** switches each make one part of the app available to members. Chat is for simple conversations, Cowork is for longer tasks that Claude works through on its own in a local workspace folder, and Code is for software development. The **Claude Code** switch is separate and applies to the standalone Claude Code command-line tool.
139The **Chat in Claude Desktop**, **Cowork in Claude Desktop**, and **Code in Claude Desktop** switches each make one part of the app available to members. Chat is for simple conversations, Cowork is for longer tasks that Claude works through on its own in a local workspace folder, and Code is for software development. The **Claude Code** switch is separate and applies to the standalone Claude Code command-line tool. To set up Claude Code on agency devices, see [Connect Claude Code to Claude for Government](/docs/government/deploy-claude-code/configure).
140140 
141141When Chat and Cowork are both available, Claude Desktop presents them together as **Home** in its sidebar, next to **Code**. From Home, a member chooses **Chat** or **Cowork** in the message box, and the sidebar lists their chats and tasks together.
142142 
from line 152
152152 **Claude Desktop home** needs Claude Desktop 1.52386.0 or later. Earlier versions ignore it and follow the switches.
153153</Note>
154154 
155### Claude Code
156 
157The **Claude Code** section of the **Config** page holds your organization's settings for Claude Code, in the command-line tool and in Code in Claude Desktop 2.9939.2 or later. Claude for Government delivers them after a member signs in.
158 
159* **Blocked shell commands**: command names, such as `curl` or `ssh`, that Claude Code never runs. None are blocked by default.
160* **Managed hooks**: hooks that run in every member's Claude Code sessions, such as a command that writes an audit record after each tool use. None are set by default.
161* **Member-added hooks**: whether hooks and custom status lines that members set up in their own or their projects' settings run as well. **Blocked** by default. Managed hooks still run, and in Claude Desktop so do hooks inside plugins.
162* **Plugin sources**: where members can install Claude Code plugins from, one of **None**, **Approved sources only** with an **Approved plugin sources** list, or **Any source** with a **Blocked plugin sources** list. **None** by default. The two switches under [Member-added plugins and marketplaces](#member-added-plugins-and-marketplaces) narrow **Any source**. While **Let members add plugin marketplaces** is off, members install only from the **Approved plugin sources** list. While **Let members add their own plugins** is off, they cannot add a source of their own from a file or folder on their machine.
163* **Sideloaded plugins**: whether members can load plugins, agents, or connector files with a command-line flag. **Blocked** by default.
164* **Minimum Claude Code version**: Claude Code below this version does not start and tells the member to update. No minimum by default.
165* **Maximum Claude Code version**: Claude Code above this version does not start. No maximum by default.
166* **Opening from the browser**: whether links in web pages and editors can open Claude Code with a prompt filled in. **Blocked** by default.
167* **Shell command sandbox**: whether members' shell commands run inside Claude Code's sandbox. The default, **Claude Code default**, leaves that to Claude Code's own settings. **Off** runs the commands without the sandbox, for workspaces where it cannot start, such as containers.
168 
169Related controls sit outside this section. Under [Tool and connector cards](#tool-and-connector-cards), the **Shell commands**, **Web fetch**, and **Web search** cards turn a whole tool off for Claude Code or make it ask every time. The **Member-added connectors** setting on the **Connectors** card sets which other connectors members can use in Claude Code, beyond web search and the ones you add there: **None** (the default), **Only these**, or **Any connector**. In Claude Desktop 2.2553.0 or later it also governs connectors delivered inside plugins: a remote one connects under **Any connector** or when its address is listed under **Only these**, and a local MCP server does not start under **None** or **Only these**. [Bypass-permissions mode and Auto mode](#bypass-permissions-mode-and-auto-mode) apply to Claude Code as described there.
170 
171Connectors you add on the **Connectors** card reach the Claude Code command-line tool when you tick **Claude Code** under **Apply to**, as [Connectors](/docs/government/connectors/overview) describes.
172 
173### Bypass-permissions mode and Auto mode
174 
175**Bypass-permissions mode** controls whether members can start Claude Code in bypass-permissions mode, which skips permission prompts. **Auto mode** controls whether members can switch the Claude Code command-line tool, and Cowork and Code in Claude Desktop, to Auto mode, in which Claude approves routine actions itself and still asks about risky ones; when it is **Allowed**, new Code sessions in Claude Desktop 2.9939.2 or later and new interactive sessions in the Claude Code command-line tool 2.1.283 or later start in it on models that support Auto mode, unless another mode is chosen. Both are **Blocked** by default.
176 
155177### Member-added plugins and marketplaces
156178 
157179Two switches that control whether members can add plugins of their own in Claude Desktop. **Let members add plugin marketplaces** lets members add plugin marketplaces and install plugins from them. **Let members add their own plugins** lets members upload plugin files or have Claude create a plugin for them. Both switches are off by default.
from line 186
164186 
165187### Let members create skills
166188 
167Controls whether members can create or upload skills of their own in Claude Desktop. The **Let members create skills** switch is on by default.
189Controls whether members can create or upload skills of their own. The **Let members create skills** switch is on by default.
168190 
169191While the switch is off, members cannot create new skills or upload skill files, and Claude does not offer to create or update skills in conversations. Skills that members already made, skills your organization provides, and built-in skills keep working.
170192 
from line 211
189211<Note>
190212 **Block reads outside workspace folders** needs Claude Desktop 1.46388.1 or later. Earlier versions ignore it.
191213</Note>
214 
215### Microsoft 365 features
216 
217The **Claude for Microsoft 365** switch under [Product availability](#product-availability) turns the add-in for Excel, Word, and PowerPoint on or off for members. The **Attach files to chat** switch on the **Microsoft 365 features** card, under **Sessions and access**, is on by default; turning it off stops members from attaching files to conversations in the add-in.
218 
219### File access rules (Microsoft 365)
220 
221Rules for the Claude for Microsoft 365 add-in, under **Sessions and access**, that block its features depending on a file's Microsoft Purview sensitivity label. There are no rules by default. Click **Add rule**, then choose what the rule does (**Block**, or **Allow only matching files**), the **Feature** it governs, which files it **Applies to**, and one or more label conditions.
222 
223When a rule blocks Claude on the open file, members see a "Claude is unavailable for this document" screen, and a blocked attachment is refused with a message that names the file. A file whose label the add-in cannot read counts as blocked for any feature that has a rule for that file type.
192224 
193225## Tool and connector cards
194226 

