Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20261005T190707Z

56 pages moved out of 261 read.

Pages moved 56 significant first
Pages read 261 in this capture
Captured 19:07 UTC
Corpus hash 67472caaae39 corpus-hash

What this read moved

26-50 of 56, page 2 of 3

This capture is too large to show at once. Changes 26-50 of 56 are below, significant first; the rest are on the following screens.

claude-tag/admins/federated-access/authorization-server Changed · +17 / -17 lines

from line 6
66 
77<BetaNote />
88 
9<Note>Authorization servers are connected at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag): open **Federated agent access** in the left navigation and use the **Authorization servers** section. Connecting a server needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
9<Note>Authorization servers are connected on the [**Federated agent access**](https://claude.ai/admin-settings/claude-tag/federated-cloud-access) page, under **Claude Tag** in the admin settings sidebar. Use its **Authorization servers** section. Connecting a server needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
1010 
1111With an authorization server connection, Claude presents a short-lived identity token to an OAuth 2.0 authorization server you run, receives one of your access tokens in return, and calls your APIs with it. No long-lived credential for your systems is stored in Claude, and [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) holds each access token only until it expires. The identity token names your organization and the [agent](/docs/claude-tag/concepts/agent-identity) making the request (Claude's identity in one Slack channel), and your server decides whether to issue a token for it.
1212 
from line 22
2222 * may have a path, with no spaces or special characters in it
2323 * has no port number (the console drops `:443`), query, fragment, or sign-in details
2424 * isn't an IP address, a private-network name, an Anthropic-owned host, or a cloud token-exchange host
25* The token endpoint is on a different host from the APIs Claude will call with the returned token, for example `auth.example.com` and `api.example.com`.
25* The token endpoint is on a different host from the APIs Claude will call with the returned token, for example `auth.example.com` and `api.example.com`, or its address has a folder of its own, like `/oauth2` in `https://auth.example.com/oauth2/token`.
2626* Your server can reach `https://identity.anthropic.com` to fetch Anthropic's signing keys.
27* An organization can register up to 5 [gateways](/docs/claude-tag/admins/federated-access/connect-a-gateway), and a token endpoint counts as one.
27* An organization can register up to 5 [gateways](/docs/claude-tag/admins/federated-access/connect-a-gateway), and an authorization server's audience address (its **Issuer URL** value, or its token endpoint when that field is empty) counts as one.
2828 
2929## Copy the values from the console
3030 
from line 74
7474 </Step>
7575 
7676 <Step title="Confirm the subject check and register">
77 Select the checkbox labeled **This authorization server checks that each token's subject belongs to your organization**. The **Register server** button stays disabled until you do. The checkbox is your confirmation that the server makes the subject check described under [Configure the authorization server](#configure-the-authorization-server), and a server that doesn't must not be connected. Then click **Register server**. The dialog notes that the automatic connection check doesn't run for token endpoints. The endpoint is registered as a gateway with the check marked **Skipped**, and the dialog moves to the second step.
77 Select the checkbox labeled **This authorization server checks that each token's subject belongs to your organization**. The **Register server** button stays disabled until you do. The checkbox is your confirmation that the server makes the subject check described under [Configure the authorization server](#configure-the-authorization-server), and a server that doesn't must not be connected. Then click **Register server**. The dialog notes that the automatic connection check doesn't run for token endpoints. The token's audience, your **Issuer URL** value or the token endpoint if you left that field empty, is registered as a gateway with the check marked **Skipped**, and the dialog moves to the second step.
7878 
79 If you close the dialog at that point, the endpoint stays registered and counts toward the limit. To continue later, click **Connect an authorization server** again, enter the same address, and select the checkbox again, which returns you to the second step. Don't use **Add to bundle** on the endpoint's row in the **Gateways** table; that would connect the address as a gateway, after which the server can't be connected.
79 If you close the dialog at that point, the audience address stays registered and counts toward the limit. To continue later, click **Connect an authorization server** again, enter the same **Token endpoint** and **Issuer URL**, and select the checkbox again, which returns you to the second step. Don't use **Add to bundle** on that address's row in the **Gateways** table; that would connect the address as a gateway, after which the server can't be connected.
8080 </Step>
8181 
82 <Step title="Choose the APIs and the Access bundle">
83 Optionally enter a **Resource**, the API the returned token should be scoped to as an absolute URI (for example `https://api.example.com`), and a **Scope**, space-separated scopes to request. In **Allowed API hosts**, add the hosts Claude may call with the returned token, for example `api.example.com`. A wildcard as the leftmost label matches any subdomain; an entry or wildcard that covers the token endpoint's host is rejected. Then choose a bundle from the **Access bundle** list (or click **New bundle**, enter a **Bundle name**, and click **Create bundle**) and click **Connect server**.
82 <Step title="Choose the APIs and the bundle">
83 Optionally enter a **Resource**, the API the returned token should be scoped to as an absolute URI (for example `https://api.example.com`), and a **Scope**, space-separated scopes to request. In **Allowed API hosts**, add the hosts Claude may call with the returned token, for example `api.example.com`. A wildcard as the leftmost label matches any subdomain. An entry or wildcard can cover the token endpoint's host only when the endpoint's address has a folder of its own, like `/oauth2` in `https://auth.example.com/oauth2/token`. In that case, list the paths Claude may use, such as `/graphql`, under **Allowed API paths**. A listed path covers everything under it, and a path that overlaps the token endpoint's folder isn't allowed. Then choose a bundle from the **Access bundle** list (or create one: click **New bundle** if the dialog shows it, enter a **Bundle name**, and click **Create bundle**) and click **Connect server**.
8484 
85 This creates a [connection](/docs/claude-tag/admins/add-connections) in that bundle, labeled **Authorization server** on its **Credentials** tab, with the API hosts under **Allowed hosts**. Agent Proxy attaches the access token as an `Authorization: Bearer` header to every request Claude makes to those hosts. A token endpoint can be connected once in your organization, in one bundle; to use it in several scopes (workspaces or channels), attach that bundle to each.
85 This creates a [connection](/docs/claude-tag/admins/add-connections) in that bundle, with the API hosts under **Allowed hosts**. Agent Proxy attaches the access token as an `Authorization: Bearer` header to every request Claude makes to those hosts. A token endpoint can be connected once in your organization, in one bundle, and the connection applies wherever that bundle applies.
8686 </Step>
8787</Steps>
8888 
89The **Authorization servers** table lists each server by its **Token endpoint**, with its **Access bundle**, its **Allowed hosts**, when it was **Added**, and a **Remove** action. The endpoint also appears in the **Gateways** table with its check marked **Skipped** and a note that a connected authorization server uses it.
89The **Authorization servers** table lists each server by its **Token endpoint**, with its **Access bundle**, its **Allowed hosts**, when it was **Added**, and a **Remove** action. The audience address also appears in the **Gateways** table with its check marked **Skipped** and a note that a connected authorization server uses it.
9090 
9191## Let agents use the APIs
9292 
93Claude uses the connection in channels whose scope has the bundle attached. [Attach the bundle to a workspace or channel](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) if it isn't attached already.
93Claude uses the connection in the channels where its bundle applies. A bundle you created in the connect dialog applies nowhere until you choose places; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab).
9494 
9595Claude also needs to know what the APIs are for. Add a line like this to the scope's [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions):
9696 
from line 106
106106 
107107[Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, such as a Slack channel. A test from a personal session, such as a direct message with `@Claude`, won't work.
108108 
109In a channel whose workspace or channel has the bundle attached, start a new thread and ask Claude to make a small read:
109In a channel where the connection applies, start a new thread and ask Claude to make a small read:
110110 
111111```text wrap theme={null}
112112@Claude call GET /openapi.json on https://api.example.com and tell me what the API offers.
from line 116
116116 
117117## Remove the server
118118 
119In the **Authorization servers** table, click **Remove** in the server's row, then **Remove server** in the confirmation. Claude stops using the connection within about a minute, in existing threads as well as new ones, and the connection is removed from its bundle. An access token your server already issued stays valid with your server until it expires, and Agent Proxy discards it with the connection. The endpoint stays registered as a gateway, so to free its place in the limit, also click **Remove** in its row of the **Gateways** table. To change the address, do both removals, then connect the server again with the new address.
119In the **Authorization servers** table, click **Remove** in the server's row, then **Remove server** in the confirmation. Claude stops using the connection within about a minute, in existing threads as well as new ones, and the connection is removed from its bundle. An access token your server already issued stays valid with your server until it expires, and Agent Proxy discards it with the connection. The audience address stays registered as a gateway, so to free its place in the limit, also click **Remove** in that address's row of the **Gateways** table. To change the address, do both removals, then connect the server again with the new address.
120120 
121121## Common errors
122122 
from line 123
123123Five messages come up while connecting:
124124 
125125* **"The issuer URL must be an https URL on the same host as the token endpoint. Leave it empty to use the token endpoint as the audience."**: the **Issuer URL** value is not an HTTPS URL on the token endpoint's host. Enter the issuer identifier your server uses there, or clear the field.
126* **"This token endpoint is already connected in the bundle"**: the server already has its one connection. [Attach that bundle to the scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) instead.
126* **"This token endpoint is already connected in the bundle"**: the server already has its one connection. Apply that bundle where you need the server instead; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab).
127127* **"This organization has reached its limit of 5 registered gateways, which includes token endpoints"**: remove an unused row from the **Gateways** table first.
128* **"The allowed hosts can't include the token endpoint's host"**: an **Allowed API hosts** entry, or a wildcard in it, covers the token endpoint's host. Put the token endpoint on a different host from the APIs.
129* **"That address is already connected as a gateway. Enter your authorization server's own addresses, or remove the gateway first."**: the token endpoint, or the **Issuer URL** value, is the address of a gateway connected in one of your Access bundles. Enter the server's own addresses, or delete that gateway's connection from its bundle first.
128* **"The allowed hosts can't include the token endpoint's host"**: an **Allowed API hosts** entry, or a wildcard in it, covers the token endpoint's host, and the endpoint's address has no folder of its own. Put the token endpoint on a different host from the APIs, or use a token endpoint address with a folder of its own, like `/oauth2` in `https://auth.example.com/oauth2/token`.
129* **"That address is already connected as a gateway. Enter your authorization server's own addresses, or remove the gateway first."**: the token endpoint, or the **Issuer URL** value, is the address of a gateway connected in one of your bundles. Enter the server's own addresses, or delete that gateway's connection from its bundle first, as [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab) describes.
130130 
131131For other dialog messages, see [Troubleshoot federated agent access](/docs/claude-tag/admins/federated-access/troubleshooting).
132132 
133If Claude reports HTTP 403 with a reason that starts with [`request blocked: federated connections work only in agent sessions (such as a Slack channel), not in personal sessions (such as a direct message)`](/docs/claude-tag/admins/federated-access/troubleshooting#request-blocked-federated-connections-work-only-in-agent-sessions-such-as-a-slack-channel--not-in-personal-sessions-such-as-a-direct-message), the request came from a personal session, such as a direct message with `@Claude`. A personal session runs under a person's own account. [Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, so test again from a new thread in a Slack channel under the [scope](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit) of the Access bundle that holds the connection.
133If Claude reports HTTP 403 with a reason that starts with [`request blocked: federated connections work only in agent sessions (such as a Slack channel), not in personal sessions (such as a direct message)`](/docs/claude-tag/admins/federated-access/troubleshooting#request-blocked-federated-connections-work-only-in-agent-sessions-such-as-a-slack-channel--not-in-personal-sessions-such-as-a-direct-message), the request came from a personal session, such as a direct message with `@Claude`. A personal session runs under a person's own account. [Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, so test again from a new thread in a Slack channel where the connection [applies](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit).
134134 
135135## Related resources
136136 
137* [Give Claude access](/docs/claude-tag/admins/add-connections): the Access bundle and connection model
137* [Give Claude access](/docs/claude-tag/admins/add-connections): the bundle and connection model
138138* [Attach a bundle to a scope](/docs/claude-tag/admins/attach-to-scope): where a connection applies
139139* [Identity token reference](/docs/claude-tag/admins/federated-access/token-reference): every claim in the token, lifetimes, and key rotation
140140* [Connect a gateway](/docs/claude-tag/admins/federated-access/connect-a-gateway): the alternative where your own service verifies the token on every request

claude-tag/admins/federated-access/aws Changed · +11 / -11 lines

from line 6
66 
77<BetaNote />
88 
9<Note>AWS roles are connected at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag): open **Federated agent access** in the left navigation and use the **Cloud roles** section. Connecting a role needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
9<Note>AWS roles are connected on the [**Federated agent access**](https://claude.ai/admin-settings/claude-tag/federated-cloud-access) page, under **Claude Tag** in the admin settings sidebar. Use its **Cloud roles** section. Connecting a role needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
1010 
11With an AWS role connection, Claude signs in to an IAM role in your AWS account with a short-lived identity token and calls AWS with the role's permissions. No access key is stored in Claude. The token names your organization and the [agent](/docs/claude-tag/concepts/agent-identity) making the request (Claude's identity in one Slack channel), and your role's trust policy decides which tokens to accept. If someone else manages your AWS account, give them the values from the console and the trust policy below; the console steps need a Claude Tag admin.
11With an AWS role connection, Claude signs in to an IAM role in your AWS account with a short-lived identity token and calls AWS with the role's permissions. No access key is stored in Claude. The token names your organization and the [agent](/docs/claude-tag/concepts/agent-identity) making the request (Claude's identity in one Slack channel), and your role's trust policy decides which tokens to accept. If someone else manages your AWS account, give them the values from the console and the trust policy below; the console steps need an organization Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration).
1212 
1313## Before you begin
1414 
from line 83
8383 </Step>
8484 
8585 <Step title="Narrow the allowed AWS hosts">
86 The **Allowed AWS hosts** field starts with `*.amazonaws.com`, which lets Claude use the role with any AWS service. Keep that entry for the first verification, then narrow the list to the hosts Claude needs from the connection's [**Edit connection** dialog](/docs/claude-tag/admins/add-connections#set-allowed-websites) on the bundle's **Credentials** tab. A wildcard covers subdomains only: `*.s3.us-west-2.amazonaws.com` matches `example-reports.s3.us-west-2.amazonaws.com` but not `s3.us-west-2.amazonaws.com`. The AWS CLI and SDKs use both forms for S3, so list both the plain host and the wildcard for each region, and for `us-east-1` also `*.s3.amazonaws.com`, the older global S3 address some tools still use there. Every host must end in `.amazonaws.com`. The sign-in itself goes to the AWS Security Token Service (STS) from Anthropic's side and doesn't need an entry here.
86 The **Allowed AWS hosts** field starts with `*.amazonaws.com`, which lets Claude use the role with any AWS service. Keep that entry for the first verification, then narrow the list to the hosts Claude needs from the connection's [**Edit connection** dialog](/docs/claude-tag/admins/add-connections#set-allowed-websites), which you open from the connection's row on the **Connectors** tab; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab). A wildcard covers subdomains only: `*.s3.us-west-2.amazonaws.com` matches `example-reports.s3.us-west-2.amazonaws.com` but not `s3.us-west-2.amazonaws.com`. The AWS CLI and SDKs use both forms for S3, so list both the plain host and the wildcard for each region, and for `us-east-1` also `*.s3.amazonaws.com`, the older global S3 address some tools still use there. Every host must end in `.amazonaws.com`. The sign-in itself goes to the AWS Security Token Service (STS) from Anthropic's side and doesn't need an entry here.
8787 </Step>
8888 
8989 <Step title="Confirm the trust policy">
from line 90
9090 Select the checkbox labeled **The role's trust policy requires the subject prefix shown above**. The **Connect role** button stays disabled until you do. Select it only if the trust policy pins `sub` to one or more full subjects under your **Subject prefix**, or to your prefix followed by `*` under `StringLike`, as described under [Create the identity provider and role in AWS](#create-the-identity-provider-and-role-in-aws).
9191 </Step>
9292 
93 <Step title="Choose an Access bundle and connect">
94 Choose a bundle from the **Access bundle** list, or click **New bundle**, enter a **Bundle name**, and click **Create bundle**. Then click **Connect role**. This creates a [connection](/docs/claude-tag/admins/add-connections) in that bundle, labeled **AWS role** on its **Credentials** tab, with the hosts you entered under **Allowed hosts**. A role can be connected in one bundle only; to use it in several scopes (workspaces or channels), attach that bundle to each.
93 <Step title="Choose a bundle and connect">
94 Choose a bundle from the **Access bundle** list, or create one: click **New bundle** if the dialog shows it, enter a **Bundle name**, and click **Create bundle**. Then click **Connect role**. This creates a [connection](/docs/claude-tag/admins/add-connections) in that bundle, with the hosts you entered under **Allowed hosts**. A role can be connected in one bundle only, and it applies wherever that bundle applies.
9595 </Step>
9696</Steps>
9797 
98The **Cloud roles** table has **Role**, **Access bundle**, **Allowed hosts**, **Added**, and **Actions** columns. Each connection's name appears under **Role** with the role's ARN and an **AWS role** chip beneath it, and **Remove** is under **Actions**.
98The **Cloud roles** table has **Role**, **Access bundle**, **Allowed hosts**, **Added**, and **Actions** columns. Each connection's name appears under **Role** with the role's ARN and an **AWS role** chip beneath it, and **Check trust policy** and **Remove** are under **Actions**.
9999 
100100## Let agents use the role
101101 
102Claude uses the role in channels whose scope has the bundle attached. [Attach the bundle to a workspace or channel](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) if it isn't attached already.
102Claude uses the role in the channels where its bundle applies. A bundle you created in the connect dialog applies nowhere until you choose places; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab).
103103 
104104Claude also needs to know what the role is for. Add a line like this to the scope's [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions):
105105 
from line 115
115115 
116116[Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, such as a Slack channel. A test from a personal session, such as a direct message with `@Claude`, won't work.
117117 
118In a channel whose workspace or channel has the bundle attached, start a new thread and ask Claude to run a connectivity check. The check is Claude's own request to `sts.amazonaws.com`, so keep `*.amazonaws.com` under the connection's **Allowed hosts** for this check, or add `sts.amazonaws.com` if you already narrowed the list. The sign-in itself needs no entry there. After the check passes, remove `sts.amazonaws.com` again if you added it, or narrow the wildcard. While it is listed, Claude can send any STS request signed with the role's credentials. If the role is allowed to assume another role, the credentials AWS returns are readable in Claude's sandbox. The call needs no permissions policy on the role. Send Claude this prompt:
118In a channel where the role's connection applies, start a new thread and ask Claude to run a connectivity check. The check is Claude's own request to `sts.amazonaws.com`, so keep `*.amazonaws.com` under the connection's **Allowed hosts** for this check, or add `sts.amazonaws.com` if you already narrowed the list. The sign-in itself needs no entry there. After the check passes, remove `sts.amazonaws.com` again if you added it, or narrow the wildcard. While it is listed, Claude can send any STS request signed with the role's credentials. If the role is allowed to assume another role, the credentials AWS returns are readable in Claude's sandbox. The call needs no permissions policy on the role. Send Claude this prompt:
119119 
120120```text wrap theme={null}
121121@Claude Connectivity check for this channel's AWS connection. Please run exactly:
from line 142
142142 
143143Two messages come up while connecting:
144144 
145* **"This role is already connected in the bundle"**: the role already has its one connection. [Attach that bundle to the scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) instead.
145* **"This role is already connected in the bundle"**: the role already has its one connection. Apply that bundle where you need the role instead; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab).
146146* **"Enter a role ARN like `arn:aws:iam::123456789012:role/ClaudeTag`"**: the **Role ARN** field rejected the value, most often because the ARN is in the AWS GovCloud (US) or AWS China partition, which can't be connected.
147147 
148148For other dialog messages, see [Troubleshoot federated agent access](/docs/claude-tag/admins/federated-access/troubleshooting).
149149 
150If Claude reports HTTP 403 with a reason that starts with [`request blocked: federated connections work only in agent sessions (such as a Slack channel), not in personal sessions (such as a direct message)`](/docs/claude-tag/admins/federated-access/troubleshooting#request-blocked-federated-connections-work-only-in-agent-sessions-such-as-a-slack-channel--not-in-personal-sessions-such-as-a-direct-message), the request came from a personal session, such as a direct message with `@Claude`. A personal session runs under a person's own account. [Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, so test again from a new thread in a Slack channel under the [scope](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit) of the Access bundle that holds the connection.
150If Claude reports HTTP 403 with a reason that starts with [`request blocked: federated connections work only in agent sessions (such as a Slack channel), not in personal sessions (such as a direct message)`](/docs/claude-tag/admins/federated-access/troubleshooting#request-blocked-federated-connections-work-only-in-agent-sessions-such-as-a-slack-channel--not-in-personal-sessions-such-as-a-direct-message), the request came from a personal session, such as a direct message with `@Claude`. A personal session runs under a person's own account. [Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, so test again from a new thread in a Slack channel where the connection [applies](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit).
151151 
152152## Related resources
153153 
154* [Give Claude access](/docs/claude-tag/admins/add-connections): the Access bundle and connection model
154* [Give Claude access](/docs/claude-tag/admins/add-connections): the bundle and connection model
155155* [Attach a bundle to a scope](/docs/claude-tag/admins/attach-to-scope): where a role connection applies
156156* [Identity token reference](/docs/claude-tag/admins/federated-access/token-reference): every claim in the token, lifetimes, and key rotation
157157* [Troubleshoot federated agent access](/docs/claude-tag/admins/federated-access/troubleshooting): console and runtime errors for every connection type

claude-tag/admins/federated-access/connect-a-gateway Changed · +9 / -9 lines

from line 6
66 
77<BetaNote />
88 
9<Note>Gateways are connected at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag): open **Federated agent access** in the left navigation and use the **Gateways** section. Connecting a gateway needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
9<Note>Gateways are connected on the [**Federated agent access**](https://claude.ai/admin-settings/claude-tag/federated-cloud-access) page, under **Claude Tag** in the admin settings sidebar. Use its **Gateways** section. Connecting a gateway needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
1010 
1111A gateway is a service you run between Claude and your internal systems. Every request Claude sends it carries a signed identity token naming your organization and the [agent](/docs/claude-tag/concepts/agent-identity) making the request (Claude's identity in one Slack channel). The gateway checks the token, decides what that agent may do, and forwards the request with your own credentials. No long-lived credential for your systems is stored in Claude.
1212 
from line 18
1818* The gateway has a public HTTPS address with a domain name, such as `https://gateway.example.com`, on the standard HTTPS port. The console rejects a path, port, trailing slash, IP address, private-network name, Anthropic-owned host, or cloud token-exchange host.
1919* The gateway can reach `https://identity.anthropic.com` to fetch Anthropic's signing keys.
2020* If you start from Anthropic's [sample gateway](https://github.com/anthropics/claude-tag-wif-gateway-sample) (Python, Apache 2.0), terminate TLS in front of it, because it listens on plain HTTP, and set its `audience` to the public address you register.
21* An organization can register up to 5 addresses, counting gateways and authorization-server token endpoints together.
21* An organization can register up to 5 addresses, counting gateways and authorization-server audience addresses together.
2222 
2323## Copy the values and deploy the gateway
2424 
from line 69
6969 Leave the **Run the check** option selected and click **Run check and connect**. The check can take up to a minute. If it fails, nothing is registered; see [Common errors](#common-errors). If the gateway can't be reached from the internet yet, select the **Skip the check** option, enter a **Reason for skipping**, and click **Connect without the check**. The reason is shown in the **Gateways** table, under the **Skipped** result's **Details**. Entering an address that is already registered runs the check again (unless you skip it) without changing the stored result, then moves to the bundle step.
7070 </Step>
7171 
72 <Step title="Add the gateway to an Access bundle">
73 Choose a bundle from the **Access bundle** list, or click **New bundle**, enter a **Bundle name**, and click **Create bundle**. Then click **Add to bundle**. This creates a connection in that bundle, labeled **Gateway** on its **Credentials** tab, with the gateway's host as its allowed website. A gateway can be in more than one bundle; the **Access bundle** list offers only the bundles it isn't in yet. Click **Not now** to finish without a bundle.
72 <Step title="Add the gateway to a bundle">
73 Choose a bundle from the **Access bundle** list, or create one: click **New bundle** if the dialog shows it, enter a **Bundle name**, and click **Create bundle**. Then click **Add to bundle**. This creates a connection in that bundle, with the gateway's host as its allowed website. A gateway can be in more than one bundle, and it applies wherever those bundles apply. The **Access bundle** list offers only the bundles it isn't in yet. Click **Not now** to finish without a bundle.
7474 </Step>
7575</Steps>
7676 
from line 78
7878 
7979## Let agents reach the gateway
8080 
81Claude uses the gateway in channels whose scope has the bundle attached. [Attach the bundle to a workspace or channel](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) if it isn't attached already.
81Claude uses the gateway in the channels where its bundle applies. A bundle you created in the connect dialog applies nowhere until you choose places; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab).
8282 
8383Claude also needs to know the gateway exists. Add a line like this to the scope's [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions):
8484 
from line 94
9494 
9595[Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, such as a Slack channel. A test from a personal session, such as a direct message with `@Claude`, won't work.
9696 
97In a channel under the bundle's scope, start a new thread and ask Claude to make a small read through the gateway:
97In a channel where the gateway's connection applies, start a new thread and ask Claude to make a small read through the gateway:
9898 
9999```text wrap theme={null}
100100@Claude call GET /list-services on https://gateway.example.com and tell me what it returns.
from line 108
108108 
109109One message comes up while connecting. **"The check didn't pass"** means the gateway isn't reachable from the internet over HTTPS, its root route doesn't answer an empty `POST` directly, or the subject check is missing or rejects the **Control subject**. See [The check didn't pass](/docs/claude-tag/admins/federated-access/troubleshooting#the-check-didn%E2%80%99t-pass).
110110 
111A bundle-step note that the gateway is already in a bundle isn't an error; the **Access bundle** list then offers the bundles it isn't in yet. To use the gateway in more channels without adding it to another bundle, [attach a bundle it's in to each scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle).
111A bundle-step note that the gateway is already in a bundle isn't an error; the **Access bundle** list then offers the bundles it isn't in yet. To use the gateway in more channels without adding it to another bundle, apply a bundle it's in wherever you need the gateway; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab).
112112 
113113For other dialog messages, see [Troubleshoot federated agent access](/docs/claude-tag/admins/federated-access/troubleshooting).
114114 
115If Claude reports HTTP 403 with a reason that starts with [`request blocked: federated connections work only in agent sessions (such as a Slack channel), not in personal sessions (such as a direct message)`](/docs/claude-tag/admins/federated-access/troubleshooting#request-blocked-federated-connections-work-only-in-agent-sessions-such-as-a-slack-channel--not-in-personal-sessions-such-as-a-direct-message), the request came from a personal session, such as a direct message with `@Claude`. A personal session runs under a person's own account. [Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, so test again from a new thread in a Slack channel under the [scope](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit) of the Access bundle that holds the connection.
115If Claude reports HTTP 403 with a reason that starts with [`request blocked: federated connections work only in agent sessions (such as a Slack channel), not in personal sessions (such as a direct message)`](/docs/claude-tag/admins/federated-access/troubleshooting#request-blocked-federated-connections-work-only-in-agent-sessions-such-as-a-slack-channel--not-in-personal-sessions-such-as-a-direct-message), the request came from a personal session, such as a direct message with `@Claude`. A personal session runs under a person's own account. [Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, so test again from a new thread in a Slack channel where the connection [applies](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit).
116116 
117117## Related resources
118118 
119* [Give Claude access](/docs/claude-tag/admins/add-connections): the Access bundle and connection model
119* [Give Claude access](/docs/claude-tag/admins/add-connections): the bundle and connection model
120120* [Attach a bundle to a scope](/docs/claude-tag/admins/attach-to-scope): where a gateway connection applies
121121* [Identity token reference](/docs/claude-tag/admins/federated-access/token-reference): every claim in the token, lifetimes, and key rotation
122122* [Troubleshoot federated agent access](/docs/claude-tag/admins/federated-access/troubleshooting): console and runtime errors for every connection type

