One read of Claude Documentationclaude-docs-20261002T063708Z
25 pages moved out of 259 read.
Pages moved
25
significant first
Pages read
259
in this capture
Captured
06:37 UTC
Corpus hash
6a2d4d7a34f0
corpus-hash
What this read moved
1-25 of 25claude-tag/admins/add-connections Changed · +5 / -7 lines
from line 12
1212
1313An [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of credentials, domain entries, repository grants, plugins, and instructions that Claude uses in the channels the bundle covers. A connection is one service credential inside a bundle, like a Datadog API key or a warehouse service account, that Claude uses to act in that service from any channel under the bundle's [scope](/docs/claude-tag/concepts/glossary#scope).
1414
15If you're in [setup](/docs/claude-tag/admins/setup-overview), you add these connections there; skip to [Decide what to connect](#decide-what-to-connect). The steps below are for creating a bundle outside setup, on the admin page directly.
15You create your first bundle on the admin page, after you finish [setup](/docs/claude-tag/admins/setup-overview) and launch.
1616
1717<Steps>
1818 <Step title="Open the admin page">
from line 113
113113To get there, open the bundle from the scope that covers the channel, under **Claude Tag's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag); if the scope has no bundle yet, [create one](#your-first-access-bundle) first. On the bundle's **Domains** tab, fill in the form and click **Add domain**:
114114
115115* **Domain**: the hostname to allow; a wildcard is allowed as the leftmost label, like `*.example.com`, and covers subdomains at any depth but not `example.com` itself
116* **Ports**: needed only when the service listens on something other than 443
116* **Ports**: `443` unless the service listens on another port
117117
118For example, to let Claude check a vendor's status page at `status.example.org`, enter `status.example.org` in the **Domain** field and leave the **Ports** field empty.
118For example, to let Claude check a vendor's status page at `status.example.org`, enter `status.example.org` in the **Domain** field and leave the other fields as they are.
119119
120120You don't have to predict the full list up front. When a request is blocked, Claude says so in the thread and names the host, with wording like "blocked by the network egress proxy" (that is, by Agent Proxy); add that host here and retry. If the host is listed and Claude still reports it blocked, check these in order:
121121
from line 141
141141
142142### Allow all hosts
143143
144Allow-all egress is off by default; ask your Anthropic account team to enable it for your organization. Once enabled, you can enter `*` alone as the domain. A `*` entry needs ports assigned; it admits any host on those ports, with no credential attached.
144To allow every host, enter `*` alone as the domain. A `*` entry needs ports assigned. It admits any host on those ports, with no credential attached.
145145
146146With `*` active:
147147
from line 148
148148* Requests to hosts that no connection covers go through with no credential attached.
149149* A `*` entry never carries a credential, and a connection's credential still travels only to its [allowed websites](#set-allowed-websites).
150150* Private and internal network addresses and cloud metadata endpoints remain blocked.
151
152Without allow-all egress enabled, saving `*` fails with a generic "Couldn't add domain." error that doesn't name the cause. If the capability is later disabled, you can disable an existing `*` entry or narrow it to specific hosts, but you can't keep it active.
153151
154152### Web search vs. network requests
155153
claude-tag/admins/restrict-access Changed · +10 / -4 lines
from line 73
7373
74741. **Ask it to stay quiet.** Saying "stay quiet in this thread unless tagged" stops Claude following an active thread.
75752. **Remove it from the channel.** Run `/remove @Claude`. It can no longer read or post there.
763. **Turn the scope's Enable Claude Tag switch off.** Claude stops responding in that scope even if someone invites it back; an @-mention gets a disabled notice instead of a reply. Only an Owner can change it. The switch sits at the top of the scope's panel at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope. If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead, turn it off at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag**. Claude then stops responding in every connected workspace, not in one scope.
763. **Turn the scope's Enable Claude Tag switch off.** Claude stops responding in that scope even if someone invites it back; an @-mention gets a disabled notice instead of a reply. Only an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) can change it. The switch sits at the top of the scope's panel at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope. If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead, turn it off at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag**. Claude then stops responding in every connected workspace, not in one scope.
77774. **Remove the channel's scope.** Choose **Remove this scope** from the scope's options menu. Claude keeps answering in the channel with the access it inherits from its workspace, and deletes the channel's sessions, memory, routines, and published artifacts; see [what each action deletes](/docs/claude-tag/concepts/data-lifecycle#actions-in-claude). To stop it answering as well, run `/remove @Claude` or turn the scope's **Enable Claude Tag in this channel** switch off first.
78785. **Delete the bundle.** This revokes its credentials everywhere it was attached (the credentials are removed; memory, routines, and transcripts are not). Running sessions may keep a revoked credential for a short window before the change propagates.
79796. **Uninstall the app.** This removes Claude from the workspace and deletes the workspace's Claude data the same way [disconnecting the workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing) does.
from line 318
318318
319319* Create and edit [Access bundles](/docs/claude-tag/admins/add-connections), including their credentials, domain entries, and repository grants, and attach bundles to the organization, a workspace, or a channel
320320* Edit workspace and channel settings at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), such as custom instructions and the default model
321* Turn the **Enable Claude Tag** switch on or off at **Default Slack**, a workspace, or a channel
321322* Add and remove [channel managers](#delegate-channel-setup-to-channel-managers), if the role also sets **Identity & Access** to **Can manage**
323* Set up [**Managed by**](/docs/claude-tag/admins/managed-by) for a channel, on the **Admin** tab of the channel's Configure page
322324* Set a scope's [**How should Claude work in channels with guests**](#restrict-guest-channels) setting to **Restrict** or **Channel only**; choosing **Full access** or setting a scope back to **Inherit** stays with Owners
323325
324326Some actions stay outside the permission:
325327
326* **Owner-only**: turning Claude Tag on or off, the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle, the [**Member access**](#restrict-who-can-use-claude) restriction, pairing or disconnecting workspaces, [channel name patterns](#block-or-auto-join-channels-by-name) and the bundles on them, and the [**Channels Claude can search**](#limit-which-channels-claude-can-search) setting
328* **Owner-only**: the **Enable Claude Tag for your organization** toggle, the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle, the [**Member access**](#restrict-who-can-use-claude) restriction, pairing or disconnecting workspaces, [channel name patterns](#block-or-auto-join-channels-by-name) and the bundles on them, and the [**Channels Claude can search**](#limit-which-channels-claude-can-search) setting
327329* **The Claude GitHub App**: [installing the app](/docs/claude-tag/admins/configure-github) needs an owner of your GitHub organization
328330* **Spend limits and usage analytics**: [usage analytics](#usage-analytics) is open to anyone with permission to view your organization's Analytics dashboard; [spend limits](/docs/claude-tag/admins/set-spend-limit) live on the usage page
329331
from line 425
423425
424426## Permissions by role
425427
426Creating bundles and binding them to scopes need an Owner or a [Claude Tag admin](#delegate-claude-tag-administration). Pairing workspaces needs an Owner. A [channel manager](#delegate-channel-setup-to-channel-managers) configures only the channels assigned to them. Everything else happens inside the channel and is open to its members. The table lists each action and who can take it, with no column for Claude Tag admins; the actions that permission covers are listed under [Delegate Claude Tag administration](#delegate-claude-tag-administration).
428Creating bundles and binding them to scopes need an Owner or a [Claude Tag admin](#delegate-claude-tag-administration). Pairing workspaces needs an Owner. Editing [channel name patterns](#block-or-auto-join-channels-by-name) and changing [which channels Claude can search](#limit-which-channels-claude-can-search) need an Owner too.
427429
430A [channel manager](#delegate-channel-setup-to-channel-managers) configures only the channels assigned to them. Everything else happens inside the channel and is open to its members. The built-in **Admin** role doesn't include the **Claude Tag Admin** permission. A member with that role can take the actions in the Channel member column, in channels they belong to.
431
432The table lists each action and who can take it, with no column for Claude Tag admins; the actions that permission covers are listed under [Delegate Claude Tag administration](#delegate-claude-tag-administration).
433
428434| Action | Owner | Channel manager | Channel member |
429435| :- | :- | :- | :- |
430436| Pair a workspace | Yes | No | No |
from line 456
450456* **Renaming or rebranding the app.** The Claude app's name, @-handle, and avatar in Slack are fixed; there is no per-workspace rename setting.
451457* **Per-user spend caps on channel work.** Spend limits apply at the organization and channel level. There's no way to cap what one member can spend in channels; DM usage from a member who has connected a Claude account bills to that member's own seat and follows the seat's usual limits.
452458* **Per-channel responder allowlist.** The restriction toggle governs who can invoke Claude across the workspace; you can't narrow it to a list of people for one channel only.
453* **An open-internet switch in Claude Tag settings.** A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) adds that hostname on a [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential); for broad web access, an Owner pins an [environment](/docs/claude-tag/concepts/glossary#environment) whose network access level is Full access on the scope. [Allow-all egress](/docs/claude-tag/admins/add-connections#allow-all-hosts), a `*` entry on the Domains tab, is off by default and enabled per organization by Anthropic.