government/deploy-claude-code/configure New page · 170 lines, new page

# Connect Claude Code to Claude for Government ## Before you begin ## The managed settings ### Before sign-in ### Optional: web proxy settings in the managed settings ## Deploy the settings ### macOS ### Windows ### Linux and Windows Subsystem for Linux ### A single machine set up by hand ## Sign in ## Confirm it worked ## Troubleshooting ## Things to know

A whole new page. There's nothing to diff it against, so here is what it says.

# Connect Claude Code to Claude for Government

> Deploy the managed settings that send the Claude Code command-line tool to Claude for Government sign-in, limit what it contacts before a user signs in, and verify the result on macOS, Windows, and Linux.

> **Who this is for:** IT administrators who install the Claude Code command-line tool on agency devices and connect it to Claude for Government.

In Claude for Government, Claude Code is in early access. To request access for your agency, contact your Anthropic representative.

A fresh install of Claude Code asks the user to sign in with a claude.ai or Claude Console account. To connect it to Claude for Government instead, each device needs a small managed settings file that sends users to your agency's Claude for Government sign-in. Everything else that governs Claude Code is set on the [Config](/docs/government/config/settings) page in this portal and delivered to Claude Code after the user signs in.

This page covers the device side: the managed settings, where to put them on each operating system, how a user signs in, and how to confirm a device is set up. Claude Code built into Claude Desktop (the **Code** tab) is configured through Claude Desktop instead, as [Connect Claude Desktop to Claude for Government](/docs/government/deploy-desktop/configure) describes.

## Before you begin

* **Claude Code is turned on for the organization.** A tenant administrator or organization owner turns on the **Claude Code** switch under [Product availability](/docs/government/config/settings#product-availability) on the **Config** page. It is off by default, and while it is off Claude Code exits right after the user signs in.
* **User accounts exist.** Claude Code signs users in to the same accounts as this portal. Each user needs a [routing rule](/docs/government/tenant-admin/identity-and-access) that covers them and a [seat tier](/docs/government/org-admin/seat-tiers) with at least one model enabled.
* **Claude Code is current.** This setup requires Claude Code 2.1.267 or later (`claude --version`).
* **Claude Desktop is current.** Update Claude Desktop to [the supported version](/docs/government/deploy-desktop/configure#before-you-begin) before turning on Claude Code for the terminal.
* **Devices can reach Claude for Government.** Claude Code must reach the gateway address over HTTPS on port 443, and the user's browser must reach the Claude for Government host, its sign-in service, and your agency's identity provider, the same hosts that [Claude Desktop sign-in](/docs/government/deploy-desktop/configure#before-you-begin) needs.
* **You can place a system-level file or policy.** The settings count only from a system-level location: a file in a system directory, a macOS configuration profile, or a machine-level Windows registry policy. Deliver them through your device management system or by hand with administrator rights.

## The managed settings

Claude Code reads device-level policy from what it calls managed settings. For Claude for Government they contain two keys that turn on gateway sign-in, an `env` block, and one key recommended on devices that also run Claude Desktop.

| Key | Value | Purpose |
| - | - | - |
| `forceLoginMethod` | `"gateway"` | Required. Replaces Claude Code's sign-in choices with a single **Cloud gateway** screen. |
| `forceLoginGatewayUrl` | The Claude for Government gateway address | Required. The address the **Cloud gateway** screen connects to. |
| `env` | The eight variables shown below | Required. Keeps Claude Code's telemetry to Anthropic and its pre-sign-in background connections off from the first launch, and sets its request headers, request body fields, and certificate checking as described below. |
| `parentSettingsBehavior` | `"merge"` | Recommended on devices that also run Claude Desktop, harmless elsewhere: Code sessions inside Claude Desktop then keep Claude Desktop's own restrictions alongside these settings, as [Interaction with Claude Code's own managed settings](/docs/third-party/claude-desktop/code#interaction-with-claude-code%E2%80%99s-own-managed-settings) describes. |

As a `managed-settings.json` file:

```json theme={null}
{
  "forceLoginMethod": "gateway",
  "forceLoginGatewayUrl": "https://<claude-for-government-gateway-address>",
  "env": {
    "CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC": "1",
    "DISABLE_TELEMETRY": "1",
    "DISABLE_ERROR_REPORTING": "1",
    "CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL": "1",
    "ANTHROPIC_CUSTOM_HEADERS": "",
    "CLAUDE_CODE_EXTRA_BODY": "",
    "NODE_TLS_REJECT_UNAUTHORIZED": "1",
    "NODE_EXTRA_CA_CERTS": ""
  },
  "parentSettingsBehavior": "merge"
}
```

Your Anthropic representative provides the gateway address. Replace `<claude-for-government-gateway-address>` with it so the value is the full address starting with a single `https://`, including any path. The address is the same for every device and contains no credentials, so one file serves your whole fleet.