claude-tag/admins/federated-access/gcp Changed · +9 / -9 lines

from line 6
66 
77<BetaNote />
88 
9<Note>Google Cloud identities are connected at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag): open **Federated agent access** in the left navigation and use the **Cloud roles** section. Connecting an identity needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
9<Note>Google Cloud identities are connected on the [**Federated agent access**](https://claude.ai/admin-settings/claude-tag/federated-cloud-access) page, under **Claude Tag** in the admin settings sidebar. Use its **Cloud roles** section. Connecting an identity needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
1010 
11With a Google Cloud identity connection, Claude exchanges a short-lived identity token at a workload identity pool you create and calls Google Cloud APIs with the result. No service account key is stored in Claude. The token names your organization and the [agent](/docs/claude-tag/concepts/agent-identity) making the request (Claude's identity in one Slack channel), and your pool's attribute condition decides which tokens to accept. If someone else manages your Google Cloud project, give them the values from Claude's admin settings and the settings below; the console steps need a Claude Tag admin.
11With a Google Cloud identity connection, Claude exchanges a short-lived identity token at a workload identity pool you create and calls Google Cloud APIs with the result. No service account key is stored in Claude. The token names your organization and the [agent](/docs/claude-tag/concepts/agent-identity) making the request (Claude's identity in one Slack channel), and your pool's attribute condition decides which tokens to accept. If someone else manages your Google Cloud project, give them the values from Claude's admin settings and the settings below; the console steps need an organization Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration).
1212 
1313Before you start, decide whether Claude acts as the federated identity itself, with roles granted to it directly, or as a service account you create. Both forms are covered below.
1414 
from line 93
9393 </Step>
9494 
9595 <Step title="Narrow the allowed Google hosts">
96 Replace the prefilled `*.googleapis.com` entry in the **Allowed Google hosts** field with the hosts Claude needs, for example `storage.googleapis.com`. A wildcard as the leftmost label, such as `*.storage.googleapis.com`, matches any subdomain but not the name itself. Every host must be `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. You can change the list later from the connection's [**Edit connection** dialog](/docs/claude-tag/admins/add-connections#set-allowed-websites) on the bundle's **Credentials** tab.
96 Replace the prefilled `*.googleapis.com` entry in the **Allowed Google hosts** field with the hosts Claude needs, for example `storage.googleapis.com`. A wildcard as the leftmost label, such as `*.storage.googleapis.com`, matches any subdomain but not the name itself. Every host must be `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. You can change the list later from the connection's [**Edit connection** dialog](/docs/claude-tag/admins/add-connections#set-allowed-websites), which you open from the connection's row on the **Connectors** tab; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab).
9797 </Step>
9898 
9999 <Step title="Confirm the attribute condition">
from line 100
100100 Select the checkbox labeled **The provider's attribute condition requires the subject prefix shown above**. The **Connect identity** button stays disabled until you do. Select the checkbox only if the provider's attribute condition pins `assertion.sub` to one or more full subjects under your **Subject prefix**, or at minimum pins `assertion.sub` to your **Subject prefix** (or, if you mapped it, `attribute.org` to your organization ID), as described under [Create the pool and provider in Google Cloud](#create-the-pool-and-provider-in-google-cloud).
101101 </Step>
102102 
103 <Step title="Choose an Access bundle and connect">
104 Choose a bundle from the **Access bundle** list, or click **New bundle**, enter a **Bundle name**, and click **Create bundle**. Then click **Connect identity**. This creates a [connection](/docs/claude-tag/admins/add-connections) in that bundle, labeled **Google Cloud identity** on its **Credentials** tab, with the hosts you entered under **Allowed hosts**. The same provider can be connected more than once, for example once with a service account and once without, as long as no two Google Cloud connections in one bundle share a host under **Allowed hosts**. To use a connection in several scopes (workspaces or channels), attach its bundle to each.
103 <Step title="Choose a bundle and connect">
104 Choose a bundle from the **Access bundle** list, or create one: click **New bundle** if the dialog shows it, enter a **Bundle name**, and click **Create bundle**. Then click **Connect identity**. This creates a [connection](/docs/claude-tag/admins/add-connections) in that bundle, with the hosts you entered under **Allowed hosts**. The same provider can be connected more than once, for example once with a service account and once without, as long as no two Google Cloud connections in one bundle share a host under **Allowed hosts**. Each connection applies wherever its bundle applies.
105105 </Step>
106106</Steps>
107107 
from line 109
109109 
110110## Let agents use the identity
111111 
112Claude uses the identity in channels whose scope has the bundle attached. [Attach the bundle to a workspace or channel](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) if it isn't attached already.
112Claude uses the identity in the channels where its bundle applies. A bundle you created in the connect dialog applies nowhere until you choose places; see [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab).
113113 
114114Claude also needs to know what the identity is for. Add a line like this to the scope's [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions):
115115 
from line 125
125125 
126126[Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, such as a Slack channel. A test from a personal session, such as a direct message with `@Claude`, won't work.
127127 
128In a channel whose workspace or channel has the bundle attached, start a new thread and ask Claude to run a connectivity check. The check reads a bucket's metadata, so the identity needs the `storage.buckets.get` permission on the bucket, and `storage.googleapis.com` must be under the connection's **Allowed hosts**. Send Claude this prompt, replacing `example-reports` with a bucket the identity can read:
128In a channel where the identity's connection applies, start a new thread and ask Claude to run a connectivity check. The check reads a bucket's metadata, so the identity needs the `storage.buckets.get` permission on the bucket, and `storage.googleapis.com` must be under the connection's **Allowed hosts**. Send Claude this prompt, replacing `example-reports` with a bucket the identity can read:
129129 
130130```text wrap theme={null}
131131@Claude Connectivity check for this channel's Google Cloud connection. Please run exactly:
from line 155
155155 
156156For other dialog messages, see [Troubleshoot federated agent access](/docs/claude-tag/admins/federated-access/troubleshooting).
157157 
158If Claude reports HTTP 403 with a reason that starts with [`request blocked: federated connections work only in agent sessions (such as a Slack channel), not in personal sessions (such as a direct message)`](/docs/claude-tag/admins/federated-access/troubleshooting#request-blocked-federated-connections-work-only-in-agent-sessions-such-as-a-slack-channel--not-in-personal-sessions-such-as-a-direct-message), the request came from a personal session, such as a direct message with `@Claude`. A personal session runs under a person's own account. [Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, so test again from a new thread in a Slack channel under the [scope](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit) of the Access bundle that holds the connection.
158If Claude reports HTTP 403 with a reason that starts with [`request blocked: federated connections work only in agent sessions (such as a Slack channel), not in personal sessions (such as a direct message)`](/docs/claude-tag/admins/federated-access/troubleshooting#request-blocked-federated-connections-work-only-in-agent-sessions-such-as-a-slack-channel--not-in-personal-sessions-such-as-a-direct-message), the request came from a personal session, such as a direct message with `@Claude`. A personal session runs under a person's own account. [Federated connections](/docs/claude-tag/admins/federated-access/limits#where-federated-connections-work) work only in agent sessions, so test again from a new thread in a Slack channel where the connection [applies](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit).
159159 
160160## Related resources
161161 
162* [Give Claude access](/docs/claude-tag/admins/add-connections): the Access bundle and connection model
162* [Give Claude access](/docs/claude-tag/admins/add-connections): the bundle and connection model
163163* [Attach a bundle to a scope](/docs/claude-tag/admins/attach-to-scope): where an identity connection applies
164164* [Identity token reference](/docs/claude-tag/admins/federated-access/token-reference): every claim in the token, lifetimes, and key rotation
165165* [Limits](/docs/claude-tag/admins/federated-access/limits): what the credential-minting block refuses, and the other limits for Google Cloud identities

claude-tag/admins/federated-access/limits Changed · +5 / -4 lines

from line 24
2424 
2525| Limit | Value |
2626| :- | :- |
27| Registered addresses per organization | 5, counting gateways and authorization-server token endpoints together. |
27| Registered addresses per organization | 5, counting gateways and authorization-server audience addresses together. |
2828| Token reuse | Claude reuses one token for a session's requests to the same gateway for about five minutes, half the token's lifetime, or until the gateway answers 401, and then requests a new one (current behavior, may change). A gateway sees the same `jti` on many requests. |
2929| Gateway address | An HTTPS host name only, with no path, port, query, or trailing slash. The host name needs a domain, like `gateway.example.com`, uses only letters, numbers, hyphens, and dots, and has at most 253 characters (current behavior, may change). The console rejects an IP address, a private-network name, an Anthropic-owned host, or a host cloud providers use for token exchange, and names the reason. The connection check also refuses a host name that resolves to a private address. |
3030| [Allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) on the gateway's connection | Exactly the gateway's host, the only host Claude sends the token to. It can't be widened or given a wildcard. |
from line 50
5050| **Allowed Google hosts** | `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. |
5151| OAuth scope | `https://www.googleapis.com/auth/cloud-platform`, always, with no setting to change it. On Google Cloud APIs, IAM decides what the credential can do. An API that needs an OAuth scope of its own answers 403 whatever IAM allows; see [The cloud API answers 403 after a successful exchange](/docs/claude-tag/admins/federated-access/troubleshooting#the-cloud-api-answers-403-after-a-successful-exchange). |
5252| **Block requests that mint new credentials** | On by default. When on, requests to Google's credential-minting and credential-delivering endpoints are refused, including over gRPC; see [What the credential-minting block refuses](#what-the-credential-minting-block-refuses). The block is best effort and doesn't replace least-privilege IAM. |
53| Google Cloud connections in one bundle | No two Google Cloud connections in the same Access bundle can cover the same host under **Allowed hosts**, whatever their providers or service accounts. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The same provider can be connected again with different hosts, or in another bundle. |
53| Google Cloud connections in one bundle | No two Google Cloud connections in the same bundle can cover the same host under **Allowed hosts**, whatever their providers or service accounts. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The same provider can be connected again with different hosts, or in another bundle. |
5454 
5555### What the credential-minting block refuses
5656 
from line 76
7676| Token audience | Your authorization server's issuer identifier as you entered it (an HTTPS URL on the same host as the token endpoint, with the same address rules), or the token endpoint URL exactly when you left the issuer identifier empty. It can't be changed after the server is connected. |
7777| **Resource** | Optional. An absolute URI with no fragment, at most 256 characters with no spaces (current behavior, may change). |
7878| **Scope** | Optional. Space-separated scope words with no quotes or backslashes, at most 256 characters in total (current behavior, may change). |
79| **Allowed API hosts** | Must not include the token endpoint's host. |
79| **Allowed API hosts** | Can include the token endpoint's host only when the endpoint's address has a folder of its own, like `/oauth2` in `https://auth.example.com/oauth2/token`, and you list **Allowed API paths**. |
80| **Allowed API paths** | Needed only when an allowed host covers the token endpoint's host. 1 to 32 paths, each starting with `/`, not ending with `/`, at most 256 characters, and not overlapping the token endpoint's folder. A path can't contain spaces, non-English letters, `..`, `//`, a part ending with a dot, or any of `%`, `?`, `#`, `;`, `@`, `+`, or a backslash (current behavior, may change). |
8081| Token exchange | A form-encoded `POST` that doesn't follow redirects and must complete within about 10 seconds (current behavior, may change). |
8182| Access token reuse | Reused until about five minutes before it expires (for tokens shorter than 10 minutes, until half their lifetime has passed) when `expires_in` is between 5 minutes and 1 day. When `expires_in` is missing or shorter, the token is used for one request. When it is longer than a day, the token isn't cached either, so every request goes to the token endpoint. (Current behavior, may change.) |
8283| Subject check | Your authorization server performs it; the console has no connection check for token endpoints. The server must accept only your own agents' full subjects, or at minimum check that each token's subject starts with your organization's **Subject prefix**. |
83| Endpoint reuse | A registered address can be connected as a gateway or as an authorization server, not both. A token endpoint stays listed in the **Gateways** table after you remove its authorization server, and frees its place among the 5 registered addresses only when you remove it there too. |
84| Endpoint reuse | A registered address can be connected as a gateway or as an authorization server, not both. An authorization server's audience address stays listed in the **Gateways** table after you remove the server, and frees its place among the 5 registered addresses only when you remove it there too. |
8485 
8586## Testing
8687 

claude-tag/admins/federated-access/overview Changed · +16 / -6 lines

## Manage federated connections on the Connectors tab

from line 6
66 
77<BetaNote />
88 
9<Note>Federated connections are managed at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag): open **Federated agent access** in the left navigation. Connecting a gateway, cloud role, or authorization server needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
9<Note>Federated connections are managed on the [**Federated agent access**](https://claude.ai/admin-settings/claude-tag/federated-cloud-access) page, under **Claude Tag** in the admin settings sidebar. Connecting a gateway, cloud role, or authorization server needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
1010 
1111In Slack channels, Claude Tag acts under its own [agent identity](/docs/claude-tag/concepts/agent-identity) rather than as any person. Federated agent access lets that identity prove itself to your systems with a short-lived, signed identity token instead of a credential you store in Claude.
1212 
13In the console, you connect your gateway, AWS role, Google Cloud identity, or authorization server under **Federated agent access** and add it to an [Access bundle](/docs/claude-tag/admins/add-connections) attached to the channels where Claude should use it. Your cloud or gateway administrator configures that system to trust Anthropic's issuer and to check that each token's subject belongs to your organization, and the system then decides what the agent may do. To confirm the connection works, ask Claude in one of those channels to make a small request, then check its reply and your system's logs.
13In the console, you connect your gateway, AWS role, Google Cloud identity, or authorization server under **Federated agent access**, add it to a [bundle](/docs/claude-tag/concepts/glossary#access-bundle), and [apply it to the channels](#manage-federated-connections-on-the-connectors-tab) where Claude should use it. Your cloud or gateway administrator configures that system to trust Anthropic's issuer and to check that each token's subject belongs to your organization, and the system then decides what the agent may do. To confirm the connection works, ask Claude in one of those channels to make a small request, then check its reply and your system's logs.
1414 
1515Federated agent access goes one way: Claude proves who it is to your systems. For your workloads proving who they are to the Claude API, see [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation) on the Claude Developer Platform.
1616 
from line 29
2929 
3030## How it works
3131 
321. When a request from Claude's sandbox needs one of your systems, [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) matches it by destination to a federated connection in one of the channel's Access bundles. Until an admin connects a system in **Federated agent access** and adds it to a bundle attached to the channel, nothing matches and no token is issued for Claude's requests.
321. When a request from Claude's sandbox needs one of your systems, [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) matches it by destination to a federated connection that applies to the channel. Until an admin connects a system in **Federated agent access** and applies the connection to the channel, nothing matches and no token is issued for Claude's requests.
33332. Anthropic issues an identity token. The token is a JSON Web Token (JWT) signed by Anthropic and valid for 10 minutes. Its subject names your organization and the agent, in the form `wimse://identity.anthropic.com/org/<your organization ID>/agent/<agent ID>`, and its audience names the destination. Claude reuses one token for a session's requests to the same gateway for about five minutes, or until the gateway answers 401, and then requests a new one. The other connection types use a token once, in an exchange.
34343. Your side accepts the token. A gateway verifies it directly. AWS or Google Cloud exchanges it for a short-lived cloud credential. Your authorization server exchanges it for an access token. Agent Proxy attaches the result to Claude's request, or signs the request with it for AWS, and forwards the request. The model and the sandbox are never given the token or the credential that comes back.
3535 
from line 54
5454| A Google Cloud credential already exchanged | As long as Google Cloud issued it for |
5555| An access token from your authorization server | The `expires_in` your server returned |
5656 
57Anthropic doesn't review your gateway, trust policy, or authorization server. When you connect a gateway, the console offers a connection check that confirms the gateway rejects a token whose subject isn't your organization. The other connection types have no check in the console, so you verify them yourself with the steps on each setup page.
57Anthropic doesn't review your gateway, trust policy, or authorization server. When you connect a gateway, the console offers a connection check that confirms the gateway rejects a token whose subject isn't your organization. The other connection types have no connection check. For an AWS role, **Check trust policy** in the role's row of the **Cloud roles** table checks a trust policy you paste against that connection's token format. The check runs in your browser and doesn't change the connection. You verify the rest yourself with the steps on each setup page.
5858 
5959## Before you begin
6060 
61* **Federated agent access** appears in the console's left navigation. It's missing for organizations whose compliance configuration excludes federated agent access.
61* **Federated agent access** appears under **Claude Tag** in the console's left navigation. It's missing for organizations whose compliance configuration excludes federated agent access.
6262* An organization Owner, or an admin with full Claude Tag management permission, makes the connection in the console.
6363* Your cloud or gateway administrator configures the system on your side: the gateway operator, your AWS or Google Cloud IAM administrator, or your authorization server's operator. Each setup page lists the values they configure.
64* An [Access bundle](/docs/claude-tag/admins/add-connections) is attached to the [scope](/docs/claude-tag/concepts/glossary#scope) of the channels where Claude should use the connection. To use a connection in several places, attach its bundle to each scope. A gateway can also be added to more than one bundle; an AWS role or authorization server is connected in one bundle only.
64* You know which channels, workspaces, or all of Slack Claude should use the connection in. A connection applies wherever its [bundle](/docs/claude-tag/concepts/glossary#access-bundle) applies. A gateway can also be added to more than one bundle; an AWS role or authorization server is connected in one bundle only.
6565 
6666Federated connections work in Slack channels, where Claude acts under your organization's agent identity. They don't work in one-to-one direct messages from members who have connected a Claude account, which run under [the individual's own account](/docs/claude-tag/concepts/agent-identity#direct-message-channels).
67 
68## Manage federated connections on the Connectors tab
69 
70After you connect a system, choose where the connection applies. Each connect dialog puts the connection in the bundle you choose or create there.
71 
72The connection then also appears as a connector on the **Connectors** tab under **Claude's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), where the tab's search finds it by name or host and its row in the connector's **Access from** table shows its type in the **Credential** column. Manage it from there:
73 
74* **Choose where it applies**: a bundle you create in the connect dialog applies nowhere until you choose places. The bundle is listed on the **Bundles** tab, where you add places under **Where it applies** and click **Save changes**. To choose places from the connector's page instead, see [Give Claude access](/docs/claude-tag/admins/add-connections).
75* **Edit its allowed hosts**: in the connector's **Access from** table, open the connection's **⋮** menu and choose **Edit** to open the **Edit connection** dialog.
76* **Delete it from its bundle**: open the connection's bundle from the **Bundles** tab, and under **What's in it** choose **Remove credential** from the connection's **⋮** menu, then click **Delete** to confirm. The **Set by** column of the connector's **Access from** table names that bundle.
6777 
6878## Related resources
6979 

claude-tag/admins/federated-access/troubleshooting Changed · +20 / -20 lines

from line 6
66 
77<BetaNote />
88 
9<Note>Federated connections are managed at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag): open **Federated agent access** in the left navigation. Changing them needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
9<Note>Federated connections are managed on the [**Federated agent access**](https://claude.ai/admin-settings/claude-tag/federated-cloud-access) page, under **Claude Tag** in the admin settings sidebar. Changing them needs an organization Owner, or an admin with full Claude Tag management permission.</Note>
1010 
1111This page covers what goes wrong after you connect a gateway, AWS role, Google Cloud identity, or authorization server through **Federated agent access**. It's organized by where the problem shows up: a message in a console dialog, an error Claude reports in the thread, or a rejection in your own logs. The token terms used below are explained on the [identity token reference](/docs/claude-tag/admins/federated-access/token-reference).
1212 
1313First confirm two things that have nothing to do with federation:
1414 
15* The connection is in an [Access bundle attached to the channel's scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle). For a gateway, the scope's custom instructions also [name the gateway's address](/docs/claude-tag/admins/federated-access/connect-a-gateway#let-agents-reach-the-gateway), so Claude knows the gateway exists.
15* The connection applies to the channel, as [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab) describes. For a gateway, the scope's custom instructions also [name the gateway's address](/docs/claude-tag/admins/federated-access/connect-a-gateway#let-agents-reach-the-gateway), so Claude knows the gateway exists.
1616* You tested in a new thread. A thread already running isn't told about a connection added after it started; ask Claude for the service by name, or send [`@Claude !restart`](/docs/claude-tag/users/commands#restart-a-stuck-or-wrong-context-session) in that thread.
1717 
1818If Claude reports that a host isn't allowed before any request is sent, see [Claude says a host isn't allowed](/docs/claude-tag/admins/troubleshooting#claude-says-a-host-isn%E2%80%99t-allowed-or-it-can%E2%80%99t-reach-the-internet).
from line 27
2727| "Too many checks in a short time." followed by how long to wait | Your organization ran the connection check too many times in quick succession. The limit counts every admin in the organization. Entering an address that is already registered runs the check again and counts too, unless the **Skip the check** option is selected. | Wait the time the message names. To add an existing gateway to a bundle, click **Add to bundle** (**Add to another bundle** on a row already in one) in the **Gateways** table instead of entering its address again. |
2828| "Too many attempts in a short time." in the **Connect an authorization server** dialog | A general request limit, not the connection check; registering a token endpoint never runs the check. | Wait the time the message names and try again. |
2929| "Connecting a gateway needs full Claude Tag management permission. Ask an organization owner." or "This needs full Claude Tag management permission. Ask an organization owner." | Your account can't change federated connections. Channel managers, and admins whose Claude Tag permission covers specific channels only, can't connect a gateway, cloud role, or authorization server. | Ask an organization Owner, or an admin with full Claude Tag management permission, to make the connection from their own account. |
30| A dialog message containing "isn't enabled for your organization yet", or **Federated agent access** is missing from the left navigation | Federated agent access isn't available to organizations whose compliance configuration excludes it. The navigation item is also hidden from channel managers and from admins whose Claude Tag permission covers specific channels only, because connecting a system needs full Claude Tag management permission. | Ask an organization Owner, or an admin with full Claude Tag management permission, to open the page. If it's missing for them too, your organization's compliance configuration excludes the feature. |
31| "This organization has reached its limit of 5 gateways. Remove one to connect another." or, in the **Connect an authorization server** dialog, "…limit of 5 registered gateways, which includes token endpoints." | An organization can register 5 addresses. A token endpoint is registered the same way as a gateway, so it counts toward the same 5 and appears in the **Gateways** table marked "Used by a connected authorization server. Manage it from the Authorization servers section." An address is either a gateway or a token endpoint in your organization, not both. | In the **Gateways** table, click **Remove** in the row of a gateway you no longer use. To free a token endpoint's row, click **Remove** in the server's row of the **Authorization servers** table first, then remove the endpoint from the **Gateways** table. See [Removing and reconnecting a gateway](#removing-and-reconnecting-a-gateway). |
30| A dialog message containing "isn't enabled for your organization yet", or **Federated agent access** is missing under **Claude Tag** in the left navigation | Federated agent access isn't available to organizations whose compliance configuration excludes it. The navigation item is also hidden from channel managers and from admins whose Claude Tag permission covers specific channels only, because connecting a system needs full Claude Tag management permission. | Ask an organization Owner, or an admin with full Claude Tag management permission, to open the page. If it's missing for them too, your organization's compliance configuration excludes the feature. |
31| "This organization has reached its limit of 5 gateways. Remove one to connect another." or, in the **Connect an authorization server** dialog, "…limit of 5 registered gateways, which includes token endpoints." | An organization can register 5 addresses. An authorization server's audience address, its **Issuer URL** value or its token endpoint, is also registered as a gateway, so it counts toward the same 5 and appears in the **Gateways** table marked "Used by a connected authorization server. Manage it from the Authorization servers section." An address is either a gateway or a token endpoint in your organization, not both. | In the **Gateways** table, click **Remove** in the row of a gateway you no longer use. To free an authorization server's row, click **Remove** in the server's row of the **Authorization servers** table first, then remove its address from the **Gateways** table. See [Removing and reconnecting a gateway](#removing-and-reconnecting-a-gateway). |
3232| "This gateway is already registered. Close this dialog and pick it from the list to add it to a bundle." | The address is already registered in your organization, and the dialog couldn't load its row to continue. This message is rare: entering a registered address normally runs the connection check again without changing the stored result, then moves on to the bundle step. | Click **Cancel**, then click **Add to bundle** (**Add to another bundle** on a row already in one) in the gateway's row of the **Gateways** table. |
33| "This role is already connected in the bundle `<bundle>`." or "This token endpoint is already connected in the bundle `<bundle>`." | An AWS role or token endpoint can be connected in only one Access bundle, and this one already is. | To use the connection in more channels, [attach that bundle to each scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) instead. To move it, in **Access bundles**, open the bundle's **Credentials** tab, open the **⋮** menu on the connection's row, and choose **Delete**. Then connect it again from its own dialog and pick the new bundle. |
34| "`<name>` already covers `<host>` in this bundle, so Claude would never use this connection for the hosts they share. Change the hosts or choose another bundle." in the **Connect a Google Cloud identity** dialog | Another Google Cloud connection in the bundle you chose already has that host under **Allowed hosts**, whatever its provider or service account. Claude uses the first connection in a bundle whose hosts match a request, so the new connection would never be used for the shared host. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The dialog won't connect until the overlap is gone. | Remove the shared host from the new connection's **Allowed Google hosts**, or choose another bundle. To give the host to the new connection instead, first narrow the existing one: in **Access bundles**, open the bundle's **Credentials** tab, open the **⋮** menu on the connection's row, choose **Edit**, and change **Allowed hosts**. |
33| "This role is already connected in the bundle `<bundle>`." or "This token endpoint is already connected in the bundle `<bundle>`." | An AWS role or token endpoint can be connected in only one bundle, and this one already is. | To use the connection in more channels, apply that bundle in more places instead. To move it, delete the connection from its bundle, as [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab) describes. Then connect it again from its own dialog and pick the new bundle. |
34| "`<name>` already covers `<host>` in this bundle, so Claude would never use this connection for the hosts they share. Change the hosts or choose another bundle." in the **Connect a Google Cloud identity** dialog | Another Google Cloud connection in the bundle you chose already has that host under **Allowed hosts**, whatever its provider or service account. Claude uses the first connection in a bundle whose hosts match a request, so the new connection would never be used for the shared host. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The dialog won't connect until the overlap is gone. | Remove the shared host from the new connection's **Allowed Google hosts**, or choose another bundle. To give the host to the new connection instead, first narrow the existing one's **Allowed hosts** in its **Edit connection** dialog, as [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab) describes. |
3535| "Couldn't connect the gateway. Try again.", "Couldn't add the gateway to the bundle.", "Couldn't connect the role. Try again.", "Couldn't connect the identity. Try again.", "Couldn't register the authorization server. Try again.", or "Couldn't connect the authorization server. Try again." | The request failed for a reason the dialog doesn't name, most often a temporary one. | Try once more. If the message persists, contact your Anthropic account team with the details under [Contact Anthropic](#contact-anthropic). |
3636| "The issuer URL must be an https URL on the same host as the token endpoint. Leave it empty to use the token endpoint as the audience." in the **Connect an authorization server** dialog | The **Issuer URL** value must be an HTTPS URL on the same host as the token endpoint, or empty. The token is only ever presented to that server, so its audience must name that server. | Enter the issuer identifier your authorization server uses, on the token endpoint's host, or clear the field to use the token endpoint as the audience. |
37| "This token endpoint is already connected. Manage it from the Authorization servers section." in the **Connect an authorization server** dialog | An authorization server with this token endpoint is already connected in one of your organization's Access bundles, and a server can be connected only once. The dialog checks this before it registers anything. | To use the server in more channels, [attach its bundle to each scope](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle). To connect it again, remove it first: in the **Authorization servers** table, click **Remove** in the server's row. |
38| "That address is already connected as a gateway. Enter your authorization server's own addresses, or remove the gateway first." in the **Connect an authorization server** dialog | The token endpoint, or the **Issuer URL** value, is the address of a gateway connected in one of your organization's Access bundles. One address can't be both, because a token sent to the gateway could be replayed to the server as a grant. | Enter the token endpoint and issuer identifier your authorization server publishes. To use that address for the server instead, remove the gateway first: in **Access bundles**, open the bundle that holds the gateway, open its **Credentials** tab, open the **⋮** menu on the gateway's row, and choose **Delete**. Then, in the **Gateways** table under **Federated agent access**, click **Remove** in the gateway's row. |
37| "This token endpoint is already connected. Manage it from the Authorization servers section." in the **Connect an authorization server** dialog | An authorization server with this token endpoint is already connected in one of your organization's bundles, and a server can be connected only once. The dialog checks this before it registers anything. | To use the server in more channels, apply its bundle in more places. To connect it again, remove it first: in the **Authorization servers** table, click **Remove** in the server's row. |
38| "That address is already connected as a gateway. Enter your authorization server's own addresses, or remove the gateway first." in the **Connect an authorization server** dialog | The token endpoint, or the **Issuer URL** value, is the address of a gateway connected in one of your organization's bundles. One address can't be both, because a token sent to the gateway could be replayed to the server as a grant. | Enter the token endpoint and issuer identifier your authorization server publishes. To use that address for the server instead, remove the gateway first: delete the gateway's connection from its bundle, as [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab) describes. Then, in the **Gateways** table under **Federated agent access**, click **Remove** in the gateway's row. |
3939| "That address is registered by a connected authorization server. Enter your gateway's address, or remove the server first." in the **Connect a gateway** dialog | The address you entered is a connected authorization server's token endpoint or audience, for example a server whose **Issuer URL** is the bare host `https://auth.example.com`. One address can't be both, because a token sent to the gateway could be replayed to that server as a grant. | Enter the host your gateway answers on. To use that address for a gateway instead, remove the server first: in the **Authorization servers** table, click **Remove** in the server's row. |
4040| "That address is already a connected authorization server's audience. Enter this server's own issuer URL." in the **Connect an authorization server** dialog | The **Issuer URL** value (or the token endpoint, when **Issuer URL** is empty) is already another connected authorization server's audience or token endpoint. Two servers can't share an audience, because a token minted for one would be valid at the other. | In the **Issuer URL** field, enter the issuer identifier this server publishes. If the other server holds this identifier by mistake, remove that server first: in the **Authorization servers** table, click **Remove** in its row, then connect it again with its own issuer URL. |
4141| "The address is too long. Issuer URLs have at most 256 characters." under the **Issuer URL** field of the **Connect an authorization server** dialog | The **Issuer URL** field accepts at most 256 characters, the same limit as the **Token endpoint** field. | Check that the field holds only the issuer identifier, for example `https://auth.example.com`, and not a longer value pasted by mistake. |
from line 69
6969 
7070### Removing and reconnecting a gateway
7171 
72In the **Gateways** table, click **Remove** in the gateway's row and confirm with **Remove gateway**. Claude stops using the gateway at once. A connection that used the gateway stays in its Access bundle but stops working, and Claude reports [request blocked: this credential's audience isn't registered as a gateway for this organization](#request-blocked-this-credential%E2%80%99s-audience-isn%E2%80%99t-registered-as-a-gateway-for-this-organization) until the gateway is registered again.
72In the **Gateways** table, click **Remove** in the gateway's row and confirm with **Remove gateway**. Claude stops using the gateway at once. A connection that used the gateway stays in its bundle but stops working, and Claude reports [request blocked: this credential's audience isn't registered as a gateway for this organization](#request-blocked-this-credential%E2%80%99s-audience-isn%E2%80%99t-registered-as-a-gateway-for-this-organization) until the gateway is registered again.
7373 
7474To reconnect, click **Connect a gateway** in the **Gateways** section and enter the same address. Registering the address restores the existing connection, which is still in the bundle; the bundle step then offers only bundles the gateway isn't in.
7575 
from line 91
9191 
9292**How to resolve**
9393 
94Use the connection from a channel whose scope has the bundle attached. No setting enables federated connections in personal sessions.
94Use the connection from a channel where it applies. No setting enables federated connections in personal sessions.
9595 
9696### request blocked: this credential's audience isn't registered as a gateway for this organization
9797 
from line 101
101101 
102102**What it means**
103103 
104The gateway was removed from the **Gateways** table, but its connection is still in an Access bundle. Claude can't get a token for an address that isn't registered.
104The gateway was removed from the **Gateways** table, but its connection is still in a bundle. Claude can't get a token for an address that isn't registered.
105105 
106106**How to resolve**
107107 
108To keep the gateway, register the same address again; see [Removing and reconnecting a gateway](#removing-and-reconnecting-a-gateway). To drop it, in **Access bundles**, open the bundle's **Credentials** tab, open the **⋮** menu on the connection's row, and choose **Delete**.
108To keep the gateway, register the same address again; see [Removing and reconnecting a gateway](#removing-and-reconnecting-a-gateway). To drop it, delete the connection from its bundle, as [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab) describes.
109109 
110110### Claude says Google credentials are not enabled for this organization
111111 
from line 157
157157 
158158**What it means**
159159 
160The authorization server connection's allowed hosts cover the token endpoint's own host, for example through a wildcard such as `*.example.com` that covers `auth.example.com`. The connect dialog refuses this when the connection is created, and so does every later edit of its allowed hosts, so the message isn't expected; the same rule is checked again on every request. The access token your server returns must never be sent back to the server that issued it, so every request with this connection is refused until an admin fixes it.
160The authorization server connection's allowed hosts cover the token endpoint's own host, for example through a wildcard such as `*.example.com` that covers `auth.example.com`, and the connection lists no allowed API paths. The connect dialog accepts such hosts only when you also list **Allowed API paths**, so the message isn't expected; the same rule is checked again on every request. The access token your server returns must never be sent back to the server that issued it, so every request with this connection is refused until an admin fixes it.
161161 
162162**How to resolve**
163163 
164In **Access bundles**, open the bundle's **Credentials** tab, open the **⋮** menu on the connection's row, choose **Edit**, and in the **Edit connection** dialog set **Allowed hosts** to only the APIs Claude calls with the returned token, for example `api.example.com`, with no wildcard that covers the token endpoint's host. If the API and the token endpoint share a host, use a different host for one of them.
164Open the connection's **Edit connection** dialog, as [Manage federated connections on the Connectors tab](/docs/claude-tag/admins/federated-access/overview#manage-federated-connections-on-the-connectors-tab) describes, and set **Allowed hosts** to only the APIs Claude calls with the returned token, for example `api.example.com`, with no wildcard that covers the token endpoint's host. If the API and the token endpoint share a host, use a different host for one of them, or [remove the server](/docs/claude-tag/admins/federated-access/authorization-server#remove-the-server) and connect it again with **Allowed API paths** listed.
165165 
166166### credential injection temporarily unavailable; retry the request
167167 

claude-tag/admins/for-slack-admins Changed · +3 / -3 lines

from line 40
4040 
4141## What installing does not grant
4242 
43Credentials for GitHub, Google Drive, a data warehouse, or anything else are provisioned separately by a Claude organization Owner and live on Anthropic's side rather than in Slack.
43Credentials for GitHub, Google Drive, a data warehouse, or anything else are provisioned separately by an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) of the Claude organization and live on Anthropic's side rather than in Slack.
4444 
4545It responds when @-mentioned, and may respond to other messages it judges warrant a reply.
4646 
from line 54
5454 
5555Uninstalling the Claude app from your workspace removes it from Slack and deletes the workspace's Claude data on Anthropic's side, the same way [disconnecting the workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing) from the Claude console does. What Claude posted in Slack, such as messages, canvases, and files, stays in Slack under your workspace's own retention settings.
5656 
57On Enterprise Grid, this applies when the app was installed on an individual workspace and you uninstall it there. Removing an org-wide installation, from the whole grid or from one of its workspaces, doesn't delete data on its own; to delete it, ask the Claude organization Owner to disconnect the grid in their Claude settings.
57On Enterprise Grid, this applies when the app was installed on an individual workspace and you uninstall it there. Removing an org-wide installation, from the whole grid or from one of its workspaces, doesn't delete data on its own; to delete it, ask an Owner of the Claude organization to disconnect the Grid in its Claude Tag settings.
5858 
5959## Related resources
6060 
6161* [Security and data handling](/docs/claude-tag/concepts/security-and-data): where credentials are stored and what leaves your workspace
62* [Pair your Slack workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace): what the Claude Owner does with the code you send
62* [Pair your Slack workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace): what the Claude organization's Owner does with the code you send
6363 