459* **An open-internet switch in Claude Tag settings.** A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) adds that hostname on a [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential); for broad web access, an Owner pins an [environment](/docs/claude-tag/concepts/glossary#environment) whose network access level is Full access on the scope. [Allow-all egress](/docs/claude-tag/admins/add-connections#allow-all-hosts), a `*` entry on the Domains tab, admits any host on the ports it lists.
454460* **A web search toggle for channels.** No setting turns web search off for channel sessions; the web search capability setting in claude.ai admin settings governs claude.ai chat, not channels. Web search runs on Anthropic's servers rather than from the channel sandbox, so Domains entries and egress settings don't govern it, and a search opens no new path out of the sandbox; search requests travel to Anthropic the same way the session's model traffic already does. See [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests).
455461* **A switch to turn workspace search off.** Claude can search public channels by keyword the same way any Slack user can; it can't read a channel's full history unless it's been added there. No setting turns workspace search off. The [**Channels Claude can search**](#limit-which-channels-claude-can-search) setting narrows it to channels Claude is in. No setting enables search in [channels that include guests](#restrict-guest-channels), where it's unavailable.
456462* **Session length enforcement.** Your organization's Slack session-length policy is not enforced on this surface.
claude-tag/admins/setup-overview Changed · +101 / -92 lines
## Buy usage credits ## Give Claude access to your tools ### Connect GitHub ### Create accounts for Claude's other tools ## Choose Claude's first tools ## Connect GitHub ## Create accounts for Claude's other tools
from line 1
11# Set up Claude Tag
22
3> Set up Claude Tag for your organization: pair your Slack workspace, choose and connect Claude's tools, set a spending limit, launch, and test that it works. Every step on one page.
3> Set up Claude Tag for your organization: pair your Slack workspace, add Claude to channels, launch, give Claude access to your tools, and check that it works.
44
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66
77<BetaNote />
88
9Claude Tag is Claude working in your team's Slack channels. It can also act in your other tools, like your issue tracker or data warehouse, through accounts you create for it during setup.
9Claude Tag is Claude working in your team's Slack channels. Setup connects Claude to your Slack workspace and turns Claude Tag on. Claude gets access to your other tools, like your issue tracker or data warehouse, after setup. Running setup requires the Owner role in a Claude organization on a Team or Enterprise plan.
1010
11Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and click **Start setup** (**Resume setup** if you started earlier). The setup page walks you through these steps in order. This page covers each one in the same order, and each section says what to have ready before the step and what each choice means.
11Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and click **Start setup** (**Resume setup** if you started earlier). The setup page walks you through these steps in order.
1212
13131. [Pair your Slack workspace](#pair-your-slack-workspace): install the Slack app and redeem a pairing code
142. [Choose Claude's first tools](#choose-claude%E2%80%99s-first-tools): select at least two tools
153. [Connect GitHub](#connect-github): install the Claude GitHub App and grant repositories
164. [Create accounts for Claude's other tools](#create-accounts-for-claude%E2%80%99s-other-tools): one account and API key per tool
175. [Launch Claude Tag](#launch-claude-tag): set the monthly spend limit and turn Claude Tag on
142. [Buy usage credits](#buy-usage-credits): appears only when your organization pays by card in US dollars and has no credits
153. [Launch Claude Tag](#launch-claude-tag): add Claude to channels and turn Claude Tag on
1816
19The console saves your progress, so you can leave and come back to where you stopped. When you've launched, [verify your setup](#verify-your-setup).
17If you leave after pairing a workspace, click **Resume setup** to continue from the next step. Your choices on the launch step aren't saved until you click **Launch Claude Tag**.
2018
19When you've launched, [give Claude access to your tools](#give-claude-access-to-your-tools) and [verify your setup](#verify-your-setup).
20
2121<Accordion title="Before you start: check that you have what setup needs">
2222 | Prerequisite | Why you need it | If you don't have it |
2323 | :- | :- | :- |
from line 27
2727 | **Owner** role in the Claude organization you're setting up | Pairing a workspace is an Owner-only write. Roles are per organization, so being an Owner elsewhere doesn't carry over. | Ask an Owner to run setup, or have one promote you at [`claude.ai/admin-settings/members`](https://claude.ai/admin-settings/members) |
2828 | A **Slack workspace admin** | Running `@Claude connect` requires a Slack workspace admin; installing the app usually does too. | If that's someone else, [send them the install request](#if-you-re-not-the-slack-workspace-admin) early (app approval can take time), and plan to be online together when you pair; pairing codes expire 15 minutes after they're issued |
2929 | **Usage credits** (Team plans) | Channel work draws from your organization's usage balance; on a Team plan nothing runs until credits are loaded. | Check whether your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise) before buying; otherwise, buy credits at [`claude.ai/admin-settings/usage`](https://claude.ai/admin-settings/usage) |
30 | *(Optional)* The **Claude GitHub App** linked to your Claude organization | Linking GitHub first turns setup's GitHub step into repository selection instead of an app install. | [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) first, or grant repository access after setup |
31 | *(Optional)* A **channel to test in** | You'll invite Claude to a channel to [verify your setup](#verify-your-setup). | Create a private Slack channel for the pilot, or pick any existing one |
30 | A **public channel** for Claude to join | The launch step asks you to select at least one public channel, and you can [verify your setup](#verify-your-setup) there. | Create a public Slack channel for the pilot, or pick any existing one |
3231
3332 If any of your services restrict traffic by IP, file the [network requirements](/docs/claude-tag/admins/network-requirements) request with your network team early; in many organizations, IP allowlist changes take days to approve.
3433
from line 55
5655 Open any channel and add Claude to it with `/invite @Claude`. Claude posts a short welcome message when it joins. Then send `@Claude connect` as a new message with no other text. Claude replies in the channel with a message only you can see, containing the pairing code:
5756
5857 > Connect **this workspace** (Acme) to your Claude organization for billing: have a Claude **organization admin** redeem this code in Claude admin settings. The code works once and expires in 15 minutes.
59
58 >
6059 > `workspace_a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6`
61
60 >
6261 > *Once connected, Claude usage in this workspace is billed to that organization.*
6362
6463 Only a Slack workspace admin (or Grid org admin) can run this command; anyone else gets a message naming who to ask.
from line 71
7271 Paste the pairing code Claude sent into the **Paste the pairing code** field. **Connected to** followed by your workspace name appears under it when the code is accepted.
7372 </Step>
7473
75 <Step title="Choose where Claude can reply when tagged">
76 Select **Entire workspace (recommended)** or **Specific channel**.
77
78 If you select **Specific channel**, enter each channel's ID in the **Channel IDs** field, separated by commas, like `C0B1SLDGBPG, C0ARH08HQCA`. To find a channel's ID in Slack, right-click the channel, choose **Copy**, then **Copy link**; the ID is the part after the last slash. For a private channel, invite `@Claude` to it in Slack first.
79
80 If you aren't asked where Claude can reply, Claude replies across the whole workspace once you [launch](#launch-claude-tag).
81 </Step>
82
8374 <Step title="Click Pair workspace">
84 You see a confirmation that the pairing worked. Select **Next: Choose Claude’s tools**.
75 The setup page opens [**Buy usage credits**](#buy-usage-credits) when that step applies to your organization, and [**Launch Claude Tag**](#launch-claude-tag) otherwise.
8576 </Step>
8677</Steps>
8778
88Claude doesn't answer mentions in Slack until you finish [Launch Claude Tag](#launch-claude-tag); a mention before then gets "Claude is disabled in this channel."
79Pairing covers the whole workspace. Claude doesn't answer mentions in Slack until you finish [Launch Claude Tag](#launch-claude-tag). A mention before then gets "Claude is disabled in this channel."
8980
81After launch, people can tag Claude in any channel it has joined. To keep Claude to certain channels, see [Limit Claude Tag to specific channels](/docs/claude-tag/admins/restrict-access#limit-claude-tag-to-specific-channels).
82
9083<Accordion title="If you're not the Slack workspace admin">
9184 Only a Slack workspace admin can run `@Claude connect`, and in most workspaces only an admin can install the app. If that's not you, send the Slack admin the message below and have them return the pairing code:
9285
from line 92
9992 When a Slack Org Owner or Org Admin sends `@Claude connect`, the reply includes two codes. One begins `workspace_` and pairs only the workspace the admin sent the command in, and one begins `enterprise_` and pairs the whole Grid. Paste the `enterprise_` code. See [Pair an Enterprise Grid](/docs/claude-tag/admins/workspaces#pair-an-enterprise-grid).
10093</Accordion>
10194
102## Choose Claude's first tools
95## Buy usage credits
10396
10497**Where:** the Claude Tag setup page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
10598
106Select at least two tools your team uses, then click **Next: Connect GitHub**. Selecting a tool here doesn't connect it. In [Create accounts for Claude's other tools](#create-accounts-for-claude%E2%80%99s-other-tools), you create an account for Claude in each tool you selected and paste that account's API key on the setup page.
99Claude's work in channels draws from your organization's usage balance, and this step adds credits to that balance. The setup page shows the step only when your organization is on a Team or self-serve Enterprise plan, pays by card in US dollars, and has no usage credits. Every other organization goes from pairing to [Launch Claude Tag](#launch-claude-tag).
107100
108The list shows widely used tools; use **Search all tools** for one that isn't shown. GitHub isn't in the list; you set it up in [Connect GitHub](#connect-github). You can add more tools any time after setup.