Claude Code honors the two sign-in keys only from a system-level location and ignores them in a user's own settings or a per-user registry policy.

### Before sign-in

Your organization's settings reach Claude Code only after a user has signed in. Until then, the first four variables keep Claude Code's release-notes download, update checks, automatic setup of the official plugin marketplace, and usage telemetry and error reporting to Anthropic off from the first launch. After sign-in the organization's settings keep them off.

The last four variables are required as shown. `ANTHROPIC_CUSTOM_HEADERS` and `CLAUDE_CODE_EXTRA_BODY` set to empty strings keep extra request headers and extra request body fields off. `NODE_TLS_REJECT_UNAUTHORIZED` set to `"1"` keeps certificate checking on. `NODE_EXTRA_CA_CERTS` names your agency's certificate authority bundle if your devices need one, and is otherwise left empty.

For what each variable controls, see [Environment variables](https://code.claude.com/docs/en/env-vars) in the Claude Code documentation.

### Optional: web proxy settings in the managed settings

If your devices use a web proxy that you manage, add `HTTPS_PROXY` and `HTTP_PROXY` (the proxy's address, for example `http://proxy.example.gov:8080`) and `NO_PROXY` (your bypass list, keeping `localhost`, `127.0.0.1`, and `::1`) to the same `env` block, each under both its uppercase and lowercase name. Claude Code then uses that proxy wherever the device connects from, in place of any other proxy setting on the device. If your devices connect directly, leave these variables out rather than setting them to empty strings, because an empty value switches off a proxy a user would otherwise use. On a device that also runs Claude Desktop, Claude Desktop applies the same proxy values to the sessions it runs, as [Interaction with Claude Code managed settings](/docs/third-party/claude-desktop/network-proxy#interaction-with-claude-code-managed-settings) describes.

## Deploy the settings

Deliver the settings through your device management system wherever you can, and before users start Claude Code for the first time, so that their first launch lands on the **Cloud gateway** screen. Claude Code reads managed settings when it starts; a user who had it open when the settings arrived quits and starts it again. Use one location per device. If a device receives more than one, Claude Code uses the macOS profile or machine-level Windows policy and ignores the file.

### macOS

Place the JSON above at `/Library/Application Support/ClaudeCode/managed-settings.json`, or deploy a configuration profile that sets the same top-level keys in the `com.anthropic.claudecode` managed preferences domain, with `env` as a dictionary of strings.

### Windows

Place the JSON above at `C:\Program Files\ClaudeCode\managed-settings.json`, or deliver it as machine policy: a string (`REG_SZ`) value named `Settings` under `HKLM\SOFTWARE\Policies\ClaudeCode` whose data is the whole JSON document on one line. As a `.reg` file:

```text theme={null}
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\ClaudeCode]
; substitute the Claude for Government gateway address
"Settings"="{\"forceLoginMethod\":\"gateway\",\"forceLoginGatewayUrl\":\"https://<claude-for-government-gateway-address>\",\"env\":{\"CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC\":\"1\",\"DISABLE_TELEMETRY\":\"1\",\"DISABLE_ERROR_REPORTING\":\"1\",\"CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL\":\"1\",\"ANTHROPIC_CUSTOM_HEADERS\":\"\",\"CLAUDE_CODE_EXTRA_BODY\":\"\",\"NODE_TLS_REJECT_UNAUTHORIZED\":\"1\",\"NODE_EXTRA_CA_CERTS\":\"\"},\"parentSettingsBehavior\":\"merge\"}"
```

A value under `HKEY_CURRENT_USER` does not turn on gateway sign-in.

### Linux and Windows Subsystem for Linux

On Linux, place the JSON above at `/etc/claude-code/managed-settings.json` (root required).

Claude Code inside Windows Subsystem for Linux (WSL) reads that same path inside each distribution. To manage the setting from Windows instead, add `"wslInheritsWindowsSettings": true` to the machine-level Windows policy or file alongside the keys above; Claude Code inside WSL then reads the Windows settings first and needs no file inside the distribution.

### A single machine set up by hand

To try the setup before a fleet rollout, create the file at the path for the machine's operating system from an administrator account, then start Claude Code as an ordinary user.

## Sign in

With the settings in place, a user's first sign-in on a device goes as follows.

<Steps>
  <Step title="Start Claude Code">
    The user runs `claude` in a terminal. After the first-run theme choice, the **Cloud gateway** screen shows the gateway address, and the user presses **Enter** to connect.
  </Step>

  <Step title="Confirm the gateway certificate">
    The first time each user connects from a device, Claude Code shows the first 16 characters of the gateway's TLS certificate fingerprint (SHA-256) and asks them to trust it. Publish the expected fingerprint to your users with the rollout (they compare it ignoring colons and letter case), and again when Anthropic renews the certificate, because users are asked again after a renewal. Your Anthropic representative provides it.
  </Step>

  <Step title="Finish sign-in in the browser">
    Claude Code opens the Claude for Government sign-in page in the default browser and shows a one-time code in the terminal. The user signs in with your identity provider, checks that the code on the page matches the terminal, and approves.
  </Step>

  <Step title="Return to the terminal">
    If the terminal shows **Signed in to Cloud gateway as** followed by the user's email address, the user confirms with **Yes, continue**. The terminal then shows **Connected to Cloud gateway**, and Claude Code downloads the organization's settings and restarts to apply them. If those settings include items Claude Code asks users to approve, such as a [Telemetry endpoint](/docs/government/config/settings#telemetry-endpoint), it shows a **Managed settings require approval** prompt the first time and whenever those settings change; **No** exits Claude Code. Unattended runs such as `claude -p` apply the settings without prompting.
  </Step>
</Steps>

A sign-in lasts until the organization's [Session idle timeout](/docs/government/config/settings#session-idle-timeout) or [Maximum session length](/docs/government/config/settings#maximum-session-length) is reached, and at most 30 days. It also ends when the user's account is deactivated, or when the user signs in to Claude Code on more devices than Claude for Government allows at once (six), which ends the sign-in closest to expiring (see [Sessions](/docs/government/account/sessions#how-long-sessions-last)). Claude Code then asks the user to sign in again, which they do with `/login`.