claude-tag/admins/healthcare Changed · +19 / -17 lines

from line 10
1010 
1111If your Claude organization has the HIPAA configuration applied to Claude Code (local mode) and Cowork (local mode), Claude Tag isn't available in that organization. [Plan and organization requirements](#plan-and-organization-requirements) describes the alternative.
1212 
13This page is for the Claude organization Owner and the compliance lead deciding where Claude works. It describes how to configure Claude Tag so PHI stays out of Claude's reach. It is not legal advice. Review your setup with your legal and compliance teams before you turn Claude on.
13This page is for the Claude organization's Owners and the compliance lead deciding where Claude works. It describes how to configure Claude Tag so PHI stays out of Claude's reach. It is not legal advice. Review your setup with your legal and compliance teams before you turn Claude on.
1414 
1515## What Claude can read in Slack
1616 
from line 28
2828 
2929## Plan and organization requirements
3030 
31Limiting Claude to approved channels needs an [Enterprise plan](https://claude.com/pricing), in addition to the [general prerequisites for Claude Tag](/docs/claude-tag/admins/setup-overview). Only the Enterprise plan has a [setting that turns Claude on or off for an individual channel](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope).
31Limiting Claude to approved channels needs an [Enterprise plan](https://claude.com/pricing), in addition to the [general prerequisites for Claude Tag](/docs/claude-tag/admins/setup-overview). The Enterprise plan has a [setting that turns Claude on or off for an individual channel](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope).
3232 
3333Claude Tag [isn't available in a Claude organization](/docs/claude-tag/concepts/security-and-data) that has any of these:
3434 
from line 40
4040 
4141## Limit Claude to PHI-free channels
4242 
43An Owner turns Claude off everywhere by default, turns it on only in channels approved as PHI-free, turns off direct messages, and blocks channel names that signal PHI. Every setting in these steps is at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
43An Owner turns Claude off everywhere by default, turns it on only in channels approved as PHI-free, turns off direct messages, and blocks channel names that signal PHI. Every setting in these steps is at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), and the workspace and channel settings are on the **Channels** tab under **Claude's access**.
4444 
4545<Steps>
4646 <Step title="Turn Claude off by default">
47 Go to **Claude Tag's access** → **Slack** → **Default Slack** and turn off the **Enable Claude Tag in Slack** switch at the top of the panel. [Limit Claude Tag to specific channels](/docs/claude-tag/admins/restrict-access#limit-claude-tag-to-specific-channels) has the full procedure.
47 Go to [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack) and turn off the **Respond in all channels** switch at the top of the **General** tab. [Limit Claude Tag to specific channels](/docs/claude-tag/admins/restrict-access#limit-claude-tag-to-specific-channels) has the full procedure.
4848 </Step>
4949 
50 <Step title="Reset workspace and channel entries that have their own setting">
51 A workspace or channel entry's own **Enable Claude Tag** setting takes precedence over **Default Slack**, so an entry switched on during an earlier pilot keeps Claude active there. Under **Claude Tag's access** → **Slack**, open each workspace and channel entry that has its own setting and click **Use inherited setting** under the switch.
50 <Step title="Reset workspaces and channels that have their own setting">
51 A workspace's or channel's own **Enable Claude Tag** setting takes precedence over the **Slack** page, so a workspace or channel switched on during an earlier pilot keeps Claude active there. On the **Channels** tab, open each workspace's and channel's page that has its own setting, and click the **Use inherited setting** link under its switch.
5252 </Step>
5353 
5454 <Step title="Turn Claude on in each approved channel">
55 Go to **Claude Tag's access** → **Slack**, select the entry for the approved channel, and turn on its **Enable Claude Tag in this channel** switch. If the channel isn't listed under **Slack**, [add the channel with **Add channel**](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) first.
55 On the **Channels** tab, open the approved channel's page and turn on its **Enable Claude Tag in this channel** switch. If the channel isn't listed on the **Channels** tab, [set it up](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) first.
5656 </Step>
5757 
5858 <Step title="Turn off direct messages">
59 On the same [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) page, turn off the [**Allow direct messages** toggle](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages). Claude is then reachable only in channels.
59 On the same [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) page, select **Edit** on the **Direct messages** row and turn off the [**Allow direct messages** toggle](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages). Claude is then reachable only in channels.
6060 </Step>
6161 
6262 <Step title="Block channel names that signal PHI">
63 Go to **Claude Tag's access** → **Slack** → **Default Slack** → **Advanced** → **Blocked channel patterns** and add the naming patterns your workspace uses for clinical or patient channels, for example `*-patient-*`. Claude won't read or respond in a matching channel even if someone invites it. See [Block or auto-join channels by name](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name).
63 Go to [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack), open the **Advanced** tab, and under **Channels** add the naming patterns your workspace uses for clinical or patient channels to **Blocked channel patterns**, for example `*-patient-*`. Claude won't read or respond in a matching channel even if someone invites it. See [Block or auto-join channels by name](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name).
6464 </Step>
6565</Steps>
6666 
6767Any member of the workspace can still invite `@Claude` to a channel that isn't approved. Claude stays silent there, and an @-mention gets a notice that Claude is disabled in that channel instead of a reply.
6868 
69Only an Owner of your Claude organization or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) can change an **Enable Claude Tag** switch, and only an Owner can change the **Allow direct messages** toggle. Give the **Claude Tag Admin** permission only to people you trust to approve a channel as PHI-free.
69Only an Owner of your Claude organization or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) can change the **Respond in all channels** switch or an **Enable Claude Tag** switch, and only an Owner can change the **Allow direct messages** toggle. Give the **Claude Tag Admin** permission only to people you trust to approve a channel as PHI-free.
7070 
7171## Connect only PHI-free tools
7272 
73In a channel, Claude signs in to tools outside Slack only through the connections an Owner adds, and each connection is attached to specific channels through an [access bundle](/docs/claude-tag/admins/attach-to-scope). For a healthcare organization, apply these rules when deciding what to connect:
73In a channel, Claude signs in to tools outside Slack only through Claude Tag connectors. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you add a connector.
7474 
75For a healthcare organization, apply these rules when deciding what to connect:
76 
7577* Connect only tools that never hold PHI, such as your code host, issue tracker, and internal documentation
7678* Leave electronic health record systems, clinical systems, and patient communication tools unconnected
7779* Treat email and calendar as PHI-bearing unless your compliance team has confirmed otherwise, and leave them unconnected until then
78* Attach each bundle to the approved channels that need it, not to **Default Slack** (the entry whose settings apply to every channel in every connected workspace), so a connection never reaches a channel it wasn't reviewed for
80* Add connectors inside bundles, and add each bundle to the approved channels that need it, not to the **Slack** page (whose settings apply to every channel in every connected workspace), so a connector never reaches a channel it wasn't reviewed for
7981 
8082Members' own claude.ai connectors, such as their email or calendar, are a separate path to tools outside Slack. In a one-to-one direct message from a member who has connected a Claude account, Claude works on that member's own Claude account and can use those connectors, so keep the **Allow direct messages** toggle off as described in [Limit Claude to PHI-free channels](#limit-claude-to-phi-free-channels). In channels, Claude can [use a member's own connectors for that member's requests](/docs/claude-tag/concepts/personal-connectors) after the member allows it, and no organization setting turns off personal connectors in channels entirely. These controls apply:
8183 
8284* **Block a connector for everyone.** A connector you restrict for your organization on the [**Connectors** admin page](https://claude.ai/admin-settings/connectors) stays restricted when Claude uses a member's connectors in a channel.
83* **Require human review.** On the Enterprise plan, turn on **Require human review of every message** in the **Personal connectors** section at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), so a member reviews every result before it posts to the channel.
85* **Require human review.** On the Enterprise plan, go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), select **Edit** on the **Personal connectors** row, and turn on **Require human review of every message**, so a member reviews every result before it posts to the channel.
8486* **Treat the rest as PHI-bearing.** Include members' remaining claude.ai connectors in the tools that must stay PHI-free.
8587 
8688## Train your workspace and monitor approved channels
from line 95
9395 
9496Claude keeps separate notes for each channel. From a public channel it can also save workspace notes, and those inform its replies in every channel in the workspace. Notes from a private channel stay in that channel's own store and aren't read anywhere else.
9597 
96Anyone in a channel can ask Claude what it remembers there and tell it to correct or delete a note. An Owner can view, edit, and delete the memory notes of a channel or of the workspace at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the channel's or workspace's entry → options menu → **View memory files**.
98Anyone in a channel can ask Claude what it remembers there and tell it to correct or delete a note. An Owner can view, edit, and delete the memory notes of the workspace or of a channel. Go to [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels), open the workspace's page (or a channel's page, when that channel has memory of its own), open its **⋯** menu, and select **View memory files**. The **Memory** tab of the [**Activity** page](/docs/claude-tag/admins/audit) opens the same files.
9799 
98100By default, your Slack conversations with Claude aren't used to train Anthropic's models. Anthropic's [model training policy](https://privacy.anthropic.com/en/articles/7996885-how-do-you-use-personal-data-in-model-training) describes when data is used. Claude Tag data is kept until one of the admin actions in [Data lifecycle and deletion](/docs/claude-tag/concepts/data-lifecycle) deletes it, and during the beta you can't set a shorter retention period.
99101 
from line 107
105107 
1061081. Report it to your organization's HIPAA privacy officer and follow your incident process.
1071092. Delete the message in Slack.
1083. If the message was posted in a channel where Claude is turned on, have an Owner delete that channel's transcripts and memory immediately by [removing the channel's entry](/docs/claude-tag/concepts/data-lifecycle#delete-data-or-request-deletion) under **Claude Tag's access** → **Slack**.
1094. If that channel is public, have an Owner also check the workspace's memory, because workspace notes Claude saved from that channel are stored with the workspace and aren't deleted with the channel's entry. Go to **Claude Tag's access** → **Slack** → your workspace's entry → options menu → **View memory files**, and delete any note that contains the information. Deleting a note removes it from what Claude reads in every channel right away.
1103. If the message was posted in a channel where Claude is turned on, have an Owner delete that channel's transcripts and memory immediately by [removing the channel's scope](/docs/claude-tag/concepts/data-lifecycle#delete-data-or-request-deletion). On the **Channels** tab under **Claude's access**, open the channel's page and choose **Remove this scope** from its **⋯** menu, if the menu lists it.
1114. If that channel is public, have an Owner also check the workspace's memory, because workspace notes Claude saved from that channel are stored with the workspace and aren't deleted with the channel's scope. On the **Channels** tab, open your workspace's page, choose **View memory files** from its **⋯** menu, and delete any note that contains the information. Deleting a note removes it from what Claude reads in every channel right away.
1101125. Email [[email protected]](mailto:[email protected]) to request deletion of the data Claude Tag retained that the admin controls in steps 3 and 4 don't delete, including the workspace's stored memory and any transcript in another channel whose session found the message through search. Include the workspace, the channel, and the time of the message.
111113 
112Removing a channel's entry also turns Claude off in that channel, because the channel then inherits the setting from **Default Slack**, where you turned Claude off. To turn Claude back on later, add the channel again under **Claude Tag's access** → **Slack** and turn on its **Enable Claude Tag in this channel** switch.
114Removing a channel's scope also turns Claude off in that channel, because the channel then inherits the off setting from the **Slack** page. To turn Claude back on later, [set the channel up again](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) on the **Channels** tab and turn on its **Enable Claude Tag in this channel** switch.
113115 
114116## Related resources
115117 

claude-tag/admins/managed-by Changed · +3 / -3 lines

from line 35
3535* **Sharing:** no channel in the pairing is shared outside its workspace. That rules out Slack Connect channels, including ones with a pending invitation, and channels shared across the workspaces of an Enterprise Grid.
3636* **You:** you are a member of every managing channel you add.
3737* **Managing channel:** its [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting resolves to **Allow**. The list accepts a managing channel set to **Block**, but Claude refuses every read and change there.
38* **Managed channel:** the channel has its own channel scope on the **Slack** tab in admin settings. If it doesn't appear there, [add the channel](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel).
38* **Managed channel:** the channel has its own page on the **Channels** tab under **Claude's access** in admin settings. If it isn't listed there, [set the channel up](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel).
3939 
4040A managed channel can have up to five managing channels. A private managed channel has extra rules, listed under [Public and private channels](#public-and-private-channels).
4141 
from line 196
196196| This channel isn't set as a manager of the other channel | No pairing exists, or it was removed | Add this channel under **Managed by** on the other channel's Configure page |
197197| A channel is shared with another organization | The managed or managing channel is a Slack Connect channel, has a pending invitation, or is shared across Enterprise Grid workspaces | Use channels that belong to one workspace only |
198198| You aren't in the managing channel, or in the private managed channel | You tried to add a managing channel you haven't joined, or to add managing channels to a private channel you aren't in | Join the channel in Slack, then try again |
199| This channel's settings are locked by an admin | The managing channel's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**, on the channel or inherited from its workspace or **Default Slack access** | Set **Channel member edits** to **Allow** on the managing channel's scope |
199| This channel's settings are locked by an admin | The managing channel's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**, on the channel or inherited from its workspace or the **Slack** page | Set **Channel member edits** to **Allow** on the managing channel's scope |
200200| You need your Claude account connected in this organization | You selected **Confirm** or **Cancel** without a Claude account in the organization connected to your Slack account | Connect your account from the Claude app's **Home** tab in Slack, then select the button again |
201201| Claude isn't in one of the channels | Claude was removed from the managed or managing channel, or never added | Run `/invite @Claude` in that channel |
202202| One of those channels is archived | One of the managing channels is archived in Slack | Remove the archived channel, then try again |
203203| A private channel can only be managed by private channels | The managed channel is private and the managing channel is public, or was made public later | Pick a private managing channel |
204204| The managed channel may have been made private or deleted | The managed channel was made private or deleted, or Claude is no longer in it | Check the channel in Slack. If it was made private, an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) who is a member of it adds private managing channels again |
205| Claude isn't set up in the managed channel with its own channel configuration | The managed channel has no channel scope of its own on the **Slack** tab | [Add the channel](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) in admin settings |
205| Claude isn't set up in the managed channel with its own channel configuration | The managed channel has no page of its own on the **Channels** tab | [Set the channel up](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) in admin settings |
206206| The managed channel already has five managing channels | Five is the most a managed channel can have | Remove one before adding another |
207207| The file would be too large | The core instructions are over 16 KiB, or a reference file is over 100 KiB | Shorten the text, or move detail into a reference file |
208208| The managed channel already has the most reference files | Twenty reference files exist | Ask Claude to delete one first |

claude-tag/admins/migrate-from-earlier Changed · +11 / -7 lines

from line 8
88 
99If your organization already used the earlier Claude in Slack, including [Claude Code in Slack](https://code.claude.com/docs/en/slack), Claude Tag replaces it. Your existing Slack app and `@Claude` handle stay, and no data migrates. What changes is who Claude acts as and who sets it up.
1010 
11<Note>On the Team plan, a single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) replaces the **Claude Tag version** controls described on this page, and there is nothing to migrate; the switch appears only while no scope routes to the earlier app.</Note>
11<Note>If your Team plan organization has the single [**Respond in channels** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan), it has no **Claude Tag version** controls and there is nothing to migrate.</Note>
1212 
1313## Switch your workspace to Claude Tag
1414 
from line 18
1818 </Step>
1919 
2020 <Step title="Check for channels still on Legacy">
21 Under **Claude Tag's access** → **Slack**, open each scope's **Advanced** section. Pairing defaults every scope's **Claude Tag version** to **New**, so this is usually quick. Set any showing **Legacy** to **New**.
21 Pairing defaults every workspace and channel to **New**, so this is usually quick.
22 
23 1. Go to [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels). A workspace or channel set to Legacy shows **legacy Claude in Slack** in the **Changes from defaults** column.
24 2. Open each one, and on its **Advanced** tab set **Claude Tag version** to **New**.
25 3. The **Slack** row never shows that marker, so also go to [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack) and set **Claude Tag version** on its **Advanced** tab to **New** if it shows **Legacy**.
2226 </Step>
2327 
2428 <Step title="Give Claude its connections">
2529 The New version starts with no access of its own. GitHub repositories and other connections do not carry over from individual users' linked accounts, so code requests in a switched channel have nothing to clone until you configure them. Follow the [setup overview](/docs/claude-tag/admins/setup-overview) to add connections, and [GitHub access](/docs/claude-tag/admins/configure-github) for code work specifically.
2630 
27 If your teams keep custom skills in a repository's `.claude/skills/` folder, those skills apply only in threads that have the repository. Grant the repository in an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle) and have users name it in the first message. To give skills to every channel under a scope, add them through a [skills repository](/docs/claude-tag/admins/skills-repo).
31 If your teams keep custom skills in a repository's `.claude/skills/` folder, those skills apply only in threads that have the repository. Add the repository to a [bundle](/docs/claude-tag/concepts/glossary#access-bundle) that applies to the channel, and have users name it in the first message. To give skills to every channel in a workspace or in all of Slack, add them through a [skills repository](/docs/claude-tag/admins/skills-repo).
2832 </Step>
2933 
3034 <Step title="Tell your users">
from line 36
3236 </Step>
3337</Steps>
3438 
35**You'll see:** the workspace appears under **Where Claude Tag works**, and the **Claude Tag version** on each scope shows **New**.
39**You'll see:** the workspace under **Connected workspaces** on the **Slack** page, **New** as the **Slack** page's **Claude Tag version**, and no row on the **Channels** tab showing **legacy Claude in Slack**.
3640 
3741### If `@Claude` doesn't respond at all
3842 
3943On Enterprise Grid, an earlier install can lose its connection and stop responding in every workspace. See [Claude is silent everywhere on Enterprise Grid](/docs/claude-tag/admins/troubleshooting#claude-is-silent-everywhere-on-enterprise-grid) for the reinstall that refreshes it without uninstalling, then send `@Claude connect` again in a channel of that workspace and [pair the workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace) with the new code.
4044 
41<Warning>The earlier Claude in Slack app, shown as **Legacy** in admin settings, is being deprecated; check with your account team for the cutover date. After that date, channels still set to Legacy stop responding until the scope's Claude Tag version is set to New.</Warning>
45<Warning>The earlier Claude in Slack app, shown as **Legacy** in admin settings, is being deprecated; check with your account team for the cutover date. After that date, channels still set to Legacy stop responding until their **Claude Tag version** is set to **New**.</Warning>
4246 
4347## What stays the same
4448 
from line 62
5862| Standing work | None | Routines and channel watching |
5963| Who sets it up | Each user, individually | An Owner, once |
6064 
61The **Claude Tag version** setting on each scope chooses whether the New or Legacy version answers there, and the scope's **Enable Claude Tag** switch turns both off. Access bundles only apply where the New version answers. See [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) for both controls and where to set them.
65The **Claude Tag version** setting on each workspace's and channel's page chooses whether the New or Legacy version answers there, and the page's enable switch turns both off. Bundles only apply where the New version answers. See [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) for both controls and where to set them.
6266 
6367## Two versions of the same Slack app
6468 
65The earlier Claude in Slack and Claude Tag are two versions of the same `@Claude` Slack app, not two apps, so there is nothing to uninstall. You choose which version answers per scope with the **Claude Tag version** setting (**New**, **Legacy**, or **Inherit**), so one workspace can run both during a phased switch. Turning a scope's **Enable Claude Tag** switch off silences both versions there; to keep the earlier behavior in a scope, set its **Claude Tag version** to **Legacy**.
69The earlier Claude in Slack and Claude Tag are two versions of the same `@Claude` Slack app, not two apps, so there is nothing to uninstall. You choose which version answers in each workspace and channel with the **Claude Tag version** setting (**New**, **Legacy**, or **Inherit**), so one workspace can run both during a phased switch. Turning off a workspace's or channel's enable switch silences both versions there. To keep the earlier behavior in a workspace or channel, set its **Claude Tag version** to **Legacy**.
6670 
6771To tell which version answered in a channel, look at who authored the work. The New version authors code as the Claude GitHub App and keeps work in the channel's thread; if `@Claude` still opens pull requests under the asker's name, that channel is answering with the Legacy version.
6872 