101Enter an amount and click **Buy now** to charge your organization's saved payment method. To continue without buying, click **Skip**, then buy credits at [`claude.ai/admin-settings/usage`](https://claude.ai/admin-settings/usage) before your team starts tagging Claude.
109102
110See [Give Claude access](/docs/claude-tag/admins/add-connections) for which services to connect first.
103## Launch Claude Tag
111104
112## Connect GitHub
105**Where:** the Claude Tag setup page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
113106
114**Where:** the Claude Tag setup page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). If the app isn't installed yet, select **Start setup** on the step to open your [Claude GitHub settings](/docs/claude-tag/admins/configure-github), where you sign in with GitHub, authorize your organization, and install the app.
107On the launch step, you add Claude to channels and turn Claude Tag on. You also set a monthly spend limit here, unless setup included the [**Buy usage credits**](#buy-usage-credits) step.
115108
116Claude reaches GitHub through the [Claude GitHub App](/docs/claude-tag/admins/configure-github) rather than an account and credential, so GitHub has its own step. The setup page shows one of three things, depending on where the Claude GitHub App is installed:
109The spend limit caps how much of your organization's usage balance Claude Tag can use each month.
117110
118* **Connect GitHub**, when the app isn't linked to your Claude organization yet. Only an owner of your GitHub organization can install the app. If that's you, follow the steps shown. If not, send the message the step shows to a GitHub organization owner, skip this step, and continue with setup. After they install the app, [grant repositories](/docs/claude-tag/admins/configure-github#grant-repository-access) from the admin page.
119* **Choose your GitHub repos**, when the app is already linked. Grant every repository or pick specific ones.
120* **The Claude app is installed on \[username], a personal account**, when the app was installed on someone's personal GitHub account rather than an organization. Claude Tag connects to a GitHub organization only. A GitHub organization owner installs the app on the organization that owns your repositories (see [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization)). You can skip the step and continue with setup while that happens, then [grant repositories](/docs/claude-tag/admins/configure-github#grant-repository-access) from the admin page afterward.
111* **Channel work**: draws from that balance, not from individual seats
112* **Direct messages (DMs)**: DMs from members who have connected a Claude account run on the member's own claude.ai account and aren't capped by this limit. For members who haven't connected one, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#direct-messages-from-members-without-a-claude-account).
113* **Launch usage credit**: if your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise), the launch step shows the amount, with the date it runs through once the credit is active. After launch, the admin page shows the credit under **Included usage** with how much is used. You're billed for usage beyond it, up to the spend limit.
121114
122The repositories you grant apply to every channel Claude is in. If your team won't hand Claude code work, skip this step.
115<Steps>
116 <Step title="Set monthly spend limits">
117 If setup included the [**Buy usage credits**](#buy-usage-credits) step, the launch step has no spend limit picker. Set a limit after launch at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag).
123118
124## Create accounts for Claude's other tools
119 Otherwise, choose from `$500`, `$1,000`, `$2,500`, `$5,000`, **Unlimited**, or **Custom** (a US-dollar amount up to `$1,000,000`). `$2,500` is preselected unless your organization already has a Claude Tag spend limit. Usage bills against your organization's balance up to that amount each month. See [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) for what counts toward the cap, per-channel limits, and what users see when it's reached.
120 </Step>
125121
126**Where:** your company's email admin console and each tool you selected, then the Claude Tag setup page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
122 <Step title="Add Claude to your channels">
123 Choose which channels Claude joins when you launch.
127124
128Treat Claude like a new hire. You give it an email address, add it to each tool as a member, and then, signed in as Claude, create an API key in that tool. The setup page asks you for those keys, one per tool. Claude's own account in each tool is what lets you see exactly what it did in that tool's logs and cut off its access without touching anyone else's. [How agent identity works](/docs/claude-tag/concepts/agent-identity) has the full model.
125 * **If the launch step lists public channels from the workspace you paired**: select at least one. **Launch Claude Tag** stays unavailable until you do. Claude joins the channels you selected when you launch, so people can tag it there right away.
126 * **If the launch step shows no channel list**: launch, then run `/invite @Claude` in a channel in Slack.
129127
130Work through one tool end to end before starting the next.
131
132<Steps>
133 <Step title="Create an email address for Claude">
134 In your company's email admin console, create a new user for Claude, for example `[email protected]`, the same way you'd create a mailbox for a new hire. Every tool invitation and verification email for Claude lands in that inbox. Any address works; the setup page shows `claude@` followed by your domain only as an example, and Claude Tag never stores the address itself.
128 To add Claude to a private channel, or to more channels later, run `/invite @Claude` in that channel.
135129 </Step>
136130
137 <Step title="Add Claude to the tool as a member">
138 In the tool's member or user settings, invite `[email protected]` the way you'd add a new teammate. Open the invitation from Claude's inbox and finish creating the account, including a password. Give the account the narrowest role that covers the work; read-only where the tool offers it.
131 <Step title="Let members know they can now tag Claude">
132 The **Let members know they can now tag Claude** toggle is on by default. After launch, Claude DMs each member of the workspace to help them get started. Those DMs don't count toward your usage. Turn the toggle off to skip them.
139133
140 For a tool that offers service accounts, create one in the tool's admin settings instead of inviting the email address, scoped read-only or to the specific project.
134 The admin page has a matching row, **Let people know they can talk to Claude**. To send the DMs from the admin page, select **Notify members now** on that row and confirm. The row reads **Members notified** once the DMs have gone out.
141135 </Step>
142136
143 <Step title="Create an API key in Claude's account">
144 Sign in to the tool as Claude and create the credential that tool's [connection guide](/docs/claude-tag/admins/connections/overview) names, usually an API key or personal access token from the tool's settings. Copy it; it belongs to Claude's account, so Claude's actions show up in the tool's audit log under Claude's name.
137 <Step title="Click Launch Claude Tag">
138 Claude Tag turns on. From here on, Claude answers mentions in the workspace you paired. The setup page shows **You're set**. Click **Done** to open the Claude Tag admin page.
145139 </Step>
146
147 <Step title="Paste the key on the setup page">
148 Back on the setup page, each tool you selected is listed. Click **Connect** next to the tool and paste the key you just created. Then repeat the last three steps for the next tool you selected: add Claude as a member, create an API key in Claude's account, and paste it here. Claude keeps the one email address for every tool.
149 </Step>
150140</Steps>
151141
152To finish this step later, select **Skip** and confirm past the warning that Claude won't be able to act in the unconnected tools. Claude still works from what's in Slack: it can catch a team up on a channel, turn a thread into a doc, and search the web. See [Give Claude access](/docs/claude-tag/admins/add-connections) for what access to give each account, and the [per-service connection guides](/docs/claude-tag/admins/connections/overview) for the credential fields per tool.
142To stop before launching, leave the setup page. Your pairing is saved, and your choices on the launch step aren't.
153143
154## Launch Claude Tag
144## Give Claude access to your tools
155145
156**Where:** the Claude Tag setup page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
146Setup connects Claude to Slack and to nothing else. After launch, Claude reaches your other tools through personal connectors and through access you give Claude itself.
157147
158Channel work draws from your organization's usage balance, not from individual seats; the spend limit caps how much of that balance Claude Tag can use each month. DMs from members who have connected a Claude account run on the member's own claude.ai account and aren't capped by this limit. For members who haven't, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#direct-messages-from-members-without-a-claude-account). If your organization has a [launch usage credit](https://support.claude.com/en/articles/15575654-claude-tag-launch-promo-for-claude-team-and-enterprise), the launch screen shows the amount and the date it runs through, and after launch the admin page shows it under **Included usage** with how much is used. You're billed for usage beyond it, up to the spend limit.
148* **Personal connectors**: Claude can use a member's own claude.ai connectors for that member's requests in a channel. You don't connect anything for these. See [Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) for how members approve that use.
149* **Access you give Claude**: you connect a tool on the Claude Tag admin page with credentials that belong to Claude rather than to a person. Claude then works in that tool for everyone in the channels you choose, and can use it for [work it starts on its own](/docs/claude-tag/users/proactivity).
159150
160If the setup page shows a **Buy usage credits** step before Launch, buy credits on that step to continue. The launch screen then doesn't include **Set monthly spend limits**, so set a limit after launch at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag).
151### Connect GitHub
161152
153Connect GitHub if your team will give Claude code work. Claude reaches GitHub through the [Claude GitHub App](/docs/claude-tag/admins/configure-github). Only an owner of your GitHub organization can install it.
154
155[Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) to install the app, then [grant repositories](/docs/claude-tag/admins/configure-github#grant-repository-access).
156
157### Create accounts for Claude's other tools
158
159**Where:** your company's email admin console and each tool you're connecting, then the Claude Tag admin page at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
160
161In each tool other than GitHub, Claude works through an account of its own, so you can see what it did in that tool's logs and cut off its access without touching anyone else's. You give Claude an email address, add it to each tool as a member, then sign in as Claude and create an API key. [How agent identity works](/docs/claude-tag/concepts/agent-identity) has the full model.
162
163Work through one tool end to end before starting the next.
164
162165<Steps>
163 <Step title="Set monthly spend limits">
164 Choose from `$500`, `$1,000`, `$2,500`, `$5,000`, **Unlimited**, or **Custom** (a US-dollar amount up to `$1,000,000`). Usage bills against your organization's balance up to that amount each month. See [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) for what counts toward the cap, per-channel limits, and what users see when it's reached.