## Confirm it worked

Run through these checks on one configured device before the wider rollout.

<Steps>
  <Step title="Check the sign-in screen">
    Start `claude` as a user who has not signed in. The only sign-in option is the **Cloud gateway** screen showing your gateway address. If Claude Code offers claude.ai or Claude Console sign-in instead, the managed settings did not reach it.
  </Step>

  <Step title="Check the background connections are off">
    Before signing in, run `claude doctor`. On the standard installer it reports auto-updates as disabled by `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC`, which shows the `env` block reached Claude Code. (Homebrew, WinGet, and Linux package installs report updates as managed by the package manager instead.)
  </Step>

  <Step title="Check the setting sources">
    After sign-in, run `/status` inside Claude Code. The API provider reads **Cloud gateway** with your gateway address, and **Setting sources** lists **Enterprise managed settings (remote)**.
  </Step>

  <Step title="Check that organization settings arrived">
    Change one visible Claude Code setting on the [Config](/docs/government/config/settings#claude-code) page for a test organization, start a new Claude Code session as a member of it, and confirm the change took effect.
  </Step>
</Steps>

## Troubleshooting

| What you see | Likely cause | What to do |
| - | - | - |
| Claude Code offers claude.ai and Claude Console sign-in instead of the **Cloud gateway** screen | The managed settings did not reach Claude Code: wrong path, a Windows value under `HKEY_CURRENT_USER` or with another name, a misspelled key, or Claude Code was already running | Check the location for the operating system above, then quit and restart Claude Code |
| The **Cloud gateway** screen says to contact your IT administrator | `forceLoginGatewayUrl` is missing or empty | Add the gateway address to the same managed settings and restart Claude Code |
| Claude Code reports that it could not resolve the gateway host, or another connection error for the address shown | The address in `forceLoginGatewayUrl` is not exactly the one your Anthropic representative provided, or the device cannot reach it | Correct the address, or restore the device's route to the gateway over HTTPS on port 443, then restart Claude Code |
| `Unable to connect to Anthropic services` at first start, before any sign-in screen | The sign-in keys did not reach Claude Code from a system-level location, or Claude Code is out of date | Update Claude Code, or check the settings location, then start it again |
| `claude doctor`, run before sign-in on the standard installer, reports auto-updates as enabled | The `env` block did not reach Claude Code | Compare the deployed settings with the sample above, then restart Claude Code |
| When it starts or right after sign-in, Claude Code exits with `Cloud gateway <address> refused managed settings for this account (403): Claude Code may not be enabled for your organization` | The **Claude Code** switch is off at a level that applies to the user (tenant, organization, or directory group) | Turn on the **Claude Code** switch under [Product availability](/docs/government/config/settings#product-availability) at that level (at the tenant level, **Reset to default** instead lets each organization's own switch decide), then have the user start Claude Code again. [**Compare config across levels**](/docs/government/config/overview#comparing-settings-across-levels) on the **Config** page shows which level turns it off for a user |
| When it starts or right after sign-in, Claude Code exits with `Couldn't load settings from Cloud gateway <address>` | Claude Code could not reach the gateway while loading the organization's settings | Confirm the device reaches the gateway over HTTPS on port 443, then have the user start Claude Code again. If it persists on a connected device, contact your Anthropic representative |
| In a session that was working, every request fails with a 403 error saying the product is not available for the organization | The **Claude Code** switch was turned off while Claude Code was running | Turn the switch back on at the level that turned it off; the next request then succeeds |
| Before the user has signed in, Claude Code exits with `Administrator policy requires a Cloud gateway sign-in on this machine` | A credential from earlier use is present: `ANTHROPIC_API_KEY` or `ANTHROPIC_AUTH_TOKEN` in the environment, an `apiKeyHelper` in the user's settings, or a saved Claude Console key | Remove the variable or the `apiKeyHelper` entry, or have the user run `claude auth logout`, then start `claude` and sign in |
| Claude Code says the gateway's TLS certificate changed and asks the user to run `/login` | The gateway certificate was renewed | Confirm the new fingerprint with your Anthropic representative, send it to users, and have them run `/login` and accept it |

## Things to know

* Only the gateway sign-in described on this page delivers the organization's settings to Claude Code.
* A claude.ai sign-in left on a device from earlier use is ignored once these settings are in place. A leftover `ANTHROPIC_API_KEY`, `ANTHROPIC_AUTH_TOKEN`, `apiKeyHelper`, or saved Claude Console key is not: until the user has signed in through the gateway, Claude Code stops and asks for its removal, as [Troubleshooting](#troubleshooting) describes.
* Where the Claude Code extension for VS Code is used, have users remove an earlier claude.ai sign-in with `claude auth logout` or the extension's **Claude Code: Logout** command before they sign in through the gateway, not after: both commands clear every credential Claude Code has stored, the gateway sign-in included.
* To take a device out of this setup, have its users sign out with `claude auth logout` before you remove the settings.
* After sign-in, the organization's settings turn off the Claude Code settings that run a helper command (`apiKeyHelper`, `proxyAuthHelper`, `awsAuthRefresh`, `awsCredentialExport`, `gcpAuthRefresh`, `otelHeadersHelper`), wherever it is set. If your devices reach the network through a proxy that needs a helper command to authenticate, raise this with your Anthropic representative before you deploy.
* With these settings Claude Code does not check for or install updates in the background. Distribute new versions through your software deployment tooling, or have users run `claude update` (standard installer) or their package manager.
* Code sessions inside Claude Desktop sign in through Claude Desktop, not through these settings, but on a device that has this file its `env` block applies to them too, and `parentSettingsBehavior` set to `"merge"` keeps Claude Desktop's own restrictions in force alongside it.