claude-tag/admins/restrict-access Changed · +68 / -61 lines

from line 8
88 
99In channels, Claude Tag responds only where it's been added and addressed, and the controls on this page narrow that further. One-to-one DMs are a separate surface. A DM from a member who has connected a Claude account runs on that member's own account; see [how DMs differ from channels](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A [DM from a member who hasn't](#direct-messages-from-members-without-a-claude-account) can bill to your organization. In a [group DM](#group-dms), the work bills to your organization.
1010 
11<Note>Most controls on this page require the Owner role in your Claude organization; the [permissions table](#permissions-by-role) below lists which actions a channel manager or a channel member can take. On the Enterprise plan, an Owner can delegate many of these controls through the [**Claude Tag Admin** permission](#delegate-claude-tag-administration).</Note>
11<Note>Most controls on this page require the Owner role in your Claude organization; the [permissions table](#permissions-by-role) lists which actions a channel manager or a channel member can take. On the Enterprise plan, an Owner can delegate many of these controls through the [**Claude Tag Admin** permission](#delegate-claude-tag-administration).</Note>
1212 
1313## Control who can invoke Claude Tag
1414 
from line 18
1818 
1919### Restrict who can use Claude
2020 
21At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), under **Where Claude Tag works**, click **Manage** next to **Member access**. The **Claude Tag in Slack** dialog lists your connected workspaces and shows a toggle that controls who in your Slack workspace can use Claude at all; its label depends on your plan. You must be an Owner of your Claude organization to change it.
21Go to [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack) and open the **Advanced** tab. Under **Access**, a toggle controls who in your Slack workspace can use Claude at all; its label depends on your plan. You must be an Owner of your Claude organization to change it.
2222 
2323| Plan | Toggle | Off (default) | On |
2424| :- | :- | :- | :- |
from line 28
2828The toggle applies to channels and DMs alike. While the toggle is off, a [DM from a member who hasn't connected a Claude account](#direct-messages-from-members-without-a-claude-account) can bill to your organization.
2929 
3030<Info>
31 You may see the earlier three-option **Members** dropdown instead of the toggle. The dialog keeps the dropdown while your organization's stored choice matches neither toggle state. That happens for an Enterprise organization that previously chose **Open to any organization member** (now marked deprecated), and for a Team organization still restricted by role from an earlier Enterprise plan. Switch to one of the toggle's two states. The dropdown is then replaced by the toggle, and the deprecated option is no longer offered.
31 You may see the earlier three-option **Members** dropdown instead of the toggle. The **Access** group keeps the dropdown while your organization's stored choice matches neither toggle state. That happens for an Enterprise organization that previously chose **Open to any organization member** (now marked deprecated), and for a Team organization still restricted by role from an earlier Enterprise plan. Switch to one of the toggle's two states. The dropdown is then replaced by the toggle, and the deprecated option is no longer offered.
3232</Info>
3333 
3434#### Restrict by role on Enterprise
from line 37
3737 
3838Restricting by role spans three console pages.
3939 
401. On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), turn on **Restrict to roles with Claude Tag access**.
401. On the [**Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack) page's **Advanced** tab, turn on **Restrict to roles with Claude Tag access** under **Access**.
41412. On [`claude.ai/admin-settings/groups`](https://claude.ai/admin-settings/groups), create groups and add the relevant members.
42423. On [`claude.ai/admin-settings/roles`](https://claude.ai/admin-settings/roles), create a custom role with the **Claude Tag in Slack** capability turned on or off, and choose which groups hold the role in the role editor.
4343 
from line 57
5757 
5858### Restrict who can link a Claude account by email domain
5959 
60On Enterprise plans, if your organization belongs to a parent enterprise organization, you see one more toggle in the same **Manage** dialog, **Restrict to your verified domains**. It needs an Owner to change and is disabled while Claude Tag is off for the organization. The check uses the enterprise's verified domains, which every organization under the enterprise shares.
60On Enterprise plans, if your organization belongs to a parent enterprise organization, you see one more toggle in the same **Access** group on the **Slack** page's **Advanced** tab, **Restrict to your verified domains**. It needs an Owner to change. The check uses the enterprise's verified domains, which every organization under the enterprise shares.
6161 
6262When the toggle is on, a Slack user whose profile email isn't on one of the enterprise's verified domains can't link a Claude account to this organization; the sign-in is refused.
6363 
from line 65
6565 
6666## Control where Claude Tag operates
6767 
68The restriction toggle decides who can use Claude. The controls in this section decide where it works at all, from one channel up to a workspace, and which generation answers in each scope (a scope is a channel, a workspace, or your whole organization). On the Team plan, a single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) replaces the per-scope version controls. The other controls in this section work the same way on both plans.
68The restriction toggle decides who can use Claude. The controls in this section decide where it works at all, from one channel up to a workspace, and which generation answers in each scope (a scope is a channel, a workspace, or your whole organization). Each scope has its own page under [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels), and the **Slack** page there holds the settings for your whole organization.
6969 
70If the **Slack** page's **General** tab shows a **Respond in channels** switch rather than **Respond in all channels**, your organization has a [single on-or-off switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) in place of the per-scope switches and version settings. The other controls in this section work the same way either way.
71 
7072### Quiet or remove Claude Tag
7173 
7274Six ways to stop Claude Tag from responding, ordered from quietest to most complete:
from line 75
7375 
74761. **Ask it to stay quiet.** Saying "stay quiet in this thread unless tagged" stops Claude following an active thread.
75772. **Remove it from the channel.** Run `/remove @Claude`. It can no longer read or post there.
763. **Turn the scope's Enable Claude Tag switch off.** Claude stops responding in that scope even if someone invites it back; an @-mention gets a disabled notice instead of a reply. Only an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) can change it. The switch sits at the top of the scope's panel at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope. If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead, turn it off at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag**. Claude then stops responding in every connected workspace, not in one scope.
774. **Remove the channel's scope.** Choose **Remove this scope** from the scope's options menu. Claude keeps answering in the channel with the access it inherits from its workspace, and deletes the channel's sessions, memory, routines, and published artifacts; see [what each action deletes](/docs/claude-tag/concepts/data-lifecycle#actions-in-claude). To stop it answering as well, run `/remove @Claude` or turn the scope's **Enable Claude Tag in this channel** switch off first.
785. **Delete the bundle.** This revokes its credentials everywhere it was attached (the credentials are removed; memory, routines, and transcripts are not). Running sessions may keep a revoked credential for a short window before the change propagates.
783. **Turn off the scope's switch.**
79 * **Stop Claude in one workspace or channel:** open the workspace's or channel's page on the **Channels** tab and turn off the **Enable Claude Tag in this workspace** or **Enable Claude Tag in this channel** switch at the top of its **General** tab. Claude stops responding in that scope even if someone invites it back; an @-mention gets a disabled notice instead of a reply. Only an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) can change it.
80 * **Stop Claude in every channel:** turn off the **Respond in all channels** switch at the top of the **Slack** page's **General** tab. Claude stops responding in every channel except in workspaces and channels whose own switch is on. If the **Slack** page shows **Respond in channels** instead, turning it off stops Claude in every channel of every connected workspace.
814. **Remove the channel's scope.** If the **⋯** menu on the channel's page lists **Remove this scope**, choose it. Claude deletes the channel's sessions, memory, routines, and published artifacts; see [what each action deletes](/docs/claude-tag/concepts/data-lifecycle#actions-in-claude). Where the channel's workspace has its own setting on, or has no setting of its own and the **Slack** page's setting is on, Claude keeps answering in the channel with the access it inherits from its workspace. To stop it answering in that case, run `/remove @Claude` first.
825. **Delete the bundle.** On the bundle's page, choose **Delete bundle** from its menu. This revokes its credentials everywhere it applied (the credentials are removed; memory, routines, and transcripts are not). Running sessions may keep a revoked credential for a short window before the change propagates. An Owner or a [Claude Tag admin](#delegate-claude-tag-administration) can delete a bundle, except that only an Owner can delete one a [channel rule](/docs/claude-tag/admins/attach-to-scope#attach-a-bundle-to-channels-by-name) names.
79836. **Uninstall the app.** This removes Claude from the workspace and deletes the workspace's Claude data the same way [disconnecting the workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing) does.
8084 
8185To keep Claude out of channels by name ahead of time, add a [blocked channel pattern](#block-or-auto-join-channels-by-name) instead.
from line 88
8488 
8589Steps 4 through 6, and disconnecting the workspace, each delete something different:
8690 
87* **Remove the channel's scope (step 4):** deletes the channel's sessions, memory, routines, and published artifacts. Claude keeps answering in the channel with the access it inherits from its workspace; see [what each action deletes](/docs/claude-tag/concepts/data-lifecycle#actions-in-claude).
91* **Remove the channel's scope (step 4):** deletes the channel's sessions, memory, routines, and published artifacts; see [what each action deletes](/docs/claude-tag/concepts/data-lifecycle#actions-in-claude).
8892* **Delete the bundle (step 5):** removes the credentials in that bundle. Memory, routines, and session transcripts stay.
8993* **Uninstall the app (step 6):** Anthropic deletes the workspace's Claude data, the same set as disconnecting the workspace, plus the app's installation credential; see [what each action deletes](/docs/claude-tag/concepts/data-lifecycle#actions-in-slack).
9094* **[Disconnect the workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing)** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag): Anthropic deletes the workspace's sessions and transcripts, memory, routines and artifacts, scopes, and members' account links, and the app stays installed so a workspace admin can pair again; see [what each action deletes](/docs/claude-tag/concepts/data-lifecycle#actions-in-claude).
9195 
92Access bundles belong to your organization, not to a workspace, so uninstalling or disconnecting keeps them; only their bindings to that workspace's scopes go. To delete one channel's data while Claude stays in the workspace, remove that channel's scope (step 4) rather than uninstalling.
96Bundles belong to your organization, not to a workspace, so uninstalling or disconnecting keeps them; only the places they apply in that workspace go. To delete one channel's data while Claude stays in the workspace, remove that channel's scope (step 4) rather than uninstalling.
9397 
9498### Limit Claude Tag to specific channels
9599 
96To let Claude respond only in channels you choose, for example during a pilot confined to one channel, turn Claude off everywhere with the [**Enable Claude Tag in Slack** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) on **Default Slack access**, then turn each chosen channel's **Enable Claude Tag in this channel** switch on. Both changes happen in the **Claude Tag's access** section at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). One-to-one DMs, guest channels, and shared channels need more than the **Enable Claude Tag** switches; each gets its own treatment after the steps.
100To let Claude respond only in channels you choose, for example during a pilot confined to one channel, turn off **Respond in all channels** on the **Slack** page, then turn on each chosen channel's **Enable Claude Tag in this channel** switch. Both pages are on the **Channels** tab under [**Claude's access**](https://claude.ai/admin-settings/claude-tag?access=channels). One-to-one DMs, guest channels, and shared channels need more than these switches; each gets its own treatment after the steps.
97101 
98These steps need the per-scope switches. If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead, you can't limit Claude this way. Use [blocked channel patterns](#block-or-auto-join-channels-by-name) to keep it out of specific channels.
102These steps need the per-scope switches. If the **Slack** page shows [**Respond in channels**](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead, you can't limit Claude this way. Use [blocked channel patterns](#block-or-auto-join-channels-by-name) to keep it out of specific channels.
99103 
100104<Note>Turning Claude off in a scope silences the earlier Claude in Slack there too. If you're in the middle of migrating from the earlier app, decide which scopes stay on **Legacy** before you start; the earlier app keeps answering in those channels.</Note>
101105 
102106<Steps>
103 <Step title="Turn Claude Tag off everywhere">
104 At the top of the [**Default Slack access**](/docs/claude-tag/admins/attach-to-scope) panel, turn off the **Enable Claude Tag in Slack** switch.
107 <Step title="Turn Claude Tag off in every channel">
108 Go to [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack) and turn off the **Respond in all channels** switch at the top of the **General** tab.
105109 </Step>
106110 
107111 <Step title="Reset the scopes that override it">
108 Open each workspace or channel scope that has its own setting, except the ones you're keeping on **Legacy**, and click **Use inherited setting** under its **Enable Claude Tag** switch. The scope then follows the off state on **Default Slack access**.
112 Open each workspace's or channel's page that has its own setting, except the ones you're keeping on **Legacy**. Its switch shows **Set for this workspace** or **Set for this channel** underneath. Click the **Use inherited setting** link beside that line. The scope then follows the off state on the **Slack** page.
109113 </Step>
110114 
111115 <Step title="Switch each chosen channel back on">
112 Find the channel with **Search channels**; channels Claude was added to are already listed. If it isn't listed, create a scope for it with **Add channel** as described in [Attach to a channel](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel). Turn on the **Enable Claude Tag in this channel** switch at the top of the channel's scope panel.
116 On the **Channels** tab, find the channel with the search field; channels Claude was added to are already listed. If it isn't listed, set it up as described in [Attach to a channel](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel). Open the channel's page and turn on the **Enable Claude Tag in this channel** switch at the top of its **General** tab.
113117 
114118 A channel's own setting wins over the off setting above it, so Claude responds in the chosen channels and nowhere else.
115119 </Step>
from line 124
120124One-to-one DMs, guest channels, and shared channels sit outside the per-scope switches:
121125 
122126* **One-to-one DMs.** The per-scope switches don't cover one-to-one DMs from members who have connected a Claude account. To close those off too, turn off the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle. For members who haven't connected an account, see [Stop direct messages from members without a Claude account](#stop-direct-messages-from-members-without-a-claude-account).
123* **Guest channels.** By default Claude is off in any channel that includes a Slack guest. If a chosen channel has guests, also set [**How should Claude work in channels with guests**](#restrict-guest-channels) to **Full access** or **Channel only** on its scope.
124* **Shared channels.** A [channel shared across workspaces in your Enterprise Grid](#channels-shared-across-workspaces-in-your-enterprise-grid) takes its settings from **Default Slack access** only and can't serve as a chosen channel. Claude doesn't work in a [Slack Connect channel](#slack-connect-channels), one shared with another company.
127* **Guest channels.** By default Claude is off in any channel that includes a Slack guest. If a chosen channel has guests, also set [**How should Claude work in channels with guests**](#restrict-guest-channels) to **Full access** or **Channel only** on its page's **Advanced** tab.
128* **Shared channels.** A [channel shared across workspaces in your Enterprise Grid](#channels-shared-across-workspaces-in-your-enterprise-grid) takes its settings from the **Slack** page only and can't serve as a chosen channel. Claude doesn't work in a [Slack Connect channel](#slack-connect-channels), one shared with another company.
125129 
126130The **Enable Claude Tag** switch covers [group DMs](#group-dms), and a group DM can't serve as a chosen channel. While the switch that covers a workspace is off, Claude doesn't answer in that workspace's group DMs.
127131 
from line 133
129133 
130134### Block or auto-join channels by name
131135 
132**Channel name rules** steer where Claude works by channel name instead of channel by channel. The rules sit in the **Advanced** section of the **Default Slack access** panel and of each workspace scope's panel at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), as a **Blocked channel patterns** list and an **Auto-join channels** table:
136**Channel name rules** steer where Claude works by channel name instead of channel by channel. The rules sit on the **Advanced** tab of the **Slack** page and of each workspace's page under [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels), in the **Channels** group, as a **Blocked channel patterns** list and an **Auto-join channels** table:
133137 
134138* **Blocked channel patterns**: Claude won't read or respond in a channel whose name matches, even if someone invites it there. When it's added to such a channel or @-mentioned in one, it posts a notice that an admin has blocked it there, and otherwise stays silent.
135139* **Auto-join channels**: Claude joins a public channel whose name matches one of its patterns when the channel is created or renamed. Private channels still need an invite. To add Claude to an existing channel, invite it as usual.
136140 
137Each row of the **Auto-join channels** table is one pattern, added with **Add pattern**. A row can also carry [access bundles](/docs/claude-tag/admins/attach-to-scope#attach-a-bundle-to-channels-by-name), which attach in every matching channel Claude is in; a row with no bundles is marked **Auto-join only**, and Claude joins matching channels whether or not a row carries bundles. Editing the patterns or the bundles on a row needs an Owner of your Claude organization.
141Each row of the **Auto-join channels** table is one pattern, added with **Add pattern**. A row can also carry [bundles](/docs/claude-tag/admins/attach-to-scope#attach-a-bundle-to-channels-by-name), which attach in every matching channel Claude is in; a row with no bundles is marked **Auto-join only**, and Claude joins matching channels whether or not a row carries bundles. A channel rule added with **Add a channel rule…** on the **Channels** tab shows up as a row here too. Editing the patterns or the bundles on a row needs an Owner of your Claude organization.
138142 
139143Removing a pattern row also detaches the row's bundles. A row marked **Not auto-joined** shows a pattern that still has bundles attached but that the auto-join list no longer carries. Claude joins no new channels for it, but its bundles still attach in matching channels Claude is already in; remove the bundles from the row to end that.
140144 
141145A pattern is written in lowercase, like Slack channel names, plus two wildcards: `*` matches any run of characters and `?` matches exactly one. `inc-*` matches every channel whose name starts with `inc-`, and `*-confidential-*` matches any name containing `-confidential-`. The blocked list and the auto-join table each hold up to 50 patterns of up to 80 characters.
142146 
143A channel that matches a blocked pattern stays off-limits even when it also matches an auto-join pattern. Patterns on **Default Slack access** apply in every connected workspace. A workspace scope can add its own patterns but can't remove the organization's.
147A channel that matches a blocked pattern stays off-limits even when it also matches an auto-join pattern. Patterns on the **Slack** page apply in every connected workspace. A workspace scope can add its own patterns but can't remove the organization's.
144148 
145149About once a week, Claude sends the person who connected the workspace a direct message suggesting public channels to add it to. To stop those messages, select **Stop these suggestions** in any of them.
146150 
147151### Restrict guest channels
148152 
149By default, Claude is disabled in any channel that includes a Slack guest. You can change this default per scope with the **How should Claude work in channels with guests** setting, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope → the collapsed **Advanced** section. The setting has three values:
153By default, Claude is disabled in any channel that includes a Slack guest. You can change this default per scope with the **How should Claude work in channels with guests** setting. It's in the **Access** group on the **Advanced** tab of the **Slack** page and of each workspace's and channel's page under [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels). The setting has three values:
150154 
151155| Value | What Claude does in a channel that includes a guest |
152156| - | - |
153157| **Restrict** (default) | Doesn't reply. When someone mentions it, Claude posts a short notice that it doesn't respond in channels that include guests, with a link to this setting. |
154158| **Channel only** | Replies, but while a guest is present it runs with [channel-only access](#how-channel-only-works). The channel's own instructions still apply. |
155| **Full access** | Replies with the full access the scope gives it. Bundles, connections, and instructions from the workspace and from **Default Slack access** apply, along with repositories, memory, and skills. |
159| **Full access** | Replies with the full access the scope gives it. Bundles, connectors, and instructions from the workspace and from the **Slack** page apply, along with repositories, memory, and skills. |
156160 
157A channel without its own value shows **Inherit** and takes the value from its workspace, or from **Default Slack access**. Only an organization Owner can choose **Full access** or set a scope back to **Inherit**. The setting applies to every guest channel the scope covers. To open one channel rather than a whole workspace, set it on the channel's own scope.
161A channel without its own value shows **Inherit** and takes the value from its workspace, or from the **Slack** page. An Owner or a [Claude Tag admin](#delegate-claude-tag-administration) can choose **Restrict** or **Channel only**. Only an organization Owner can choose **Full access** or set a scope back to **Inherit**. The setting applies to every guest channel the scope covers. To open one channel rather than a whole workspace, set it on the channel's own page.
158162 
159163Under every value, guests in the channel can read what Claude posts there.
160164 
from line 170
166170 
167171Use **Channel only** to keep Claude available in a channel shared with contractors, clients, or agency partners without exposing the rest of the organization's setup to that conversation. While a guest is in the channel, Claude has:
168172 
169* No [access bundles](/docs/claude-tag/admins/attach-to-scope) inherited from the workspace or the organization. A bundle attached directly to the channel still applies.
173* No [bundles](/docs/claude-tag/admins/attach-to-scope) inherited from the workspace or the organization. A bundle attached directly to the channel still applies.
170174* No connections inherited from the workspace or the organization. A connection set directly on the channel still applies.
171175* No repositories from the workspace or the organization.
172176* No instructions set on the workspace or the organization. Instructions set on the channel itself still apply.
from line 193
189193 
190194### Limit which channels Claude can search
191195 
192By default, workspace search covers public channels across the workspace, including ones Claude hasn't been added to. The **Channels Claude can search** setting narrows workspace search to channels Claude is in. You set it per scope at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope → **Advanced**. Changing it needs an Owner of your Claude organization.
196By default, workspace search covers public channels across the workspace, including ones Claude hasn't been added to. The **Channels Claude can search** setting narrows workspace search to channels Claude is in. You set it per scope in the **Channels** group on the **Advanced** tab of the **Slack** page or of a workspace's or channel's page under [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels). Changing it needs an Owner of your Claude organization.
193197 
194198The setting has two values:
195199 
from line 204
200204 
201205Most organizations can leave this on **All public channels**. Under **Only channels Claude is in**, Claude can't find messages in your other public channels, so its answers can miss context your team expects it to have.
202206 
203On a workspace or channel scope the setting also offers **Inherit**, which takes the value from the workspace or from **Default Slack access**. The most specific scope that sets a value decides, in this order:
207On a workspace's or channel's page the setting also offers **Inherit**, which takes the value from the workspace or from the **Slack** page. The most specific scope that sets a value decides, in this order:
204208 
2052091. The channel's own value
2062102. The workspace's value
2073. The value on **Default Slack access**, which is **All public channels** until you change it
2113. The value on the **Slack** page, which is **All public channels** until you change it
208212 
209213A value on a channel or workspace replaces the value it would inherit, in either direction. In a channel set to **All public channels**, workspace search covers public channels across the workspace even when the channel's workspace is set to **Only channels Claude is in**.
210214 
from line 220
216220 
217221A Slack Connect channel is a channel your Slack workspace shares with another company. Claude doesn't work in Slack Connect channels, and no setting at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) turns it on there. When someone mentions `@Claude` in one, Claude posts a notice that it isn't turned on for Slack Connect channels and doesn't answer.
218222 
219If a channel Claude already works in becomes a Slack Connect channel, Claude stops answering there, including in threads it was already part of. You also can't add a Slack Connect channel as a scope. The **Add channel** drawer reports that Claude can't be added to it yet.
223If a channel Claude already works in becomes a Slack Connect channel, Claude stops answering there, including in threads it was already part of.
220224 
221225### Channels shared across workspaces in your Enterprise Grid
222226 
223227What happens in a channel shared across more than one workspace inside your Enterprise Grid depends on whether every workspace in it is connected to the same Claude organization.
224228 
225When the workspaces all belong to your one Claude organization, Claude replies in the channel, but only with the access and settings on your organization's [Default Slack access](/docs/claude-tag/admins/attach-to-scope) scope. Bundles, instructions, and memory set on a workspace or on that channel don't reach it. Claude posts a notice in the thread explaining these limits, but not on every reply. Where guest access is at its default **Restrict**, the [guest check](#restrict-guest-channels) still runs first and can refuse the reply.
229When the workspaces all belong to your one Claude organization, Claude replies in the channel, but only with the access and settings on your organization's [**Slack**](/docs/claude-tag/admins/attach-to-scope) page. Bundles, instructions, and memory set on a workspace or on that channel don't reach it. Claude posts a notice in the thread explaining these limits, but not on every reply. Where guest access is at its default **Restrict**, the [guest check](#restrict-guest-channels) still runs first and can refuse the reply.
226230 
227231When the workspaces belong to different Claude organizations, each with its own settings and plan, Claude won't reply and posts a refusal message instead.
228232 
from line 234
230234 
231235### Migrate from the earlier Claude in Slack
232236 
233If your organization used the earlier Claude in Slack app, the **Claude Tag version** setting on each scope chooses which generation answers `@Claude` there. Access bundles only apply where the New version answers. See [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) for the values and [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/migrate-from-earlier) for the switch.
237If your organization used the earlier Claude in Slack app, the **Claude Tag version** setting on the **Advanced** tab of each scope's page chooses which generation answers `@Claude` there. Bundles only apply where the New version answers. See [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) for the values and [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/migrate-from-earlier) for the switch.
234238 
235239### Allow or disable direct messages
236240 
237241The **Allow direct messages** toggle controls whether members can message Claude in a one-to-one DM or in a [group DM](#group-dms). When it's off, Claude is reachable only in channels, and no [DM from a member without a Claude account](#direct-messages-from-members-without-a-claude-account) bills to your organization. The default is on, and you must be an Owner of your Claude organization to change it.
238242 
239On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), the toggle appears in one of two places: directly on the Claude Tag settings page, or in the **Manage** dialog on the Slack entry under **Where Claude Tag works**. It's the same setting in both places, so change it wherever it appears for your organization.
243To change it, go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), select **Edit** on the **Direct messages** row, and turn **Allow direct messages** on or off in the dialog. The change saves as soon as you flip the toggle. **Edit** is unavailable while **Enable Claude Tag in Slack**, the switch on the same page, is off. Turning off **Respond in all channels** (or **Respond in channels**) on the **Slack** page doesn't affect direct messages from members who have connected a Claude account. For members who haven't, see [Stop direct messages from members without a Claude account](#stop-direct-messages-from-members-without-a-claude-account).
240244 
241245### Group DMs
242246 
243247A group DM is a Slack direct message among several people. When members add Claude to one, Claude acts with its own [service accounts](/docs/claude-tag/concepts/agent-identity), and the work bills to your organization's [usage balance](/docs/claude-tag/admins/set-spend-limit). [Use Claude Tag in a group DM](/docs/claude-tag/users/group-dms) covers what members can do there.
244248 
245A group DM has no [scope](/docs/claude-tag/concepts/glossary#scope) of its own, so you can't attach an [Access bundle](/docs/claude-tag/admins/attach-to-scope) to one group DM or turn Claude off in one. You control every group DM in a workspace together:
249A group DM has no [scope](/docs/claude-tag/concepts/glossary#scope) of its own, so you can't attach a [bundle](/docs/claude-tag/admins/attach-to-scope) to one group DM or turn Claude off in one. You control every group DM in a workspace together:
246250 
247* **Access.** Claude works with the Access bundles, instructions, and repositories on the workspace's scope and on **Default Slack access**.
251* **Access.** Claude works with the bundles, instructions, and repositories on the workspace's page and on the **Slack** page.
248252* **Stop Claude from answering in group DMs.** Use either control. No setting covers group DMs alone.
249253 * Turn off the [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) that covers the workspace. Claude also stops answering in the channels that follow that switch.
250254 * Turn off the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle. Claude also stops answering one-to-one DMs.
from line 258
254258 
255259Who is in a group DM, and how Slack shares it, can change whether Claude answers:
256260 
257* **A Slack guest is in the group DM.** In a workspace outside Enterprise Grid, Claude follows the [**How should Claude work in channels with guests**](#restrict-guest-channels) value on the workspace's scope or on **Default Slack access**. Under the default, **Restrict**, Claude posts its guest notice instead of an answer. Under **Channel only**, Claude runs with [channel-only access](#how-channel-only-works). Under **Full access**, Claude answers.
261* **A Slack guest is in the group DM.** In a workspace outside Enterprise Grid, Claude follows the [**How should Claude work in channels with guests**](#restrict-guest-channels) value on the workspace's page or on the **Slack** page. Under the default, **Restrict**, Claude posts its guest notice instead of an answer. Under **Channel only**, Claude runs with [channel-only access](#how-channel-only-works). Under **Full access**, Claude answers.
258262* **Someone from another company is in the group DM, through Slack Connect.** Claude doesn't answer, and no setting changes that.
259263* **On Enterprise Grid, the people in the group DM share no workspace.** Claude doesn't answer.
260264 
from line 269
265269A member's DMs bill to your organization when every one of these is true:
266270 
267271* **The workspace is connected to your organization.** The DMs bill the Claude organization the Slack workspace is paired to.
268* **Member access is open.** The [restriction toggle](#restrict-who-can-use-claude) is off, which is its default.
272* **Anyone in the workspace can use Claude.** The [restriction toggle](#restrict-who-can-use-claude) is off, which is its default.
269273* **Direct messages are allowed.** The [**Allow direct messages**](#allow-or-disable-direct-messages) toggle is on, which is its default.
270* **Claude is on for the workspace.** The workspace's [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) is on, or the one at **Default Slack access** is on when the workspace follows it. If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead, that switch is on.
274* **Claude is on for the workspace.** The workspace's [**Enable Claude Tag in this workspace** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) is on, or **Respond in all channels** on the **Slack** page is on when the workspace follows it. If the **Slack** page has the single [**Respond in channels** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead, that switch is on.
271275* **The member is a full member of the Slack workspace.** A Slack guest's DMs don't bill to your organization.
272276 
273277#### Limits on direct messages from members without a Claude account
from line 292
288292 
289293A DM session for a member without a Claude account runs as Claude's own identity, the way a [channel session](/docs/claude-tag/concepts/agent-identity#channel-sessions) does. Two facts decide what it can reach:
290294 
291* **Access bundles.** The session reaches the same [access bundles](/docs/claude-tag/admins/attach-to-scope) as a channel the member creates in that workspace.
295* **Bundles.** The session reaches the same [bundles](/docs/claude-tag/admins/attach-to-scope) as a channel the member creates in that workspace.
292296* **Personal connectors.** The member has no Claude account, so the session has no [personal connectors](/docs/claude-tag/concepts/personal-connectors).
293297 
294298#### Daily brief offer for members without a Claude account
from line 305
301305 
302306#### Stop direct messages from members without a Claude account
303307 
304Three controls stop Claude from answering these DMs on your organization's bill. Each one needs the Owner role, applies to members who have already started, and changes something beyond these DMs.
308Three controls stop Claude from answering these DMs on your organization's bill. Each one applies to members who have already started and changes something beyond these DMs.
305309 
306310| Control | Where | What else changes |
307311| :- | :- | :- |
308| Turn on the restriction toggle | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Where Claude Tag works** > **Member access** > **Manage** | Members without a Claude account in your organization can't use Claude in channels either. See [Restrict who can use Claude](#restrict-who-can-use-claude) |
309| Turn off the **Allow direct messages** toggle | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the page or in the **Manage** dialog on the Slack entry under **Where Claude Tag works** | Members who have connected a Claude account can't DM Claude either |
310| Turn off the **Enable Claude Tag** switch for the workspace or at **Default Slack access** | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Claude Tag's access** > **Slack** > the scope | Claude stops responding in every channel that follows that scope's switch. One-to-one DMs from members who have connected a Claude account keep working |
312| Turn on the restriction toggle | [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack), under **Access** on the **Advanced** tab | Members without a Claude account in your organization can't use Claude in channels either. See [Restrict who can use Claude](#restrict-who-can-use-claude) |
313| Turn off the **Allow direct messages** toggle | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), in the dialog that **Edit** on the **Direct messages** row opens | Members who have connected a Claude account can't DM Claude either |
314| Turn off the workspace's **Enable Claude Tag in this workspace** switch, or, for a workspace that follows the **Slack** page, its **Respond in all channels** (or **Respond in channels**) switch | The top of the page's **General** tab. Open the workspace's page or the **Slack** page from the **Channels** tab under [**Claude's access**](https://claude.ai/admin-settings/claude-tag?access=channels) | Claude stops responding in every channel that follows that switch. One-to-one DMs from members who have connected a Claude account keep working |
311315 
312316To confirm the change, have a member who hasn't connected a Claude account send Claude a DM. With **Allow direct messages** off, Claude answers "Your Claude admin has disabled sending direct messages to Claude." With either of the other two controls, Claude answers with a prompt to connect a Claude account. In both cases nothing bills to your organization.
313317 
from line 342
338342 
339343A member whose custom role includes the permission is a Claude Tag admin. A Claude Tag admin can:
340344 
341* Create and edit [Access bundles](/docs/claude-tag/admins/add-connections), including their credentials, domain entries, and repository grants, and attach bundles to the organization, a workspace, or a channel
345* Create and edit [bundles](/docs/claude-tag/admins/add-connections), including their credentials, domain entries, and repository grants, and attach bundles to the organization, a workspace, or a channel
342346* Edit workspace and channel settings at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), such as custom instructions and the default model
343* Turn the **Enable Claude Tag** switch on or off at **Default Slack**, a workspace, or a channel
347* Turn Claude on or off for a workspace or a channel with its **Enable Claude Tag** switch, or for every channel with the **Respond in all channels** switch on the **Slack** page
344348* Add and remove [channel managers](#delegate-channel-setup-to-channel-managers), if the role also sets **Identity & Access** to **Can manage**
345349* Set up [**Managed by**](/docs/claude-tag/admins/managed-by) for a channel, on the **Admin** tab of the channel's Configure page
346350* Set a scope's [**How should Claude work in channels with guests**](#restrict-guest-channels) setting to **Restrict** or **Channel only**; choosing **Full access** or setting a scope back to **Inherit** stays with Owners
from line 351
347351 
348352Some actions stay outside the permission:
349353 
350* **Owner-only**: the **Enable Claude Tag for your organization** toggle, the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle, the [**Member access**](#restrict-who-can-use-claude) restriction, pairing or disconnecting workspaces, [channel name patterns](#block-or-auto-join-channels-by-name) and the bundles on them, and the [**Channels Claude can search**](#limit-which-channels-claude-can-search) setting
354* **Owner-only**: the **Enable Claude Tag in Slack** switch, the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle, the [restriction toggle](#restrict-who-can-use-claude), pairing or disconnecting workspaces, [channel name patterns](#block-or-auto-join-channels-by-name) and the bundles on them, and the [**Channels Claude can search**](#limit-which-channels-claude-can-search) setting
351355* **The Claude GitHub App**: [installing the app](/docs/claude-tag/admins/configure-github) needs an owner of your GitHub organization
352356* **Spend limits and usage analytics**: [usage analytics](#usage-analytics) is open to anyone with permission to view your organization's Analytics dashboard; [spend limits](/docs/claude-tag/admins/set-spend-limit) live on the usage page
353357 
from line 410
406410Channel managers are built on [custom roles](https://claude.ai/admin-settings/roles). When you add the first manager to a channel, you create a custom role for it, named **Channel managers** plus the channel's name and ID, with the **Claude Tag channel setup** permission. A custom role works only for members on the **Custom roles** access level, so the last step below checks each manager's level.
407411 
408412<Steps>
409 <Step title="Open the channel's panel">
410 At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), select the channel's row on the **Slack** tab under **Claude Tag's access**. The channel must be a public or private channel. If it isn't listed, [add Claude to the channel](/docs/claude-tag/users/getting-started#add-claude-to-a-channel) in Slack first.
413 <Step title="Open the channel's page">
414 Go to [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels) and open the channel's page. The channel must be a public or private channel. If it isn't listed, [add Claude to the channel](/docs/claude-tag/users/getting-started#add-claude-to-a-channel) in Slack first.
411415 </Step>
412416 
413417 <Step title="Add people or a group">
414 In the panel's header, select the people-icon button labeled **Add channel managers who can add connections and repos to this channel**. In the popup, select **Add users** to add people, which also creates a group named after the channel, or **Add groups** to add a group from [`claude.ai/admin-settings/groups`](https://claude.ai/admin-settings/groups). The same group can manage several channels.
418 In the page's header, select **Add managers**. Search for people and groups, and select each one to add. People you add join the channel's default group. A group you pick comes from [`claude.ai/admin-settings/groups`](https://claude.ai/admin-settings/groups), and the same group can manage several channels.
415419 </Step>
416420 
417421 <Step title="Check each manager's access level">
418 When you add a member on the User or Claude Code user level, you move them to the **Custom roles** level in the same step; if they already hold other custom roles, you confirm the move first. For a member on any other level, you see **Not in effect** until you change their level on the Members page. Adding a group changes nobody's level; group members who aren't on the **Custom roles** level show **Not in effect** too.
422 When you add a member on the User or Claude Code user level, you move them to the **Custom roles** level in the same step; if they already hold other custom roles, you confirm the move first. For a member on any other level, you see **Not in effect** until you change their level on the Members page. Adding a group changes nobody's level.
419423 
420424 If you're a Claude Tag admin, the move also needs **User Management** set to **Can manage** on your role. Without it, the member is still added but shows **Not in effect** until their access level is changed on the Members page.
421425 
from line 429
425429 
426430Owners can already configure every channel, so you see them as **Already has full access** and can't add them.
427431 
428Leave the role as it was created: assigned to its channel, with **Claude Tag channel setup** as its only permission. If the role's permissions are changed on the Roles page, the channel's channel-managers popup stops recognizing the role and refuses to add or remove any, with a notice that points you to the Roles page. To recover, set the role's permissions back to exactly **Claude Tag channel setup**; the group and its members are kept. To give channel managers any other permission, create a separate role for it.
432Leave the role as it was created: assigned to its channel, with **Claude Tag channel setup** as its only permission. If the role's permissions are changed on the Roles page, the channel's **Add managers** list stops recognizing the role and refuses to add or remove any, with a notice that points you to the Roles page. To recover, set the role's permissions back to exactly **Claude Tag channel setup**; the group and its members are kept. To give channel managers any other permission, create a separate role for it.
429433 
430434### Remove a channel manager
431435 
432To remove a channel manager, open the same popup from the people-icon button on the channel's panel. The current managers are listed under **Channel managers**. Remove a member you added directly, or detach a group you added. The member keeps their access level and any other custom roles. The manager cards on the channel's Configure page disappear for them.
436To remove a channel manager, select **Add managers** on the channel's page. The current managers are listed first, each with a check mark. Select a member you added directly, or a group you added, to remove it. The member keeps their access level and any other custom roles. The manager cards on the channel's Configure page disappear for them.
433437 
434438### Verify a channel manager's access
435439 
436The popup behind the people-icon button on the channel's panel shows each manager's status under **Channel managers**. A member whose access level doesn't support the role appears as **Not in effect**; the role works only on the **Custom roles** access level, so change the member's level on the Members page to put it into effect. An active manager sees the **Default model**, repository, and access bundle cards on the channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel), so asking them to open that page confirms the setup.
440In the list behind **Add managers** on the channel's page, people added directly show **Not in effect** when their access level doesn't support the role; the role works only on the **Custom roles** access level, so change the member's level on the Members page to put it into effect. An active manager sees the **Default model**, repository, and access bundle cards on the channel's [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel), so asking them to open that page confirms the setup.
437441 
438442### Audit channel manager activity
439443 
from line 447
443447* **Credential changes.** Each credential a channel manager creates, updates, rotates, or deletes, with the Slack workspace and channel it was for and the roles that granted the permission, so you can tell a channel manager's change from an Owner's. Secrets are never included.
444448* **Configure page changes.** Which settings a channel manager saved from the Configure page, such as the default model, repositories, or channel instructions. The log records which fields changed, not the values entered.
445449 
446The [Audit page](/docs/claude-tag/admins/audit), labeled **Activity** in the console, at [`claude.ai/admin-settings/claude-tag/audit`](https://claude.ai/admin-settings/claude-tag/audit) doesn't list these events; it covers scheduled work, memory, and network events.
450The [**Activity** page](/docs/claude-tag/admins/audit) at [`claude.ai/admin-settings/claude-tag/audit`](https://claude.ai/admin-settings/claude-tag/audit) doesn't list these events; it covers scheduled work, memory, and network events.
447451 
448452## Permissions by role
449453 
from line 460
456460| Action | Owner | Channel manager | Channel member |
457461| :- | :- | :- | :- |
458462| Pair a workspace | Yes | No | No |
459| Create, rename, delete, or bind an Access bundle | Yes | Only to create a bundle for an assigned channel | No |
460| Edit a bundle's Repositories, Domains, or Instructions tab | Yes | No | No |
461| Edit a bundle's Credentials or Plugins tab | Yes | Yes, in a bundle created for an assigned channel | No |
463| Create, edit, or delete a bundle, or choose where it applies | Yes | Only to create a bundle for an assigned channel | No |
464| Edit a bundle's repositories, domains, or instructions | Yes | No | No |
465| Edit a bundle's credentials or plugins | Yes | Yes, in a bundle created for an assigned channel | No |
466| Add or delete a [channel rule](/docs/claude-tag/admins/attach-to-scope#attach-a-bundle-to-channels-by-name), or change the bundles on one | Yes | No | No |
467| Set guest channels to **Full access** or back to **Inherit** | Yes | No | No |
468| Change other settings on a scope's page, such as instructions, model, and the **Enable Claude Tag** switch | Yes | No | No |
462469| Add a channel manager | Yes | No | No |
463470| Set a channel's default model or repositories from the Configure page | Yes | Yes, in assigned channels | No |
464471| Set a channel's default model by asking Claude in a thread, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block** | Yes | Yes | Yes |
from line 486
479486* **Per-user spend caps on channel work.** Spend limits apply at the organization and channel level. There's no way to cap what one member can spend in channels; one-to-one DM usage from a member who has connected a Claude account bills to that member's own seat and follows the seat's usual limits.
480487* **A switch for group DMs alone, or settings for one group DM.** You can't attach a bundle to one group DM, turn Claude off in one, or stop Claude from answering in group DMs without also stopping it in one-to-one DMs or the workspace's channels. See [Group DMs](#group-dms).
481488* **Per-channel responder allowlist.** The restriction toggle governs who can invoke Claude across the workspace; you can't narrow it to a list of people for one channel only.
482* **An open-internet switch in Claude Tag settings.** A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) adds that hostname on a [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential); for broad web access, an Owner pins an [environment](/docs/claude-tag/concepts/glossary#environment) whose network access level is Full access on the scope. [Allow-all egress](/docs/claude-tag/admins/add-connections#allow-all-hosts), a `*` entry on the Domains tab, admits any host on the ports it lists.
489* **An open-internet switch in Claude Tag settings.** A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) [adds that hostname to a bundle as a domain](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential); for broad web access, an Owner pins an [environment](/docs/claude-tag/concepts/glossary#environment) whose network access level is Full access on the scope. [Allow-all egress](/docs/claude-tag/admins/add-connections#allow-all-hosts), a `*` domain entry, admits any host on the ports it lists.
483490* **A web search toggle for channels.** No setting turns web search off for channel sessions; the web search capability setting in claude.ai admin settings governs claude.ai chat, not channels. Web search runs on Anthropic's servers rather than from the channel sandbox, so Domains entries and egress settings don't govern it, and a search opens no new path out of the sandbox; search requests travel to Anthropic the same way the session's model traffic already does. See [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests).
484491* **A switch to turn workspace search off.** Claude can search public channels by keyword the same way any Slack user can; it can't read a channel's full history unless it's been added there. No setting turns workspace search off. The [**Channels Claude can search**](#limit-which-channels-claude-can-search) setting narrows it to channels Claude is in. No setting enables search in [channels that include guests](#restrict-guest-channels), where it's unavailable.
485492* **Session length enforcement.** Your organization's Slack session-length policy is not enforced on this surface.