166 <Step title="Create an email address for Claude">
167 In your company's email admin console, create a new user for Claude with any address, for example `[email protected]`, the same way you'd create a mailbox for a new hire. Every tool invitation and verification email for Claude lands in that inbox.
165168 </Step>
166169
167 <Step title="Let members know they can now tag Claude">
168 The toggle is on by default: after launch, Claude DMs each member of the workspace to help them get started. Those DMs don't count toward your usage. Turn the toggle off to skip them.
170 <Step title="Add Claude to the tool as a member">
171 In the tool's member or user settings, invite `[email protected]` the way you'd add a new teammate. Open the invitation from Claude's inbox and finish creating the account, including a password. Give the account the narrowest role that covers the work, read-only where the tool offers it.
169172
170 The admin page has a matching row, **Let people know they can talk to Claude**. To send the DMs from the admin page, select **Notify members now** on that row and confirm. The row reads **Members notified** once the DMs have gone out.
173 For a tool that offers service accounts, create one in the tool's admin settings instead of inviting the email address, scoped read-only or to the specific project.
171174 </Step>
172175
173 <Step title="Click Launch Claude Tag">
174 Claude Tag turns on and you return to the Claude Tag admin page, which now shows your workspace under **Where Claude Tag works**. Claude answers mentions in the workspace you paired from here on. If you skipped connecting tools, a **Finish setting up Claude Tag** card sits at the top of the admin page; its **Finish setup** button reopens the steps you skipped.
176 <Step title="Create an API key in Claude's account">
177 Sign in to the tool as Claude and create the credential that tool's [connection guide](/docs/claude-tag/admins/connections/overview) names, usually an API key or personal access token from the tool's settings. Copy it. The credential belongs to Claude's account, so Claude's actions show up in the tool's audit log under Claude's name.
175178 </Step>
179
180 <Step title="Add the key as a connection">
181 On the Claude Tag admin page, [create an Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle), a named set of connections, repositories, plugins, and instructions, if you don't have one. Then [add a connection](/docs/claude-tag/admins/add-connections#add-a-connection) for the tool and paste the key you created. Claude can use the tool in the [workspace or channels you attach the bundle to](/docs/claude-tag/admins/attach-to-scope).
182
183 For the next tool, start again from **Add Claude to the tool as a member**. Claude keeps the one email address for every tool.
184 </Step>
176185</Steps>
177186
178To leave setup without turning Claude Tag on, select **Finish later**. Everything you've set is saved, and the admin page shows a resume card that brings you back here. Until you launch, the Claude app is in your Slack workspace but every mention gets "Claude is disabled in this channel."
187See [Give Claude access](/docs/claude-tag/admins/add-connections) for which services to connect first and what access to give each account, and the [per-service connection guides](/docs/claude-tag/admins/connections/overview) for the credential fields per tool.
179188
180189## Verify your setup
181190
182**Where:** Slack, in any channel of the workspace you paired.
191**Where:** Slack, in a channel you added Claude to at launch or any other channel of the workspace you paired.
183192
184Run the first check, then the ones that match what you connected.
193Run the first check after you launch, then the ones that match what you connected.
185194
186195### Check that Claude responds
187196
188Add Claude to the channel, then mention it:
197If you didn't select this channel at launch, add Claude to it. Then mention Claude:
189198
190199```text wrap theme={null}
191200/invite @Claude
from line 210
201210
202211### Check a tool you connected
203212
204Skip this check if you skipped [Create accounts for Claude's other tools](#create-accounts-for-claude%E2%80%99s-other-tools). Otherwise, in a new thread, ask what the channel can reach:
213Run this check after you [connect a tool with Claude's own account](#create-accounts-for-claude%E2%80%99s-other-tools). In a new thread, ask what the channel can reach:
205214
206215```text wrap theme={null}
207216@Claude what can you access from this channel?
from line 230
221230
222231### Check GitHub
223232
224Skip this check if you skipped [Connect GitHub](#connect-github). Otherwise, ask about a repository you granted:
233Run this check after you [connect GitHub](#connect-github). Ask about a repository you granted:
225234
226235```text wrap theme={null}
227236@Claude list the open pull requests in your-org/your-repo and who each one is waiting on
from line 250
2412502. Under **Claude Tag's access**, open the **Slack** tab.
2422513. In the list on the left, select **Default Slack** to change how Claude works everywhere, or select a workspace or channel to change it in that one place.
243252
244What you connected during setup is attached to the workspace you paired, or to each channel you listed if you chose **Specific channel**. **Default Slack** is the layer above that: anything you add there applies in every workspace and channel, and each entry below it adds to that for one place.
253Anything you add on **Default Slack** applies in every workspace and channel. Anything you add on a workspace or channel applies there in addition.
245254
246Every entry has the same sections: **Connectors**, **Repositories**, **Plugins**, **Custom instructions**, **Access bundles**, and, under **Advanced**, the **Default model**. An [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of connections, repositories, plugins, and instructions that you can attach to more than one place. Setup created one on your workspace's entry, named after the workspace (for example, **Tag Test default**), holding the tools you connected.
255Every entry in the list on the left has **Connectors**, **Repositories**, **Custom instructions**, and **Access bundles** sections, and a collapsed **Advanced** section with settings such as the [**Default model**](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope) and the [**Environment**](/docs/claude-tag/concepts/glossary#environment). A **Plugins** section appears once your organization has plugins available to [attach](/docs/claude-tag/admins/add-connections#attach-plugins). An [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of connections, repositories, plugins, and instructions that you can attach to more than one place.
247256
248257| To do this | Go to | Learn more |
249258| :- | :- | :- |
250259| Change the model Claude replies with | The entry's **Advanced** section, **Default model**. Set it on **Default Slack** to change it everywhere, or on one channel. | [Choose the model for a scope](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope) |
251260| Give Claude standing instructions | The **Custom instructions** field on **Default Slack** for every channel, or on one channel's entry for that channel only. | [Customize](/docs/claude-tag/admins/customize) |
252| Connect another tool, or one you skipped | **Connectors** on the entry, or the bundle named after your workspace under **Access bundles**. | [Give Claude access](/docs/claude-tag/admins/add-connections) |
261| Connect a tool | **Connectors** on the entry, or an Access bundle under **Access bundles**. | [Give Claude access](/docs/claude-tag/admins/add-connections) |
253262| Let Claude reach a site or API that has no credential | The **Domains** list of the Access bundle, under **Access bundles**. | [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) |
254263| Grant more repositories | **Repositories** on the entry. | [Configure GitHub access](/docs/claude-tag/admins/configure-github) |
255264| Give one channel more than the default | Select the channel and add to it. | [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope) |
claude-tag/concepts/agent-identity Changed · +3 / -3 lines
from line 8
88
99Claude Tag's identity depends on where you message it.
1010
11In Slack channels, Claude acts with its own service accounts, rather than as a specific user. An organization Owner [provisions this identity during setup](/docs/claude-tag/admins/setup-overview), so it arrives with its own account in each system it works in: the Claude app in Slack, the Claude GitHub App on GitHub, and a service account in every other connected tool. Actions it takes are attributed to those accounts; for example, posts come from the Claude app and pull requests show the Claude GitHub App as the author. Claude can also use your own claude.ai connectors for a task you hand it in a channel, after you allow it. See [Personal connectors in a channel](#personal-connectors-in-a-channel).
11In Slack channels, Claude acts with its own service accounts, rather than as a specific user. An organization Owner [provisions this identity](/docs/claude-tag/admins/setup-overview#give-claude-access-to-your-tools), so Claude has its own account in each system it works in: the Claude app in Slack, the Claude GitHub App on GitHub, and a service account in every other connected tool. Actions it takes are attributed to those accounts; for example, posts come from the Claude app and pull requests show the Claude GitHub App as the author. Claude can also use your own claude.ai connectors for a task you hand it in a channel, after you allow it. See [Personal connectors in a channel](#personal-connectors-in-a-channel).
1212
1313In direct messages (DMs) between `@Claude` and a user who has connected a Claude account, the provisioned identity does not apply. DMs are one-to-one only; group DMs aren't supported. A DM has no channel to scope it to, so a DM session runs on [the individual's own claude.ai account](#direct-message-channels) instead, with their personal connectors. GitHub is the exception in attribution: a pull request opened from a DM is authored by the Claude GitHub App, the same as in channels, though the session can only work with repositories connected on that user's own account. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages). For DMs from users who haven't connected a Claude account, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#direct-messages-from-members-without-a-claude-account).
1414
from line 26
2626
2727The diagram below traces one request through this process.