government/deploy-microsoft-365/configure New page · 154 lines, new page

# Deploy Claude for Microsoft 365 in Claude for Government ## Before you begin ## Download the manifest ## Deploy from the Microsoft 365 admin center ### Deploy from the Add-ins page ### Deploy from Integrated apps ## What users see ## Confirm the deployment

A whole new page. There's nothing to diff it against, so here is what it says.

# Deploy Claude for Microsoft 365 in Claude for Government

> Download the Claude for Microsoft 365 manifest from your Claude for Government host and deploy the add-in to users from the Microsoft 365 admin center.

> **Who this is for:** Microsoft 365 administrators who make the Claude for Microsoft 365 add-in available to agency users in Excel, Word, and PowerPoint.

In Claude for Government, Claude for Microsoft 365 is in early access. To request access for your agency, contact your Anthropic representative.

Claude for Microsoft 365 is an Office add-in that opens Claude in a pane beside the workbook, document, or presentation a user is editing. In Claude for Government, Office loads the add-in from your Claude for Government host, and the add-in sends its sign-in and chat traffic to that host. The host is written into the add-in's manifest, a small XML file that tells Office where to load the add-in from. You make the add-in available from the Microsoft 365 admin center by uploading the manifest and assigning it to users.

Microsoft 365 Government tenants can't use the public add-in store, so you deploy the manifest yourself (see Microsoft's [guidance for Office Add-ins on government clouds](https://learn.microsoft.com/en-us/office/dev/add-ins/publish/government-cloud-guidance)).

This page covers the add-in that runs inside Office. The [Microsoft 365 connector](/docs/government/connectors/microsoft-365), which lets Claude Desktop read your agency's Outlook, OneDrive, SharePoint, and Teams content, is a separate feature with its own setup.

## Before you begin

Confirm each of the following before you deploy the manifest.

* **Claude for Microsoft 365 is turned on for the organization.** Check the **Claude for Microsoft 365** switch under [Product availability](/docs/government/config/settings#product-availability). It is off by default. While it is off, users who sign in from the add-in are told that Claude for Microsoft 365 is not turned on for their organization.
* **User accounts exist.** The add-in signs users in to the same accounts as this portal. Each user needs a [routing rule](/docs/government/tenant-admin/identity-and-access) that covers them and a [seat tier](/docs/government/org-admin/seat-tiers) with at least one model enabled.
* **Office is a supported version.** The add-in needs the Office builds listed under supported versions for [Excel](/docs/office-agents/excel#supported-versions), [Word](/docs/office-agents/word#supported-versions), and [PowerPoint](/docs/office-agents/powerpoint#supported-versions).
* **Devices can reach your Claude for Government host.** Office on every device must reach your Claude for Government host over HTTPS (port 443). That host serves the add-in and carries its sign-in requests and chat traffic.
* **Devices can reach Microsoft's Office add-in library.** At startup the pane loads Microsoft's `office.js` library from one of these Microsoft hosts, chosen by the `?officecdn=` parameter you add when you [download the manifest](#download-the-manifest):
  * no `?officecdn=` parameter: `appsforoffice.microsoft.com`
  * `?officecdn=gcc`: `appsforoffice.gcc.cdn.office.net`
  * `?officecdn=gcch`: `appsforoffice.gcch.cdn.office.net`
  * `?officecdn=dod`: `appsforoffice.dod.cdn.office.net`
* **Your telemetry collector accepts the add-in's requests.** When a [**Telemetry endpoint**](/docs/government/config/settings#telemetry-endpoint) is set, the pane on each device sends traces and logs directly to that collector. The collector must be reachable from users' networks and must accept cross-origin requests from your Claude for Government host, which is the add-in's origin.
* **Your connectors accept the add-in's requests.** The pane on each device connects directly to every connector that applies to Claude for Microsoft 365 (see the [**Connectors** card](/docs/government/config/settings#tool-and-connector-cards)). Each connector must be reachable from users' networks and must accept cross-origin requests from your Claude for Government host, which is the add-in's origin.
* **Browsers can reach sign-in.** Sign-in happens in the user's default web browser, not in the pane. Browsers on each device must reach your Claude for Government host, the Claude for Government sign-in service (a separate host that your Anthropic representative provides), and your agency's identity provider. These are the same hosts [Claude Desktop sign-in](/docs/government/deploy-desktop/configure#before-you-begin) needs.
* **You can deploy add-ins in the Microsoft 365 admin center.** Users need the Microsoft 365 Apps versions and Exchange Online mailboxes listed in Microsoft's [requirements for Centralized Deployment](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/centralized-deployment-of-add-ins).

## Download the manifest

Your Claude for Government host serves the manifest at the fixed path `/office/manifest-fedstart.xml`. If you are unsure of your host, ask your Anthropic representative.

```text theme={null}
https://<claude-for-government-host>/office/manifest-fedstart.xml
```

If your tenant is in GCC High or DoD, add `?officecdn=gcch` or `?officecdn=dod` to the end of the address, and in GCC you can add `?officecdn=gcc`. The pane then loads Microsoft's `office.js` library from the Office CDN inside your cloud, as Microsoft's [guidance for Office Add-ins on government clouds](https://learn.microsoft.com/en-us/office/dev/add-ins/publish/government-cloud-guidance) recommends.

```text theme={null}
https://<claude-for-government-host>/office/manifest-fedstart.xml?officecdn=gcch
```

Choose the cloud before your first deployment. To change it later, remove the add-in in the admin center, download the file again with the new parameter, and deploy the new file.

