Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20261008T173704Z

12 pages moved out of 265 read.

Pages moved 12 significant first
Pages read 265 in this capture
Captured 17:37 UTC
Corpus hash 00782de8e3b1 corpus-hash

What this read moved

1-12 of 12

government/account/overview Changed · +22 / -0 lines

from line 12
1212 
1313## What's here
1414 
15<Frame caption="Video: Your account, usage limits, and getting help (1 min 57 s). Narrated with an AI-generated voice, with on-screen captions.">
16 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-05-your-account-usage-limits-and-getting-help.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=691f1dc9497295c364c0e8f81020b942" aria-label="Video walkthrough: Your account, usage limits, and getting help" data-path="images/government/videos/user-05-your-account-usage-limits-and-getting-help.mp4" />
17</Frame>
18 
19<Accordion title="Transcript">
20 Your account pages are in the web portal. In a browser, open your agency's Claude for Government address and sign in. Account shows your email, organization, role, and seat tier, all read-only.
21 
22 Usage shows your allowance: a 5-hour window and a 7-day window, each with the share you have used and when it resets. If either reaches 100 percent, Claude pauses until that window resets. Claude Desktop itself does not show this allowance.
23 
24 Sessions lists every place you are signed in, whether in a browser or in Claude Desktop, and when each sign-in began. To sign out a computer you no longer have, select Sign out on its row.
25 
26 In the app, your session ends after a period of inactivity that your agency sets, 24 hours unless they change it. Claude then tells you that you have been signed out and asks you to sign in again.
27 
28 Select Sign in again. Your browser opens to confirm it is you, and then you are back in the same conversation. Your chats stay on your computer.
29 
30 If something isn't working, your help desk may ask for a diagnostic report. From Help, choose Troubleshooting, then Generate Diagnostic Report.
31 
32 The dialog lists what goes in: app and system details, your configuration with secrets removed, network checks, and recent errors. It never includes your conversations. Select Export to file and attach the file to your ticket.
33 
34 Who to ask: your organization's owner for a seat, a larger allowance, or a wrong organization or role. Your IT help desk for anything about the app on your computer. Your administrators can take it from there.
35</Accordion>
36 
1537* The [**Account**](/docs/government/account/profile) tab shows who you are, including your name, email address, organization, role, and seat tier. Everything on this tab is read-only. Your name and email come from your agency's directory; your organization, role, and seat tier are set by your directory or by an administrator.
1638* The [**Usage**](/docs/government/account/usage) tab shows how much of your personal allowance you have used in the current 5-hour and 7-day windows, and when each one next resets. If you have hit a limit and Claude is paused, this tab is marked with a pulsing indicator in the navigation so you can spot it at a glance.
1739* The [**Sessions**](/docs/government/account/sessions) tab lists every browser and desktop application where you are currently signed in, with the option to sign any of them out remotely.

government/config/overview Changed · +24 / -0 lines

from line 6
66 
77The **Config** page in the admin portal is where you set product behavior such as the session timeout, Claude Desktop banner, product availability, and telemetry for the people you manage. The same page appears at both the tenant and the organization level, with the same list of settings, and this page explains how the two levels fit together. For the settings themselves, see [Available settings](/docs/government/config/settings).
88 
9<Frame caption="Video: Config essentials (2 min 23 s). Narrated with an AI-generated voice, with on-screen captions.">
10 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-06-config-essentials.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=8624805f501e6ca7e01e12e6e94602ab" aria-label="Video walkthrough: Config essentials" data-path="images/government/videos/admin-06-config-essentials.mp4" />
11</Frame>
12 
13<Accordion title="Transcript">
14 Config sets product behavior for the people you manage. The tenant and each organization share the same page, and each level starts from the one above it.
15 
16 In the admin view, open Config under Settings. Settings are grouped on the left, and the scope bar at the top shows which level you are editing.
17 
18 Product availability has a switch for each product and feature. Chat, Cowork, and Code in Claude Desktop are on by default. Here the organization turns Code in Claude Desktop off and saves.
19 
20 To treat one directory group differently, choose it in the scope bar. The same editor appears for that group, and Code in Claude Desktop is turned back on for its members, unless a higher-priority group has settings for them.
21 
22 Under Integrations, Web search is off by default. Turning it on asks you to acknowledge how search works. Require approval for each search stays on, so members approve every search.
23 
24 Under Sessions and access, Session idle timeout signs out inactive members after 24 hours by default. Lower levels can only shorten it, and lowering it applies from the next sign-in.
25 
26 In the tenant view, open the same page and set the Claude Desktop banner for everyone. Choose Must use this value, open Preview impact, then save. Every organization now uses this value.
27 
28 Back in the organization's Config, the banner shows Locked by your tenant and cannot be changed there.
29 
30 You do not need to push anything. Claude Desktop checks for changes at launch and about every 10 minutes while it runs, or every 30 minutes on older versions, and prompts members to relaunch when something changed.
31</Accordion>
32 
933## How settings are applied
1034 
1135Each setting is resolved through a chain that runs from the Anthropic default, to your tenant, to each organization. Directory groups add two further levels, described under [Group-specific settings](#group-specific-settings) below. A value set at any level becomes the starting point for the levels below it. An organization that doesn't set a value uses the tenant's value, and a tenant that doesn't set a value uses the Anthropic default. When you expand a setting you can see each step of this chain, which value is currently **In effect**, where it came from, and (in the tenant view) which organizations have set their own value.

government/connectors/overview Changed · +24 / -0 lines

from line 8
88 
99A **connector** is a link between Claude and an external service. The service runs a Model Context Protocol (MCP) server, which is a standard way for a service to publish a set of tools that Claude can call. You add the server once here, and Claude for Government delivers it to the products you select.
1010 
11<Frame caption="Video: Connectors and plugins (2 min 8 s). Narrated with an AI-generated voice, with on-screen captions.">
12 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-07-connectors-and-plugins.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=43f78d15928eea46d27229f8dbc04db6" aria-label="Video walkthrough: Connectors and plugins" data-path="images/government/videos/admin-07-connectors-and-plugins.mp4" />
13</Frame>
14 
15<Accordion title="Transcript">
16 A connector lets Claude reach another service, such as Microsoft 365 or a system of your own. A plugin packages skills and commands for Claude Desktop.
17 
18 Microsoft 365 setup starts in Microsoft Entra. An Entra administrator registers an application, approves its Microsoft Graph permissions, and sends you two values, the tenant ID and the client ID.
19 
20 On Config, under Integrations, expand Microsoft 365. Paste the Tenant ID and the Client ID, keep Azure cloud on Commercial unless your Microsoft tenant is in GCC High or DoD. Check that Access matches what Entra approved, and save.
21 
22 Members then connect Microsoft 365 in Claude Desktop with their own work account, and Claude reaches only what each member can already open.
23 
24 For a system of your own, open Add connector on the Connectors card. Name it, enter the server's address, and choose how Claude authenticates, for example a shared secret or member sign-in. Select Next.
25 
26 Discover tools asks the server which tools it offers. If the server cannot be reached from your browser, add tool names by hand on the next step.
27 
28 Under Apply to, choose the products that receive it, here Claude Desktop only. Under Tool policy, switch off any tool you do not want, then save the connector. Members are still asked before Claude uses an allowed tool.
29 
30 On the Plugins card, select Add plugins and drop a zip file. The preview shows its name and version. Choose Auto-install for everyone, or Members choose, then add it.
31 
32 You do not need to push anything. Claude Desktop picks up the connector and the plugin when it next checks for changes. Members find plugins under Customize, Plugins.
33</Accordion>
34 
1135## The Connectors card
1236 
1337The **Connectors** card appears on your [tenant](/docs/government/tenant-admin/configuration) or [organization](/docs/government/org-admin/configuration) Config page alongside the built-in connector cards, and on the Config page for each [directory group](/docs/government/config/overview#group-specific-settings). It lists the connectors added at the level you are viewing and the connectors that level inherits, with each one's name, address, the products it applies to, and a summary of how many of its tools are allowed. Click **Add connector** to open the wizard, or click the edit icon next to a connector added at this level to change it.