2828
29<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/oY6LusJt4c576Dc3/images/claude-tag/diagrams/request-path.svg?fit=max&auto=format&n=oY6LusJt4c576Dc3&q=85&s=a7f2e0f4303072b4c8e4f3197bf0cb12" alt="Diagram showing the request path across three zones, labeled your Slack workspace, Anthropic's infrastructure, and your systems. A task mentioned in the Slack workspace runs in a session sandbox in the middle zone, one sandbox per thread, holding no credentials. Outbound requests pass to Agent Proxy, which injects the credential drawn from the credential store; a request that no rule, domain entry, or environment network access setting allows is blocked. Credentialed requests reach your systems, like GitHub, a data warehouse, monitoring, or any HTTP API. A dashed return path shows results posting back in the thread, as Claude." width="1000" height="440" data-path="images/claude-tag/diagrams/request-path.svg" />
29<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/lijct3C2aoA3LHFn/images/claude-tag/diagrams/request-path.svg?fit=max&auto=format&n=lijct3C2aoA3LHFn&q=85&s=10d796e77738a52a505dcab2c9950cda" alt="Diagram showing the request path across three zones, labeled your Slack workspace, Anthropic's infrastructure, and your systems. A task mentioned in the Slack workspace runs in a session sandbox in the middle zone, one sandbox per thread, holding no stored credentials. Outbound requests pass to Agent Proxy, which injects the credential drawn from the credential store; a request that no rule, domain entry, or environment network access setting allows is blocked. Credentialed requests reach your systems, like GitHub, a data warehouse, monitoring, or any HTTP API. A dashed return path shows results posting back in the thread, as Claude." width="1000" height="440" data-path="images/claude-tag/diagrams/request-path.svg" />
3030
31<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/oY6LusJt4c576Dc3/images/claude-tag/diagrams/request-path-dark.svg?fit=max&auto=format&n=oY6LusJt4c576Dc3&q=85&s=a728805c81b642004e1e15da96967e4c" alt="Diagram showing the request path across three zones, labeled your Slack workspace, Anthropic's infrastructure, and your systems. A task mentioned in the Slack workspace runs in a session sandbox in the middle zone, one sandbox per thread, holding no credentials. Outbound requests pass to Agent Proxy, which injects the credential drawn from the credential store; a request that no rule, domain entry, or environment network access setting allows is blocked. Credentialed requests reach your systems, like GitHub, a data warehouse, monitoring, or any HTTP API. A dashed return path shows results posting back in the thread, as Claude." width="1000" height="440" data-path="images/claude-tag/diagrams/request-path-dark.svg" />
31<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/lijct3C2aoA3LHFn/images/claude-tag/diagrams/request-path-dark.svg?fit=max&auto=format&n=lijct3C2aoA3LHFn&q=85&s=613ad7bf32eee0f85bd3a26064dcc74a" alt="Diagram showing the request path across three zones, labeled your Slack workspace, Anthropic's infrastructure, and your systems. A task mentioned in the Slack workspace runs in a session sandbox in the middle zone, one sandbox per thread, holding no stored credentials. Outbound requests pass to Agent Proxy, which injects the credential drawn from the credential store; a request that no rule, domain entry, or environment network access setting allows is blocked. Credentialed requests reach your systems, like GitHub, a data warehouse, monitoring, or any HTTP API. A dashed return path shows results posting back in the thread, as Claude." width="1000" height="440" data-path="images/claude-tag/diagrams/request-path-dark.svg" />
3232
3333<Steps>
3434 <Step title="Tag Claude in a channel">
claude-tag/concepts/data-lifecycle Changed · +3 / -3 lines
from line 65
6565| An Owner turns a scope's **Enable Claude Tag** switch off, turns off Claude in Slack for the organization, or turns off [direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages) | Nothing is deleted. Turning the setting back on resumes with the existing memory, routines, and sessions | No, in the affected scope |
6666| An Owner detaches a bundle from a scope, or deletes an Access bundle | Detaching removes the binding, and deleting a bundle removes its credentials everywhere it was attached. Memory, routines, and transcripts are unaffected | Yes, without that access |
6767| An Owner deletes entries from a scope's memory files, or someone in the channel tells Claude to forget an entry | The entry is removed from what Claude reads and from the memory files view. Earlier versions of the scope's memory remain stored with the scope until the scope's data is deleted | Yes |
68| An Owner deletes a routine from the [**Scheduled work** tab](/docs/claude-tag/admins/audit#what-the-audit-view-lists), or someone asks Claude to delete it in the channel or direct message where it was set up | The routine and the sessions it ran are deleted. Pausing a routine there, or disabling it from the channel, keeps it on record | Yes |
68| An Owner deletes a channel's routine from the [**Scheduled work** tab](/docs/claude-tag/admins/audit#what-the-audit-view-lists), or someone asks Claude to delete a routine in the channel or direct message where it was set up | The routine and the sessions it ran are deleted. Pausing a routine there, or disabling it from the channel, keeps it on record | Yes |
6969| A member selects **Disconnect** in the Claude app's **Home** tab in Slack | Removes the link between their Slack and Claude accounts and revokes the tokens Claude Tag held for them. Their earlier direct-message conversations and notes, and channel work they started, aren't deleted; those go with the workspace | In channels, yes. Direct messages and personal connectors stop working for that member until they reconnect |
7070| A member is removed from your Claude organization | Nothing is deleted. They lose access within minutes, and routines they set up in direct messages are turned off. Their account link, direct-message conversations, and notes stay until the workspace is disconnected | Not to that member |
7171| A member deletes their own Claude account | On Team and Enterprise plans, deleting an individual account doesn't remove the Claude Tag data your organization holds about that member, including their direct-message conversations and notes and their account link. A member who wants the link and its tokens removed can select **Disconnect** in Slack before deleting their account | Not to that member |
from line 76
7676
7777A direct-message conversation with Claude is stored the same way a channel thread is, as a session with a transcript, together with the notes Claude keeps for that conversation. Both are deleted with the workspace the member messaged Claude from, when that workspace is disconnected or the app is uninstalled from it, and when your Claude organization is deleted. They aren't deleted when the member selects **Disconnect** in Slack, when the member's Claude account is deleted on a Team or Enterprise plan, or when an Owner turns off direct messages.
7878
79Routines a member set up in a direct message belong to that member's Claude account. An Owner can delete them from the **Scheduled work** tab, or the member can ask Claude in the direct message to delete one. They are turned off when the member is removed from your Claude organization, and disconnecting the workspace doesn't delete them.
79Routines a member set up in a direct message belong to that member's Claude account. The member can ask Claude in the direct message to delete one. They are turned off when the member is removed from your Claude organization, and disconnecting the workspace doesn't delete them.
8080
8181When a member first opens a direct message with Claude, the welcome Claude writes, which suggests channels based on the member's recent public-channel activity, runs as a short session that is stored like any other.
8282
from line 87
8787* **Disconnect a workspace or an Enterprise Grid** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), or uninstall the app from the workspace in Slack. Deletes all of that workspace's data. See [Revoke a pairing](/docs/claude-tag/admins/workspaces#revoke-a-pairing)
8888* **Remove a channel's scope** in the **Claude Tag's access** section. Deletes that channel's data recorded so far
8989* **Delete a scope's memory files**: select **View memory files** in the scope's options menu, choose a file, then select **Delete**. You can also tell Claude in the channel to forget an entry. See [Check and correct what Claude Tag remembers](/docs/claude-tag/users/memory#check-and-correct-what-claude-tag-remembers)
90* **Delete a routine** from the **Scheduled work** tab, or ask Claude to delete it in the channel or direct message where it was set up. See [Audit Claude Tag activity](/docs/claude-tag/admins/audit)
90* **Delete a routine**: an Owner deletes a channel's routine from the **Scheduled work** tab. You can also ask Claude to delete a routine in the channel or direct message where it was set up. See [Audit Claude Tag activity](/docs/claude-tag/admins/audit)
9191
9292There is no control in Slack or in your Claude admin settings that deletes a single thread's transcript on its own. During the beta, Claude Tag session transcripts and memory aren't included in your organization's data exports, and the Compliance API doesn't list or delete Claude Tag sessions. For a deletion request these controls don't cover, contact your account team or [[email protected]](mailto:[email protected]).
9393
claude-tag/concepts/security-and-data Changed · +7 / -7 lines
from line 8
88
99In channels, Claude acts under its own service accounts that an Owner provisions. By default it can read and post in Slack channels it's been added to and search public channels by keyword; it has no access to your external systems until an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) adds connections. Each connection is scoped to specific channels and workspaces, and the actions Claude takes in connected tools are attributable to its own service accounts.
1010
11Every channel request, whether a person typed it or a schedule triggered it, follows the same path: it runs in an isolated sandbox that holds no credentials. In an Anthropic-hosted environment, requests leave that sandbox only through Agent Proxy and reach your systems under the agent's own accounts. Sessions in a [self-hosted environment](https://code.claude.com/docs/en/self-hosted-environments) run on runners inside your network, and Claude can't use Access bundles in those sessions yet.
11Every channel request, whether a person typed it or a schedule triggered it, follows the same path: it runs in an isolated sandbox, and the credentials you provision aren't placed in that sandbox. In an Anthropic-hosted environment, requests leave that sandbox only through Agent Proxy and reach your systems under the agent's own accounts. Sessions in a [self-hosted environment](https://code.claude.com/docs/en/self-hosted-environments) run on runners inside your network, and Claude can't use Access bundles in those sessions yet.
1212
1313DMs from members who have connected a Claude account run on the member's own claude.ai account instead and are covered separately on [How agent identity works](/docs/claude-tag/concepts/agent-identity#direct-message-channels). For DMs from members who haven't, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#access-in-a-direct-message-from-a-member-without-a-claude-account).