Open the address in a browser and save the file. Open the saved file and check that the `SourceLocation` line names your Claude for Government host. If it doesn't, contact your Anthropic representative.

If your host answers to more than one name, pick one name and always download from it. The add-in's identity follows the host name in the address, so files downloaded under two names install as two separate add-ins.

The manifest installs Claude in Excel, Word, and PowerPoint and asks Office for permission to read and change the open document, which is how Claude edits the file a user is working in. The admin center and Office list the add-in as **Claude for Government**, and the ribbon button is labeled **Claude**.

## Deploy from the Microsoft 365 admin center

Microsoft doesn't offer its **Integrated apps** page in its [government clouds](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/test-and-deploy-microsoft-365-apps), so GCC, GCC High, and DoD tenants deploy from **Settings** > **Add-ins** (Microsoft's [Centralized Deployment](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/centralized-deployment-of-add-ins)). If your admin center shows **Integrated apps** instead, follow [Deploy from Integrated apps](#deploy-from-integrated-apps). In either case, upload the file you saved rather than entering its web address, so that Microsoft's service doesn't have to reach your Claude for Government host.

### Deploy from the Add-ins page

<Steps>
  <Step title="Open the Microsoft 365 admin center">
    Sign in to the Microsoft 365 admin center for your cloud with an account that can deploy add-ins.
  </Step>

  <Step title="Open the Add-ins page">
    In the left pane, select **Show all**, then select **Settings** > **Add-ins**.
  </Step>

  <Step title="Start a custom deployment">
    Select **Deploy Add-in**, then select **Next**.
  </Step>

  <Step title="Choose a custom upload">
    Under **Deploy a custom add-in**, select **Upload custom apps**.
  </Step>

  <Step title="Upload the manifest">
    Choose the option to upload a manifest file from your device, browse to the `manifest-fedstart.xml` file you saved, and select **Upload**.
  </Step>

  <Step title="Choose users">
    On the **Configure add-in** page, choose who gets the add-in: **Everyone**, **Specific users/groups**, or **Just me**. Deploying to yourself or a small group first lets you confirm the add-in works on a representative device before a wider rollout.
  </Step>

  <Step title="Deploy">
    Select **Deploy**.
  </Step>
</Steps>

### Deploy from Integrated apps

<Steps>
  <Step title="Open the Microsoft 365 admin center">
    Sign in to the Microsoft 365 admin center with an account that can deploy add-ins.
  </Step>

  <Step title="Open Integrated apps">
    Select **Settings** > **Integrated apps**.
  </Step>

  <Step title="Start a custom upload">
    Select **Upload custom apps** and choose **Office Add-in** as the app type.
  </Step>

  <Step title="Upload the manifest">
    Choose the option to upload the manifest file from your device and upload `manifest-fedstart.xml`.
  </Step>

  <Step title="Choose users">
    Assign the add-in to everyone, specific users or groups, or just yourself. A small group first lets you confirm it works before a wider rollout.
  </Step>

  <Step title="Review the summary">
    Select **Next** through the remaining pages and review the summary.
  </Step>

  <Step title="Finish the deployment">
    Select **Finish deployment**.
  </Step>
</Steps>

A deployment can take up to 24 hours to reach every assigned user, and users may need to restart the Office application before the add-in appears.

To change who has the add-in or to remove it later, see Microsoft's [Manage add-ins in the Microsoft 365 admin center](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-addins-in-the-admin-center).

## What users see

Once the deployment reaches a user, a **Claude** button appears on the **Home** tab of the ribbon in Excel, Word, and PowerPoint. The add-in is also listed under **Admin Managed** in Office's add-ins window. Selecting the button opens the Claude pane, which shows a **Log in** button.

When the user selects **Log in**, the pane shows a short code and opens the Claude for Government sign-in page in the user's default browser. If the browser doesn't open, the user selects **Continue in browser** under the code. The code is valid for 10 minutes, after which the pane offers **Start over**. In the browser, the user:

1. Enters their agency email address.
2. Signs in through your agency's identity provider.
3. Acknowledges the U.S. Government system-use notification.
4. Checks that the code shown matches the one in the pane, then selects **Approve**.

When the user returns to the pane it shows **You're signed in**, and selecting **Continue** opens Claude. On a user's first sign-in the pane shows a short welcome and a notice to acknowledge before the chat box appears. For what users can do once signed in, see the Claude for Microsoft 365 guides for [Excel](/docs/office-agents/excel), [Word](/docs/office-agents/word), and [PowerPoint](/docs/office-agents/powerpoint).