government/deploy-desktop/configure Changed · +60 / -0 lines

from line 71
7171 
7272## Configure a single machine
7373 
74<Frame caption="Video: Pilot Claude Desktop on one machine (1 min 34 s). Narrated with an AI-generated voice, with on-screen captions.">
75 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-08-pilot-claude-desktop-on-one-machine.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=753d21fb976775a19f3cca9521b738b3" aria-label="Video walkthrough: Pilot Claude Desktop on one machine" data-path="images/government/videos/admin-08-pilot-claude-desktop-on-one-machine.mp4" />
76</Frame>
77 
78<Accordion title="Transcript">
79 A fresh install connects to claude.ai. One setting, the bootstrap address on your Claude for Government host, points it at Claude for Government. Everything else arrives at sign-in.
80 
81 First confirm your test account has a seat tier, the device and browser can reach your host and identity provider, and you have administrator rights.
82 
83 Open the app and stay on the sign-in screen. Enable Developer Mode from Help, Troubleshooting, then open Developer, Configure Third-Party Inference.
84 
85 The window opens on Connection. Change nothing there. In Source, enter the bootstrap address, leave Trust bootstrap-delivered settings off, and select Apply Changes.
86 
87 After the relaunch, choose Sign in with your organization. The app shows a pairing code, and you finish sign-in in your browser.
88 
89 Then a small window, Apply settings from your organization, lists a Gateway base URL. Confirm it is on your host and select Allow.
90 
91 For your fleet, turn on Disable Claude.ai sign-in under Workspace, keep the trust switch off, and use Export for the macOS, Jamf, Intune, or Group Policy files.
92 
93 One end-to-end check is a short Claude Desktop banner on the Config page. If it appears in the app after sign-in, per-user delivery works.
94</Accordion>
95 
7496<Note>
7597 Installing by hand needs administrator rights on the device. On Windows, the installer registers a Windows system service, so it must run as a local administrator. On macOS, installing to the shared Applications folder requires an administrator. On Linux, installing the package requires root.
7698</Note>
from line 139
117139 
118140## Deploy to your fleet
119141 
142<Frame caption="Video: Deploy to your fleet (1 min 31 s). Narrated with an AI-generated voice, with on-screen captions.">
143 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-09-deploy-to-your-fleet.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=bde163c8a3661fd5393106756950713c" aria-label="Video walkthrough: Deploy to your fleet" data-path="images/government/videos/admin-09-deploy-to-your-fleet.mp4" />
144</Frame>
145 
146<Accordion title="Transcript">
147 Push two values as device policy, the bootstrap address and the setting that hides the claude.ai sign-in option. On macOS they live in a configuration profile, on Windows in machine policy. Deliver them before the app, and note they carry no secrets.
148 
149 On Windows, deploy the MSIX package machine-wide. Anthropic publishes Intune install and detection scripts, and an offline installer for networks that cannot reach downloads.claude.ai.
150 
151 Cowork needs the Virtual Machine Platform feature, enabled with a restart before rollout. Run the Cowork readiness check on one device per hardware model.
152 
153 Allow the app to reach your host, and browsers to reach the host, its sign-in service, and your identity provider. Cowork and Code also download components from downloads.claude.ai.
154 
155 Decide on updates. If your agency distributes app updates itself, turn on Block automatic updates on the Config page, lock it, and add the disableAutoUpdates value to the profile. Otherwise, leave updates on.
156 
157 With the configuration delivered first, users land directly on the organization sign-in screen, and the configuration window becomes read-only. After a profile change, fully quit and reopen the app.
158</Accordion>
159 
120160When your device management system deploys Claude Desktop, end users receive the app without running an installer themselves. The management system installs the package with the system or root account on each platform, so end users need no administrator rights and see no elevation prompt. Push both the app installer and the configuration profile below through the same system.
121161 
122162The recommended profile contains two keys. In the macOS and Windows profiles below, write every value as a string exactly as shown, including booleans as the strings `"true"` or `"false"`; the Linux file uses native JSON types, as shown.
from line 248
208248To keep Linux devices on the versions your agency distributes, add the line `CLAUDE_DESKTOP_ADD_REPO=false` to `/etc/default/claude-desktop`, and create that file if it does not exist. The package then does not add the repository when it installs or upgrades. On a device that already has the package, also delete `/etc/apt/sources.list.d/claude-desktop.list`.
209249 
210250## Confirm it worked
251 
252<Frame caption="Video: Verify a managed device and spot common failures (1 min 40 s). Narrated with an AI-generated voice, with on-screen captions.">
253 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-10-verify-a-managed-device-and-spot-common-failures.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=3a725133f700322bdfcf0d684f9fd1c8" aria-label="Video walkthrough: Verify a managed device and spot common failures" data-path="images/government/videos/admin-10-verify-a-managed-device-and-spot-common-failures.mp4" />
254</Frame>
255 
256<Accordion title="Transcript">
257 On a managed device, the sign-in screen offers only Sign in with your organization, and the configuration window is read-only. Under Help, Troubleshooting, Generate Diagnostic Report saves a report that shows what the app read.
258 
259 Sign in as a test user with a seat tier. Chat should work, the picker should list that user's models, and your Config page banner should appear in the app.
260 
261 If the picker is empty, nothing is wrong with the device. Most often the user has no seat tier, and an organization owner assigns one on the Users page.
262 
263 Only the claude.ai sign-in means the configuration did not reach the app. Check delivery and the diagnostic report, then quit and reopen.
264 
265 A prompt to apply settings at every launch means the address was set per user. Have the user check the address and select Allow, and deliver it machine-wide to stop the prompt.
266 
267 A Microsoft page saying you cannot access this right now comes from a Conditional Access policy, which your identity team resolves. Nothing in the app changes it.
268 
269 On current app versions, Your session has expired with Sign in again is expected after the idle timeout your tenant sets, 24 hours by default. Signing in again reconnects the app. Older versions may call it a configuration sync issue, so update them.
270</Accordion>
211271 
212272Run through these checks on a configured machine from either path.
213273 