claude-tag/admins/setup-overview Changed · +24 / -25 lines

from line 25
2525 | A **Team or Enterprise plan** on claude.ai | Claude Tag is available on Team and Enterprise plans, on Anthropic's first-party service. It isn't available on individual plans (Free, Pro, or Max), or for third-party deployments. | Start a Team or Enterprise plan at [claude.com/pricing](https://claude.com/pricing) |
2626 | A Claude organization **without Zero Data Retention (ZDR), customer-managed encryption (CMEK), or the HIPAA configuration for Claude Code (local mode) and Cowork (local mode)** | Claude Tag stores channel memory and session transcripts, which ZDR doesn't permit. A CMEK policy and the HIPAA configuration don't allow Claude Tag either. | Claude Tag isn't available to organizations with any of these. See [Healthcare organizations](/docs/claude-tag/admins/healthcare#plan-and-organization-requirements) |
2727 | **Routines** enabled for your Claude organization | Until it is, Claude answers every mention and DM with a reply that it's unavailable and does no work. | An admin turns on [**Admin settings > Capabilities > Remote sessions > Routines**](https://claude.ai/admin-settings/capabilities) |
28 | **Owner** role in the Claude organization you're setting up | Pairing a workspace is an Owner-only write. Roles are per organization, so being an Owner elsewhere doesn't carry over. | Ask an Owner to run setup, or have one promote you at [`claude.ai/admin-settings/members`](https://claude.ai/admin-settings/members) |
28 | **Owner** role in the Claude organization you're setting up | Setup pairs a workspace and turns Claude Tag on, and only an Owner can do either. Roles are per organization, so being an Owner elsewhere doesn't carry over. | Ask an Owner to run setup, or have one promote you at [`claude.ai/admin-settings/members`](https://claude.ai/admin-settings/members) |
2929 | A **Slack workspace admin** | Running `@Claude connect` requires a Slack workspace admin; installing the app usually does too. | If that's someone else, [send them the install request](#if-you-re-not-the-slack-workspace-admin) early (app approval can take time), and plan to be online together when you pair; pairing codes expire 15 minutes after they're issued |
3030 | **Usage credits** (Team plans) | Channel work draws from your organization's usage balance; on a Team plan nothing runs until credits are loaded. | Buy credits at [`claude.ai/admin-settings/usage`](https://claude.ai/admin-settings/usage) |
3131 | A **public channel** for Claude to join | The launch step asks you to select at least one public channel, and you can [verify your setup](#verify-your-setup) there. | Create a public Slack channel for the pilot, or pick any existing one |
from line 148
148148After launch, Claude reaches your other tools through personal connectors and through access you give Claude itself.
149149 
150150* **Personal connectors**: Claude can use a member's own claude.ai connectors for that member's requests in a channel. You don't connect anything for these. See [Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) for how members approve that use.
151* **Access you give Claude**: you connect a tool on the Claude Tag admin page with credentials that belong to Claude rather than to a person. Claude then works in that tool for everyone in the channels you choose, and can use it for [work it starts on its own](/docs/claude-tag/users/proactivity).
151* **Access you give Claude**: you connect a tool on the Claude Tag admin page with credentials that belong to Claude rather than to a person. Claude then works in that tool and can use it for [work it starts on its own](/docs/claude-tag/users/proactivity).
152152 
153153### Connect GitHub
154154 
from line 181
181181 Sign in to the tool as Claude and create the credential that tool's [connection guide](/docs/claude-tag/admins/connections/overview) names, usually an API key or personal access token from the tool's settings. Copy it. The credential belongs to Claude's account, so Claude's actions show up in the tool's audit log under Claude's name.
182182 </Step>
183183 
184 <Step title="Add the key as a connection">
185 On the Claude Tag admin page, [create an Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle), a named set of connections, repositories, plugins, and instructions, if you don't have one. Then [add a connection](/docs/claude-tag/admins/add-connections#add-a-connection) for the tool and paste the key you created. Claude can use the tool in the [workspace or channels you attach the bundle to](/docs/claude-tag/admins/attach-to-scope).
184 <Step title="Add the key as a connector">
185 Go to [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag). Under **Claude's access**, select the **Connectors** tab and click **Add**. Then [add a connector](/docs/claude-tag/admins/add-connections#add-a-connection) for the tool and paste the key you created. The first credential you add for a service from the **Connectors** tab is on in every workspace and channel as soon as you save it. To give it narrower reach, see [where a new connector applies](/docs/claude-tag/admins/add-connections#add-a-connection) before you save the connector.
186186 
187187 For the next tool, start again from **Add Claude to the tool as a member**. Claude keeps the one email address for every tool.
188188 </Step>
from line 210
210210 
211211**Passed when:** Claude replies in a thread under your message. The reply ends with a footer naming the model and a **Configure** link.
212212 
213**If not:** a notice that starts "Claude isn't on in this channel yet" means you haven't finished [Launch Claude Tag](#launch-claude-tag). No reply at all means the channel isn't covered; check that the workspace appears under **Claude Tag's access** on the **Slack** tab in admin settings, then see [Nothing responds](/docs/claude-tag/admins/troubleshooting#nothing-responds).
213**If not:** a notice that starts "Claude isn't on in this channel yet" means you haven't finished [Launch Claude Tag](#launch-claude-tag). No reply at all means the channel isn't covered. Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), check that the workspace appears on the **Channels** tab under **Claude's access**, then see [Nothing responds](/docs/claude-tag/admins/troubleshooting#nothing-responds).
214214 
215215### Check a tool you connected
216216 
from line 230
230230 
231231**Passed when:** the first reply lists the tools you connected, the second comes back with data, and the request appears in that tool's audit log under Claude's account.
232232 
233**If not:** a tool missing from the list means its connection didn't save; open the Access bundle in admin settings and [connect it again](/docs/claude-tag/admins/add-connections#add-a-connection). "I can't reach…" in a thread you started before connecting means Claude wasn't told about the new connection; start a fresh thread. Anything else, see [Access and connections](/docs/claude-tag/admins/troubleshooting#access-and-connections).
233**If not:** when a tool is missing from the list, go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and open the **Connectors** tab under **Claude's access**. If the tool isn't there, [connect it again](/docs/claude-tag/admins/add-connections#add-a-connection). If it is, open its page and check that it applies to the channel you asked in. "I can't reach…" in a thread you started before connecting means Claude wasn't told about the new connector; start a fresh thread. Anything else, see [Access and connections](/docs/claude-tag/admins/troubleshooting#access-and-connections).
234234 
235235### Check GitHub
236236 
from line 248
248248 
249249## After setup
250250 
251After launch, you change anything about Claude Tag from the admin page:
251After launch, you change Claude Tag from [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). Organization-wide settings such as **Enable Claude Tag in Slack**, **Direct messages**, and **Model** sit at the top of the page. Below them, **Claude's access** holds what Claude can reach, in four tabs:
252252 
2531. Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
2542. Under **Claude Tag's access**, open the **Slack** tab.
2553. In the list on the left, select **Default Slack** to change how Claude works everywhere, or select a workspace or channel to change it in that one place.
253* **Bundles**: named sets of connectors, repositories, domains, plugins, and instructions that you add to more than one place. See [bundle](/docs/claude-tag/concepts/glossary#access-bundle) in the glossary.
254* **Connectors**: each service Claude connects to, its credentials, and where Claude may use each one
255* **Skills and plugins**: the skills and plugins Claude uses anywhere in Slack
256* **Channels**: **Slack**, whose page holds the settings for every workspace and channel, then each connected workspace with its channel rules and channels
256257 
257Anything you add on **Default Slack** applies in every workspace and channel. Anything you add on a workspace or channel applies there in addition.
258On the **Channels** tab, select **Slack** to change how Claude works everywhere, or select a workspace or channel to change it in that one place. A workspace or channel inherits what's set above it. Its own instructions and access add to what it inherits, and its own model replaces the inherited one.
258259 
259Every entry in the list on the left has **Connectors**, **Repositories**, **Custom instructions**, and **Access bundles** sections, and a collapsed **Advanced** section with settings such as the [**Default model**](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope) and the [**Environment**](/docs/claude-tag/concepts/glossary#environment). A **Plugins** section appears once your organization has plugins available to [attach](/docs/claude-tag/admins/add-connections#attach-plugins). An [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle) is a named set of connections, repositories, plugins, and instructions that you can attach to more than one place.
260 
261260| To do this | Go to | Learn more |
262261| :- | :- | :- |
263| Change the model Claude replies with | The entry's **Advanced** section, **Default model**. Set it on **Default Slack** to change it everywhere, or on one channel. | [Choose the model for a scope](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope) |
264| Give Claude standing instructions | The **Custom instructions** field on **Default Slack** for every channel, or on one channel's entry for that channel only. | [Customize](/docs/claude-tag/admins/customize) |
265| Connect a tool | **Connectors** on the entry, or an Access bundle under **Access bundles**. | [Give Claude access](/docs/claude-tag/admins/add-connections) |
266| Let Claude reach a site or API that has no credential | The **Domains** list of the Access bundle, under **Access bundles**. | [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) |
267| Grant more repositories | **Repositories** on the entry. | [Configure GitHub access](/docs/claude-tag/admins/configure-github) |
268| Give one channel more than the default | Select the channel and add to it. | [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope) |
262| Change the model Claude replies with | **Model** at the top of the Claude Tag page to change the default everywhere, or **Model** on a workspace's or channel's page. | [Choose the model for a scope](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope) |
263| Give Claude standing instructions | **Slack instructions** on the **Slack** page for every channel, or **Channel instructions** on one channel's page for that channel only. | [Customize](/docs/claude-tag/admins/customize) |
264| Connect a tool | **Add** on the **Connectors** tab. | [Give Claude access](/docs/claude-tag/admins/add-connections) |
265| Let Claude reach a site or API that has no credential | **Add > Domain** under **What's in it** on a bundle's page. | [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) |
266| Grant more repositories | The **GitHub** page, which you open from the **Connectors** tab. | [Configure GitHub access](/docs/claude-tag/admins/configure-github) |
267| Give one channel more than the default | The channel's page, from the **Channels** tab: **Add** under **Claude's access**, then pick what to add, such as **Connector**, **Domain**, or **Bundle**. | [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope) |
269268| Limit where Claude works or who can use it | | [Restrict where Claude operates](/docs/claude-tag/admins/restrict-access) |
270269| Require review of personal connector results | On the Enterprise plan, the **Personal connectors** section of the admin page. | [Admin controls for personal connectors](/docs/claude-tag/concepts/personal-connectors#admin-controls-for-personal-connectors) |
271| Pair another workspace, or disconnect one | The Slack row's **⋮** menu under **Where Claude Tag works**. Disconnecting permanently deletes the workspace's Claude data. See [Data lifecycle and deletion](/docs/claude-tag/concepts/data-lifecycle). | [Manage workspaces](/docs/claude-tag/admins/workspaces) |
270| Pair another workspace, or disconnect one | **Connected workspaces** on the **Slack** page. Disconnecting permanently deletes the workspace's Claude data. See [Data lifecycle and deletion](/docs/claude-tag/concepts/data-lifecycle). | [Manage workspaces](/docs/claude-tag/admins/workspaces) |
272271| Change the spend limit | [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag). | [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) |
273| Turn Claude Tag off | The **Enable Claude Tag for your organization** toggle at the top of the admin page. | |
272| Turn Claude Tag off | The **Enable Claude Tag in Slack** switch at the top of the Claude Tag page. It also turns off direct messages. | [Turn Claude Tag on or off](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
274273| Bring in the first users | | [Getting started for users](/docs/claude-tag/users/getting-started) |
275274 
276275## Common setup issues
from line 280
281280 
282281* [How Claude Tag works](/docs/claude-tag/concepts/how-it-works): what happens between a mention and a reply
283282* [How agent identity works](/docs/claude-tag/concepts/agent-identity): why Claude gets its own accounts, and what that means for audit logs and access
284* [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit): how Default Slack, workspaces, and channels inherit Access bundles
283* [Configure per-channel access](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit): how Slack, workspaces, and channels inherit bundles
285284* [Claude Tag settings map](/docs/claude-tag/concepts/settings-map): every setting, and whether admins, channel members, or users control it
286* [Glossary](/docs/claude-tag/concepts/glossary): Access bundle, scope, session, and the other terms on this page
285* [Glossary](/docs/claude-tag/concepts/glossary): bundle, scope, session, and the other terms on this page
287286* [Network requirements](/docs/claude-tag/admins/network-requirements): what your services must allowlist so Claude can reach them
288287* [Claude Tag in production at Anthropic](https://claude.com/blog/ai-ci-cd-on-call): how Anthropic runs Claude Tag as its first responder for CI/CD failures
289288 

claude-tag/admins/skills-repo Changed · +5 / -5 lines

from line 24
2424 </Step>
2525 
2626 <Step title="Grant Claude write access to the repository">
27 Open an [Access bundle](/docs/claude-tag/admins/add-connections#your-first-access-bundle), go to its **Repositories** tab, and add the repository. The Claude GitHub App must already be linked to your GitHub organization; see [Configure GitHub access](/docs/claude-tag/admins/configure-github).
27 At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open a [bundle](/docs/claude-tag/admins/add-connections) on the **Bundles** tab under **Claude's access**. In its **What's in it** section, select **Add**, then **Repository**, and pick the repository. The Claude GitHub App must already be linked to your GitHub organization; see [Configure GitHub access](/docs/claude-tag/admins/configure-github).
2828 </Step>
2929 
30 <Step title="Attach the plugins to a scope">
31 In the same bundle's **Plugins** tab, toggle on the plugins from your new marketplace; each is off until you enable it. See [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins).
30 <Step title="Add the plugins to the bundle">
31 On the same bundle's page, select **Add**, then **Plugin**, and pick each plugin from your new marketplace. A plugin isn't in the bundle until you add it, and the bundle's plugins apply wherever the bundle applies; see [Choose where a bundle applies](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) and [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins).
3232 </Step>
3333</Steps>
3434 
35**You'll see:** the repository appears in the bundle's Repositories list, and the marketplace's plugins appear in the bundle's Plugins tab, each labeled with the marketplace name.
35**You'll see:** the repository and the plugins appear in the bundle's **What's in it** table, with **Repository** or **Plugin** as each row's type.
3636 
3737## How updates propagate
3838 
from line 74
7474* The same layout inside a single top-level folder
7575* For a single skill, a `SKILL.md` at the top level whose frontmatter declares the plugin's components
7676 
77An archive with no manifest, with more than one `plugin.json`, or with the manifest anywhere else is rejected at upload. After upload, the plugin is in your organization's catalog but not attached anywhere. To make it available in channels, toggle it on in a bundle's **Plugins** tab or add it directly on a scope; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins).
77An archive with no manifest, with more than one `plugin.json`, or with the manifest anywhere else is rejected at upload. After upload, the plugin is in your organization's catalog but not attached anywhere. To make it available in channels, add it to a bundle with **Add**, then **Plugin**, on the bundle's page, or add it for all of Slack from the **Skills and plugins** tab under **Claude's access**; see [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins).
7878 
7979## Repository context files and MCP servers
8080 

claude-tag/admins/troubleshooting Changed · +51 / -63 lines

### The page shows your plan as Free

from line 12
1212 
1313If someone reports that Claude can't reach a service you connected, check two things before anything else:
1414 
15* The connection reaches that channel through an attached bundle. To check, go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Claude Tag's access** > **Slack** > the channel's scope (or its workspace's scope, if the channel isn't listed) > **Access summary**, which includes access [inherited from wider scopes](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit). If there's no **Access summary** section, or the connection isn't in it, [attach the bundle](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle) to the channel's scope; if the channel has no scope yet, select **Add channel** on its workspace to [create the scope](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel) first.
16* The test ran in a new thread; an existing thread isn't told about a connection added after it started, though the connection works there if the request names the service.
15* The connector applies to that channel. To check, go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open the **Channels** tab under **Claude's access**, and select the channel (or its workspace, if the channel isn't listed). The page's **Claude's access** table includes access [inherited from wider scopes](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit), and its **Inheritance** column names where each bundle, and each item outside a bundle, comes from. If the connector isn't there, add it to the channel, its workspace, or a [bundle that applies there](/docs/claude-tag/admins/attach-to-scope#attach-the-bundle).
16* The test ran in a new thread; an existing thread isn't told about a connector added after it started, though the connector works there if the request names the service.
1717 
1818## Setup errors
1919 
from line 32
3232| **Launch Claude Tag** to finish | "Couldn't turn on personal connectors in channels. Try again." | Launch didn't finish. Click **Launch Claude Tag** again. |
3333| Claude to join the channels you selected on the **Launch Claude Tag** step | "Couldn't add Claude to some channels. Add Claude from Slack instead." | Claude Tag is on, but Claude didn't join every channel you selected. Run `/invite @Claude` in each channel it's missing from. |
3434| A reply from Claude while you're still in setup | A notice that starts "Claude isn't on in this channel yet." | Claude Tag isn't turned on until you finish [Launch Claude Tag](/docs/claude-tag/admins/setup-overview#launch-claude-tag). Finish setup, then mention `@Claude` again. A channel that's turned off after launch gets a different notice; see [Claude is disabled in this channel](#claude-is-disabled-in-this-channel). |
35| A connected tool to work in your test | “I can't reach…” | Claude isn't told about a connection added after the thread started. Ask it to use the service by name, or start a fresh thread. |
36| The **Where Claude Tag works** section with a **+ Connect** button | Only the legacy Claude in Slack toggles | Your organization isn't enabled for Claude Tag. Contact your account team. |
37| Claude to respond in Slack | "Claude Tag has been turned off for your Claude organization…" | The **Enable Claude Tag for your organization** toggle is off. An Owner turns it on at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). See [the troubleshooting entry](#claude-tag-is-turned-off-for-your-organization). |
35| A connected tool to work in your test | “I can't reach…” | Claude isn't told about a connector added after the thread started. Ask it to use the service by name, or start a fresh thread. |
36| Claude to respond in Slack | "Claude Tag has been turned off for your Claude organization…" | The **Enable Claude Tag in Slack** switch is off. An Owner turns it on at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). See [the troubleshooting entry](#claude-tag-is-turned-off-for-your-organization). |
3837| Claude to respond in Slack | "Claude Tag is unavailable because Routines aren't enabled for your organization…" | Routines isn't enabled for your Claude organization, which Claude Tag requires. An admin turns on [**Admin settings > Capabilities > Remote sessions > Routines**](https://claude.ai/admin-settings/capabilities). Anyone can then mention `@Claude` again. See [the troubleshooting entry](#claude-tag-is-unavailable-because-routines-are-not-enabled). |
3938| Claude to respond in Slack | "Claude in Slack is not available for your organization" or "Claude isn't available for organizations with restricted compliance settings." | The paired Claude organization has a restricted compliance configuration, such as Zero Data Retention (ZDR), that Claude Tag can't run under. No setting lifts the restriction; contact your account team. See [the troubleshooting entry](#restricted-compliance-settings-block-claude-tag). |
40| The **Slack** tab to list your scopes | "Couldn't load Slack scopes. Reload the page to try again." | Reload the page. See [Couldn't load Slack scopes](#couldn%E2%80%99t-load-slack-scopes). |
39| The **Slack** page or a workspace or channel page to load | "Couldn't load Slack scopes. Reload the page to try again." | Reload the page. See [Couldn't load Slack scopes](#couldn%E2%80%99t-load-slack-scopes). |
4140| A reply in your test channel | "Couldn't check this channel just now" | Mention `@Claude` again. See [Couldn't check this channel just now](#couldn%E2%80%99t-check-this-channel-just-now). |
4241| A reply in your test channel | "Something went wrong starting a session" | Retry first. If it persists, see [the session-start entries](#something-went-wrong-starting-a-session). |
4342 
from line 146
147146 
148147**How to resolve**
149148 
150Nothing is misconfigured. If an auto-join pattern brought Claude in, review the patterns in the scope's **Advanced** section. If Claude shouldn't be in the channel, remove it with `/remove @Claude`, or [turn the scope's **Enable Claude Tag in this channel** switch off](/docs/claude-tag/admins/restrict-access#quiet-or-remove-claude-tag) so it stops responding there even if it's added again. If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead of the per-scope switches, remove Claude and add a [blocked channel pattern](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name) for the channel's name. If you want every join in the audit log attributed to a person, ask members to add Claude with `/invite @Claude` rather than the buttons; Slack records an invite as the inviting member's action.
149Nothing is misconfigured. If an auto-join pattern brought Claude in, review the auto-join patterns on the **Advanced** tab of the workspace's page or of the **Slack** page. If Claude shouldn't be in the channel, remove it with `/remove @Claude`, or [turn the scope's **Enable Claude Tag in this channel** switch off](/docs/claude-tag/admins/restrict-access#quiet-or-remove-claude-tag) so it stops responding there even if it's added again. If the **Slack** page has a single [**Respond in channels** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead of per-channel switches, remove Claude and add a [blocked channel pattern](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name) for the channel's name. If you want every join in the audit log attributed to a person, ask members to add Claude with `/invite @Claude` rather than the buttons; Slack records an invite as the inviting member's action.
151150 
152151## Guest and shared channels
153152 
from line 173
174173Either fix works:
175174 
176175* Remove the guests from the channel, or move the conversation to a channel with no guests; this changes no settings, so no other channel is affected.
177* Change **How should Claude work in channels with guests** for the scope covering this channel, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope → the collapsed **Advanced** section. **Channel only** restores replies with [channel-only access](/docs/claude-tag/admins/restrict-access#how-channel-only-works). **Full access** restores replies with the scope's full access, and only an organization Owner can choose it. See [restrict guest channels](/docs/claude-tag/admins/restrict-access#restrict-guest-channels) for what each value exposes.
176* Change **How should Claude work in channels with guests** for the scope covering this channel. Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open the **Channels** tab under **Claude's access**, select the channel, its workspace, or **Slack**, and open the page's **Advanced** tab. **Channel only** restores replies with [channel-only access](/docs/claude-tag/admins/restrict-access#how-channel-only-works). **Full access** restores replies with the scope's full access, and only an organization Owner can choose it. See [restrict guest channels](/docs/claude-tag/admins/restrict-access#restrict-guest-channels) for what each value exposes.
178177 
179Either value applies to every guest channel that scope covers. To limit the change to one channel, set the value on the channel's own scope.
178Either value applies to every guest channel that scope covers. To limit the change to one channel, set the value on the channel's own page.
180179 
181180Claude can't search the workspace from a channel that includes guests, even under **Full access**. Removing the guests restores search as well.
182181 
from line 196
197196**How to resolve**
198197 
1991981. Mention Claude again; the retry usually clears it.
2002. If one channel hits this repeatedly, the membership check may be failing on an unusually large channel. If you set the **How should Claude work in channels with guests** setting to **Full access** on the channel's scope, Claude skips the guest check in every channel that scope covers, so this message usually stops. Weigh [what Full access exposes](#claude-doesn%E2%80%99t-respond-in-channels-that-include-guests) first.
1992. If one channel hits this repeatedly, the membership check may be failing on an unusually large channel. If you set the **How should Claude work in channels with guests** setting to **Full access** on the channel's page, Claude skips the guest check in every channel that scope covers, so this message usually stops. Weigh [what Full access exposes](#claude-doesn%E2%80%99t-respond-in-channels-that-include-guests) first.
201200 
202201### This channel is shared across multiple workspaces
203202 
from line 258
259258 
260259**What it means**
261260 
262The channel is shared across more than one Slack workspace, and every one of those workspaces belongs to your Claude organization. Claude works there, but only with the access and settings on your [**Default Slack access**](/docs/claude-tag/admins/attach-to-scope) scope. Bundles, instructions, and memory attached to a workspace or to this channel don't apply.
261The channel is shared across more than one Slack workspace, and every one of those workspaces belongs to your Claude organization. Claude works there, but only with the access and settings on your [**Slack** page](/docs/claude-tag/admins/attach-to-scope), which apply in every workspace. Bundles, access, instructions, and memory added to a workspace or to this channel don't apply.
263262 
264263Claude posts the notice about once a month in each such channel, not on every reply, so replies there run under the same defaults even when no notice accompanies them.
265264 
266265**How to resolve**
267266 
268Nothing is broken. To use a channel's own repositories, connections, or instructions, work in a channel that belongs to a single workspace, or add what the channel needs to the **Default Slack access** scope. In a single-workspace channel, requests use that channel's own configuration and the notice doesn't appear.
267Nothing is broken. To use a channel's own repositories, connectors, or instructions, work in a channel that belongs to a single workspace, or add what the channel needs on the **Slack** page. In a single-workspace channel, requests use that channel's own configuration and the notice doesn't appear.
269268 
270269### Claude isn't available in channels shared across your Enterprise Grid
271270 
from line 306
307306 
308307**What you see**
309308 
310A banner at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the **Slack** tab under **Claude Tag's access**, reads:
309A banner on the **Slack** page or on a workspace or channel page, each of which you open from the **Channels** tab under **Claude's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), reads:
311310 
312311> Couldn't load Slack scopes. Reload the page to try again.
313312 
313The same failure on the **Claude's access** tabs themselves reads "Couldn't load Claude's access. Try again." with a **Retry** button.
314 
314315**What it means**
315316 
316317The request that loads your scope list from Claude's backend failed; it isn't a Slack permissions problem, and your configuration is intact.
from line 318
317318 
318319**How to resolve**
319320 
3201. Reload the page. If the reload worked, the scope list renders. That's the usual outcome.
3211. Reload the page, or select **Retry**. If it worked, the page's settings or the tab's list render. That's the usual outcome.
3213222. If the banner persists across reloads, check [`status.anthropic.com`](https://status.anthropic.com) for an active incident and try again in a few minutes.
3223233. If it continues with no incident posted, contact [Anthropic support](https://support.claude.com) with the time it occurred.
323324 
324### The page shows your plan as Free
325 
326**What you see**
327 
328You open the admin console expecting your organization's settings and land on your personal account settings instead, showing the **Free plan** and no Claude Tag section anywhere.
329 
330**What it means**
331 
332You're signed into a personal claude.ai account, which is a separate workspace from your organization. claude.ai sends a personal account to its own settings page rather than to the admin console, so the **Free** you see is your personal account's plan, not a broken admin page.
333 
334**How to resolve**
335 
336Use the workspace switcher in claude.ai to switch to your organization, then reopen [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). If the switch worked, the page shows your organization's plan and the Claude Tag settings.
337 
338325### Already connected to a different organization
339326 
340327**What you see**
from line 335
348335**How to resolve**
349336 
3503371. Find the Claude organization that holds the pairing. Check any other organizations your company has.
3512. Have an Owner in that organization [disconnect the workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing) from their **Connected workspaces** list.
3382. Have an Owner in that organization [disconnect the workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing) under **Connected workspaces** on their **Slack** page.
3523393. Send `@Claude connect` again for a fresh code and redeem it here.
353340 
354341<Warning>
from line 498
511498 
512499**How to resolve**
513500 
514An Owner turns Claude Tag on at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and [pairs the workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace). If the workspace is already paired, check the **Claude Tag version** on the channel's scope, then on its workspace's, and set it to **New** or **Inherit**; see [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/migrate-from-earlier). Once Claude Tag is on and the workspace is paired, the notice stops appearing.
501An Owner turns on **Enable Claude Tag in Slack** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and [pairs the workspace](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace). If the workspace is already paired, check the **Claude Tag version** on the **Advanced** tab of the channel's page, then of its workspace's page, and set it to **New** or **Inherit**; see [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/migrate-from-earlier). Once Claude Tag is on and the workspace is paired, the notice stops appearing.
515502 
516503### Claude Tag is turned off for your organization
517504 
from line 512
525512 
526513**What it means**
527514 
528The **Enable Claude Tag for your organization** toggle is off in admin settings, or your organization isn't enabled for Claude Tag. The toggle that matters is the one in the Claude organization the reply's parenthetical points to.
515The **Enable Claude Tag in Slack** switch is off in admin settings, or your organization isn't enabled for Claude Tag. The switch that matters is the one in the Claude organization the reply's parenthetical points to.
529516 
530517**How to resolve**
531518 
5321. An Owner switches the toggle on at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). If the toggle was the problem, a mention in Slack now gets a normal reply.
5191. An Owner turns on the **Enable Claude Tag in Slack** switch at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). If the switch was the problem, a mention in Slack now gets a normal reply.
5335202. If the message persists, check which Claude organization the workspace is paired to. If your company has more than one (a trial organization alongside the main one, for example), an Owner in the wrong organization can [revoke the pairing](/docs/claude-tag/admins/workspaces#revoke-a-pairing) so you can pair the workspace to the right one.
5343. If the right organization has the toggle on and the message persists, contact your account team to confirm Claude Tag is enabled for it.
5213. If the right organization has the switch on and the message persists, contact your account team to confirm Claude Tag is enabled for it.
535522 
536523<Warning>
537524 Revoking the pairing deletes the workspace's Claude data, including its memory, channel configurations, sessions, and the routines set up in its channels. The deletion can't be undone. See [Data lifecycle and deletion](/docs/claude-tag/concepts/data-lifecycle) for the full list of what's deleted.
from line 580
593580 
594581**What it means**
595582 
596This channel's **Enable Claude Tag in this channel** switch is off, either set on the channel's scope itself or inherited from a scope above it. If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead of the per-scope switches, the same notice means the switch is off, or the channel's workspace is switched off on its own.
583This channel's **Enable Claude Tag in this channel** switch is off, either set on the channel's page itself or inherited from its workspace, or from the **Slack** page, whose **Respond in all channels** switch is off. If the **Slack** page has a single [**Respond in channels** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead of per-channel switches, the same notice means that switch is off, or the channel's workspace is switched off on its own.
597584 
598585**How to resolve**
599586 
600An Owner turns the scope back on:
587An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) turns the channel back on:
601588 
6025891. Open [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag).
6032. Under **Claude Tag's access**, open the **Slack** tab and select the channel's scope.
6043. Turn on the **Enable Claude Tag in this channel** switch at the top of the scope's panel.
5902. Under **Claude's access**, open the **Channels** tab and select the channel.
5913. On the **General** tab, turn on the **Enable Claude Tag in this channel** switch.
605592 
606If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead of the per-scope switches, check that the switch is on at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag**. If the fix worked, a mention in the channel gets a reply.
593If the switch is inherited from the **Slack** page, you can instead select the **Slack** row on the **Channels** tab and turn on **Respond in all channels** at the top of its **General** tab. That also turns Claude back on in every other channel that inherits the switch from the **Slack** page.
607594 
595If the **Slack** page has a single [**Respond in channels** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead of per-channel switches, select the **Slack** row on the **Channels** tab and check that **Respond in channels** is on. If the fix worked, a mention in the channel gets a reply.
596 
608597## Access and connections
609598 
610599Access and connection errors usually mean Claude responded but couldn't reach a connected service, a repository, or a capability the sender's seat doesn't include. A scope left on **Legacy** only looks like an access problem; there, the earlier Claude in Slack answers instead of Claude Tag, so bundles and connections never apply.
from line 606
617606 
618607**What it means**
619608 
620A channel session's outbound network access is deny-by-default. A host is reachable when a bundle's connection or [Domains list](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) allows it, or when the network access setting of the environment the scope's sessions run on allows it; anything else is blocked. Web search is separate and works regardless, so Claude can answer from search while being unable to fetch the same page; enabling web search in claude.ai admin settings doesn't open network access for channels. See [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests).
609A channel session's outbound network access is deny-by-default. A host is reachable when a connector or an [allowed domain](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) that applies to the channel allows it, or when the network access setting of the environment the scope's sessions run on allows it; anything else is blocked. Web search is separate and works regardless, so Claude can answer from search while being unable to fetch the same page; enabling web search in claude.ai admin settings doesn't open network access for channels. See [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests).
621610 
622611**How to resolve**
623612 
624* For specific hosts, add them to the bundle's [Domains list](/docs/claude-tag/admins/add-connections#add-a-domain); if the channel's scope has no bundle attached, [attach one](/docs/claude-tag/admins/attach-to-scope) first. A credential-bearing service belongs in a connection instead.
625* For broad access, pin an organization-scoped environment whose network access level is Full access on the scope; see [the environment entry below](#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one).
613* For specific hosts, [add each one as a domain](/docs/claude-tag/admins/add-connections#add-a-domain) that applies to the channel, for example with **Add > Domain** on the page of a bundle that applies there. A credential-bearing service belongs in a connector instead.
614* For broad access, pin an organization-scoped environment whose network access level is Full access in the **Environment** setting on the **Advanced** tab of the channel's, workspace's, or **Slack** page; see [the environment entry below](#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one).
626615 
627616Test in a new thread. If the fix worked, the fetch that failed succeeds there.
628617 
from line 623
634623 
635624**What it means**
636625 
637Bundles attach per scope. The working channel's scope has the bundle; the failing one likely doesn't.
626Access is applied per place. The working channel gets the connector from its own page, its workspace, or a bundle that applies there; the failing one likely doesn't.
638627 
639628**How to resolve**
640629 
641Attach the bundle to the failing channel's scope, or move the work to a channel under a covered scope. Test in a new thread, or ask Claude to use the service by name in the existing one. If the fix worked, asking `@Claude what can you access from this channel?` in a new thread lists the service.
630Apply the connector to the failing channel. Open the connector's page from the **Connectors** tab under **Claude's access**. Under **Assign access**, pick the credential in the **Access** column of the channel's workspace, or select **Add place** to add the channel, then select **Save changes**. See [Add a connector](/docs/claude-tag/admins/add-connections#add-a-connection). If a bundle holds the connector, add the channel to that bundle's **Where it applies** list instead. You can also move the work to a channel the connector already covers. Test in a new thread, or ask Claude to use the service by name in the existing one. If the fix worked, asking `@Claude what can you access from this channel?` in a new thread lists the service.
642631 
643632### GitHub doesn't work in this channel
644633 
from line 637
648637 
649638**What it means**
650639 
651The most likely cause is a channel whose scope still has **Claude Tag version** set to **Legacy**, so the earlier Claude in Slack answers instead of Claude Tag. The other causes are a missing bundle attachment, a stale thread, an ungranted repository, or a repository the GitHub App installation doesn't cover.
640The most likely cause is a channel whose scope still has **Claude Tag version** set to **Legacy**, so the earlier Claude in Slack answers instead of Claude Tag. The other causes are a repository that isn't granted to the channel, a stale thread, or a repository the GitHub App installation doesn't cover.
652641 
653642**How to resolve**
654643 
655644Go through these checks in order; the same checks, in the same order, apply when GitHub worked in a channel and then stopped.
656645 
6571. **Which version answers the channel**: if `@Claude` opens pull requests under the asker's name, the channel is on **Legacy**, and bundles only apply where Claude Tag answers. Switch the scope's **Claude Tag version** setting per [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/restrict-access#migrate-from-the-earlier-claude-in-slack). You're on the right version when pull requests open under the Claude GitHub App.
6582. **A bundle with GitHub access on this channel's scope**: bundles attach per scope, so the bundle that carries GitHub access must be attached to a scope that covers this channel; [Attach the bundle to a scope](/docs/claude-tag/admins/attach-to-scope) covers attachment and inheritance. If the bundle is attached, asking `@Claude what can you access from this channel?` in a new thread lists GitHub.
6593. **A fresh thread**: a new thread picks up every configuration change, so test in one before checking anything further.
6604. **The repository granted in the bundle**: the repository must be listed in the bundle's **Repositories** tab, per [Grant repository access](/docs/claude-tag/admins/configure-github#grant-repository-access). If the repository is granted, asking Claude to read a file from it works in a new thread. Granting makes the repository available to clone, but the code doesn't enter a session until a request names it.
6615. **The GitHub App installation covers the repository**: if Claude reports a repository isn't available, isn't configured, or returned a 403, check the installation, since the app's repository selection is upstream of the bundle grant. At [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github), the organization that owns the repository should show **Connected** under **Connected GitHub accounts**. If its row shows a **Needs permissions** status instead, the install is waiting on a GitHub organization owner. Click **Review permissions** to approve it on github.com. If you aren't a GitHub organization owner, use **Copy message** under **Not a GitHub account owner?** on that settings page to send the request to someone who is. If the organization isn't listed at all, install the app with **Install on another organization**; [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) covers both.
6461. **Which version answers the channel**: if `@Claude` opens pull requests under the asker's name, the channel is on **Legacy**, and connectors only apply where Claude Tag answers. Switch the scope's **Claude Tag version** setting per [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/restrict-access#migrate-from-the-earlier-claude-in-slack). You're on the right version when pull requests open under the Claude GitHub App.
6472. **The repository granted to this channel**: open the channel from the **Channels** tab under **Claude's access** and check that the repository is in its **Claude's access** table, whether added on the channel's page, inherited from its workspace or the **Slack** page, or held by a bundle that applies there. [Grant repository access](/docs/claude-tag/admins/configure-github#grant-repository-access) covers granting it, and [Attach the bundle to a scope](/docs/claude-tag/admins/attach-to-scope) covers how access inherits. Granting makes the repository available to clone, but the code doesn't enter a session until a request names it.
6483. **A fresh thread**: a new thread picks up every configuration change, so test in one before checking anything further. If the repository is granted, asking Claude to read a file from it works in a new thread.
6494. **The GitHub App installation covers the repository**: if Claude reports a repository isn't available, isn't configured, or returned a 403, check the installation, since the app's repository selection is upstream of the grant in Claude. At [`claude.ai/admin-settings/github`](https://claude.ai/admin-settings/github), the organization that owns the repository should show **Connected** under **Connected GitHub accounts**. If its row shows a **Needs permissions** status instead, the install is waiting on a GitHub organization owner. Click **Review permissions** to approve it on github.com. If you aren't a GitHub organization owner, use **Copy message** under **Not a GitHub account owner?** on that settings page to send the request to someone who is. If the organization isn't listed at all, install the app with **Install on another organization**; [Link your GitHub organization](/docs/claude-tag/admins/configure-github#link-your-github-organization) covers both.
662650 
663651For GitHub Enterprise Server repositories, confirm [the GHE host is registered](/docs/claude-tag/admins/configure-github#github-enterprise-server) instead. The github.com App install doesn't cover them.
664652 