1414
from line 16
1616
1717Each Slack thread runs in its own sandbox. In an Anthropic-hosted environment, every outbound call from that sandbox passes through the same checkpoints.
1818
19<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/oY6LusJt4c576Dc3/images/claude-tag/diagrams/request-path.svg?fit=max&auto=format&n=oY6LusJt4c576Dc3&q=85&s=a7f2e0f4303072b4c8e4f3197bf0cb12" alt="Diagram showing the request path across three zones, labeled your Slack workspace, Anthropic's infrastructure, and your systems. A task mentioned in the Slack workspace runs in a session sandbox in the middle zone, one sandbox per thread, holding no credentials. Outbound requests pass to Agent Proxy, which injects the credential drawn from the credential store; a request that no rule, domain entry, or environment network access setting allows is blocked. Credentialed requests reach your systems, like GitHub, a data warehouse, monitoring, or any HTTP API. A dashed return path shows results posting back in the thread, as Claude." width="1000" height="440" data-path="images/claude-tag/diagrams/request-path.svg" />
19<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/lijct3C2aoA3LHFn/images/claude-tag/diagrams/request-path.svg?fit=max&auto=format&n=lijct3C2aoA3LHFn&q=85&s=10d796e77738a52a505dcab2c9950cda" alt="Diagram showing the request path across three zones, labeled your Slack workspace, Anthropic's infrastructure, and your systems. A task mentioned in the Slack workspace runs in a session sandbox in the middle zone, one sandbox per thread, holding no stored credentials. Outbound requests pass to Agent Proxy, which injects the credential drawn from the credential store; a request that no rule, domain entry, or environment network access setting allows is blocked. Credentialed requests reach your systems, like GitHub, a data warehouse, monitoring, or any HTTP API. A dashed return path shows results posting back in the thread, as Claude." width="1000" height="440" data-path="images/claude-tag/diagrams/request-path.svg" />
2020
21<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/oY6LusJt4c576Dc3/images/claude-tag/diagrams/request-path-dark.svg?fit=max&auto=format&n=oY6LusJt4c576Dc3&q=85&s=a728805c81b642004e1e15da96967e4c" alt="Diagram showing the request path across three zones, labeled your Slack workspace, Anthropic's infrastructure, and your systems. A task mentioned in the Slack workspace runs in a session sandbox in the middle zone, one sandbox per thread, holding no credentials. Outbound requests pass to Agent Proxy, which injects the credential drawn from the credential store; a request that no rule, domain entry, or environment network access setting allows is blocked. Credentialed requests reach your systems, like GitHub, a data warehouse, monitoring, or any HTTP API. A dashed return path shows results posting back in the thread, as Claude." width="1000" height="440" data-path="images/claude-tag/diagrams/request-path-dark.svg" />
21<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/lijct3C2aoA3LHFn/images/claude-tag/diagrams/request-path-dark.svg?fit=max&auto=format&n=lijct3C2aoA3LHFn&q=85&s=613ad7bf32eee0f85bd3a26064dcc74a" alt="Diagram showing the request path across three zones, labeled your Slack workspace, Anthropic's infrastructure, and your systems. A task mentioned in the Slack workspace runs in a session sandbox in the middle zone, one sandbox per thread, holding no stored credentials. Outbound requests pass to Agent Proxy, which injects the credential drawn from the credential store; a request that no rule, domain entry, or environment network access setting allows is blocked. Credentialed requests reach your systems, like GitHub, a data warehouse, monitoring, or any HTTP API. A dashed return path shows results posting back in the thread, as Claude." width="1000" height="440" data-path="images/claude-tag/diagrams/request-path-dark.svg" />
2222
2323| Checkpoint | The guarantee |
2424| :- | :- |
25| The sandbox | Holds no credentials |
25| The sandbox | Holds none of the credentials you provision |
2626| Agent Proxy | Injects credentials from the credential store at request time, and blocks a request that no [connection](/docs/claude-tag/admins/add-connections#set-allowed-websites), [**Domains** entry](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential), or [environment network access level](/docs/claude-tag/admins/add-connections#broad-web-access-through-the-environment) allows |
2727| Your systems | See the agent's own accounts, so its actions there are attributable |
2828
from line 51
5151
5252In an Anthropic-hosted environment, outbound traffic from a channel session's sandbox is default-deny. Requests go only to hosts an allow layer covers, and the layers are a [connection's Allowed websites](/docs/claude-tag/admins/connections/custom#fill-out-the-custom-tool-form), the [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential), and the network access setting of the [environment](/docs/claude-tag/concepts/glossary#environment) the scope's sessions run on. A new environment's default level, Trusted access, already covers a [documented set of package registries and developer hosts](https://code.claude.com/docs/en/cloud-environments#default-allowed-domains). See [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) for what happens to a request under each layer.
5353
54<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/Tf9m3OvmKAZp3uXC/images/claude-tag/diagrams/proxy-decision.svg?fit=max&auto=format&n=Tf9m3OvmKAZp3uXC&q=85&s=a4aecacf4e23944d5a2ecaacf6cf95a1" alt="Flow diagram across two zones, labeled Anthropic's infrastructure and your systems. In the first zone, a session sandbox that holds no credentials sends every outbound request to Agent Proxy, which matches it against admin rules. Three outcomes branch toward your systems: on a rule match, the credential is attached at the boundary and the request proceeds; on an allowlist-only match, from the bundle's Domains list or the environment's network access setting, the request is sent without credentials; on no match, the request is blocked entirely (the default-deny outcome) and the host is unreachable." width="1000" height="400" data-path="images/claude-tag/diagrams/proxy-decision.svg" />
54<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/lijct3C2aoA3LHFn/images/claude-tag/diagrams/proxy-decision.svg?fit=max&auto=format&n=lijct3C2aoA3LHFn&q=85&s=31de5c6d6a10b635374d9fa4861a111f" alt="Flow diagram across two zones, labeled Anthropic's infrastructure and your systems. In the first zone, a session sandbox that holds no stored credentials sends every outbound request to Agent Proxy, which matches it against admin rules. Three outcomes branch toward your systems: on a rule match, the credential is attached at the boundary and the request proceeds; on an allowlist-only match, from the bundle's Domains list or the environment's network access setting, the request is sent without credentials; on no match, the request is blocked entirely (the default-deny outcome) and the host is unreachable." width="1000" height="400" data-path="images/claude-tag/diagrams/proxy-decision.svg" />
5555
56<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/Tf9m3OvmKAZp3uXC/images/claude-tag/diagrams/proxy-decision-dark.svg?fit=max&auto=format&n=Tf9m3OvmKAZp3uXC&q=85&s=d2ad1dd61b859e9f2aebfceedbc247c3" alt="Flow diagram across two zones, labeled Anthropic's infrastructure and your systems. In the first zone, a session sandbox that holds no credentials sends every outbound request to Agent Proxy, which matches it against admin rules. Three outcomes branch toward your systems: on a rule match, the credential is attached at the boundary and the request proceeds; on an allowlist-only match, from the bundle's Domains list or the environment's network access setting, the request is sent without credentials; on no match, the request is blocked entirely (the default-deny outcome) and the host is unreachable." width="1000" height="400" data-path="images/claude-tag/diagrams/proxy-decision-dark.svg" />
56<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/lijct3C2aoA3LHFn/images/claude-tag/diagrams/proxy-decision-dark.svg?fit=max&auto=format&n=lijct3C2aoA3LHFn&q=85&s=b67da069feb4070186d4eca67eb40878" alt="Flow diagram across two zones, labeled Anthropic's infrastructure and your systems. In the first zone, a session sandbox that holds no stored credentials sends every outbound request to Agent Proxy, which matches it against admin rules. Three outcomes branch toward your systems: on a rule match, the credential is attached at the boundary and the request proceeds; on an allowlist-only match, from the bundle's Domains list or the environment's network access setting, the request is sent without credentials; on no match, the request is blocked entirely (the default-deny outcome) and the host is unreachable." width="1000" height="400" data-path="images/claude-tag/diagrams/proxy-decision-dark.svg" />
5757
5858Because requests to any other host are blocked, data can only leave the sandbox to hosts an allow layer covers. An admin sets the Allowed websites list on each connection and the Domains tab on each bundle. An admin sets the environment's network access level, which defaults to Trusted access, from the **Cloud environments** page in [admin settings](https://claude.ai/admin-settings). See [Set allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) and [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential).
5959
60Organizations can opt in to allow-all egress, where a `*` entry on a bundle's Domains tab admits requests to any host on the ports that entry lists, still without credentials. Private and internal network addresses and cloud metadata endpoints remain blocked. Allow-all egress is off by default and enabled per organization by Anthropic; see [Allow all hosts](/docs/claude-tag/admins/add-connections#allow-all-hosts).
60Allow-all egress is a `*` entry on a bundle's Domains tab. The entry admits requests to any host on the ports it lists, still without credentials. Private and internal network addresses and cloud metadata endpoints remain blocked. See [Allow all hosts](/docs/claude-tag/admins/add-connections#allow-all-hosts).