government/desktop/import Changed · +52 / -0 lines

from line 8
88 
99## Before you begin
1010 
11<Frame caption="Video: Signing in for the first time (1 min 32 s). Narrated with an AI-generated voice, with on-screen captions.">
12 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-01-signing-in-for-the-first-time.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=fcfdbcaa5f3ee9e9496e6014ed516b65" aria-label="Video walkthrough: Signing in for the first time" data-path="images/government/videos/user-01-signing-in-for-the-first-time.mp4" />
13</Frame>
14 
15<Accordion title="Transcript">
16 Claude Desktop is installed and connected for you by your agency. You sign in with your work account. No separate Claude account is needed.
17 
18 Open Claude. The sign-in screen says the app runs through your organization. Choose Sign in with your organization.
19 
20 Claude shows a pairing code, and opens your browser. The code works for a few minutes. If it expires, just start again.
21 
22 In the browser, enter your work email and select Continue. Then sign in the way you always do at your agency.
23 
24 Next comes the system use notification. Read it, and acknowledge it.
25 
26 Compare the code with the one in Claude, then select Approve. The page confirms you're signed in. Go back to Claude.
27 
28 You arrive on Home. Home and Code sit at the top of the sidebar, above your projects and recent chats.
29 
30 If your organization offers both Chat and Cowork, you pick one in the message box. The model picker is at the bottom right. Your seat decides which models it lists, so a colleague may see others.
31 
32 Code is for software work, in a folder you choose on your computer.
33 
34 If you can sign in but the model picker is empty, you have no seat yet. Ask your organization's owner to assign you one.
35</Accordion>
36 
1137* **You have an account on the web app.** It must use the same work email address as your account in Claude Desktop.
1238* **You are signed in to the web app in your default browser.** The import opens a browser tab there and asks for a one-time code, which expires after a few minutes.
1339 
from line 40
1440> **For administrators:** Anthropic enables the import for each organization. If a member's **Import & export** page says import is not enabled and their app is up to date, contact your Anthropic representative. The import needs Claude Desktop to download a component, so on a network that blocks `downloads.claude.ai`, deploy the offline installer described under [Installer and packaging](/docs/government/deploy-desktop/windows-checklist#installer-and-packaging) in the Windows fleet checklist. To remind members to run the import, turn on the [**Show the Claude for Government Web import banner**](/docs/government/config/settings#show-the-claude-for-government-web-import-banner) switch on the **Config** page.
1541 
1642## Run the import
43 
44<Frame caption="Video: Bringing your chats and projects over from Claude for Government Web (2 min 10 s). Narrated with an AI-generated voice, with on-screen captions.">
45 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-02-bringing-your-chats-and-projects-over.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=b7860d7dd7807b95aecc486b1aaf26f7" aria-label="Video walkthrough: Bringing your chats and projects over from Claude for Government Web" data-path="images/government/videos/user-02-bringing-your-chats-and-projects-over.mp4" />
46</Frame>
47 
48<Accordion title="Transcript">
49 If you used Claude for Government - Web, you can copy your chats and projects into Claude Desktop. First, sign in to the web app in your browser with the same work email you use in Claude Desktop.
50 
51 In Claude Desktop, open Settings from the account menu at the bottom of the sidebar, then Import and export, and select Import. The app does not prompt you to do this. Run it when you are ready.
52 
53 Select Sign in to Claude for Government Web, then Sign in. Claude shows a one-time code and opens the web app in your browser.
54 
55 In the browser tab that opens, sign in if you are asked, enter the code from Claude, and approve the connection. Then go back to Claude.
56 
57 Check that the email shown is yours, then select Fetch export. The web app gathers your chats and projects, and Claude downloads them.
58 
59 Select Continue, review what will be added, then select Import. When it finishes, the dialog reports what came over. Select Done.
60 
61 Your conversations appear in the sidebar with their files, and your projects under Projects with their files and instructions. Projects other people shared with you do not come over.
62 
63 Imported chats open in Chat. The first time you continue one, Claude asks whether to resume the imported session. Select Trust and resume to continue the conversation.
64 
65 A project that had instructions shows a notice. Claude won't follow imported instructions until you accept them: select Review instructions, check them, and save, or choose Use as is.
66 
67 The import only copies. Your chats and projects stay in the web app too. You can run it again, and chats already imported are skipped. If the Import page says import isn't enabled, ask your administrator.
68</Accordion>
1769 
1870You start the import yourself from **Settings**, whenever you are ready. If Claude Desktop's home screen shows a **Pick up where you left off in Claude for Government Web** banner, its **Start import** button takes you to the **Import & export** page in **Settings**. If you click **Skip for now** or close the banner, it can come back a few days later, until you run the import or have skipped it a few times. Claude Desktop versions earlier than 2.16120.0 hide the banner permanently after one skip.
1971 

government/desktop/plugins Changed · +24 / -0 lines

from line 6
66 
77A plugin is a package that adds capabilities to Claude in a single step, such as skills, slash commands, sub-agents, and hooks. Plugins work in Cowork and in Code. See the [Plugins overview](/docs/plugins/overview) for more on what a plugin can contain.
88 
9<Frame caption="Video: Connectors, plugins, and skills from your agency (2 min 6 s). Narrated with an AI-generated voice, with on-screen captions.">
10 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-04-connectors-plugins-and-skills.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=953d050db0ec38bd9d0db7399e96cf40" aria-label="Video walkthrough: Connectors, plugins, and skills from your agency" data-path="images/government/videos/user-04-connectors-plugins-and-skills.mp4" />
11</Frame>
12 
13<Accordion title="Transcript">
14 Open Customize in the sidebar for your skills, connectors, and plugins. A connector lets Claude reach another service. The ones you can use come from your organization: here, Microsoft 365 and Web Search.
15 
16 If your organization has set up Microsoft 365, select Connect and sign in with your Microsoft work account. Claude can then search your mail, calendar, files, and Teams chats, reaching only what you can already open.
17 
18 In a chat, ask about your mail, and Claude asks before it searches. The card shows the search it wants to run. Allow it once, allow it for this task, or deny it.
19 
20 A plugin packages skills and commands from your organization. Plugins lists the ones already installed. Some install automatically. Open one to see its skills and switch it on or off.
21 
22 To find the rest, select Browse and open the Organization tab, which lists everything your organization offers you. Each plugin's plus sign installs it, and it then appears under Plugins.
23 
24 A skill teaches Claude one task your way, set up once and reused. If your organization allows it, select Add under Skills. Upload skill takes a skill file you have, and Create a skill lets you write one.
25 
26 The skill appears in your list, switched on. Skills you add stay on this computer. To give one to colleagues, your administrators package it in a plugin.
27 
28 Back in Chat, ask for something the skill covers and Claude loads it on its own. Here it rewrites a sentence in plain language.
29 
30 If Microsoft 365, web search, or a plugin you expect is missing, ask your organization's owner, who decides what is turned on for you.
31</Accordion>
32 
933## Where plugins come from
1034 
1135In Claude for Government, plugins reach you in three ways:

government/desktop/video-walkthroughs New page · 159 lines, new page

# Video walkthroughs for Claude Desktop ## End-user series ### Signing in for the first time ### Bringing your chats and projects over from Claude for Government Web ### Chat, Cowork, and Code ### Connectors, plugins, and skills from your agency ### Your account, usage limits, and getting help

A whole new page. There's nothing to diff it against, so here is what it says.

# Video walkthroughs for Claude Desktop

> Watch short narrated walkthroughs of signing in to Claude Desktop with Claude for Government, bringing your work over, and finding your way around the app.

> **Who this is for:** Anyone using Claude Desktop connected to Claude for Government. If you set up or manage Claude for Government for your agency, see [Video walkthroughs for administrators](/docs/government/video-walkthroughs) instead.

Each video is one to three minutes long and narrated, with on-screen captions.

## End-user series

The videos run from the first sign-in to getting help.

### Signing in for the first time

Signing in to Claude Desktop with your work account and a pairing code, and where Chat, Cowork, Code, and the model picker are.

<Frame caption="Video: Signing in for the first time (1 min 32 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-01-signing-in-for-the-first-time.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=fcfdbcaa5f3ee9e9496e6014ed516b65" aria-label="Video walkthrough: Signing in for the first time" data-path="images/government/videos/user-01-signing-in-for-the-first-time.mp4" />
</Frame>

<Accordion title="Transcript">
  Claude Desktop is installed and connected for you by your agency. You sign in with your work account. No separate Claude account is needed.

  Open Claude. The sign-in screen says the app runs through your organization. Choose Sign in with your organization.

  Claude shows a pairing code, and opens your browser. The code works for a few minutes. If it expires, just start again.

  In the browser, enter your work email and select Continue. Then sign in the way you always do at your agency.

  Next comes the system use notification. Read it, and acknowledge it.

  Compare the code with the one in Claude, then select Approve. The page confirms you're signed in. Go back to Claude.

  You arrive on Home. Home and Code sit at the top of the sidebar, above your projects and recent chats.

  If your organization offers both Chat and Cowork, you pick one in the message box. The model picker is at the bottom right. Your seat decides which models it lists, so a colleague may see others.

  Code is for software work, in a folder you choose on your computer.

  If you can sign in but the model picker is empty, you have no seat yet. Ask your organization's owner to assign you one.
</Accordion>

### Bringing your chats and projects over from Claude for Government Web

Copying your conversations and projects from Claude for Government Web into Claude Desktop. Read more: [Run the import](/docs/government/desktop/import#run-the-import).