claude-tag/admins/workspaces Changed · +49 / -20 lines

### What each Claude Tag switch turns off

from line 16
1616 
1717A Slack workspace or Enterprise Grid pairs with one Claude organization at a time.
1818 
19To move a pairing to a different Claude organization, an Owner in the organization that currently holds it must [disconnect it](#revoke-a-pairing) first. Until then, the console refuses the new pairing as [already connected to a different organization](/docs/claude-tag/admins/troubleshooting#already-connected-to-a-different-organization). Once the pairing moves, changes the previous organization's admins make in their settings no longer reach that workspace.
19To move a pairing to a different Claude organization, an Owner in the organization that currently holds it must [disconnect it](#revoke-a-pairing) first. Until then, Claude Tag refuses the new pairing as [already connected to a different organization](/docs/claude-tag/admins/troubleshooting#already-connected-to-a-different-organization). Once the pairing moves, changes the previous organization's admins make in their settings no longer reach that workspace.
2020 
2121If your company has more than one Claude organization (a subsidiary with its own, for example), agree on which one holds the pairing before connecting.
2222 
2323<Steps>
2424 <Step title="Open the pairing dialog">
25 At [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), under **Where Claude Tag works**, either select **+ Connect** at the top right, or open the **⋮** menu on the Slack row and select **+ Add workspace**.
25 Go to [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack). On the **General** tab, under **Connected workspaces**, click **Connect a workspace**.
2626 </Step>
2727 
2828 <Step title="Get a pairing code from Slack">
from line 30
3030 
3131 Pick a channel that belongs to just the new workspace. Claude can decline to reply in [guest and shared channels](/docs/claude-tag/admins/troubleshooting#guest-and-shared-channels).
3232 </Step>
33 
34 <Step title="Finish the dialog and launch">
35 Once the code is accepted, click **Next**, work through the dialog's remaining steps, and click **Launch Claude** on the last one.
36 </Step>
3337</Steps>
3438 
3539<Note>If your organization used the earlier Claude in Slack app, the new workspace is added alongside your existing one, not in place of it.</Note>
3640 
37**You'll see:** the new workspace in the Slack row's connected list and as a scope in the **Claude Tag's access** section.
41**You'll see:** the new workspace in the **Connected workspaces** list with the status **Active**, and as a row on the **Channels** tab.
3842 
3943## Set up Claude Tag on Enterprise Grid
4044 
from line 69
6569Paste the `enterprise_` code in one of these places:
6670 
6771* **During setup:** paste the code into the **Paste the pairing code** field on the [setup page](/docs/claude-tag/admins/setup-overview#pair-your-slack-workspace)
68* **After setup:** go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Where Claude Tag works** > the Slack row's **⋮** menu > **+ Add workspace**, and paste the code into the dialog
72* **After setup:** click **Connect a workspace** under **Connected workspaces** on the **Slack** page, as in [Pair another workspace](#pair-another-workspace), and paste the code into the dialog. The Grid's row in the list shows **Enterprise Grid**.
6973 
7074Claude answers a one-to-one direct message according to the pairing of the sender's home workspace, so only the Grid-wide pairing covers DMs from every workspace in the Grid.
7175 
from line 77
7377 
7478## Turn Claude Tag on or off and set the version for a scope
7579 
76Each scope has two controls, an **Enable Claude Tag** switch that turns Claude on or off there and a **Claude Tag version** setting that chooses which version answers while the scope is on. On the Team plan, a single [**Enable Claude Tag** switch](#turn-claude-tag-on-or-off-on-the-team-plan) replaces them. Both controls are on the scope's panel at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → the scope. Channels Claude was added to appear under **Slack** automatically, and the **Search channels** field finds a channel's scope by name or ID.
80Each workspace and channel has its own page with two controls: an enable switch that turns Claude on or off there, and a **Claude Tag version** setting that chooses which version answers while it's on. On the Team plan, a [single switch on the **Slack** page](#turn-claude-tag-on-or-off-on-the-team-plan) replaces them. To open a workspace's or channel's page, go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open the **Channels** tab under **Claude's access**, and select the workspace or channel. To find a channel, search for it by name.
7781 
78The **Enable Claude Tag** switch sits at the top of the scope's panel. While the switch is off, Claude doesn't respond to @-mentions in the scope. One-to-one direct messages from members who have connected a Claude account are unaffected. Turning the switch on routes the scope to **New**. To make a workspace or channel follow its parent again, click **Use inherited setting** under the switch.
82The enable switch, **Enable Claude Tag in this workspace** or **Enable Claude Tag in this channel**, sits at the top of the page's **General** tab. While the switch is off, Claude doesn't respond to @-mentions there. One-to-one direct messages from members who have connected a Claude account are unaffected. Turning the switch on routes the workspace or channel to **New**. To make it follow its parent again, click **Use inherited setting** under the switch.
7983 
80The **Claude Tag version** setting is under the scope's **Advanced** section and is unavailable while the scope's switch is off. Choosing **Inherit** clears the scope's own setting entirely, so the scope also follows its parent for on or off.
84The **Claude Tag version** setting is on the page's **Advanced** tab and is unavailable while Claude Tag is off there. Choosing **Inherit** clears the workspace's or channel's own setting entirely, so it also follows its parent for on or off.
8185 
8286| Label | Effect |
8387| :- | :- |
84| **New** | Claude Tag. Access bundles, skills, and custom instructions apply |
88| **New** | Claude Tag. Bundles, skills, and custom instructions apply |
8589| **Legacy** | The earlier per-user Claude in Slack. Bundles and skills do not apply. Being deprecated; see [Migrate from the earlier app](/docs/claude-tag/admins/migrate-from-earlier) |
86| **Inherit** | Use the parent scope's value. Not shown at **Default Slack access** |
90| **Inherit** | Use the parent's value. Not shown on the **Slack** page |
8791 
88Both versions answer through the same @Claude app, so turning a scope's **Enable Claude Tag** switch off silences the Legacy version there too. To opt out of Claude Tag while keeping the earlier behavior, leave the switch on and set the scope's **Claude Tag version** to **Legacy**.
92Turning off **Respond in all channels** doesn't stop Claude in a workspace or channel whose own enable switch is on. On the Enterprise plan, launching setup for a single workspace turns on that workspace's enable switch, so Claude keeps responding in that workspace. The switch is at the top of the **General** tab on the **Slack** page, which sets the default for every workspace and channel. Direct messages from members who have connected a Claude account are unaffected.
8993 
94Both versions answer through the same @Claude app, so turning off a workspace's or channel's enable switch silences the Legacy version there too. To opt out of Claude Tag while keeping the earlier behavior, leave the switch on and set **Claude Tag version** to **Legacy**.
95 
9096Per-scope version changes (workspace and channel) are reversible; see [Migrate from the earlier app](/docs/claude-tag/admins/migrate-from-earlier).
9197 
98### What each Claude Tag switch turns off
99 
100Each of these switches turns Claude off in a different part of Slack. To stop only direct messages, see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
101 
102| Switch | Where it is | When it's off |
103| :- | :- | :- |
104| **Enable Claude Tag in Slack** | The top of [Claude Tag admin settings](https://claude.ai/admin-settings/claude-tag) | Claude is off in every channel and in direct messages |
105| **Respond in all channels** | The top of the **General** tab on the [**Slack** page](https://claude.ai/admin-settings/claude-tag/channels/slack) | Claude is off in channels, except where the channel's or its workspace's own enable switch is on |
106| **Respond in channels** | The same place as **Respond in all channels**, [on the Team plan](#turn-claude-tag-on-or-off-on-the-team-plan) | Claude is off in the channels of every connected workspace |
107| **Enable Claude Tag in this workspace** | The top of the **General** tab on the workspace's page | Claude is off in that workspace's channels, except a channel whose own enable switch is on |
108| **Enable Claude Tag in this channel** | The top of the **General** tab on the channel's page | Claude is off in that channel |
109 
92110## Turn Claude Tag on or off on the Team plan
93111 
94On the [Team plan](https://claude.com/pricing), you turn Claude on or off in every connected Slack workspace with one switch, at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag**. The switch doesn't override a workspace whose own **Enable Claude Tag** switch is off. On the Enterprise plan, and in a Team organization whose Slack configuration can't be expressed as one on-or-off choice (a scope set to **Legacy**, a workspace or channel set to **New**, a channel switched off, an access bundle attached to a channel, or a migration from the earlier Claude in Slack still in progress), the workspace and channel entries under **Slack** each show their own **Enable Claude Tag** switch and a **Claude Tag version** setting instead of the single switch; use [Turn Claude Tag on or off and set the version for a scope](#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope).
112On the [Team plan](https://claude.com/pricing), one switch turns Claude on or off in the channels of every connected Slack workspace: **Respond in channels**, at the top of the **General** tab at [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack). The switch doesn't override a workspace that was turned off on its own.
95113 
114On the Enterprise plan, and in a Team organization whose Slack configuration can't be expressed as one on-or-off choice, the **Slack** page shows **Respond in all channels** instead, and each workspace and channel page has its own enable switch and **Claude Tag version** setting. A Team organization gets those controls when any of these is true:
115 
116* The **Slack** page, a workspace, or a channel is set to **Legacy**
117* A workspace or channel is set to **New** on its own page
118* A channel is switched off on its own page
119* A bundle or connector is added directly to a channel
120 
121For those controls, see [Turn Claude Tag on or off and set the version for a scope](#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope).
122 
96123### Turn Claude off in channels
97124 
98Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag** and turn the switch off. An @-mention in any channel gets "Claude is disabled in this channel" while the switch is off. One-to-one direct messages from members who have connected a Claude account keep working. To stop those too, turn off the [**Allow direct messages**](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages) toggle. For members who haven't connected an account, see [Stop direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#stop-direct-messages-from-members-without-a-claude-account).
125Turn off **Respond in channels** on the **Slack** page. An @-mention in any channel gets "Claude is disabled in this channel" while the switch is off. One-to-one direct messages from members who have connected a Claude account keep working. To stop those too, go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), click **Edit** on the **Direct messages** row, and turn off [**Allow direct messages**](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages). For members who haven't connected an account, see [Stop direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#stop-direct-messages-from-members-without-a-claude-account).
99126 
100127### Turn Claude back on
101128 
102Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag** and turn the switch on. Everything you set on each scope, such as [access bundles](/docs/claude-tag/admins/attach-to-scope) and [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions), applies again. A workspace that was turned off on its own stays off, along with its channels.
129Turn on **Respond in channels** on the **Slack** page. Everything you set on the **Slack** page and on each workspace's and channel's page, such as [bundles](/docs/claude-tag/admins/attach-to-scope) and [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions), applies again. A workspace that was turned off on its own stays off, along with its channels.
103130 
104131### Turn Claude off for the whole organization
105132 
106Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and turn off the **Enable Claude Tag for your organization** toggle at the top of the page, above **Claude Tag's access**. That toggle turns off direct messages too.
133Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and turn off the **Enable Claude Tag in Slack** switch at the top of the page. That switch turns off direct messages too.
107134 
108135### Keep Claude out of specific channels
109136 
from line 138
111138 
112139### Notices that settings aren't applied
113140 
114When a workspace or channel entry shows a notice that its settings aren't applied, nothing you set there is lost.
141When a workspace's or channel's page shows a notice that its settings aren't applied, nothing you set there is lost.
115142 
116143| Notice | What to do |
117144| :- | :- |
118| "These settings aren't applied while Claude Tag is disabled. They're saved and will take effect once it's enabled." | Go to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) → **Claude Tag's access** → **Slack** → **Default Slack** → **Enable Claude Tag** and turn the switch on |
145| "These settings aren't applied while Claude Tag is disabled. They're saved and will take effect once it's enabled." | Turn on **Respond in channels** on the **Slack** page |
119146| "These settings aren't applied while Claude Tag is turned off for this workspace or channel; the org-wide Enable Claude Tag setting doesn't override that. They're saved and will take effect once it's turned back on." | The workspace, or the channel's workspace, was turned off on its own, and the switch doesn't override that. While you have the single switch, the admin page has no control for that workspace setting |
120| "These settings aren’t applied while Claude Tag setup is incomplete for this workspace or channel." | Select the **Resume** *workspace* **setup** button beside the notice and finish that workspace's setup. On a channel's entry, the button's label names the channel's workspace |
147| "These settings aren’t applied while Claude Tag setup is incomplete for this workspace or channel." | Select the **Resume** *workspace* **setup** button beside the notice and finish that workspace's setup. On a channel's page, the button's label names the channel's workspace |
121148 
122149## Revoke a pairing
123150 
124In the **Connected workspaces** list, select **Disconnect** on the workspace's row, then confirm in the dialog. Claude stops responding in that workspace's channels immediately, and your organization is no longer billed for Claude usage there. One-to-one direct messages from members who have connected a Claude account run on the member's own account, so they keep working until the deletion below removes the member's account link. A member who reconnects their account afterward can use direct messages again while the app stays installed.
151Go to [**Claude's access > Channels > Slack**](https://claude.ai/admin-settings/claude-tag/channels/slack). Under **Connected workspaces** on the **General** tab, click **Disconnect** on the workspace's row, type the workspace's name to confirm, and click **Disconnect**. While **Enable Claude Tag in Slack** is off, the same list appears under **Claude Tag in Slack** in Claude Tag admin settings.
125152 
153Claude stops responding in that workspace's channels immediately, and your organization is no longer billed for Claude usage there. One-to-one direct messages from members who have connected a Claude account run on the member's own account, so they keep working until the deletion below removes the member's account link. A member who reconnects their account afterward can use direct messages again while the app stays installed.
154 
126155<Warning>
127156 When you disconnect a workspace, Anthropic deletes its Claude data:
128157 
from line 164
135164 Deletion starts as soon as you confirm and runs to completion in the background. This can't be undone. Routines a person set up in a one-to-one direct message with Claude belong to that person's account and keep running.
136165</Warning>
137166 
138Access bundles belong to your organization, not to a workspace, so they stay available to attach to other scopes; only their bindings to the deleted scopes go.
167Bundles belong to your organization, not to a workspace, so they stay available to add to other workspaces and channels; only their bindings to the deleted workspace and its channels go.
139168 
140After you disconnect, the Slack row under **Where Claude Tag works** shows **Disconnected** with the workspace's name, and offers a **Reconnect** action, as a button on that row and in the row's **⋮** menu. **Reconnect** reopens the pairing dialog, where you redeem a fresh code from `@Claude connect`.
169After you disconnect, the workspace leaves the **Connected workspaces** list. If it was your only connected workspace, the top of Claude Tag admin settings shows that it was disconnected from Slack, with a **Reconnect** button. **Reconnect** reopens the pairing dialog, where you redeem a fresh code from `@Claude connect`.
141170 
142171The Slack app stays installed, so a workspace admin can pair the workspace again by sending `@Claude connect` in it, to the same Claude organization or a different one. If you intend the data to be deleted, wait a few minutes before pairing the workspace to the same organization again, because a new pairing that arrives while the deletion is still starting can cancel it. Once the deletion has run, the new pairing starts without the deleted data. Uninstalling the app from the workspace in Slack deletes the same data, whether or not you disconnected first; see [Quiet or remove Claude Tag](/docs/claude-tag/admins/restrict-access#quiet-or-remove-claude-tag).
143172 

claude-tag/concepts/agent-identity Changed · +13 / -11 lines

from line 10
1010 
1111In Slack channels, and in [group DMs](#group-dms) that include Claude, Claude acts with its own service accounts, rather than as a specific user. An organization Owner [provisions this identity](/docs/claude-tag/admins/setup-overview#give-claude-access-to-your-tools), so Claude has its own account in each system it works in: the Claude app in Slack, the Claude GitHub App on GitHub, and a service account in every other connected tool. Actions it takes are attributed to those accounts; for example, posts come from the Claude app and pull requests show the Claude GitHub App as the author. Claude can also use your own claude.ai connectors for a task you hand it in a channel, after you allow it. See [Personal connectors in a channel](#personal-connectors-in-a-channel).
1212 
13In one-to-one direct messages (DMs) between `@Claude` and a user who has connected a Claude account, the provisioned identity does not apply. A DM session runs on [the individual's own claude.ai account](#direct-message-channels) instead, with their personal connectors. A pull request opened from a DM is authored by the Claude GitHub App, the same as in channels, though the session can only work with repositories connected on that user's own account. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages). For DMs from users who haven't connected a Claude account, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#direct-messages-from-members-without-a-claude-account).
13In one-to-one direct messages (DMs) between `@Claude` and a user who has connected a Claude account, the provisioned identity does not apply. A DM session runs on [the individual's own claude.ai account](#direct-message-channels) instead, with their personal connectors. A pull request opened from a DM is authored by the Claude GitHub App, the same as in channels, though the session can only work with repositories connected on that user's own account. An Owner can turn off DMs for the whole organization; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages). For DMs from users who haven't connected a Claude account, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#direct-messages-from-members-without-a-claude-account).
1414 
1515<Note>
1616 How Claude behaves in channels (its standing instructions, plugins, and channel memory) is configured separately from its identity; see [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions), [plugins](/docs/claude-tag/admins/add-connections#attach-plugins), and [memory](/docs/claude-tag/users/memory) for more information.
from line 22
2222 
2323* The ask happens in your Slack workspace, when a user tags Claude to do something or a scheduled task starts.
2424* The work Claude does runs in a sandbox, an isolated working environment built for the thread.
25* The agent's credentials for any additional connections, such as GitHub or a data warehouse, reach those systems to pull the required information. An organization Owner sets up those credentials as part of [provisioning the identity](/docs/claude-tag/admins/setup-overview#create-accounts-for-claude%E2%80%99s-other-tools).
25* The agent's credentials for any additional Claude Tag connectors, such as GitHub or a data warehouse, reach those systems to pull the required information. An organization Owner sets up those credentials as part of [provisioning the identity](/docs/claude-tag/admins/setup-overview#create-accounts-for-claude%E2%80%99s-other-tools).
2626 
2727The diagram below traces one request through this process.
2828 
from line 44
4444 </Step>
4545 
4646 <Step title="Agent Proxy attaches a credential">
47 A matching credential comes from the credential store, where an admin's [connections](/docs/claude-tag/admins/add-connections) are kept. Once saved, a credential is never displayed again; Agent Proxy retrieves it only at the moment of injection and attaches it to the request at the boundary, so the model and the sandbox itself are not given the key.
47 A matching credential comes from the credential store, which keeps the credentials of the [connectors](/docs/claude-tag/admins/add-connections) an admin added. Once saved, a credential is never displayed again; Agent Proxy retrieves it only at the moment of injection and attaches it to the request at the boundary, so the model and the sandbox itself are not given the key.
4848 </Step>
4949 
5050 <Step title="The result posts back, as Claude">
from line 58
5858 
5959| When the destination | Result |
6060| :- | :- |
61| Matches a connection's rule, its [allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) | The proxy attaches that connection's credential and forwards the request. The credential stays at the proxy; the model and sandbox are not given it. |
62| Is on the [bundle](/docs/claude-tag/concepts/glossary#access-bundle)'s [Domains list](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) but matches no connection | The proxy forwards the request without a credential. |
61| Matches a credential's rule, its [allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) | The proxy attaches that credential and forwards the request. The credential stays at the proxy; the model and sandbox are not given it. |
62| Is an [allowed domain](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) that applies to the channel, but matches no credential | The proxy forwards the request without a credential. |
6363| Is allowed by the network access setting of the [environment](/docs/claude-tag/concepts/glossary#environment) the [scope](/docs/claude-tag/concepts/glossary#scope)'s sessions run on | The proxy forwards the request without a credential. |
6464| Matches none of these | The proxy blocks the request. |
6565 
from line 75
7575 
7676A host that none of the three layers above allows is blocked, and Claude names the blocked host in the thread so an admin can add it; see [Give Claude access to your tools](/docs/claude-tag/admins/add-connections).
7777 
78<a id="web-search-vs-network-requests" />
79 
7880### Web search vs. network requests
7981 
8082Claude can search the web from a channel without any Domains entry. Web search is [Anthropic's built-in web search tool](https://platform.claude.com/docs/en/agents-and-tools/tool-use/web-search-tool), which runs on Anthropic's servers, not code running in the channel's sandbox.
from line 89
8789 
8890### Agent access
8991 
90What Claude can reach in a channel comes from the [Access bundles](/docs/claude-tag/admins/add-connections) an admin attached to that channel's scope. Anyone in the channel gets the same capability, and the same request can do more in `#platform-eng` than in a general channel.
92What Claude can reach in a channel comes from the [connectors, repositories, and plugins](/docs/claude-tag/admins/add-connections) an admin applies to that channel, to its workspace, or to all of Slack, either directly or through a bundle. Anyone in the channel gets the same capability, and the same request can do more in `#platform-eng` than in a general channel.
9193 
9294This design has four consequences.
9395 
9496* **Configure once.** Everyone in the scope can use it immediately.
9597* **Predictability.** What Claude can do never changes based on who asked.
96* **Personal connectors are separate.** A shared channel session uses only the service-account connections an admin attached. Claude [uses the connectors on your own claude.ai account](#personal-connectors-in-a-channel) only for your own tasks, after you allow it.
98* **Personal connectors are separate.** A shared channel session uses only the Claude Tag connectors an admin applied, which hold service-account credentials. Claude [uses the connectors on your own claude.ai account](#personal-connectors-in-a-channel) only for your own tasks, after you allow it.
9799* **Clean audit.** Actions the channel session takes in connected tools show up under a service account your security team already knows how to reason about.
98100 
99101That service-account identity is also how Claude appears wherever it acts. In Slack, it posts as the Claude app. On GitHub, commits and pull requests show the Claude GitHub App, and pull requests link back to the Slack thread they came from. In every other connected service, actions appear under the service account an admin provisioned, in that service's audit log.
from line 102
100102 
101103### Personal connectors in a channel
102104 
103A channel session works with the channel's Access bundles, so the [connectors on your own claude.ai account](/docs/connectors/getting-started) are not part of it. When a task you hand Claude needs something only your connectors can reach, Claude can use your connector for that part of the work, and it asks you before it starts. The work runs with your permissions and is recorded under your name. Requests other people make to Claude in the task's thread run with the channel's own access, not with your connectors. Claude is designed to take direction from you, treating what other people post in the thread as information for the task rather than as instructions.
105A channel session works with the access an admin applied to the channel, so the [connectors on your own claude.ai account](/docs/connectors/getting-started) are not part of it. When a task you hand Claude needs something only your connectors can reach, Claude can use your connector for that part of the work, and it asks you before it starts. The work runs with your permissions and is recorded under your name. Requests other people make to Claude in the task's thread run with the channel's own access, not with your connectors. Claude is designed to take direction from you, treating what other people post in the thread as information for the task rather than as instructions.
104106 
105107[Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) covers how you approve connector use, when Claude holds a result for your review before posting, what other people in the channel see, and how to stop a task.
106108 
from line 119
117119| | In a channel | In a one-to-one DM |
118120| :- | :- | :- |
119121| Acts as | Its own service accounts | You |
120| Access | The channel's Access bundles | Your personal connectors |
122| Access | The access an admin applied to the channel | Your personal connectors |
121123| Attribution | The agent's accounts, in each tool's audit log | Your name, except pull requests, which the Claude GitHub App authors |
122124| Billing | The organization | Your seat |
123125 
from line 127
125127 
126128* **Connectors.** The [connectors on your account](/docs/connectors/getting-started) are available, including MCP servers you've added.
127129* **Billing.** Usage bills to your seat rather than the organization's service key.
128* **Channel-side configuration.** It doesn't follow you in; the agent's connections and repository grants don't apply in one-to-one DMs.
130* **Channel-side configuration.** It doesn't follow you in; the agent's connectors and repository grants don't apply in one-to-one DMs.
129131 
130132DM work runs under your credentials, so most of it is attributed to you and can reach only what your own accounts can. Pull requests are the exception: Claude authors them as the Claude GitHub App from DMs too, so a repository's history shows the same author either way, while the repositories it can reach are still only the ones connected on your own account.
131133 
from line 141
139141| :- | :- | :- |
140142| **Runs under** | The agent identity an admin provisioned | Your own Claude account, linked in the Claude app |
141143| **GitHub** | The Claude GitHub App; pull requests belong to the app | Your GitHub connection on claude.ai/code; pull requests open under your account |
142| **Access** | The Access bundles an admin attached to the channel | Your personal connectors |
144| **Access** | The access an admin applied to the channel | Your personal connectors |
143145| **Billing** | The organization | Your seat |
144146 
145147If `@Claude` in your workspace opens pull requests as you, you're seeing Claude Code in Slack, not a Claude Tag session.