6161
6262### Service accounts
6363
claude-tag/overview Changed · +9 / -9 lines
from line 96
9696 <a className="tm-qrow" href="/docs/claude-tag/admins/setup-overview">
9797 <span className="tm-qrow-text">
9898 <span className="tm-qrow-q">Where do I start?</span>
99 <span className="tm-qrow-sub">Pair your Slack workspace, connect the services Claude will work in, launch, and test that it works</span>
99 <span className="tm-qrow-sub">Pair your Slack workspace, launch, and test that it works</span>
100100 </span>
101101 </a>
102102
from line 211
211211You set up Claude Tag once, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), and you must be an Owner in your Claude organization to do it. The setup page at that URL walks you through it:
212212
213213* **Pair your Slack workspace**: send `@Claude connect` in Slack to get a pairing code, then enter it on the setup page.
214* **Connect the services Claude will work in**: for each one, such as your issue tracker or data warehouse, create an account for Claude and enter its credential.
215* **Grant repositories**: choose which repositories the Claude GitHub App can reach.
216* **Set a monthly spend limit and launch**.
214* **Set a monthly spend limit, add Claude to channels, and launch**.
217215
218Claude Tag starts with no access to your external systems. The services you connect during setup form an [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle), the set of tools Claude can reach, attached to the workspace or channels you paired. Once you launch, everyone in a channel Claude is in can use Claude Tag immediately, with no per-user setup.
216Once you launch, everyone in a channel Claude is in can use Claude Tag immediately, with no per-user setup.
219217
220[Set up Claude Tag](/docs/claude-tag/admins/setup-overview) walks through those steps with what to have ready, what each choice means, and how to verify Claude Tag works once you launch.
218Claude Tag starts with no access of its own to your external systems. After you launch, you connect the services Claude will work in, such as your issue tracker or data warehouse, and grant repositories to the Claude GitHub App. The services you connect form an [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle), the set of tools Claude can reach. You attach the bundle to a workspace or to channels. Members can also let Claude use their own [personal connectors](/docs/claude-tag/concepts/personal-connectors) for their requests.
221219
220[Set up Claude Tag](/docs/claude-tag/admins/setup-overview) walks through setup and connecting tools, with what to have ready, what each choice means, and how to verify Claude Tag works once you launch.
221
222222<div className="tm-strip">
223223 <div className="tm-strip-head">
224224 <p className="tm-strip-title">Security review</p>
from line 232
232232
233233<CardGroup cols={2}>
234234 <Card title="Set up Claude Tag" icon="gear" href="/docs/claude-tag/admins/setup-overview" horizontal arrow>
235 Admins: pair your Slack workspace, connect the services Claude will work in, and launch
235 Admins: pair your Slack workspace and launch
236236 </Card>
237237
238238 <Card title="Hand Claude Tag your first task" icon="paper-plane" href="/docs/claude-tag/users/getting-started" horizontal arrow>
claude-tag/admins/attach-to-scope Changed · +1 / -1 lines
from line 6
66
77<BetaNote />
88
9This page covers adding access to more workspaces and channels, and how access stacks when several bundles apply to the same place. It assumes you have already [paired a workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace) and [created an Access bundle](/docs/claude-tag/admins/add-connections). You must be an Owner in your Claude organization, or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration), to attach bundles.
9This page covers adding access to more workspaces and channels, and how access stacks when several bundles apply to the same place. It assumes you have already [paired a workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace) and [created an Access bundle](/docs/claude-tag/admins/add-connections). You must be an Owner in your Claude organization, or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration), to attach a bundle to the organization, a workspace, or a channel. [Attaching a bundle by channel name](#attach-a-bundle-to-channels-by-name) needs an Owner.
1010
1111A scope is where a bundle applies: **Default Slack access** (the organization-wide root), a workspace, or a single channel. Bundles inherit downward through those scopes, and when credentials overlap, the narrowest scope wins.
1212
claude-tag/admins/audit Changed · +2 / -2 lines
from line 23
2323
2424| Tab | What it shows |
2525| :- | :- |
26| **Scheduled work** | Every routine across your organization, with a **Scope** filter and a per-row **⋮** menu (View details, Pause/Resume, Delete) |
26| **Scheduled work** | The routines set up in channels across your organization, with a **Scope** filter and a per-row **⋮** menu (View details, Pause/Resume, Delete) |
2727| **Memory** | Each scope's memory files, where you can read what Claude has saved for that workspace or channel. Owners can also edit or delete entries there. |
2828| **Network events** | An hourly JSON export of the outbound requests Claude made through [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy). Git and MCP traffic are not included. Select a date and hour to download. |
2929
from line 31
3131
3232## Trace an action to its source
3333
34In channels, Claude acts as itself, so each action there carries the service-account identity:
34In channels, Claude acts as itself unless a task uses a member's [personal connectors](/docs/claude-tag/concepts/personal-connectors), which run with that member's permissions and are recorded under their name. Each action Claude takes as itself carries the service-account identity:
3535
3636* **In Slack**, it posts as the Claude app, and its work happens in threads anyone in the channel can read.
3737* **On code**, commits and pull requests show the Claude GitHub App as the author, and each one links back to the Slack thread it came from.
claude-tag/admins/configure-github Changed · +0 / -2 lines
from line 12
1212
1313You link GitHub once for your Claude organization, then grant repositories per Access bundle.
1414
15<Tip>If you link your GitHub organization before running [setup](/docs/claude-tag/admins/setup-overview), setup includes a step for granting repository access inline, so you don't need to return to the Repositories tab afterward.</Tip>
16
1715## Link your GitHub organization
1816
1917<Note>
claude-tag/admins/customize Changed · +1 / -1 lines
from line 24
2424| Setting | What it does | More |
2525| :- | :- | :- |
2626| Custom instructions | Standing guidance read in every session on a scope, like team conventions. Outranks channel memory. | [Add custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
27| Managed by | Which other Slack channels' members can write a channel's standing instructions by asking Claude, including from a private channel. An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) sets it on the **Admin** tab of the channel's Configure page. | [Manage a channel's instructions from another channel](/docs/claude-tag/admins/managed-by) |
27| Managed by | Which other Slack channels' members can write a channel's standing instructions by asking Claude, including from a private channel. On the Enterprise plan, an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) sets it on the **Admin** tab of the channel's Configure page. | [Manage a channel's instructions from another channel](/docs/claude-tag/admins/managed-by) |
2828| Respond automatically | Whether Claude replies to a channel's messages without an @-mention. **Respond automatically** exists only on channels, not on workspaces or your whole organization. Channel members can change it too, from Slack or the channel's Configure page, unless the scope's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**. | [Turn automatic replies on or off](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) |
2929| Plugins | Bundles of skills that teach Claude how to use a specific tool | [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins) |
3030| Connections | Which systems it can reach from each channel | [Add connections](/docs/claude-tag/admins/add-connections) |
claude-tag/admins/for-slack-admins Changed · +1 / -1 lines
from line 21
2121
2222Claude picks the channels to suggest from public channel names, topics, and purposes, and from public-channel search. Claude doesn't join a channel to evaluate it.
2323
24A Claude organization admin can also set [auto-join channel patterns](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name), so Claude joins a public channel whose name matches when the channel is created or renamed.
24A Claude organization Owner can also set [auto-join channel patterns](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name), so Claude joins a public channel whose name matches when the channel is created or renamed.
2525
2626When a member selects **Add to channel** or **Approve and post**, picks a channel in a suggestion message, or an auto-join pattern matches, Claude adds itself to that channel using its `channels:join` scope. Slack's audit log records the join as the Claude app, with no inviter shown; neither the member's selection nor the matched pattern is visible in Slack's log. If you see a join in the audit log that no one can explain, a member selected one of these buttons or an auto-join pattern matched. Outside these paths, Claude does not join channels on its own.
2727
claude-tag/admins/healthcare Changed · +3 / -1 lines
from line 56
5656 </Step>
5757</Steps>
5858
59Any member of the workspace can still invite `@Claude` to a channel that isn't approved. Claude stays silent there, and an @-mention gets a notice that Claude is disabled in that channel instead of a reply. Only an Owner of your Claude organization can change a **Claude Tag version** setting or the **Allow direct messages** toggle.
59Any member of the workspace can still invite `@Claude` to a channel that isn't approved. Claude stays silent there, and an @-mention gets a notice that Claude is disabled in that channel instead of a reply.
60
61Only an Owner of your Claude organization or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) can change an **Enable Claude Tag** switch, and only an Owner can change the **Allow direct messages** toggle. Give the **Claude Tag Admin** permission only to people you trust to approve a channel as PHI-free.
6062
6163## Connect only PHI-free tools
6264
claude-tag/admins/managed-by Changed · +3 / -1 lines
from line 8
88
99**Managed by** is a channel setting that names other Slack channels whose members can write that channel's standing instructions for Claude. The channel that carries the setting is the managed channel, and each channel it names is a managing channel. People in a managing channel ask Claude to set or update the managed channel's instructions and confirm the change on a card, and Claude follows that text in every new conversation in the managed channel. This page is for admins who set up the pairing and for the people in a managing channel who write the instructions.
1010
11Setting up **Managed by** takes an Owner of your Claude organization or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration), the roles that see the **Admin** tab on a channel's Configure page. A managing channel isn't a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers). A channel manager is a person with a role that lets them configure one channel. A managing channel is a Slack channel, and the full workspace members in it can propose and confirm changes.