<Frame caption="Video: Bringing your chats and projects over from Claude for Government Web (2 min 10 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-02-bringing-your-chats-and-projects-over.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=b7860d7dd7807b95aecc486b1aaf26f7" aria-label="Video walkthrough: Bringing your chats and projects over from Claude for Government Web" data-path="images/government/videos/user-02-bringing-your-chats-and-projects-over.mp4" />
</Frame>

<Accordion title="Transcript">
  If you used Claude for Government - Web, you can copy your chats and projects into Claude Desktop. First, sign in to the web app in your browser with the same work email you use in Claude Desktop.

  In Claude Desktop, open Settings from the account menu at the bottom of the sidebar, then Import and export, and select Import. The app does not prompt you to do this. Run it when you are ready.

  Select Sign in to Claude for Government Web, then Sign in. Claude shows a one-time code and opens the web app in your browser.

  In the browser tab that opens, sign in if you are asked, enter the code from Claude, and approve the connection. Then go back to Claude.

  Check that the email shown is yours, then select Fetch export. The web app gathers your chats and projects, and Claude downloads them.

  Select Continue, review what will be added, then select Import. When it finishes, the dialog reports what came over. Select Done.

  Your conversations appear in the sidebar with their files, and your projects under Projects with their files and instructions. Projects other people shared with you do not come over.

  Imported chats open in Chat. The first time you continue one, Claude asks whether to resume the imported session. Select Trust and resume to continue the conversation.

  A project that had instructions shows a notice. Claude won't follow imported instructions until you accept them: select Review instructions, check them, and save, or choose Use as is.

  The import only copies. Your chats and projects stay in the web app too. You can run it again, and chats already imported are skipped. If the Import page says import isn't enabled, ask your administrator.
</Accordion>

### Chat, Cowork, and Code

What Chat, Cowork, and Code are each for, when Claude asks for your approval in each, and how projects work.

<Frame caption="Video: Chat, Cowork, and Code: which one to use (2 min 35 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-03-chat-cowork-and-code.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=9402b32239886fb0f79a8648921fe53e" aria-label="Video walkthrough: Chat, Cowork, and Code: which one to use" data-path="images/government/videos/user-03-chat-cowork-and-code.mp4" />
</Frame>

<Accordion title="Transcript">
  Claude Desktop gives you three ways to work: Chat, Cowork, and Code. On Home, you pick Chat or Cowork in the message box. Code sits beside Home.

  Chat is for quick questions and drafting. For current information, Claude can search the web, if your organization has turned that on.

  By default, Claude asks before every search. It shows you the search it wants to run. Allow once runs it, and Deny skips it.

  Then Claude searches and answers.

  Chat also reads files you attach. Add a document with the plus button and ask for a summary. Out of the box, Chat doesn't reach into folders on your computer.

  For work that should end up in your files, switch to Cowork and choose a folder. Claude asks whether it may change files there. Select Allow.

  Describe the outcome: here, a one-page summary saved in the same folder. Claude plans the steps and works through them on its own. If it needs another folder, it asks first.

  When it finishes, the summary is a real file in your folder.

  Code is Claude Code, built into the app, for software development. It works directly in the folder you open, and here it asks before running a command.

  Projects keep ongoing work in one place. Under Projects, select New project, then Use an existing folder. Choose the folder, name the project, and create it.

  A project holds your folder and instructions, and you start chats or Cowork tasks in it. Projects live on your computer, not in the cloud. They are personal to you and, unlike on Claude for Government - Web, cannot be shared with colleagues.

  Chat for questions and documents. Cowork for tasks in your folders. Code for software development. Your organization decides which of the three you have, so a colleague may see a different set. If one is missing for you, ask your organization's owner.
</Accordion>

### Connectors, plugins, and skills from your agency

Connecting Microsoft 365, installing plugins your organization offers, and adding a skill, all from **Customize** in the sidebar. Read more: [Plugins in Claude Desktop](/docs/government/desktop/plugins) and [Skills in Claude Desktop](/docs/government/desktop/skills).

<Frame caption="Video: Connectors, plugins, and skills from your agency (2 min 6 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-04-connectors-plugins-and-skills.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=953d050db0ec38bd9d0db7399e96cf40" aria-label="Video walkthrough: Connectors, plugins, and skills from your agency" data-path="images/government/videos/user-04-connectors-plugins-and-skills.mp4" />
</Frame>

<Accordion title="Transcript">
  Open Customize in the sidebar for your skills, connectors, and plugins. A connector lets Claude reach another service. The ones you can use come from your organization: here, Microsoft 365 and Web Search.

  If your organization has set up Microsoft 365, select Connect and sign in with your Microsoft work account. Claude can then search your mail, calendar, files, and Teams chats, reaching only what you can already open.

  In a chat, ask about your mail, and Claude asks before it searches. The card shows the search it wants to run. Allow it once, allow it for this task, or deny it.

  A plugin packages skills and commands from your organization. Plugins lists the ones already installed. Some install automatically. Open one to see its skills and switch it on or off.

  To find the rest, select Browse and open the Organization tab, which lists everything your organization offers you. Each plugin's plus sign installs it, and it then appears under Plugins.

  A skill teaches Claude one task your way, set up once and reused. If your organization allows it, select Add under Skills. Upload skill takes a skill file you have, and Create a skill lets you write one.

  The skill appears in your list, switched on. Skills you add stay on this computer. To give one to colleagues, your administrators package it in a plugin.

  Back in Chat, ask for something the skill covers and Claude loads it on its own. Here it rewrites a sentence in plain language.

  If Microsoft 365, web search, or a plugin you expect is missing, ask your organization's owner, who decides what is turned on for you.
</Accordion>

### Your account, usage limits, and getting help

The **Account**, **Usage**, and **Sessions** pages, signing in again after an idle timeout, the diagnostic report, and who to ask for what. Read more: [Your account](/docs/government/account/overview).

<Frame caption="Video: Your account, usage limits, and getting help (1 min 57 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/user-05-your-account-usage-limits-and-getting-help.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=691f1dc9497295c364c0e8f81020b942" aria-label="Video walkthrough: Your account, usage limits, and getting help" data-path="images/government/videos/user-05-your-account-usage-limits-and-getting-help.mp4" />
</Frame>

<Accordion title="Transcript">
  Your account pages are in the web portal. In a browser, open your agency's Claude for Government address and sign in. Account shows your email, organization, role, and seat tier, all read-only.

  Usage shows your allowance: a 5-hour window and a 7-day window, each with the share you have used and when it resets. If either reaches 100 percent, Claude pauses until that window resets. Claude Desktop itself does not show this allowance.

  Sessions lists every place you are signed in, whether in a browser or in Claude Desktop, and when each sign-in began. To sign out a computer you no longer have, select Sign out on its row.

  In the app, your session ends after a period of inactivity that your agency sets, 24 hours unless they change it. Claude then tells you that you have been signed out and asks you to sign in again.

  Select Sign in again. Your browser opens to confirm it is you, and then you are back in the same conversation. Your chats stay on your computer.

  If something isn't working, your help desk may ask for a diagnostic report. From Help, choose Troubleshooting, then Generate Diagnostic Report.

  The dialog lists what goes in: app and system details, your configuration with secrets removed, network checks, and recent errors. It never includes your conversations. Select Export to file and attach the file to your ticket.