## Confirm the deployment

<Steps>
  <Step title="Open the pane">
    As a user you assigned the add-in to, open Excel, Word, or PowerPoint, select the **Claude** button on the **Home** tab of the ribbon, then select **Log in** in the pane.
  </Step>

  <Step title="Sign in">
    Complete sign-in in the browser as described under [What users see](#what-users-see), select **Continue** if the pane shows it, and step through the welcome screens.
  </Step>

  <Step title="Ask Claude about the file">
    Ask Claude a question about the open file and confirm it answers.
  </Step>
</Steps>

government/security/security-and-data-handling Changed · +18 / -4 lines

## Claude Code command-line tool

from line 4
44 
55> **Who this is for:** Security, compliance, and IT reviewers who are assessing Claude for Government for their agency, and administrators who need to explain the product's runtime behavior.
66 
7The answers on this page cover the Claude Desktop application in Claude for Government and address the security and data-handling questions that come up most often during agency security review. Claude Desktop offers three ways to work with Claude: **Chat** for simple conversations, **Cowork** for longer tasks with a local workspace folder, and **Code** for software development. Each answer states what is specific to Claude for Government (the FedRAMP High boundary, the defaults Anthropic applies for government tenants, and the relevant admin portal control), then links to the Claude Desktop documentation for the underlying mechanism. For assurance materials such as the security architecture overview, SOC 2 report, and penetration testing summary, request access through the [Anthropic Trust Center](https://trust.anthropic.com).
7The answers on this page address the security and data-handling questions that come up most often during agency security review, for the [Claude Desktop application](#claude-desktop) and for the standalone [Claude Code command-line tool](#claude-code-command-line-tool), each in its own section. Each answer states what is specific to Claude for Government (the FedRAMP High boundary, the defaults Anthropic applies for government tenants, and the relevant admin portal control), then links to the product documentation for the underlying mechanism. For assurance materials such as the security architecture overview, SOC 2 report, and penetration testing summary, request access through the [Anthropic Trust Center](https://trust.anthropic.com).
88 
99## Claude Desktop
1010 
11The sections below cover the Claude Desktop application. For the admin portal and the Compliance API, see the [Organization administration](/docs/government/org-admin/overview) and [Tenant administration](/docs/government/tenant-admin/overview) sections.
11The sections below cover the Claude Desktop application, which offers three ways to work with Claude: **Chat** for simple conversations, **Cowork** for longer tasks with a local workspace folder, and **Code** for software development. For the admin portal and the Compliance API, see the [Organization administration](/docs/government/org-admin/overview) and [Tenant administration](/docs/government/tenant-admin/overview) sections.
1212 
1313### Sandbox and isolation
1414 
from line 96
9696 
9797### Approvals and Auto mode
9898 
99By default, Claude for Government prompts the user for connector actions, for each web search, and, in Cowork, when Claude asks to add another folder to the session. In Chat and Cowork, Claude's file tools do not write outside the attached folders and the session's working folder, as described under [Sandbox and isolation](#sandbox-and-isolation). In Cowork, shell commands run without a prompt because they run inside the sandbox virtual machine. Web page fetches run without a prompt in both Chat and Cowork and are checked against the egress allowlist described above. Administrators can require a prompt on every shell command or fetch with the **Require approval for each command** and **Require approval for each fetch** sub-settings on the [Config](/docs/government/config/settings#tool-and-connector-cards) page. In Chat on Claude Desktop versions earlier than 2.110.0, every shell command prompts regardless. The reduced-approval option in Claude for Government is Auto mode, which is off by default and can be enabled through device managed configuration (it is not a setting on the Config page). Cowork does not offer a Bypass Permissions mode.
99By default, Claude for Government prompts the user for connector actions, for each web search, and, in Cowork, when Claude asks to add another folder to the session. In Chat and Cowork, Claude's file tools do not write outside the attached folders and the session's working folder, as described under [Sandbox and isolation](#sandbox-and-isolation). In Cowork, shell commands run without a prompt because they run inside the sandbox virtual machine. Web page fetches run without a prompt in both Chat and Cowork and are checked against the egress allowlist described above. Administrators can require a prompt on every shell command or fetch with the **Require approval for each command** and **Require approval for each fetch** sub-settings on the [Config](/docs/government/config/settings#tool-and-connector-cards) page. In Chat on Claude Desktop versions earlier than 2.110.0, every shell command prompts regardless. By default, members cannot switch to Auto mode. When an administrator sets the **Auto mode** setting to **Allowed** on the [Config](/docs/government/config/settings#bypass-permissions-mode-and-auto-mode) page, Claude Desktop offers it in Cowork and in Code sessions, and members can switch the Claude Code command-line tool to it. New Code sessions in Claude Desktop 2.9939.2 or later and new interactive sessions in the Claude Code command-line tool 2.1.283 or later then start in it on models that support Auto mode, unless another mode is chosen. Cowork does not offer a bypass-permissions mode.
100100 
101101<AccordionGroup>
102102 <Accordion title="Can write and send actions be gated behind approval?">
from line 106
106106 </Accordion>
107107 
108108 <Accordion title="Can Auto mode be disabled when a sensitive connector is attached?">
109 Auto mode can be disabled by policy, but not conditionally based on which connector is attached. The Auto mode policy, delivered through device managed configuration, controls whether users see Auto mode in the Cowork and Code permission selectors, and it defaults to off in Claude for Government. You can combine that policy with per-tool policies (setting a sensitive connector's tools to **ask** or **blocked**) to achieve a similar effect.
109 Not for one connector alone. Auto mode is available only while an administrator has the **Auto mode** setting at **Allowed** on the [Config](/docs/government/config/settings#bypass-permissions-mode-and-auto-mode) page, as described above, and setting it back to **Blocked** withdraws it again. To limit a sensitive connector while Auto mode is allowed, switch the connector's tools off under **Tool policy** on the [Config](/docs/government/config/settings#tool-and-connector-cards) page.
110110 </Accordion>
111111 
112112 <Accordion title="Can individual shell commands be allowlisted enterprise-wide?">
from line 215
215215 In Cowork, Claude's file tools change files in an attached folder in place, so the changes appear there immediately. A user who wants results in a particular folder attaches that folder to the task and asks Claude to save the files there. Shell commands run inside the sandbox virtual machine, and on the device they can write only to the attached folders and the task's working folder. A file that a command writes anywhere else in the virtual machine, for example under `/tmp`, does not appear in any folder on the device.
216216 
217217 By design, Chat cannot save files to other folders on the device. Claude's file tools in Chat, and the analysis steps that run in the sandbox when **Advanced file analysis in Chat** is on (the default), write only to the conversation's own working folder. For work that should end up in a particular folder, the user can run it as a Cowork task with that folder attached. See [Chat in Claude Desktop](/docs/third-party/claude-desktop/chat) for what a Chat conversation can reach, and [User identity and local data](/docs/third-party/claude-desktop/data-storage) for the folder layout.
218 </Accordion>
219</AccordionGroup>
220 
221## Claude Code command-line tool
222 
223The answers below cover the standalone Claude Code command-line tool when it signs in through Claude for Government, as [Connect Claude Code to Claude for Government](/docs/government/deploy-claude-code/configure) describes. The Claude Desktop answers above cover Code sessions inside Claude Desktop.
224 
225<AccordionGroup>
226 <Accordion title="Which domains does Claude Code need to reach?">
227 The Claude for Government gateway address that your Anthropic representative provides, over HTTPS on port 443, for sign-in, organization settings, and model inference. Sign-in finishes in the user's browser, which needs the Claude for Government host, its sign-in service, and your agency's identity provider, as for Claude Desktop. Claude Code also reaches, from the user's device, the address of each connector an administrator applies to **Claude Code** on the **Connectors** card, and that connector's sign-in service when it uses OAuth. The managed settings from [Connect Claude Code to Claude for Government](/docs/government/deploy-claude-code/configure#before-sign-in) turn off Claude Code's background connections before sign-in (release notes, update checks, and the official plugin marketplace).
228 </Accordion>
229 
230 <Accordion title="Does Claude Code send telemetry to Anthropic?">
231 No. The managed settings in [Connect Claude Code to Claude for Government](/docs/government/deploy-claude-code/configure#the-managed-settings) turn off Claude Code's usage telemetry and error reporting to Anthropic from the first launch, and the organization's settings keep them off after sign-in.
218232 </Accordion>
219233</AccordionGroup>
220234 