claude-tag/concepts/data-lifecycle Changed · +12 / -12 lines

from line 6
66 
77<BetaNote />
88 
9Claude Tag keeps a record of its work on Anthropic's side, separate from the messages in your Slack workspace. This page is for the Owner or security reviewer who needs to know what that record contains, how long Anthropic keeps it, and which actions in Slack or in your Claude admin settings delete it. For each action, the tables below say what is deleted and whether Claude keeps responding, because the two don't always go together.
9Claude Tag keeps a record of its work on Anthropic's side, separate from the messages in your Slack workspace. This page is for an Owner or security reviewer who needs to know what that record contains, how long Anthropic keeps it, and which actions in Slack or in your Claude admin settings delete it. For each action, the tables below say what is deleted and whether Claude keeps responding, because the two don't always go together.
1010 
1111## What Anthropic stores
1212 
from line 17
1717| Session transcripts | The record of one thread's, channel's, or direct message's work. A transcript holds the messages Claude was shown in the conversation and who sent them, files attached there, earlier versions of messages that were later edited, what Claude retrieved while working (Slack search results, messages it read in channels it's in, and data from connected tools), and everything Claude said and did |
1818| Memory | The notes Claude saves for each channel, the workspace notes it saves from public channels, and separate notes for each direct-message conversation. See [What Claude Tag remembers](/docs/claude-tag/users/memory) |
1919| Routines | The scheduled and run-once tasks set up in channels or in direct messages, with their instructions and run history |
20| Scopes and their settings | Each workspace and channel [scope](/docs/claude-tag/concepts/glossary#scope), with its custom instructions, version setting, and Access bundle bindings |
21| Access bundles | The connections and credentials an Owner provisions. Bundles belong to your organization, not to a workspace |
20| Scopes and their settings | Each workspace and channel [scope](/docs/claude-tag/concepts/glossary#scope), with its custom instructions, version setting, and the bundles and access applied there |
21| Bundles and connectors | The [bundles](/docs/claude-tag/concepts/glossary#bundle), connectors, and credentials set up for Claude Tag. They belong to your organization, not to a workspace |
2222| Account links | The link between each member's Slack account and their Claude account, and the tokens that link uses |
2323| Published artifacts | Pages a session published to claude.ai. See [Artifact visibility](/docs/claude-tag/concepts/security-and-data#artifact-visibility) |
2424| The app's installation credential | The token the Claude app uses to read and post in your Slack workspace |
from line 43
4343 
4444| Action | Claude-side data | Does Claude keep responding? |
4545| :- | :- | :- |
46| A Slack admin uninstalls the Claude app from a workspace | Deleted, the same as [disconnecting the workspace](#actions-in-claude), plus the app's installation credential for that workspace. Access bundles, and routines members set up in one-to-one direct messages, stay | No. The app is removed from the workspace |
46| A Slack admin uninstalls the Claude app from a workspace | Deleted, the same as [disconnecting the workspace](#actions-in-claude), plus the app's installation credential for that workspace. Bundles, and routines members set up in one-to-one direct messages, stay | No. The app is removed from the workspace |
4747| On Enterprise Grid, a Grid admin removes an org-wide installation of the app, from the whole grid or from one of its workspaces | Nothing is deleted. To delete the data, an Owner disconnects the grid, or a workspace that has its own pairing, in your Claude admin settings | No |
4848| A channel is deleted in Slack | Deleted: that channel's sessions and transcripts, including earlier sessions Claude had archived there, its channel memory, and its scope with the routines and artifacts that belong to it. Workspace notes Claude saved from a public channel aren't tied to the channel and stay until you delete them or disconnect the workspace, as does anything created under the workspace scope rather than the channel's own | Not applicable |
4949| A channel is archived in Slack | Nothing is deleted. Unarchiving the channel picks its memory, routines, and sessions back up | Not while the channel is archived |
from line 59
5959 
6060| Action | Claude-side data | Does Claude keep responding? |
6161| :- | :- | :- |
62| An Owner [disconnects a workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing) | Deleted: the workspace's sessions and transcripts, including members' direct-message conversations there; its channel, workspace, and direct-message memory; the routines set up in its channels and the artifacts published from them; its scopes with their instructions and bundle bindings; and members' account links. The Slack app and its installation credential stay so a workspace admin can pair again, and Access bundles, routines members set up in one-to-one direct messages, and what Claude posted in Slack stay too. Pairing the same workspace to the same organization again within a few minutes can cancel the deletion | Stops in channels immediately. One-to-one direct messages keep working on each member's own Claude account until the deletion removes that member's account link |
62| An Owner [disconnects a workspace](/docs/claude-tag/admins/workspaces#revoke-a-pairing) | Deleted: the workspace's sessions and transcripts, including members' direct-message conversations there; its channel, workspace, and direct-message memory; the routines set up in its channels and the artifacts published from them; its scopes with their instructions and bundle bindings; and members' account links. The Slack app and its installation credential stay so a workspace admin can pair again, and bundles, routines members set up in one-to-one direct messages, and what Claude posted in Slack stay too. Pairing the same workspace to the same organization again within a few minutes can cancel the deletion | Stops in channels immediately. One-to-one direct messages keep working on each member's own Claude account until the deletion removes that member's account link |
6363| An Owner disconnects an Enterprise Grid | The same as disconnecting a workspace, for every workspace in the grid that doesn't have its own workspace pairing, plus the app's installation credentials for those workspaces. Workspaces you paired individually stay connected and keep their data until you disconnect them | Stops in the affected workspaces |
64| An Owner removes a channel's scope with **Remove this scope** in the **Claude Tag's access** section | Deleted: the channel's sessions and transcripts recorded up to that moment, including threads still in progress, its memory, its routines, and the artifacts published from it. The Slack channel itself is unchanged | Yes. Claude stays in the channel and, when tagged again, starts fresh under the access it inherits from the workspace. To stop it as well, run `/remove @Claude` or turn the scope's **Enable Claude Tag in this channel** switch off first |
65| An Owner turns a scope's **Enable Claude Tag** switch off, turns off Claude in Slack for the organization, or turns off [direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages) | Nothing is deleted. Turning the setting back on resumes with the existing memory, routines, and sessions | No, in the affected scope |
66| An Owner detaches a bundle from a scope, or deletes an Access bundle | Detaching removes the binding, and deleting a bundle removes its credentials everywhere it was attached. Memory, routines, and transcripts are unaffected | Yes, without that access |
64| An Owner removes a channel's scope with **Remove this scope** in the **⋯** menu of the channel's page | Deleted: the channel's sessions and transcripts recorded up to that moment, including threads still in progress, its memory, its routines, and the artifacts published from it. The Slack channel itself is unchanged | Yes, where the channel's workspace has its own setting on, or has no setting of its own and the **Slack** page's setting is on. Claude stays in the channel and, when tagged again, starts fresh under the access it inherits from the workspace. To stop it as well, first run `/remove @Claude` |
65| An Owner or a Claude Tag admin turns off a workspace's **Enable Claude Tag in this workspace** switch, a channel's **Enable Claude Tag in this channel** switch, or **Respond in all channels** (or **Respond in channels**) on the **Slack** page, or an Owner turns off **Enable Claude Tag in Slack** for the organization or [direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages) | Nothing is deleted. Turning the setting back on resumes with the existing memory, routines, and sessions | No, where the setting is off |
66| An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) removes a place from a bundle's **Where it applies** list, or deletes a bundle | Removing a place removes the binding, and deleting a bundle deletes its credentials everywhere it applied. Memory, routines, and transcripts are unaffected | Yes, without that access |
6767| An Owner deletes entries from a scope's memory files, or someone in the channel tells Claude to forget an entry | The entry is removed from what Claude reads and from the memory files view. Earlier versions of the scope's memory remain stored with the scope until the scope's data is deleted | Yes |
68| An Owner deletes a channel's routine from the [**Scheduled work** tab](/docs/claude-tag/admins/audit#what-the-audit-view-lists), or someone asks Claude to delete a routine in the channel or direct message where it was set up | The routine and the sessions it ran are deleted. Pausing a routine there, or disabling it from the channel, keeps it on record | Yes |
68| An Owner deletes a channel's routine from the [**Scheduled work** tab](/docs/claude-tag/admins/audit#what-the-activity-page-lists), or someone asks Claude to delete a routine in the channel or direct message where it was set up | The routine and the sessions it ran are deleted. Pausing a routine there, or disabling it from the channel, keeps it on record | Yes |
6969| A member selects **Disconnect** in the Claude app's **Home** tab in Slack | Removes the link between their Slack and Claude accounts and revokes the tokens Claude Tag held for them. Their earlier direct-message conversations and notes, and channel work they started, aren't deleted; those go with the workspace | In channels, yes. One-to-one direct messages and personal connectors stop working for that member until they reconnect |
7070| A member is removed from your Claude organization | Nothing is deleted. They lose access within minutes, and routines they set up in one-to-one direct messages are turned off. Their account link, direct-message conversations, and notes stay until the workspace is disconnected | Not to that member |
7171| A member deletes their own Claude account | On Team and Enterprise plans, deleting an individual account doesn't remove the Claude Tag data your organization holds about that member, including their direct-message conversations and notes and their account link. A member who wants the link and its tokens removed can select **Disconnect** in Slack before deleting their account | Not to that member |
from line 84
8484 
8585The controls that delete Claude Tag data, from largest to smallest:
8686 
87* **Disconnect a workspace or an Enterprise Grid** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), or uninstall the app from the workspace in Slack. Deletes all of that workspace's data. See [Revoke a pairing](/docs/claude-tag/admins/workspaces#revoke-a-pairing)
88* **Remove a channel's scope** in the **Claude Tag's access** section. Deletes that channel's data recorded so far
89* **Delete a scope's memory files**: select **View memory files** in the scope's options menu, choose a file, then select **Delete**. You can also tell Claude in the channel to forget an entry. See [Check and correct what Claude Tag remembers](/docs/claude-tag/users/memory#check-and-correct-what-claude-tag-remembers)
87* **Disconnect a workspace or an Enterprise Grid** under **Connected workspaces** on the **Slack** page, which you open with the **Slack** row on the **Channels** tab under **Claude's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), or uninstall the app from the workspace in Slack. Deletes all of that workspace's data. See [Revoke a pairing](/docs/claude-tag/admins/workspaces#revoke-a-pairing)
88* **Remove a channel's scope**: open the channel from the **Channels** tab under **Claude's access**, then select **Remove this scope** in the page's **⋯** menu, if the menu lists it. Deletes that channel's data recorded so far
89* **Delete memory files**: open the workspace's page from the **Channels** tab (or a channel's page, when that channel has memory of its own), choose **View memory files** from its **⋯** menu if the menu lists it, pick a file, then select **Delete**. Deleting requires the Owner role. You can also tell Claude in the channel to forget an entry. See [Check and correct what Claude Tag remembers](/docs/claude-tag/users/memory#check-and-correct-what-claude-tag-remembers)
9090* **Delete a routine**: an Owner deletes a channel's routine from the **Scheduled work** tab. You can also ask Claude to delete a routine in the channel or direct message where it was set up. See [Audit Claude Tag activity](/docs/claude-tag/admins/audit)
9191 
9292There is no control in Slack or in your Claude admin settings that deletes a single thread's transcript on its own. During the beta, Claude Tag session transcripts and memory aren't included in your organization's data exports, and the Compliance API doesn't list or delete Claude Tag sessions. For a deletion request these controls don't cover, contact your account team or [[email protected]](mailto:[email protected]).

claude-tag/concepts/glossary Changed · +22 / -18 lines

## Bundle ## Personal connector ## Access bundle ## Connection

from line 1
11# Glossary
22 
3> Claude Tag terms defined in one place. See agent identity, Access bundle, channel manager, connection, scope, Agent Proxy, routine, channel memory, environment, and session.
3> Claude Tag terms defined in one place, including agent identity, bundle, connector, personal connector, scope, Agent Proxy, routine, and session.
44 
55export const BetaNote = () => <Info>Claude Tag is in public beta. Features and behavior described here may change before general availability.</Info>;
66 
77<BetaNote />
88 
9## Access bundle
10 
11A named set of connections, [domain entries](/docs/claude-tag/admins/add-connections#add-a-domain), repository access, and rules that an Owner or a [Claude Tag admin](#claude-tag-admin) creates for Claude to use. Bundles attach to scopes, and one bundle can serve many scopes. See [Give Claude access](/docs/claude-tag/admins/add-connections).
12 
139## Agent identity
1410 
1511The service accounts Claude acts with: the Claude app in Slack, the Claude GitHub App on code, and the credentials an admin provisions for every other tool. See [How agent identity works](/docs/claude-tag/concepts/agent-identity).
from line 14
1814 
1915The network layer that injects credentials into Claude's outbound requests. The model and the sandbox are not given the key; Agent Proxy adds the credential at the network boundary when a request matches the rules an admin set. See [How agent identity works](/docs/claude-tag/concepts/agent-identity#agent-proxy).
2016 
17<a id="access-bundle" />
18 
19## Bundle
20 
21A named set of connectors, repositories, [allowed domains](/docs/claude-tag/admins/add-connections#add-a-domain), plugins, and instructions that Claude uses for one kind of work, such as support triage. An Owner or a [Claude Tag admin](#claude-tag-admin) creates bundles on the **Bundles** tab under **Claude's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), then adds the places where each one applies: all of Slack, a workspace, or a channel. One bundle can apply in many places, and an Owner can also apply one to every channel whose name matches a pattern. See [Give Claude access](/docs/claude-tag/admins/add-connections).
22 
2123## Channel manager
2224 
2325A member of your Claude organization named to set up specific channels. For each channel assigned to them, a channel manager sets the default model, adds repositories their own GitHub account is an admin of, and manages credentials and plugins in the channel's own bundle, without holding the Owner role. See [Delegate channel setup to channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers).
from line 30
2830 
2931## Claude Tag admin
3032 
31A member of your Claude organization whose custom role includes the **Claude Tag Admin** permission, available on the Enterprise plan. A Claude Tag admin manages Access bundles, attaches them to scopes, and edits workspace and channel settings, without holding the Owner role. A Claude Tag admin whose role also sets **Identity & Access** to **Can manage** can add and remove [channel managers](#channel-manager). See [Delegate Claude Tag administration](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration).
33A member of your Claude organization whose custom role includes the **Claude Tag Admin** permission, available on the Enterprise plan. A Claude Tag admin manages [bundles](#bundle), chooses where they apply, and edits workspace and channel settings, without holding the Owner role. A Claude Tag admin whose role also sets **Identity & Access** to **Can manage** can add and remove [channel managers](#channel-manager). See [Delegate Claude Tag administration](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration).
3234 
3335## The earlier Claude in Slack
3436 
from line 45
4345 
4446Your admin chooses which generation answers `@Claude` in a given channel, so two channels in the same workspace can work differently. See [Migrate from the earlier Claude in Slack](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope).
4547 
46## Connection
48<a id="connection" />
4749 
48A credential for one external service that Claude uses on the channel's behalf, like a Datadog API key or a GitHub App installation. Connections belong to the agent identity, not to any user, and are grouped into [Access bundles](#access-bundle) by an admin.
49 
50A connection is not a connector. A connector belongs to your personal claude.ai account. A channel session uses the channel's connections. Claude can also [use your connectors there](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it. A one-to-one DM uses your own account instead, as [how DMs work in this model](/docs/claude-tag/concepts/agent-identity#direct-message-channels) describes.
51 
5250## Connector
5351 
54A tool you add to your own claude.ai account, like Gmail, Google Drive, or a custom MCP server, listed under [Customize > Connectors](https://claude.ai/customize/connectors). Connectors are personal. In Slack they apply in one-to-one DMs. Claude can also [use them in a channel](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it. For the agent-side equivalent that works in channels, see [Connection](#connection).
52A service Claude Tag reaches with a credential of its own. An Owner or a [Claude Tag admin](#claude-tag-admin) adds connectors on the **Connectors** tab under **Claude's access**, and each connector holds one or more credentials, such as an API key for the service, that belong to the agent identity rather than to any user. To add a connector and choose where its credentials apply, see [Add a connector](/docs/claude-tag/admins/add-connections#add-a-connection). The [federated access](/docs/claude-tag/admins/federated-access/overview) pages and their console screens say **connection** for a gateway, cloud role, or authorization server Claude reaches with a token instead of a stored key.
5553 
54A channel session uses the Claude Tag connectors that apply to its channel. Claude can also [use your personal connectors there](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it. A one-to-one DM uses your own account instead, as [how DMs work in this model](/docs/claude-tag/concepts/agent-identity#direct-message-channels) describes.
55 
5656## Environment
5757 
5858The sandboxed compute configuration a session runs in, including its network access setting. Environments used here must be scoped to the organization, not to an individual account, because channel sessions run with no user account attached.
5959 
60## Personal connector
61 
62A tool you add to your own claude.ai account, like Gmail, Google Drive, or a custom MCP server, listed under [Customize > Connectors](https://claude.ai/customize/connectors). Personal connectors apply in your one-to-one DMs with Claude. Claude can also [use them in a channel](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it. For the connectors an admin adds for Claude Tag, see [Connector](#connection).
63 
6064## Plugin
6165 
62A bundle of skills an Owner or a [Claude Tag admin](#claude-tag-admin) attaches to an Access bundle or scope, teaching Claude how to use a specific tool or follow a specific process. Anthropic provides plugins for common tools; you can add your own. See [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins).
66A package of skills that teaches Claude how to use a specific tool or follow a specific process. An Owner or a [Claude Tag admin](#claude-tag-admin) adds a plugin to a bundle, or to all of Slack, a workspace, or a channel directly. Anthropic provides plugins for common tools; you can add your own. See [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins).
6367 
6468## Routine
6569 
66A scheduled or run-once task Claude runs on its own, such as a daily digest or a channel watch. Anyone in a channel can ask Claude to set one up, list what's scheduled, or disable one. Routines run with the channel's connections, not the creator's.
70A scheduled or run-once task Claude runs on its own, such as a daily digest or a channel watch. Anyone in a channel can ask Claude to set one up, list what's scheduled, or disable one. Routines run with the channel's access, not the creator's.
6771 
6872Claude Code also has a feature named routines. Those run under an individual user's account; Claude Tag routines run under the agent identity.
6973 
7074## Rule
7175 
72The match conditions Agent Proxy checks against each outbound request. A connection pairs one credential with the rule that decides when to inject it, and a request that matches the rule gets the credential attached at the boundary. A request that nothing allows (no rule, no domain entry, no [environment](#environment) network access setting) is blocked. See [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy).
76The match conditions Agent Proxy checks against each outbound request. Each credential has a rule that decides when to inject it, and a request that matches the rule gets the credential attached at the boundary. A request that nothing allows (no rule, no domain entry, no [environment](#environment) network access setting) is blocked. See [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy).
7377 
7478## Scope
7579 
76One of three levels Claude's settings can target: Default Slack access (the organization-wide root), one Slack workspace, or one channel (public or private). Scopes inherit downward, so a channel gets its workspace's settings plus any of its own. An Owner or a [Claude Tag admin](#claude-tag-admin) attaches [Access bundles](#access-bundle) and instructions at a scope. See [Attach the bundle to a scope](/docs/claude-tag/admins/attach-to-scope).
80One of three levels Claude's settings can target: all of Slack (the **Slack** page, the organization-wide root), one Slack workspace, or one channel (public or private). Scopes inherit downward, so a channel gets its workspace's settings plus any of its own. In Claude Tag admin settings, all of Slack, each workspace, and each channel have their own pages, which you open from the **Channels** tab under **Claude's access**. An Owner or a [Claude Tag admin](#claude-tag-admin) adds [bundles](#bundle), connectors, plugins, and instructions there. See [Attach the bundle to a scope](/docs/claude-tag/admins/attach-to-scope).
7781 
7882## Session
7983 
from line 86
8286## Related resources
8387 
8488* [How Claude Tag works](/docs/claude-tag/concepts/how-it-works): the scope, channel, and thread model in action
85* [How agent identity works](/docs/claude-tag/concepts/agent-identity): how connection, scope, and Agent Proxy fit together when Claude runs a task
86* [Set up Claude Tag](/docs/claude-tag/admins/setup-overview): where bundles, scopes, and connections get created in the console
89* [How agent identity works](/docs/claude-tag/concepts/agent-identity): how connectors, scopes, and Agent Proxy fit together when Claude runs a task
90* [Set up Claude Tag](/docs/claude-tag/admins/setup-overview): where bundles and connectors get set up in Claude Tag admin settings
8791 

claude-tag/concepts/how-it-works Changed · +7 / -7 lines

from line 198
198198 
199199### Channel access
200200 
201Connections extend a session's reach into your own systems. An organization admin attaches access to a scope (the organization, a workspace, or a single channel), so the same request can do more in one channel than in another, and everyone in a given channel works with the same capability.
201Claude Tag connectors extend a session's reach into your own systems. An organization admin applies access to all of Slack, to one workspace, or to a single channel, either directly or through a [bundle](/docs/claude-tag/concepts/glossary#bundle), so the same request can do more in one channel than in another, and everyone in a given channel works with the same capability.
202202 
203A thread locks in its skills, plugins, and custom instructions when it starts, and a running thread keeps that set. Connections and domain rules are enforced on each request, so one an admin adds mid-thread works in a running thread. Claude doesn't announce a new connection in an existing thread; ask it to use the service by name. A new thread picks up every kind of change, so after a configuration change, start a new top-level thread.
203A thread locks in its skills, plugins, and custom instructions when it starts, and a running thread keeps that set. Connectors and domain rules are enforced on each request, so one an admin adds mid-thread works in a running thread. Claude doesn't announce a new connector in an existing thread; ask it to use the service by name. A new thread picks up every kind of change, so after a configuration change, start a new top-level thread.
204204 
205205#### How to identify access
206206 
from line 207
207207Because access is set per channel rather than per person, the way to find out what a session can reach is to ask it, not to guess from your own permissions.
208208 
209209* **Ask what Claude can reach.** In any channel, `@Claude what can you access from this channel?` lists its current reach.
210* **If Claude cannot reach something, the channel was not granted access.** Another channel may have the access, and an organization Owner can add it. [How agent identity works](/docs/claude-tag/concepts/agent-identity) covers the model.
211* **Personal connectors are separate from channel connections.** A connection an admin attaches to a channel is separate from a connector on your personal claude.ai account. Your own connectors work in your one-to-one DMs. Claude can also [use them in a channel](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it.
210* **If Claude cannot reach something, the channel was not granted access.** Another channel may have the access, and an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) of your Claude organization can add it. [How agent identity works](/docs/claude-tag/concepts/agent-identity) covers the model.
211* **Personal connectors are separate from Claude Tag connectors.** A connector an admin applies to a channel is separate from a connector on your personal claude.ai account. Your own connectors work in your one-to-one DMs. Claude can also [use them in a channel](/docs/claude-tag/concepts/personal-connectors) for your own tasks, after you allow it.
212212 
213213### What Claude can do in other channels
214214 
from line 287
287287 
288288<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/ZNX07pWnPReWiLwB/images/claude-tag/diagrams/three-levels-dark.svg?fit=max&auto=format&n=ZNX07pWnPReWiLwB&q=85&s=9b28d67feff32743e5cc2094e8fc3ec9" alt="Diagram showing three nested levels. A scope container holds two channels, #platform-eng and #gtm-west, and each channel holds its own threads, like 'fix checkout latency' or 'pull deal state'. The private channel is marked with a lock. Callouts mark what lives at each level (identity and access at the scope, memory at the channel plus workspace notes shared from public channels, and work in progress at the thread). A DM with Claude sits below, outside every scope, and runs on your own account." width="1000" height="648" data-path="images/claude-tag/diagrams/three-levels-dark.svg" />
289289 
290One-to-one DMs are outside this picture; they run on your own account, as covered in [Team channels and personal DMs](#team-channels-and-personal-dms) above. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
290One-to-one DMs are outside this picture; they run on your own account, as covered in [Team channels and personal DMs](#team-channels-and-personal-dms). An Owner can turn off DMs for the whole organization; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
291291 
292292## What admins can see of your conversations with Claude
293293 
from line 294
294294Admins have no page or export that shows the individual messages people send Claude.
295295 
296296* **Analytics:** the [analytics page](https://claude.ai/analytics/claude-tag) reports spend by channel and by kind of work
297* **Audit page:** the [Audit page](/docs/claude-tag/admins/audit), available to Owners, lists scheduled work, memory files, and network events
297* **Activity page:** the [**Activity** page](/docs/claude-tag/admins/audit) in Claude Tag admin settings, available to Owners, lists scheduled work, memory files, and network events
298298* **Slack threads:** everyone in a channel can read the threads where Claude works, admins included
299299* **Session transcripts:** Anthropic keeps a [transcript of each session](/docs/claude-tag/concepts/data-lifecycle#what-anthropic-stores)
300300 

claude-tag/concepts/personal-connectors Changed · +8 / -8 lines

### What Claude Tag connectors in a channel can reach ### What channel connections can reach

from line 8
88 
99Personal connectors are the tools you add to your own claude.ai account, like your calendar or your email. When a task you ask for in a Slack channel needs one of your own tools, Claude can offer to use your connector for it.
1010 
11Personal connectors in channels are on for every organization on the Team plan, with nothing for an admin to set up. On the Enterprise plan, the **Personal connectors** section at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) says when they turn on for your organization. A channel also keeps working with the connections an admin attached to it, as described in [how agent identity works](/docs/claude-tag/concepts/agent-identity).
11Personal connectors in channels are on for every organization on the Team plan, with nothing for an admin to set up. On the Enterprise plan, an admin manages them in the **Personal connectors** dialog, which opens with **Edit** on the **Personal connectors** row at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag); see [Admin controls for personal connectors](#admin-controls-for-personal-connectors). A channel also keeps working with the Claude Tag connectors an admin attached to it, as described in [how agent identity works](/docs/claude-tag/concepts/agent-identity).
1212 
1313## Where your connectors apply
1414 
from line 21
2121 
2222Claude uses your connectors only while working on a request you made yourself.
2323 
24* **You ask in a channel.** When your task needs one of your own tools, Claude can use your connector for it. The channel also uses the connections an admin attached to it, and everyone who asks there gets the same access.
24* **You ask in a channel.** When your task needs one of your own tools, Claude can use your connector for it. The channel also uses the Claude Tag connectors an admin attached to it, and everyone who asks there gets the same access.
2525* **Someone else asks in a channel.** Your connectors serve only you. Their request doesn't control or use your connectors, even in a shared channel.
26* **Claude starts work on its own.** [Routines](/docs/claude-tag/users/proactivity) and other work Claude starts on its own in a channel use the channel's connections, never your connectors.
26* **Claude starts work on its own.** [Routines](/docs/claude-tag/users/proactivity) and other work Claude starts on its own in a channel use the channel's own access, never your connectors.
2727* **You ask in a [group DM](/docs/claude-tag/users/group-dms).** Claude uses your connectors after you allow it, and only your own requests use them.
2828* **You ask in a one-to-one direct message (DM).** Your connectors apply on their own, because a DM runs on [your own claude.ai account](/docs/claude-tag/concepts/agent-identity#direct-message-channels).
2929 
from line 41
4141 
4242If a teammate posts the same request, Claude can offer to use the calendar connected on their own claude.ai account. Claude never uses your connector for their request.
4343 
44### What channel connections can reach
44### What Claude Tag connectors in a channel can reach
4545 
46Connections an admin attached to the channel give everyone in the channel the same access. They use the account the admin set up for Claude in each service, so Claude reaches whatever that account can reach, whoever asks.
46Claude Tag connectors an admin attached to the channel give everyone in the channel the same access. They use the account the admin set up for Claude in each service, so Claude reaches whatever that account can reach, whoever asks.
4747 
48If a channel connection can open a document your own account can't, Claude can still read and summarize it in that channel when you ask. See [agent access](/docs/claude-tag/concepts/agent-identity#agent-access) for how admins limit what a channel can reach.
48If a Claude Tag connector in the channel can open a document your own account can't, Claude can still read and summarize it in that channel when you ask. See [agent access](/docs/claude-tag/concepts/agent-identity#agent-access) for how admins limit what a channel can reach.
4949 
5050## Control connector use
5151 
from line 84
8484 
8585### Admin controls for personal connectors
8686 
87Admins manage personal connectors for the whole organization in the **Personal connectors** section at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). The settings there apply to every workspace and channel.
87To manage personal connectors for the whole organization, an admin goes to [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and selects **Edit** on the **Personal connectors** row. The settings in the **Personal connectors** dialog apply to every workspace and channel.
8888 
8989* **Require human review of every message.** On the Enterprise plan, an admin can turn this switch on so that Claude holds every result for the requester's review, not only the ones the [sensitive-content check](#review-results-before-posting) flags. With it on, the prompt no longer offers **Allow** and the **Home** tab no longer offers **Auto mode**. With it off, and on the Team plan, which has no such switch, each member's own [choice](#approve-connector-use) decides which results Claude holds.
9090* **Sensitive information requiring review.** Shows examples of what the check looks for. An Owner can add topics of their own under **Additional topics**, for example "Board meeting notes are confidential", and Claude holds results that touch them.
from line 97
9797 
9898## How Claude protects your connectors
9999 
100Other people can't use your connectors. Requests other people make to Claude in your task's thread run with the connections an admin attached to the channel, not with your connectors.
100Other people can't use your connectors. Requests other people make to Claude in your task's thread run with the access an admin applied to the channel, not with your connectors.
101101 
102102While Claude works on your connector task, it is designed to take direction from you. Other people's messages in the thread reach Claude as information about the task, not as instructions. A message that tells Claude to change course or share what it found can't use your connectors, and Claude is designed not to let it redirect your task.
103103 