  Who to ask: your organization's owner for a seat, a larger allowance, or a wrong organization or role. Your IT help desk for anything about the app on your computer. Your administrators can take it from there.
</Accordion>

government/org-admin/overview Changed · +22 / -0 lines

from line 6
66 
77The organization admin portal is where you manage the people, seats, and settings for a single organization in Claude for Government. It covers the day-to-day work of administering who has access, how much they can use, and how the Claude products behave for your users.
88 
9<Frame caption="Video: Organization owners: users, seat tiers, and Readiness (1 min 48 s). Narrated with an AI-generated voice, with on-screen captions.">
10 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-05-organization-owners-users-seat-tiers-and-readiness.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=d235ae566a0056c409a1b59b2a9623e7" aria-label="Video walkthrough: Organization owners: users, seat tiers, and Readiness" data-path="images/government/videos/admin-05-organization-owners-users-seat-tiers-and-readiness.mp4" />
11</Frame>
12 
13<Accordion title="Transcript">
14 In an organization, a member's role decides what they can manage, and their seat tier decides which models they can use and how much. Readiness shows what still blocks your members.
15 
16 Marcus, a Primary Owner, signs in and lands on the organization admin view.
17 
18 Under Settings, Readiness lists what blocks members. Every required step is done, but one optional item remains, Assign seat tiers to members. Select Open Users.
19 
20 Users lists every member with their role, seat tier, usage against the five-hour and seven-day limits, and last login.
21 
22 Wen is Unassigned. Wen can sign in, but Claude Desktop offers no models. Choose a tier from the Seat tier dropdown. The change applies at once, and the models appear the next time Wen starts Claude Desktop.
23 
24 Roles are User, Owner, and Primary Owner. Keep at least two Primary Owners, so one can always promote a replacement. From Priya's Role dropdown, Marcus chooses Primary Owner.
25 
26 Tiers lists the seat tiers available to your organization. Anthropic-managed tiers are read-only, and your tenant can let you create your own.
27 
28 Model access comes from the seat tier, never from the role. Tenant administrator is separate from these roles. If directory groups set roles or tiers, change the group in your provider, because the group mappings overwrite edits made by hand.
29</Accordion>
30 
931## Key concepts
1032 
1133Before you use the portal, it helps to understand how the pieces fit together.

government/overview Changed · +40 / -0 lines

from line 58
5858 
5959## The three views
6060 
61<Frame caption="Video: Finding your way around (2 min 23 s). Narrated with an AI-generated voice, with on-screen captions.">
62 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-01-finding-your-way-around.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=e815e7d6b488de1c9629bfaa2f1354ab" aria-label="Video walkthrough: Finding your way around" data-path="images/government/videos/admin-01-finding-your-way-around.mp4" />
63</Frame>
64 
65<Accordion title="Transcript">
66 Your tenant is your agency's deployment and holds its organizations. Each user belongs to one, run by Owners and Primary Owners. Tenant administrators manage the tenant.
67 
68 This video shows the web portal, which you open in a browser. Members use Claude in the Claude Desktop app, with Chat, Cowork, and Code.
69 
70 In a browser, open your agency's Claude for Government address and enter your work email.
71 
72 Select Continue, and your agency's usual sign-in page opens.
73 
74 After your agency's single sign-on, acknowledge the system-use notification.
75 
76 As an organization owner, Marcus lands on the admin view. With several organizations, tenant administrators pick one from the organization menu at the top of the page.
77 
78 Under People, Users lists each member's role and seat tier. Owners and Primary Owners manage these.
79 
80 Under Settings, Readiness lists anything blocking members from using Claude. Every step here is complete.
81 
82 The footer holds the view links. Select Switch to user view.
83 
84 The Account view shows your profile, usage, and sessions. Members who are not owners land here. Marcus is a Primary Owner and, separately, a tenant administrator.
85 
86 Switch to admin view takes you back.
87 
88 Tenant administrators also get Switch to tenant view.
89 
90 The tenant view covers every organization, with identity, seats, settings, and admins. Select an organization's name to open its admin view.
91 
92 Until setup is complete, Resume setup sits above the navigation.
93 
94 The dot on Settings flags Readiness. Its second card lists each organization, and Research Office still needs seats. Expand the row for its checklist, then follow Open to fix it.
95 
96 Admins, under Settings, lists the tenant administrators. Keep at least two.
97 
98 Switch to org view returns to the organization admin view.
99</Accordion>
100 
61101The portal has three views. Which ones you can reach depends on your role, and you switch between them using the link in the page footer.
62102 
63103| View | Who has it | What it's for |

government/tenant-admin/identity-and-access Changed · +54 / -0 lines

from line 75
7575 
7676## SCIM provisioning
7777 
78<Frame caption="Video: Directory sync (SCIM) and group mappings (2 min 3 s). Narrated with an AI-generated voice, with on-screen captions.">
79 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-04-directory-sync-scim-and-group-mappings.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=e254e02786c5f309b5c5c240c7752c4e" aria-label="Video walkthrough: Directory sync (SCIM) and group mappings" data-path="images/government/videos/admin-04-directory-sync-scim-and-group-mappings.mp4" />
80</Frame>
81 
82<Accordion title="Transcript">
83 Directory sync is optional, and without it accounts are created at first sign-in. With it, your identity provider pushes users and groups, provisioning rules place them in organizations, and each organization maps groups to seat tiers and roles.
84 
85 On Identity and access, open SCIM provisioning. Copy the SCIM base URL, which your provider may call the Tenant URL, and select Generate token.
86 
87 The token is shown once. Copy it for your provider's secret token field, then select Done. You can revoke a token here at any time.
88 
89 In your provider's provisioning settings, paste both values, assign the groups you want to sync, and turn provisioning on.
90 
91 After the first sync, your groups appear under Directory groups with member counts, and people not yet placed wait under Synced, not routed.
92 
93 Under Provisioning rules, route groups to organizations. Send research-staff to Research Office, and claude-users to Operations Bureau. The first match wins, so add the narrower group first or drag it to the top.
94 
95 Once a rule covers them, they are placed in its organization, and the list clears on its own.
96 
97 In the organization's admin view, People now includes Group mappings. Map claude-users to a seat tier, here Standard, and claude-owners to the Owner role. Each change is applied right away.
98 
99 On Users, the provisioned members now hold their mapped seat tier and role.
100 
101 While sync is connected, your directory is the source of truth. Change groups in your provider, because role or seat tier edits made by hand are overwritten by the group mappings.
102</Accordion>
103 
78104SCIM is the standard protocol identity providers use to push users and groups to a connected service automatically, so that accounts are created, updated, and deactivated in step with your agency's directory. Connecting SCIM is optional; without it, users are created the first time they sign in. With SCIM connected, a person your directory has never sent still gets an account the first time they sign in, if a [sign-in rule](#sign-in-rules) covers them.
79105 
80106[Provisioning rules](#provisioning-rules-scim), [group mappings](/docs/government/org-admin/provisioning), and [group-specific settings](/docs/government/config/overview#group-specific-settings) need SCIM, because they act on the [directory groups](#directory-groups) your identity provider pushes. Model access and usage limits come from each person's [seat tier](/docs/government/org-admin/seat-tiers), which an organization owner can assign on the [Users](/docs/government/org-admin/users) page without SCIM.
from line 128
102128Once your identity provider has pushed groups over SCIM, they appear here with their member counts. To change the order, drag a group by the handle at the start of its row or use the **…** menu at the end. The order you set here is the priority used for group-level configuration on the [Config](/docs/government/config/overview#group-specific-settings) page.
103129 
104130## Routing rules
131 
132<Frame caption="Video: Organizations, seats, and routing rules (2 min 14 s). Narrated with an AI-generated voice, with on-screen captions.">
133 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-03-organizations-seats-and-routing-rules.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=3b4fdf17a38f17ace0a31daff24dd678" aria-label="Video walkthrough: Organizations, seats, and routing rules" data-path="images/government/videos/admin-03-organizations-seats-and-routing-rules.mp4" />
134</Frame>
135 
136<Accordion title="Transcript">
137 Routing rules decide which organization each person lands in. Organizations hold users, seats, and settings, and their seats come from a billing account.
138 
139 Marcus, a tenant administrator, signs in and opens the tenant view from the footer.
140 
141 A new colleague, Rosa, tries to sign in. No routing rule covers Rosa yet, so the page says Almost there. The attempt is recorded for tenant administrators.
142 
143 On Identity and access, Rejected sign-ins lists the attempt. Select Test in preview to check whether any rule covers Rosa.
144 
145 The preview says refused at sign-in, because no rule matches Rosa yet.
146 
147 Under Sign-in routing, add the first rule. Set If to Anyone with email domain, and choose example.gov. Set Then place in to Operations Bureau, and select Add rule. Rules run top to bottom, and the first match wins.
148 
149 Run the preview again. Rosa would now be placed in Operations Bureau.
150 
151 Rosa selects Try again and signs in once more. Rosa lands in Operations Bureau and gets a seat, because one was free.
152 
153 On Organizations, expand Add organization. Enter a name and the Primary Owner's email, choose the billing account, then select Add. The owner does not automatically become a tenant administrator.
154 
155 On Seats, the billing account shows its pool and the organizations it funds. Give Research Office seats and select Save. Its first seats also seat its Primary Owner, and the setup banner clears.
156 
157 To send people to Research Office, add an identity provider group rule for them and drag it above the domain rule. Each person belongs to exactly one organization.
158</Accordion>
105159 
106160A **routing rule** is an instruction of the form "if a person matches this condition, place them in this organization." Routing rules are the **only** way a new person gets into your deployment; there is no default organization and no fallback.
107161 