11On the Enterprise plan, an Owner of your Claude organization or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) sets up **Managed by** on the **Admin** tab of a channel's Configure page. The Team plan doesn't have the **Admin** tab. [When to use Managed by](#when-to-use-managed-by) lists the other places to keep instructions for a channel.
12
13A managing channel isn't a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers). A channel manager is a person with a role that lets them configure one channel. A managing channel is a Slack channel, and the full workspace members in it can propose and confirm changes.
1214
1315## When to use Managed by
1416
claude-tag/admins/skills-repo Changed · +1 / -1 lines
from line 46
4646| The marketplace syncs | On push to the default branch, the updated plugin syncs to your organization automatically |
4747| New threads pick it up | The next thread in any covered channel uses the updated skill |
4848
49Every skill change reaches channels only after a human approves the merge; Claude opens the PR, you merge it.
49Claude opens the PR, and you merge it. To require a person's approval before a change reaches the default branch, see [Require a second approval on Claude's pull requests](/docs/claude-tag/admins/configure-github#require-a-second-approval-on-claude%E2%80%99s-pull-requests).
5050
5151## Prompt Claude to propose updates
5252
claude-tag/admins/troubleshooting Changed · +2 / -1 lines
from line 29
2929| The console to accept your pairing code | "Already connected to a different organization" | The workspace is paired to another Claude organization, often a trial org. See [Already connected to a different organization](#already-connected-to-a-different-organization). |
3030| Your Claude account to connect after you select **Connect Claude account** | The browser page refuses the connection, and Claude DMs you "This workspace is connected to a different Claude organization" | The Claude account belongs to a different organization than the one the workspace is paired with. Connect an account from that organization; if the browser is signed in to another Claude account, sign out at claude.ai first. See [This workspace is connected to a different Claude organization](#this-workspace-is-connected-to-a-different-claude-organization). |
3131| The spend limit picker on the **Launch Claude Tag** step | A **Buy usage credits** step | Your organization pays by card in US dollars and has no credits loaded. Load credits, or select **Skip** to continue without; nothing runs in channels until the balance is funded. Invoiced organizations and those billing in other currencies see the spend limit picker regardless of balance. |
32| **Launch Claude Tag** to finish | "Couldn't turn on personal connectors in channels. Try again." | Launch didn't finish. Click **Launch Claude Tag** again. |
33| Claude to join the channels you selected on the **Launch Claude Tag** step | "Couldn't add Claude to some channels. Add Claude from Slack instead." | Claude Tag is on, but Claude didn't join every channel you selected. Run `/invite @Claude` in each channel it's missing from. |
3234| A reply from Claude while you're still in setup | "Claude is disabled in this channel. Your admin can re-enable it here." | Claude Tag isn't turned on until you finish [Launch Claude Tag](/docs/claude-tag/admins/setup-overview#launch-claude-tag). Finish setup, then mention `@Claude` again. If the message persists after launch, see [Claude is disabled in this channel](#claude-is-disabled-in-this-channel). |
33| The **Connect GitHub** step to list your organization's repositories | "The Claude app is installed on \[username], a personal account. Claude Tag connects to a GitHub organization. Install it on your organization instead." | The Claude GitHub App is on a personal GitHub account. Have a GitHub organization owner [install it on the organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) that owns your repositories. You can skip the step and [grant repositories](/docs/claude-tag/admins/configure-github#grant-repository-access) after setup. |
3435| A connected tool to work in your test | “I can't reach…” | Claude isn't told about a connection added after the thread started. Ask it to use the service by name, or start a fresh thread. |
3536| The **Where Claude Tag works** section with a **+ Connect** button | Only the legacy Claude in Slack toggles | Your organization isn't enabled for Claude Tag. Contact your account team. |
3637| Claude to respond in Slack | "Claude Tag has been turned off for your Claude organization…" | The **Enable Claude Tag for your organization** toggle is off. An Owner turns it on at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). See [the troubleshooting entry](#claude-tag-is-turned-off-for-your-organization). |
claude-tag/admins/workspaces Changed · +1 / -1 lines
from line 132
132132 * Its scopes, with their instructions and bundle bindings
133133 * The links between members' Slack and Claude accounts
134134
135 Deletion starts as soon as you confirm and runs to completion in the background. This can't be undone. Routines a person set up in a direct message with Claude belong to that person's account and keep running; an Owner can delete them from the [**Scheduled work** tab](/docs/claude-tag/admins/audit).
135 Deletion starts as soon as you confirm and runs to completion in the background. This can't be undone. Routines a person set up in a direct message with Claude belong to that person's account and keep running.
136136</Warning>
137137
138138Access bundles belong to your organization, not to a workspace, so they stay available to attach to other scopes; only their bindings to the deleted scopes go.
claude-tag/concepts/settings-map Changed · +1 / -1 lines
from line 66
6666
6767* [Customize Claude Tag](/docs/claude-tag/admins/customize): the layers that shape Claude's behavior in a channel and who sets each one
6868* [How agent identity works](/docs/claude-tag/concepts/agent-identity): why channels and DMs use different access
69* [Set up Claude Tag](/docs/claude-tag/admins/setup-overview): where each setting is first created during setup
69* [Set up Claude Tag](/docs/claude-tag/admins/setup-overview): pair a workspace, launch, and give Claude access
7070
connectors/github/index Changed · +1 / -1 lines
from line 150
150150
151151## Next steps
152152
153* [Get started with connectors](/docs/connectors/getting-started): set up another connector and use it in conversations
153* [Add a connector from the directory](/docs/connectors/getting-started#add-a-connector-from-the-directory): find a connector for another service in the directory and connect it
154154* [Connectors directory](/docs/connectors/directory): browse verified and community integrations
155155
connectors/google/calendar Changed · +1 / -0 lines
from line 64
6464
6565* [Gmail](/docs/connectors/google/gmail): search and analyze your emails
6666* [Google Drive](/docs/connectors/google/drive): search and read your Drive files
67* [Add a connector from the directory](/docs/connectors/getting-started#add-a-connector-from-the-directory): find a connector for another service in the directory and connect it
6768* [Connectors directory](/docs/connectors/directory): browse verified and community integrations
6869
connectors/google/drive Changed · +1 / -0 lines
from line 130
130130* [Gmail](/docs/connectors/google/gmail): search and analyze your emails
131131* [Google Calendar](/docs/connectors/google/calendar): access your calendar information
132132* [Get started with connectors](/docs/connectors/getting-started#manage-or-disconnect-a-connector): set tool permissions and manage any connector
133* [Add a connector from the directory](/docs/connectors/getting-started#add-a-connector-from-the-directory): find a connector for another service in the directory and connect it
133134* [Connectors directory](/docs/connectors/directory): browse verified and community integrations
134135
connectors/google/gmail Changed · +1 / -0 lines
from line 63
6363
6464* [Google Calendar](/docs/connectors/google/calendar): access your calendar information
6565* [Google Drive](/docs/connectors/google/drive): search and read your Drive files
66* [Add a connector from the directory](/docs/connectors/getting-started#add-a-connector-from-the-directory): find a connector for another service in the directory and connect it
6667* [Connectors directory](/docs/connectors/directory): browse verified and community integrations
6768
connectors/microsoft/365 Changed · +1 / -1 lines
from line 188
188188
189189## Next steps
190190
191* [Get started with connectors](/docs/connectors/getting-started): set up another connector and use it in conversations
191* [Add a connector from the directory](/docs/connectors/getting-started#add-a-connector-from-the-directory): find a connector for another service in the directory and connect it
192192* [Connectors directory](/docs/connectors/directory): browse verified and community integrations
193193
connectors/slack/index Changed · +1 / -1 lines
from line 123
123123## Next steps
124124
125125* [Claude Tag](/docs/claude-tag/overview): the current product, which gives your team one Claude identity set up by an admin
126* [Get started with connectors](/docs/connectors/getting-started): set up another connector and use it in conversations
126* [Add a connector from the directory](/docs/connectors/getting-started#add-a-connector-from-the-directory): find a connector for another service in the directory and connect it
127127* [Connectors directory](/docs/connectors/directory): browse verified and community integrations
128128
third-party/claude-desktop/in-app-configuration Changed · +2 / -0 lines
from line 8
88
99From the macOS menu bar (or on Windows, the application menu ☰ in the top-left of the sign-in screen), go to **Help → Troubleshooting → Enable Developer Mode**, then **Developer → Configure Third-Party Inference…**.
1010
11Developer mode stays on across restarts. To turn it off again, go to **Developer → Open Developer Config File**, change `"allowDevTools": true` to `false` in the file that opens (or delete the file), save it, then quit and reopen Claude Desktop. The **Developer** menu is gone on the next launch.
12
1113<Frame caption="The in-app configuration window, showing the Connection section for a gateway provider.">
1214 <img src="https://mintcdn.com/claude-ai/kVj7_7KF4fI3bEAn/images/third-party/in-app-configuration-window.png?fit=max&auto=format&n=kVj7_7KF4fI3bEAn&q=85&s=c3f15a85dea85082bc6dbc9459e6a974" alt="Claude Desktop in-app configuration window with the sidebar of setting groups on the left and the Connection form on the right." width="1812" height="1462" data-path="images/third-party/in-app-configuration-window.png" />
1315</Frame>