government/connectors/overview Changed · +1 / -1 lines

from line 57
5757 
5858Choose which products receive this connector and which of its tools are available.
5959 
60Under **Apply to**, tick the products that should receive this connector: Claude Desktop and Microsoft 365. A connector with no products ticked is saved but delivered nowhere, which is a way to pause it. A connector that uses OAuth cannot be applied to Microsoft 365, because per-user sign-in is not available there. A connector with any tool switched off in the table below also cannot be applied to Microsoft 365, and the checkbox is disabled with a **needs every tool on** note until every tool is on.
60Under **Apply to**, tick the products that should receive this connector. A connector with no products ticked is saved but delivered nowhere, which is a way to pause it. A connector that uses OAuth cannot be applied to Microsoft 365, because per-user sign-in is not available there. A connector with any tool switched off in the table below also cannot be applied to Microsoft 365, and the checkbox is disabled with a **needs every tool on** note until every tool is on. A connector that uses **OAuth (pre-registered app)** with a **Tenant ID** is not delivered to the Claude Code command-line tool, and its checkbox shows a **not delivered to the Claude Code command-line tool** note.
6161 
6262Under **Tool policy**, the table lists the tools found during discovery with an on/off switch for each. **Refresh tools** probes the server again and fills in any tools that are new since you last looked, keeping the switches you have already set. **Add tool** lets you type a tool name by hand when discovery could not reach the server.
6363 

government/org-admin/readiness Changed · +1 / -1 lines

from line 30
3030* **Allocate seats** checks that the organization has been allocated at least one seat of any tier. This is advisory. Without an allocation you can still assign tiers to people individually, but anyone who signs in before you do lands without a seat and cannot send messages. **Open Seats** or **Open Billing** takes you to the page where allocations are set, depending on how your billing account is managed. If the shared seat pool is already fully distributed, the step instead explains that the pool needs to be raised and shows who can do that.
3131* **Assign seat tiers to members** checks that every active member has a seat tier, because a member without one cannot use Claude. It is advisory and sits under **Optional**, since you may leave someone unassigned on purpose, but it also catches a member left without a seat by mistake, such as a Primary Owner who was added before the organization had any seats. When a seat is free, **Open Users** takes you to the [Users](/docs/government/org-admin/users) page, where a member without a seat shows **Unassigned** and you can choose a tier for them. If your organization has no seats at all yet and nobody holds one, those members are seated automatically when seats are first allocated, and the step points to the same place as **Allocate seats**.
3232* **Assign a model to your seat tier** checks that at least one seat tier in this organization can actually reach a working model, meaning a model that is enabled, priced, and allowed by a tier whose usage limits are high enough to cover a single request. If no tier qualifies, nobody can send a message regardless of credits or seats. **Open Tiers** takes you to the [Seat tiers](/docs/government/org-admin/seat-tiers) page to add a model or raise a tier's limits. If every tier available to you is Anthropic-managed, only Anthropic can change its model list, so the step shows a waiting state.
33* **Enable a product** checks that at least one Claude product, such as Claude Desktop, Claude Code, or Claude for Microsoft 365, is enabled for this organization. This is advisory. With nothing enabled, direct API access still works, but no client application can start. Enable a product on the [Config](/docs/government/org-admin/configuration) page.
33* **Enable a product** checks that at least one Claude product, such as Claude Desktop, Claude Code, or Claude for Microsoft 365, is enabled for this organization. This is advisory. With nothing enabled, no client application can start. Enable a product on the [Config](/docs/government/org-admin/configuration) page.
3434 
3535## Things to know
3636 
Feedback