government/tenant-admin/setup-wizard Changed · +32 / -0 lines

from line 16
1616 
1717## Step 2: Domains
1818 
19<Frame caption="Video: Verify your domain and connect single sign-on (2 min 24 s). Narrated with an AI-generated voice, with on-screen captions.">
20 <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-02-verify-your-domain-and-connect-single-sign-on.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=bf307a4d18d646cbce35d3c269be51b7" aria-label="Video walkthrough: Verify your domain and connect single sign-on" data-path="images/government/videos/admin-02-verify-your-domain-and-connect-single-sign-on.mp4" />
21</Frame>
22 
23<Accordion title="Transcript">
24 Before your members can sign in, your tenant needs a verified email domain and a connection to your identity provider.
25 
26 Until single sign-on is connected, tenant administrators sign in with a link sent by email.
27 
28 Enter your email, select Email me a sign-in link, and open the link from your inbox. Confirm with Sign in, then acknowledge the system-use notification.
29 
30 Select Switch to tenant view in the footer, then Resume setup at the top, then Next.
31 
32 Sign-in finds your tenant by email domain. Unless Anthropic already verified it, type your agency's domain and select Claim. The page shows a TXT record that proves ownership.
33 
34 Your DNS administrator publishes the record. It can take a few minutes to an hour to appear.
35 
36 Once the record is live, select Verify now. The domain now shows as Verified.
37 
38 Next is Single sign-on. Copy the Redirect URI and the SP Entity ID. You will paste them into your provider.
39 
40 In your provider, create an application and paste in those values. In return, OIDC gives you a client ID, a secret, and four endpoints. SAML gives one metadata file.
41 
42 First, in another window, confirm you can sign in to your provider. This change applies to everyone, including you. Then enter the values and select Connect. The badge reads Connected. Administrators keep the emailed link as a fallback.
43 
44 If your provider uses SAML instead, paste its metadata XML on the SAML tab. Saving one replaces the other.
45 
46 Sign-in starts from Claude Desktop or the web portal. Starting from the app's tile in your provider's portal is not supported.
47 
48 Both steps are now ticked. New people cannot sign in until a routing rule places them in an organization. That is the wizard's Routing step.
49</Accordion>
50 
1951Claude for Government looks at the domain of a person's email address to decide which tenant they belong to, so at least one verified domain must be registered before anyone else can sign in. The table at the top of this step lists the domains already on your tenant, along with whether each one is verified and whether it was added by Anthropic or by you.
2052 
2153If Anthropic already verified the domain you plan to use, you can move straight on to the next step. To add another domain, type it into the **Claim a domain** field and click **Claim**. You will be shown a DNS TXT record to publish on that domain. Once the record is live, click **Verify now** next to the pending claim and the domain becomes active. DNS changes can take anywhere from a few minutes to an hour to propagate, so try again shortly if verification does not succeed on the first attempt.

government/video-walkthroughs New page · 307 lines, new page

# Video walkthroughs for administrators ## Admin series ### Finding your way around ### Verify your domain and connect single sign-on ### Organizations, seats, and routing rules ### Directory sync (SCIM) and group mappings ### Users, seat tiers, and Readiness for organization owners ### Config essentials ### Connectors and plugins ### Pilot Claude Desktop on one machine ### Deploy to your fleet ### Verify a managed device and spot common failures

A whole new page. There's nothing to diff it against, so here is what it says.

# Video walkthroughs for administrators

> Watch short narrated walkthroughs of setting up and running Claude for Government for your agency.

> **Who this is for:** Tenant administrators, organization owners, and IT administrators who set up and run Claude for Government. If you use Claude Desktop but don't administer it, see [Video walkthroughs for Claude Desktop](/docs/government/desktop/video-walkthroughs) instead.

Each video is one to three minutes long and narrated, with on-screen captions.

## Admin series

The videos follow the order of a first setup.

### Finding your way around

How a tenant, its organizations, and their users fit together, how administrators sign in to the web portal, and how to move between the admin, tenant, and account views. Read more: [The three views](/docs/government/overview#the-three-views).

<Frame caption="Video: Finding your way around (2 min 23 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-01-finding-your-way-around.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=e815e7d6b488de1c9629bfaa2f1354ab" aria-label="Video walkthrough: Finding your way around" data-path="images/government/videos/admin-01-finding-your-way-around.mp4" />
</Frame>

<Accordion title="Transcript">
  Your tenant is your agency's deployment and holds its organizations. Each user belongs to one, run by Owners and Primary Owners. Tenant administrators manage the tenant.

  This video shows the web portal, which you open in a browser. Members use Claude in the Claude Desktop app, with Chat, Cowork, and Code.

  In a browser, open your agency's Claude for Government address and enter your work email.

  Select Continue, and your agency's usual sign-in page opens.

  After your agency's single sign-on, acknowledge the system-use notification.

  As an organization owner, Marcus lands on the admin view. With several organizations, tenant administrators pick one from the organization menu at the top of the page.

  Under People, Users lists each member's role and seat tier. Owners and Primary Owners manage these.

  Under Settings, Readiness lists anything blocking members from using Claude. Every step here is complete.

  The footer holds the view links. Select Switch to user view.

  The Account view shows your profile, usage, and sessions. Members who are not owners land here. Marcus is a Primary Owner and, separately, a tenant administrator.

  Switch to admin view takes you back.

  Tenant administrators also get Switch to tenant view.

  The tenant view covers every organization, with identity, seats, settings, and admins. Select an organization's name to open its admin view.

  Until setup is complete, Resume setup sits above the navigation.

  The dot on Settings flags Readiness. Its second card lists each organization, and Research Office still needs seats. Expand the row for its checklist, then follow Open to fix it.

  Admins, under Settings, lists the tenant administrators. Keep at least two.

  Switch to org view returns to the organization admin view.
</Accordion>

### Verify your domain and connect single sign-on

Claiming and verifying your agency's email domain, then connecting your identity provider with OIDC or SAML in the setup wizard. Read more: [Step 2: Domains](/docs/government/tenant-admin/setup-wizard#step-2-domains) and [Single sign-on](/docs/government/tenant-admin/identity-and-access#single-sign-on).

<Frame caption="Video: Verify your domain and connect single sign-on (2 min 24 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-02-verify-your-domain-and-connect-single-sign-on.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=bf307a4d18d646cbce35d3c269be51b7" aria-label="Video walkthrough: Verify your domain and connect single sign-on" data-path="images/government/videos/admin-02-verify-your-domain-and-connect-single-sign-on.mp4" />
</Frame>

<Accordion title="Transcript">
  Before your members can sign in, your tenant needs a verified email domain and a connection to your identity provider.