claude-tag/concepts/security-and-data Changed · +35 / -26 lines

from line 6
66 
77<BetaNote />
88 
9In channels, Claude acts under its own service accounts that an Owner provisions. By default it can read and post in Slack channels it's been added to and search public channels by keyword; it has no access to your external systems until an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) adds connections. Each connection is scoped to specific channels and workspaces, and the actions Claude takes in connected tools are attributable to its own service accounts.
9In channels, Claude acts under its own service accounts. By default it can read and post in Slack channels it's been added to and search public channels by keyword; it has no access to your external systems until an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) adds Claude Tag connectors. An admin chooses where each connector applies, from every channel down to one, and the actions Claude takes in connected tools are attributable to its own service accounts.
1010 
11Every channel request, whether a person typed it or a schedule triggered it, follows the same path: it runs in an isolated sandbox, and the credentials you provision aren't placed in that sandbox. In an Anthropic-hosted environment, requests leave that sandbox only through Agent Proxy and reach your systems under the agent's own accounts. Sessions in a [self-hosted environment](https://code.claude.com/docs/en/self-hosted-environments) run on runners inside your network, and Claude can't use Access bundles in those sessions yet.
11Every channel request, whether a person typed it or a schedule triggered it, follows the same path: it runs in an isolated sandbox, and the credentials you provision aren't placed in that sandbox. In an Anthropic-hosted environment, requests leave that sandbox only through Agent Proxy and reach your systems under the agent's own accounts. Sessions in a [self-hosted environment](https://code.claude.com/docs/en/self-hosted-environments) run on runners inside your network, and Claude can't use the connectors an admin adds in those sessions.
1212 
1313One-to-one DMs from members who have connected a Claude account run on the member's own claude.ai account instead and are covered separately on [How agent identity works](/docs/claude-tag/concepts/agent-identity#direct-message-channels). For DMs from members who haven't, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#access-in-a-direct-message-from-a-member-without-a-claude-account).
1414 
from line 23
2323| Checkpoint | The guarantee |
2424| :- | :- |
2525| The sandbox | Holds none of the credentials you provision |
26| Agent Proxy | Injects credentials from the credential store at request time, and blocks a request that no [connection](/docs/claude-tag/admins/add-connections#set-allowed-websites), [**Domains** entry](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential), or [environment network access level](/docs/claude-tag/admins/add-connections#broad-web-access-through-the-environment) allows |
26| Agent Proxy | Injects credentials from the credential store at request time, and blocks a request that no [credential's allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites), [allowed domain](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential), or [environment network access level](/docs/claude-tag/admins/add-connections#broad-web-access-through-the-environment) allows |
2727| Your systems | See the agent's own accounts, so its actions there are attributable |
2828 
2929### Compute and the sandbox
from line 44
4444This means:
4545 
4646* **A saved credential is not displayed again.** The setup screens are write-only.
47* **The credential travels only to the hosts you named** when you added the connection.
48* **You can narrow the credential further**, to one host, one path prefix, or read-only methods, in [Add connections](/docs/claude-tag/admins/add-connections).
47* **The credential travels only to the hosts you named** when you added it.
48* **You can narrow the credential further**, to one host, one path prefix, or read-only methods; see [Restrict by path or method](/docs/claude-tag/admins/add-connections#restrict-by-path-or-method).
4949 
5050### Network egress
5151 
52In an Anthropic-hosted environment, outbound traffic from a channel session's sandbox is default-deny. Requests go only to hosts an allow layer covers, and the layers are a [connection's Allowed websites](/docs/claude-tag/admins/connections/custom#fill-out-the-custom-tool-form), the [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential), and the network access setting of the [environment](/docs/claude-tag/concepts/glossary#environment) the scope's sessions run on. A new environment's default level, Trusted access, already covers a [documented set of package registries and developer hosts](https://code.claude.com/docs/en/cloud-environments#default-allowed-domains). See [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) for what happens to a request under each layer.
52In an Anthropic-hosted environment, outbound traffic from a channel session's sandbox is default-deny. Requests go only to hosts an allow layer covers, and the layers are a [credential's allowed websites](/docs/claude-tag/admins/connections/custom#fill-out-the-custom-tool-form), the [allowed domains](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential) that apply to the channel, and the network access setting of the [environment](/docs/claude-tag/concepts/glossary#environment) the scope's sessions run on. A new environment's default level, Trusted access, already covers a [documented set of package registries and developer hosts](https://code.claude.com/docs/en/cloud-environments#default-allowed-domains). See [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) for what happens to a request under each layer.
5353 
54<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/lijct3C2aoA3LHFn/images/claude-tag/diagrams/proxy-decision.svg?fit=max&auto=format&n=lijct3C2aoA3LHFn&q=85&s=31de5c6d6a10b635374d9fa4861a111f" alt="Flow diagram across two zones, labeled Anthropic's infrastructure and your systems. In the first zone, a session sandbox that holds no stored credentials sends every outbound request to Agent Proxy, which matches it against admin rules. Three outcomes branch toward your systems: on a rule match, the credential is attached at the boundary and the request proceeds; on an allowlist-only match, from the bundle's Domains list or the environment's network access setting, the request is sent without credentials; on no match, the request is blocked entirely (the default-deny outcome) and the host is unreachable." width="1000" height="400" data-path="images/claude-tag/diagrams/proxy-decision.svg" />
54<img className="block dark:hidden" src="https://mintcdn.com/claude-ai/f29MqpCRlPctgTn5/images/claude-tag/diagrams/proxy-decision.svg?fit=max&auto=format&n=f29MqpCRlPctgTn5&q=85&s=f87bc9ca2d2de09e4feda0a60695e9bd" alt="Flow diagram across two zones, labeled Anthropic's infrastructure and your systems. In the first zone, a session sandbox that holds no stored credentials sends every outbound request to Agent Proxy, which matches it against admin rules. Three outcomes branch toward your systems: on a rule match, the credential is attached at the boundary and the request proceeds; on an allowlist-only match, from an allowed domain or the environment's network access setting, the request is sent without credentials; on no match, the request is blocked entirely (the default-deny outcome) and the host is unreachable." width="1000" height="400" data-path="images/claude-tag/diagrams/proxy-decision.svg" />
5555 
56<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/lijct3C2aoA3LHFn/images/claude-tag/diagrams/proxy-decision-dark.svg?fit=max&auto=format&n=lijct3C2aoA3LHFn&q=85&s=b67da069feb4070186d4eca67eb40878" alt="Flow diagram across two zones, labeled Anthropic's infrastructure and your systems. In the first zone, a session sandbox that holds no stored credentials sends every outbound request to Agent Proxy, which matches it against admin rules. Three outcomes branch toward your systems: on a rule match, the credential is attached at the boundary and the request proceeds; on an allowlist-only match, from the bundle's Domains list or the environment's network access setting, the request is sent without credentials; on no match, the request is blocked entirely (the default-deny outcome) and the host is unreachable." width="1000" height="400" data-path="images/claude-tag/diagrams/proxy-decision-dark.svg" />
56<img className="hidden dark:block" src="https://mintcdn.com/claude-ai/f29MqpCRlPctgTn5/images/claude-tag/diagrams/proxy-decision-dark.svg?fit=max&auto=format&n=f29MqpCRlPctgTn5&q=85&s=ccbd8f7c4ba256a77cf85358880179b7" alt="Flow diagram across two zones, labeled Anthropic's infrastructure and your systems. In the first zone, a session sandbox that holds no stored credentials sends every outbound request to Agent Proxy, which matches it against admin rules. Three outcomes branch toward your systems: on a rule match, the credential is attached at the boundary and the request proceeds; on an allowlist-only match, from an allowed domain or the environment's network access setting, the request is sent without credentials; on no match, the request is blocked entirely (the default-deny outcome) and the host is unreachable." width="1000" height="400" data-path="images/claude-tag/diagrams/proxy-decision-dark.svg" />
5757 
58Because requests to any other host are blocked, data can only leave the sandbox to hosts an allow layer covers. An admin sets the Allowed websites list on each connection and the Domains tab on each bundle. An admin sets the environment's network access level, which defaults to Trusted access, from the **Cloud environments** page in [admin settings](https://claude.ai/admin-settings). See [Set allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) and [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential).
58Because requests to any other host are blocked, data can only leave the sandbox to hosts an allow layer covers. An admin sets the allowed websites on each credential and the allowed domains. An admin sets the environment's network access level, which defaults to Trusted access, from the **Cloud environments** page in [admin settings](https://claude.ai/admin-settings). See [Set allowed websites](/docs/claude-tag/admins/add-connections#set-allowed-websites) and [Allow a host without a credential](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential).
5959 
60Allow-all egress is a `*` entry on a bundle's Domains tab. The entry admits requests to any host on the ports it lists, still without credentials. Private and internal network addresses and cloud metadata endpoints remain blocked. See [Allow all hosts](/docs/claude-tag/admins/add-connections#allow-all-hosts).
60Allow-all egress is a `*` domain. The entry admits requests to any host on the ports it lists, still without credentials. Private and internal network addresses and cloud metadata endpoints remain blocked. See [Allow all hosts](/docs/claude-tag/admins/add-connections#allow-all-hosts).
6161 
6262### Service accounts
6363 
64In channels, Claude acts under service credentials of its own, not under the account of the person who tagged it. The Slack surface is the Claude app, code work goes through the Claude GitHub App, and every other connected tool uses a service account an Owner provisions in an Access bundle. See [How agent identity works](/docs/claude-tag/concepts/agent-identity) for the full model.
64In channels, Claude acts under service credentials of its own, not under the account of the person who tagged it. The Slack surface is the Claude app, code work goes through the Claude GitHub App, and every other connected tool uses a service account whose credential a [connector](/docs/claude-tag/concepts/glossary#connection) holds. See [How agent identity works](/docs/claude-tag/concepts/agent-identity) for the full model.
6565 
66A connection belongs to that agent identity and is shared by everyone the bundle's scope covers. Anyone in a channel under that scope can ask Claude to act with the credential, so whatever the connected account can read or write is available to every member of those channels. Connect a dedicated identity you control for each service, such as a `[email protected]` seat or a native service account, rather than a personal login. A dedicated account keeps the agent's actions separately auditable in each tool's logs and lets you revoke its access without affecting a person; see [Create a dedicated account per service](/docs/claude-tag/admins/add-connections#create-a-dedicated-account-per-service).
66A connector's credential belongs to that agent identity and is shared by everyone in the channels where it applies. Anyone in one of those channels can ask Claude to act with the credential, so whatever the connected account can read or write is available to every member of those channels. Connect a dedicated identity you control for each service, such as a `[email protected]` seat or a native service account, rather than a personal login. A dedicated account keeps the agent's actions separately auditable in each tool's logs and lets you revoke its access without affecting a person; see [Create a dedicated account per service](/docs/claude-tag/admins/add-connections#create-a-dedicated-account-per-service).
6767 
68One-to-one DMs with `@Claude` from a member who has connected a Claude account run on that member's own claude.ai account instead, with that member's personal connectors, and work there is attributed to them, except pull requests, which the Claude GitHub App authors from DMs as well. For DMs from members who haven't, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#access-in-a-direct-message-from-a-member-without-a-claude-account). Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
68One-to-one DMs with `@Claude` from a member who has connected a Claude account run on that member's own claude.ai account instead, with that member's personal connectors, and work there is attributed to them, except pull requests, which the Claude GitHub App authors from DMs as well. For DMs from members who haven't, see [Direct messages from members without a Claude account](/docs/claude-tag/admins/restrict-access#access-in-a-direct-message-from-a-member-without-a-claude-account). An Owner can turn off DMs for the whole organization; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
6969 
7070Claude uses a user's [personal connectors in a channel](/docs/claude-tag/concepts/personal-connectors) only for that user's own tasks, after the user allows it. The work runs with that user's permissions and is recorded under their name. Requests other people make to Claude in the task's thread run with the channel's own access, not with that user's connectors. Claude is designed to take direction from the connector's owner, treating what other people post in the thread as information for the task rather than as instructions, and the owner can tell Claude in the task's thread to stop. On the Enterprise plan, an admin can require [the user's review of every result](/docs/claude-tag/concepts/personal-connectors#admin-controls-for-personal-connectors) before it posts. See [Personal connectors in channels](/docs/claude-tag/concepts/personal-connectors).
7171 
7272### Isolate credentials between channels
7373 
74A channel session can use only the [Access bundles](/docs/claude-tag/admins/add-connections) attached in one of three places:
74A channel session can use only the access an admin applied in one of these places:
7575 
76* **The channel itself.** A bundle you attach here applies in that channel only.
77* **The channel's workspace.** A bundle you attach here applies in every channel of that workspace.
78* **[Default Slack access](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit).** The organization-wide root; a bundle you attach here applies in every channel of every paired workspace.
76* **The channel itself.** Access added on the channel's page, or a bundle applied to the channel, reaches that channel only.
77* **The channel's workspace.** Access added on the workspace's page, or a bundle applied to the workspace, reaches every channel of that workspace.
78* **All of Slack.** Access added on the **Slack** page, or a bundle applied there, reaches every channel of every paired workspace. The first credential you add for a service on the **Connectors** tab is on here as soon as you save it. See [how scopes inherit](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit).
79* **A channel rule.** A bundle an Owner applies to a channel name pattern reaches every matching channel in all of Slack or in one workspace, including channels created or renamed later.
7980 
80A bundle attached anywhere else in your organization is invisible to the session, and no request from the session's sandbox can carry a credential from a bundle outside those three scopes.
81Access applied anywhere else in your organization is invisible to the session, and no request from the session's sandbox can carry a credential that doesn't apply to its channel.
8182 
82For example, if you attach a bundle holding finance credentials to one private channel, sessions in every other channel run as if that credential doesn't exist. If you attach the same bundle to a workspace or to Default Slack access instead, every channel beneath it gets that access, so isolation comes from where you attach the bundle, not from the bundle itself.
83For example, if a bundle holding finance credentials applies only to one private channel, sessions in every other channel run as if that credential doesn't exist. If the same bundle applies to a workspace or to all of Slack instead, every channel beneath it gets that access, so isolation comes from where the access applies, not from the bundle itself.
8384 
84Confine a credential to one channel in three steps:
85To confine a credential to one channel:
8586 
861. Attach its bundle to that channel and nowhere broader.
872. Keep the channel private. A bundle on a public channel [grants its access to anyone who joins](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel).
883. Check the channel's **Connectors**, **Repositories**, and **Plugins** sections on the [Slack tab in admin settings](/docs/claude-tag/admins/attach-to-scope). They list the access the channel gets, including rows inherited from the workspace or from Default Slack access, each with an origin line naming where it comes from.
871. Apply it to that channel and nowhere broader. The first credential you add for a service on the **Connectors** tab applies in all of Slack as soon as you save it. To keep the credential out of other channels from the start, add it in one of these ways instead:
88 * In a bundle whose **Where it applies** list holds only that channel.
89 * From the channel's page. Under **Claude's access**, click **Add** and select **Connector**. On the dialog's **Connectors** tab, select the service under **Connect new** and click **Continue**. The credential you enter in the connect form applies in that channel only.
90 * On the page of a connector already on the **Connectors** tab, select **Add credential** from the **⋮** menu at the top of the page. The new credential is off everywhere until you pick it in the channel's row under **Assign access**, selecting **Add place** if the channel isn't listed.
912. Keep the channel private. Access on a public channel [reaches anyone who joins](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel).
923. Open the channel from the **Channels** tab under **Claude's access** at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) and check its **Claude's access** table. It lists the access that reaches the channel, and an item a bundle brings is listed under that bundle's row. The **Inheritance** column shows whether each bundle, and each item outside a bundle, was added on the channel's page or inherited from the workspace or from **Slack**.
8993 
90Claude doesn't work in a channel shared with another company through [Slack Connect](/docs/claude-tag/admins/restrict-access#slack-connect-channels), so no access bundle's credentials reach one.
94Claude doesn't work in a channel shared with another company through [Slack Connect](/docs/claude-tag/admins/restrict-access#slack-connect-channels), so no connector's credentials reach one.
9195 
92When you ask Claude in one channel to post into another, Claude works with the access bundles and instructions of the channel you asked in, not the target channel's. From a private channel, Claude doesn't post anywhere else, and nothing asked elsewhere makes Claude post into a private channel. [What Claude can do in other channels](/docs/claude-tag/concepts/how-it-works#what-claude-can-do-in-other-channels) covers where Claude can post from each place you ask.
96When you ask Claude in one channel to post into another, Claude works with the access and instructions of the channel you asked in, not the target channel's. From a private channel, Claude doesn't post anywhere else, and nothing asked elsewhere makes Claude post into a private channel. [What Claude can do in other channels](/docs/claude-tag/concepts/how-it-works#what-claude-can-do-in-other-channels) covers where Claude can post from each place you ask.
9397 
9498Isolating a credential doesn't isolate what Claude knows. The [workspace notes](/docs/claude-tag/users/memory) it saves from a public channel are read by sessions in every channel of the workspace, and it can [search public channels by keyword](/docs/claude-tag/admins/restrict-access#controls-that-aren%E2%80%99t-available) without being added to them, the same way any workspace member can.
9599 
from line 107
103107 
104108## Member access
105109 
106By default, anyone in a connected Slack workspace can invoke Claude in channels, with or without a Claude account. An Owner can turn on a restriction toggle to narrow that: on Team plans it limits Claude to people with a Claude account in your organization, and on Enterprise plans it limits Claude to members whose role grants the **Claude Tag in Slack** capability. See [Restrict who can use Claude](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude). The toggle governs DMs as well as channels.
110By default, anyone in a connected Slack workspace can invoke Claude in channels, with or without a Claude account. An Owner can narrow that on the **Advanced** tab of the **Slack** page, which the **Slack** row on the **Channels** tab under **Claude's access** opens:
111 
112* **Team plans**: **Restrict to your organization** limits Claude to people with a Claude account in your organization
113* **Enterprise plans**: **Restrict to roles with Claude Tag access** limits Claude to members whose role grants the **Claude Tag in Slack** capability
114 
115See [Restrict who can use Claude](/docs/claude-tag/admins/restrict-access#restrict-who-can-use-claude). The restriction governs DMs as well as channels.
107116 
108117## Related resources
109118 

claude-tag/concepts/settings-map Changed · +13 / -13 lines

## Claude Tag admin settings ## The Claude Tag admin page

from line 10
1010 
1111| Surface | Who changes it | What it controls |
1212| :- | :- | :- |
13| [Claude Tag admin page](https://claude.ai/admin-settings/claude-tag) | An Owner in your Claude organization, or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) on the Enterprise plan | Access, behavior, and restrictions for channels, mostly per [scope](/docs/claude-tag/concepts/glossary#scope) |
13| [**Organization settings > Claude Tag**](https://claude.ai/admin-settings/claude-tag) | An Owner in your Claude organization, or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) on the Enterprise plan | Access, behavior, and restrictions for channels, mostly per [workspace and channel](/docs/claude-tag/concepts/glossary#scope) |
1414| [Usage page](https://claude.ai/admin-settings/usage/claude-tag) | An admin | Spend limits and each channel's spend against them |
1515| [Analytics page](https://claude.ai/analytics/claude-tag) | Anyone who can view the Analytics dashboard | Spend trends, projections, and per-channel reports; read-only |
1616| The **Configure** link in the footer of any Claude reply in a channel | Channel members (unless an admin restricts editing) and [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | One channel's instructions and whether Claude replies there without an @-mention. Channel managers also set the channel's default model, repositories, connections, and plugins |
1717| [Customize > Connectors](https://claude.ai/customize/connectors) on your own claude.ai account | You | Which of your personal tools apply in [one-to-one DMs](/docs/claude-tag/concepts/agent-identity#direct-message-channels) and for [your own tasks in a channel](/docs/claude-tag/concepts/personal-connectors) |
1818 
19Channel memory and routines aren't in the table because you change them by talking to Claude in the channel; see [what anyone can change from the channel](/docs/claude-tag/admins/customize#change-behavior-from-the-channel). Owners can review both, as each scope's memory files and scheduled work, from [the Audit page](/docs/claude-tag/admins/audit), labeled **Activity** in the console.
19Channel memory and routines aren't in the table because you change them by talking to Claude in the channel; see [what anyone can change from the channel](/docs/claude-tag/admins/customize#change-behavior-from-the-channel). Owners can review both on the **Scheduled work** and **Memory** tabs of the [**Activity** page](/docs/claude-tag/admins/audit). Only an Owner can edit or delete memory entries.
2020 
21## The Claude Tag admin page
21## Claude Tag admin settings
2222 
23Everything an Owner configures for channels lives at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). Most settings there apply per scope (a channel, a workspace, or the whole organization). A scope without its own setting inherits from its parent, and a channel's setting overrides its workspace's, so two channels can run with different connections, models, and instructions. Most controls need the Owner role or, on the Enterprise plan, the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); the [permissions table](/docs/claude-tag/admins/restrict-access#permissions-by-role) lists each action and who can take it.
23Everything an admin configures for channels lives at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). Most settings there apply per scope (a channel, a workspace, or the whole organization), and each scope has its own page on the **Channels** tab under **Claude's access**. A scope without its own setting inherits from its parent, and a channel's setting overrides its workspace's, so two channels can run with different connectors, models, and instructions. Most controls need the Owner role or, on the Enterprise plan, the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); the [permissions table](/docs/claude-tag/admins/restrict-access#permissions-by-role) lists each action and who can take it.
2424 
25* **Access bundles**: the connections, domain entries, repository grants, and plugins Claude uses in the channels a bundle covers. See [Give Claude access](/docs/claude-tag/admins/add-connections).
25* **Bundles**: the connectors, domains, repositories, plugins, and instructions Claude uses in the workspaces and channels a bundle applies to. The **Connectors** and **Skills and plugins** tabs add a new connector, plugin, or skill. See [Give Claude access](/docs/claude-tag/admins/add-connections).
2626* **Custom instructions**: standing guidance Claude reads in every session on a scope. See [Add custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
27* **Default model**: the model new sessions in a scope start on. The picker shows the models your organization allows for Claude Code, leaving out any that Claude Tag doesn't support, so it can be missing models you see in Claude Code itself. See [Choose the model for a scope](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope).
27* **Model**: the model new sessions in a scope start on, set in the **Model** row on the main Claude Tag page for the whole organization and on each workspace's and channel's page. The picker shows the models your organization allows for Claude Code, leaving out any that Claude Tag doesn't support, so it can be missing models you see in Claude Code itself. See [Choose the model for a scope](/docs/claude-tag/admins/customize#choose-the-model-for-a-scope).
2828* **Auto mode allow rules**: plain sentences that pre-approve actions Claude's permission checker would otherwise flag or stop in a scope's sessions. See [Auto mode allow rules](/docs/claude-tag/admins/customize#auto-mode-allow-rules).
29* **Workspace pairing and restrictions**: which Slack workspaces are paired, whether DMs are allowed, guest-channel behavior, which channels Claude can search, who can invoke Claude, and which generation of the app answers in each scope (on the Team plan, a single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) replaces the per-scope setting). See [Restrict where Claude Tag operates](/docs/claude-tag/admins/restrict-access).
30* **Channel name rules**: channel-name patterns that keep Claude out of matching channels or join it automatically to new public ones. See [Block or auto-join channels by name](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name).
31* **Personal connectors**: on the Enterprise plan, whether Claude holds every result of a member's connector task for that member's review before posting it, and the topics an Owner adds to the sensitive-content check. These settings apply to the whole organization rather than per scope. See [Admin controls for personal connectors](/docs/claude-tag/concepts/personal-connectors#admin-controls-for-personal-connectors).
29* **Workspace pairing and restrictions**: which Slack workspaces are paired, whether DMs are allowed, guest-channel behavior, which channels Claude can search, who can invoke Claude, and which generation of the app answers in each scope (some Team plan organizations have a [single on-or-off switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) in place of the per-scope setting). See [Restrict where Claude Tag operates](/docs/claude-tag/admins/restrict-access).
30* **Channel name rules**: channel-name patterns that keep Claude out of matching channels, join it automatically to new public ones, or attach a bundle to every matching channel. See [Block or auto-join channels by name](/docs/claude-tag/admins/restrict-access#block-or-auto-join-channels-by-name).
31* **Personal connectors**: on the Enterprise plan, whether Claude holds every result of a member's connector task for that member's review before posting it, and the topics an Owner adds to the sensitive-content check. These settings apply to the whole organization rather than per scope, and you reach them with **Edit** on the **Personal connectors** row of the main Claude Tag page. See [Admin controls for personal connectors](/docs/claude-tag/concepts/personal-connectors#admin-controls-for-personal-connectors).
3232 
3333## Spend limits and usage
3434 
35Spend limits live at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag), a different page than the Claude Tag admin page. It holds the organization-wide spend limit, the default spend limit for channels, per-channel limits, and each channel's spend against its limit. If your organization bills through a reseller, this page is not available. See [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) for funding the usage balance and what users see when a limit is reached.
35Spend limits live on the usage page at [`claude.ai/admin-settings/usage/claude-tag`](https://claude.ai/admin-settings/usage/claude-tag), separate from Claude Tag admin settings. The usage page holds the organization-wide spend limit, the default spend limit for channels, per-channel limits, and each channel's spend against its limit. If your organization bills through a reseller, this page is not available. See [Set a spend limit](/docs/claude-tag/admins/set-spend-limit) for funding the usage balance and what users see when a limit is reached.
3636 
3737Usage covered by a promotional credit isn't counted on the usage page and shows as \$0.00 there. To see each channel's list-price spend for the current month including covered usage, use the **List price** column of the **Spend by channel** table at [`claude.ai/analytics/claude-tag`](https://claude.ai/analytics/claude-tag).
3838 
from line 46
4646 
4747The page's **Tools and access** tab shows the channel's resolved connections and any allowed domains. Members can see those lists but not change them there. The same tab's **Plugins** card lists the channel's plugins, and members can add plugins there unless an admin has restricted editing to admins. A **Routines** tab lists the channel's routines with each one's schedule, status, and last run.
4848 
49The Configure page and the **Custom instructions** field on the scope's panel in admin settings write the same instructions, so a change from either place is visible in the other. See [Configure Claude for a channel](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel).
49The Configure page and the **Channel instructions** field on the channel's page in admin settings write the same instructions, so a change from either place is visible in the other. See [Configure Claude for a channel](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel).
5050 
51On the Enterprise plan, an Owner can name [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for a channel, and so can a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) whose role also sets **Identity & Access** to **Can manage**. For channel managers, the same page adds editable cards: the channel's default model on the **General** tab, and its repositories and access bundles on the **Tools and access** tab.
51On the Enterprise plan, an Owner can name [channel managers](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for a channel, and so can a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) whose role also sets **Identity & Access** to **Can manage**. For channel managers, the same page adds editable cards: the channel's default model on the **General** tab, and **GitHub repositories** and **Access bundles** on the **Tools and access** tab.
5252 
5353## Personal connectors on claude.ai
5454 
from line 60
6060 
6161[Claude Managed Agents](https://platform.claude.com/docs/en/managed-agents/overview) is a separate product for developers, a pre-built agent harness that runs in managed infrastructure. You configure it on the Claude Platform through the Managed Agents API, and access requires a Claude API key. An agent there is defined by its model, system prompt, tools, MCP servers, and skills. Environments choose where its sessions run (a cloud sandbox, or a self-hosted sandbox on your own infrastructure), and scheduled deployments run it on a cron schedule.
6262 
63The two products don't share settings. Nothing on the Claude Tag admin page configures a Managed Agent, and an agent defined on the Claude Platform doesn't change how Claude behaves in Slack.
63The two products don't share settings. Nothing in Claude Tag admin settings configures a Managed Agent, and an agent defined on the Claude Platform doesn't change how Claude behaves in Slack.
6464 
6565## Related resources
6666 

claude-tag/overview Changed · +3 / -3 lines

from line 80
8080 
8181When Claude works on a task, it runs in an ephemeral sandbox, not on your computer. The sandbox is created when a conversation starts, holds any code or files Claude is working with, and is discarded when the conversation goes idle. See [how Claude Tag works](/docs/claude-tag/concepts/how-it-works) for the full lifecycle.
8282 
83You extend what Claude can reach, like your repositories, ticketing systems, data warehouses, and custom tools, through [connections](/docs/claude-tag/admins/add-connections), [plugins, and skills](/docs/claude-tag/admins/customize). An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) configures these per scope (a channel, a workspace, or the whole organization). Members' own claude.ai connectors are separate from that configuration; Claude can use them in a channel for the member's own requests, as [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) describes.
83You extend what Claude can reach, like your repositories, ticketing systems, data warehouses, and custom tools, through [Claude Tag connectors](/docs/claude-tag/admins/add-connections), [plugins, and skills](/docs/claude-tag/admins/customize). An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) configures these for all of Slack, for one workspace, or for one channel. Members' own claude.ai connectors are separate from that configuration; Claude can use them in a channel for the member's own requests, as [personal connectors in channels](/docs/claude-tag/concepts/personal-connectors) describes.
8484 
8585<div className="tm-route-grid">
8686 <div className="tm-card">
from line 184
184184 
185185For your own requests, Claude can also [use the connectors on your claude.ai account](/docs/claude-tag/concepts/personal-connectors), after you allow it.
186186 
187In a one-to-one DM, Claude runs on your own claude.ai account instead of a channel's setup. Owners can disable DMs organization-wide; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
187In a one-to-one DM, Claude runs on your own claude.ai account instead of a channel's setup. An Owner can turn off DMs for the whole organization; see [Allow or disable direct messages](/docs/claude-tag/admins/restrict-access#allow-or-disable-direct-messages).
188188 
189189### Common uses
190190 
from line 212
212212 
213213Once you launch, everyone in a channel Claude is in can use Claude Tag immediately, with no per-user setup.
214214 
215Claude Tag starts with no access of its own to your external systems. After you launch, you connect the services Claude will work in, such as your issue tracker or data warehouse, and grant repositories to the Claude GitHub App. The services you connect form an [Access bundle](/docs/claude-tag/concepts/glossary#access-bundle), the set of tools Claude can reach. You attach the bundle to a workspace or to channels. Members can also let Claude use their own [personal connectors](/docs/claude-tag/concepts/personal-connectors) for their requests.
215Claude Tag starts with no access of its own to your external systems. After you launch, you connect the services Claude will work in, such as your issue tracker or data warehouse, and grant repositories to the Claude GitHub App. Members can also let Claude use their own [personal connectors](/docs/claude-tag/concepts/personal-connectors) for their requests.
216216 
217217[Set up Claude Tag](/docs/claude-tag/admins/setup-overview) walks through setup and connecting tools, with what to have ready, what each choice means, and how to verify Claude Tag works once you launch.
218218 

claude-tag/users/good-habits Changed · +5 / -5 lines

from line 166
166166| Conventions and setup for one repository: file layout, PR labels, dependencies to install | **`CLAUDE.md`** at the repo root ([loaded when the repo is](/docs/claude-tag/admins/configure-github#what-loads-from-a-repository)) | Anyone with repo write | Any session that works in that repo, from any channel |
167167| Standing rules for this channel that outrank memory | The [**Configure** page](#configure-claude-for-a-channel), in the **Channel instructions** field | Channel members, unless an admin has [restricted it](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) | This channel |
168168| A correction for this channel that you don't want to raise in the channel | [**Managed instructions**](/docs/claude-tag/admins/managed-by#correct-claude-privately-from-a-managing-channel), written from a private managing channel | Full workspace members in the managing channel who have a Claude account in your organization, after an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) sets it up | This channel |
169| How to use a tool correctly, or follow a specific process, org-wide | [**A skill**](/docs/claude-tag/admins/skills-repo) in your org's plugin marketplace | An organization Owner adds it; anyone can ask Claude to open a PR proposing the change | Every channel under the scope it's attached to |
170| Standing rules across many channels | [**Custom instructions**](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) on a workspace or organization scope | An organization Owner, or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) for a workspace scope, in the console | Every session in that scope |
169| How to use a tool correctly, or follow a specific process, org-wide | [**A skill**](/docs/claude-tag/admins/skills-repo) in your org's plugin marketplace | An organization Owner adds it; anyone can ask Claude to open a PR proposing the change | Every workspace and channel it's added to |
170| Standing rules across many channels | [**Workspace instructions** or **Slack instructions**](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) in Claude Tag admin settings | An organization Owner, or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) for a workspace | Every channel in that workspace, or in all of Slack |
171171 
172The first three are yours to write. Skills and wider-scope custom instructions are attached by an Owner, but you can still ask Claude to draft a skill change as a pull request for an admin to review:
172The first three are yours to write. You can still ask Claude to draft a skill change as a pull request for an admin to review:
173173 
174174```text wrap theme={null}
175175@Claude that worked. Open a PR to the skills repo so this query pattern is part of the Datadog skill.
from line 189
189189 
190190Use the **Channel instructions** field on that page to write standing guidance Claude reads in every new session in the channel: the channel's purpose, its conventions, the tone replies should take, and anything Claude should do or avoid there. Channel instructions outrank channel memory and sit alongside any instructions an admin has set for the workspace or organization. Save the field and the change applies to new sessions started in the channel.
191191 
192The page's **Tools and access** tab shows **Connections**, the services Claude can reach from this channel, along with any allowed domains. You can see those lists but not change them on this page. The same tab's **Plugins** card lists the channel's plugins, and you can add plugins there unless an admin has restricted editing to admins. If you've been made a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for the channel, the tab also has access bundle and repository cards you can edit.
192The page's **Tools and access** tab shows **Connections**, the services Claude can reach from this channel, along with any allowed domains. You can see those lists but not change them on this page. The same tab's **Plugins** card lists the channel's plugins, and you can add plugins there unless an admin has restricted editing to admins. If you've been made a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for the channel, the tab also has **Access bundles** and **GitHub repositories** cards you can edit.
193193 
194194## Keep thread count and review rate matched
195195 
Feedback