  Until single sign-on is connected, tenant administrators sign in with a link sent by email.

  Enter your email, select Email me a sign-in link, and open the link from your inbox. Confirm with Sign in, then acknowledge the system-use notification.

  Select Switch to tenant view in the footer, then Resume setup at the top, then Next.

  Sign-in finds your tenant by email domain. Unless Anthropic already verified it, type your agency's domain and select Claim. The page shows a TXT record that proves ownership.

  Your DNS administrator publishes the record. It can take a few minutes to an hour to appear.

  Once the record is live, select Verify now. The domain now shows as Verified.

  Next is Single sign-on. Copy the Redirect URI and the SP Entity ID. You will paste them into your provider.

  In your provider, create an application and paste in those values. In return, OIDC gives you a client ID, a secret, and four endpoints. SAML gives one metadata file.

  First, in another window, confirm you can sign in to your provider. This change applies to everyone, including you. Then enter the values and select Connect. The badge reads Connected. Administrators keep the emailed link as a fallback.

  If your provider uses SAML instead, paste its metadata XML on the SAML tab. Saving one replaces the other.

  Sign-in starts from Claude Desktop or the web portal. Starting from the app's tile in your provider's portal is not supported.

  Both steps are now ticked. New people cannot sign in until a routing rule places them in an organization. That is the wizard's Routing step.
</Accordion>

### Organizations, seats, and routing rules

Adding a sign-in routing rule that places new people in the right organization, adding an organization, and giving it seats. Read more: [Routing rules](/docs/government/tenant-admin/identity-and-access#routing-rules).

<Frame caption="Video: Organizations, seats, and routing rules (2 min 14 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-03-organizations-seats-and-routing-rules.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=3b4fdf17a38f17ace0a31daff24dd678" aria-label="Video walkthrough: Organizations, seats, and routing rules" data-path="images/government/videos/admin-03-organizations-seats-and-routing-rules.mp4" />
</Frame>

<Accordion title="Transcript">
  Routing rules decide which organization each person lands in. Organizations hold users, seats, and settings, and their seats come from a billing account.

  Marcus, a tenant administrator, signs in and opens the tenant view from the footer.

  A new colleague, Rosa, tries to sign in. No routing rule covers Rosa yet, so the page says Almost there. The attempt is recorded for tenant administrators.

  On Identity and access, Rejected sign-ins lists the attempt. Select Test in preview to check whether any rule covers Rosa.

  The preview says refused at sign-in, because no rule matches Rosa yet.

  Under Sign-in routing, add the first rule. Set If to Anyone with email domain, and choose example.gov. Set Then place in to Operations Bureau, and select Add rule. Rules run top to bottom, and the first match wins.

  Run the preview again. Rosa would now be placed in Operations Bureau.

  Rosa selects Try again and signs in once more. Rosa lands in Operations Bureau and gets a seat, because one was free.

  On Organizations, expand Add organization. Enter a name and the Primary Owner's email, choose the billing account, then select Add. The owner does not automatically become a tenant administrator.

  On Seats, the billing account shows its pool and the organizations it funds. Give Research Office seats and select Save. Its first seats also seat its Primary Owner, and the setup banner clears.

  To send people to Research Office, add an identity provider group rule for them and drag it above the domain rule. Each person belongs to exactly one organization.
</Accordion>

### Directory sync (SCIM) and group mappings

Connecting SCIM provisioning, routing directory groups to organizations, and mapping groups to seat tiers and roles. Read more: [SCIM provisioning](/docs/government/tenant-admin/identity-and-access#scim-provisioning) and [Group mappings](/docs/government/org-admin/provisioning).

<Frame caption="Video: Directory sync (SCIM) and group mappings (2 min 3 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-04-directory-sync-scim-and-group-mappings.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=e254e02786c5f309b5c5c240c7752c4e" aria-label="Video walkthrough: Directory sync (SCIM) and group mappings" data-path="images/government/videos/admin-04-directory-sync-scim-and-group-mappings.mp4" />
</Frame>

<Accordion title="Transcript">
  Directory sync is optional, and without it accounts are created at first sign-in. With it, your identity provider pushes users and groups, provisioning rules place them in organizations, and each organization maps groups to seat tiers and roles.

  On Identity and access, open SCIM provisioning. Copy the SCIM base URL, which your provider may call the Tenant URL, and select Generate token.

  The token is shown once. Copy it for your provider's secret token field, then select Done. You can revoke a token here at any time.

  In your provider's provisioning settings, paste both values, assign the groups you want to sync, and turn provisioning on.

  After the first sync, your groups appear under Directory groups with member counts, and people not yet placed wait under Synced, not routed.

  Under Provisioning rules, route groups to organizations. Send research-staff to Research Office, and claude-users to Operations Bureau. The first match wins, so add the narrower group first or drag it to the top.

  Once a rule covers them, they are placed in its organization, and the list clears on its own.

  In the organization's admin view, People now includes Group mappings. Map claude-users to a seat tier, here Standard, and claude-owners to the Owner role. Each change is applied right away.

  On Users, the provisioned members now hold their mapped seat tier and role.

  While sync is connected, your directory is the source of truth. Change groups in your provider, because role or seat tier edits made by hand are overwritten by the group mappings.
</Accordion>

### Users, seat tiers, and Readiness for organization owners

Checking the **Readiness** page, assigning seat tiers and roles on the **Users** page, and reviewing the **Tiers** page. Read more: [Organization administration](/docs/government/org-admin/overview).

<Frame caption="Video: Organization owners: users, seat tiers, and Readiness (1 min 48 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-05-organization-owners-users-seat-tiers-and-readiness.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=d235ae566a0056c409a1b59b2a9623e7" aria-label="Video walkthrough: Organization owners: users, seat tiers, and Readiness" data-path="images/government/videos/admin-05-organization-owners-users-seat-tiers-and-readiness.mp4" />
</Frame>

<Accordion title="Transcript">
  In an organization, a member's role decides what they can manage, and their seat tier decides which models they can use and how much. Readiness shows what still blocks your members.

  Marcus, a Primary Owner, signs in and lands on the organization admin view.

  Under Settings, Readiness lists what blocks members. Every required step is done, but one optional item remains, Assign seat tiers to members. Select Open Users.

  Users lists every member with their role, seat tier, usage against the five-hour and seven-day limits, and last login.

  Wen is Unassigned. Wen can sign in, but Claude Desktop offers no models. Choose a tier from the Seat tier dropdown. The change applies at once, and the models appear the next time Wen starts Claude Desktop.

  Roles are User, Owner, and Primary Owner. Keep at least two Primary Owners, so one can always promote a replacement. From Priya's Role dropdown, Marcus chooses Primary Owner.

  Tiers lists the seat tiers available to your organization. Anthropic-managed tiers are read-only, and your tenant can let you create your own.

  Model access comes from the seat tier, never from the role. Tenant administrator is separate from these roles. If directory groups set roles or tiers, change the group in your provider, because the group mappings overwrite edits made by hand.
</Accordion>

### Config essentials

Editing settings on the **Config** page for an organization or for one directory group, turning on web search, reviewing the session idle timeout, and locking a value for every organization from the tenant. Read more: [How Config works](/docs/government/config/overview).

<Frame caption="Video: Config essentials (2 min 23 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-06-config-essentials.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=8624805f501e6ca7e01e12e6e94602ab" aria-label="Video walkthrough: Config essentials" data-path="images/government/videos/admin-06-config-essentials.mp4" />
</Frame>

<Accordion title="Transcript">
  Config sets product behavior for the people you manage. The tenant and each organization share the same page, and each level starts from the one above it.

  In the admin view, open Config under Settings. Settings are grouped on the left, and the scope bar at the top shows which level you are editing.

  Product availability has a switch for each product and feature. Chat, Cowork, and Code in Claude Desktop are on by default. Here the organization turns Code in Claude Desktop off and saves.

  To treat one directory group differently, choose it in the scope bar. The same editor appears for that group, and Code in Claude Desktop is turned back on for its members, unless a higher-priority group has settings for them.

  Under Integrations, Web search is off by default. Turning it on asks you to acknowledge how search works. Require approval for each search stays on, so members approve every search.

  Under Sessions and access, Session idle timeout signs out inactive members after 24 hours by default. Lower levels can only shorten it, and lowering it applies from the next sign-in.

  In the tenant view, open the same page and set the Claude Desktop banner for everyone. Choose Must use this value, open Preview impact, then save. Every organization now uses this value.

  Back in the organization's Config, the banner shows Locked by your tenant and cannot be changed there.

  You do not need to push anything. Claude Desktop checks for changes at launch and about every 10 minutes while it runs, or every 30 minutes on older versions, and prompts members to relaunch when something changed.
</Accordion>

### Connectors and plugins

Setting up the Microsoft 365 connector, adding a connector of your own with a tool policy, and adding a plugin. Read more: [Connectors](/docs/government/connectors/overview) and [Manage plugins and connectors](/docs/government/config/plugins-and-connectors).

<Frame caption="Video: Connectors and plugins (2 min 8 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-07-connectors-and-plugins.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=43f78d15928eea46d27229f8dbc04db6" aria-label="Video walkthrough: Connectors and plugins" data-path="images/government/videos/admin-07-connectors-and-plugins.mp4" />
</Frame>

<Accordion title="Transcript">
  A connector lets Claude reach another service, such as Microsoft 365 or a system of your own. A plugin packages skills and commands for Claude Desktop.

  Microsoft 365 setup starts in Microsoft Entra. An Entra administrator registers an application, approves its Microsoft Graph permissions, and sends you two values, the tenant ID and the client ID.

  On Config, under Integrations, expand Microsoft 365. Paste the Tenant ID and the Client ID, keep Azure cloud on Commercial unless your Microsoft tenant is in GCC High or DoD. Check that Access matches what Entra approved, and save.

  Members then connect Microsoft 365 in Claude Desktop with their own work account, and Claude reaches only what each member can already open.

  For a system of your own, open Add connector on the Connectors card. Name it, enter the server's address, and choose how Claude authenticates, for example a shared secret or member sign-in. Select Next.

  Discover tools asks the server which tools it offers. If the server cannot be reached from your browser, add tool names by hand on the next step.

  Under Apply to, choose the products that receive it, here Claude Desktop only. Under Tool policy, switch off any tool you do not want, then save the connector. Members are still asked before Claude uses an allowed tool.

  On the Plugins card, select Add plugins and drop a zip file. The preview shows its name and version. Choose Auto-install for everyone, or Members choose, then add it.

  You do not need to push anything. Claude Desktop picks up the connector and the plugin when it next checks for changes. Members find plugins under Customize, Plugins.
</Accordion>

### Pilot Claude Desktop on one machine

Connecting one copy of Claude Desktop to Claude for Government with the bootstrap address, signing in, and exporting the configuration for your fleet. Read more: [Configure a single machine](/docs/government/deploy-desktop/configure#configure-a-single-machine).

<Frame caption="Video: Pilot Claude Desktop on one machine (1 min 34 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-08-pilot-claude-desktop-on-one-machine.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=753d21fb976775a19f3cca9521b738b3" aria-label="Video walkthrough: Pilot Claude Desktop on one machine" data-path="images/government/videos/admin-08-pilot-claude-desktop-on-one-machine.mp4" />
</Frame>

<Accordion title="Transcript">
  A fresh install connects to claude.ai. One setting, the bootstrap address on your Claude for Government host, points it at Claude for Government. Everything else arrives at sign-in.

  First confirm your test account has a seat tier, the device and browser can reach your host and identity provider, and you have administrator rights.

  Open the app and stay on the sign-in screen. Enable Developer Mode from Help, Troubleshooting, then open Developer, Configure Third-Party Inference.

  The window opens on Connection. Change nothing there. In Source, enter the bootstrap address, leave Trust bootstrap-delivered settings off, and select Apply Changes.

  After the relaunch, choose Sign in with your organization. The app shows a pairing code, and you finish sign-in in your browser.

  Then a small window, Apply settings from your organization, lists a Gateway base URL. Confirm it is on your host and select Allow.

  For your fleet, turn on Disable Claude.ai sign-in under Workspace, keep the trust switch off, and use Export for the macOS, Jamf, Intune, or Group Policy files.

  One end-to-end check is a short Claude Desktop banner on the Config page. If it appears in the app after sign-in, per-user delivery works.
</Accordion>

### Deploy to your fleet

Delivering the bootstrap address and the setting that hides the claude.ai sign-in option as device policy, installing the Windows package, enabling the **Virtual Machine Platform** feature that Cowork needs, allowing network access, and deciding on automatic updates. Read more: [Deploy to your fleet](/docs/government/deploy-desktop/configure#deploy-to-your-fleet).

<Frame caption="Video: Deploy to your fleet (1 min 31 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-09-deploy-to-your-fleet.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=bde163c8a3661fd5393106756950713c" aria-label="Video walkthrough: Deploy to your fleet" data-path="images/government/videos/admin-09-deploy-to-your-fleet.mp4" />
</Frame>

<Accordion title="Transcript">
  Push two values as device policy, the bootstrap address and the setting that hides the claude.ai sign-in option. On macOS they live in a configuration profile, on Windows in machine policy. Deliver them before the app, and note they carry no secrets.

  On Windows, deploy the MSIX package machine-wide. Anthropic publishes Intune install and detection scripts, and an offline installer for networks that cannot reach downloads.claude.ai.

  Cowork needs the Virtual Machine Platform feature, enabled with a restart before rollout. Run the Cowork readiness check on one device per hardware model.

  Allow the app to reach your host, and browsers to reach the host, its sign-in service, and your identity provider. Cowork and Code also download components from downloads.claude.ai.

  Decide on updates. If your agency distributes app updates itself, turn on Block automatic updates on the Config page, lock it, and add the disableAutoUpdates value to the profile. Otherwise, leave updates on.

  With the configuration delivered first, users land directly on the organization sign-in screen, and the configuration window becomes read-only. After a profile change, fully quit and reopen the app.
</Accordion>

### Verify a managed device and spot common failures

What a correctly managed device shows, and the usual causes of an empty model picker, a claude.ai sign-in screen, a repeated settings prompt, and an expired session. Read more: [Confirm it worked](/docs/government/deploy-desktop/configure#confirm-it-worked) and [Troubleshooting](/docs/government/deploy-desktop/configure#troubleshooting).

<Frame caption="Video: Verify a managed device and spot common failures (1 min 40 s). Narrated with an AI-generated voice, with on-screen captions.">
  <video controls preload="metadata" playsInline className="w-full aspect-video" src="https://mintcdn.com/claude-ai/gGFKuNSbKYs4JMmK/images/government/videos/admin-10-verify-a-managed-device-and-spot-common-failures.mp4?fit=max&auto=format&n=gGFKuNSbKYs4JMmK&q=85&s=3a725133f700322bdfcf0d684f9fd1c8" aria-label="Video walkthrough: Verify a managed device and spot common failures" data-path="images/government/videos/admin-10-verify-a-managed-device-and-spot-common-failures.mp4" />
</Frame>

<Accordion title="Transcript">
  On a managed device, the sign-in screen offers only Sign in with your organization, and the configuration window is read-only. Under Help, Troubleshooting, Generate Diagnostic Report saves a report that shows what the app read.

  Sign in as a test user with a seat tier. Chat should work, the picker should list that user's models, and your Config page banner should appear in the app.

  If the picker is empty, nothing is wrong with the device. Most often the user has no seat tier, and an organization owner assigns one on the Users page.

  Only the claude.ai sign-in means the configuration did not reach the app. Check delivery and the diagnostic report, then quit and reopen.

Cut at 300 lines. The page has the rest.

Feedback