Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · claude-docs

Admin controls changedclaude-science/admin-controls

Nearest release: v2.1.284, published 21 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 29 Sep 2026 14:37 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 29 Sep 2026 15:07 UTC.

Upstream edited
Recorded here
Lines+38added
Lines−10removed
From line 6 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits14to this page, all time

### Capabilities in custom roles

The whole hunk

from line 6, old and new numbered
/
lines
from line 6
66 
77## Organization settings
88 
9The [**Organization settings** > **Claude Science**](https://claude.ai/admin-settings/claude-science) page in claude.ai holds the controls that apply to every member of your Team or Enterprise organization who uses the app. An Owner or Primary Owner turns Claude Science on there (see [Enable Claude Science](/docs/claude-science/enable-claude-science)), and the other controls unlock once Claude Science is on. Each section below covers one control: what it governs, its default, and what changes for members when you turn it off.
9The [**Organization settings** > **Claude Science**](https://claude.ai/admin-settings/claude-science) page in claude.ai holds the controls that apply to every member of your Team or Enterprise organization who uses the app. An Owner or Primary Owner turns Claude Science on there (see [Enable Claude Science](/docs/claude-science/enable-claude-science)), and the other controls unlock once Claude Science is on. On Enterprise plans, you can also limit some of the controls to certain custom roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)). Each section below covers one control: what it governs, its default, and what changes for members when you turn it off.
1010 
1111### Defaults by plan
1212 
from line 37
3737 
3838Turning a control off doesn't delete anything on the members' computers. What members set up under that control (custom connectors, SSH hosts, their Modal connection, saved memories, and their own choices) stays on their computer, and that feature cannot be used inside the Claude Science app while the control is off. The setting shows grayed out in the app with a note that an admin turned it off, and everything works again as before if you turn the control back on. A control that is off by your plan's default instead shows a note that an admin can turn it on. When the **Allow custom skills** switch is off, skills a member added earlier keep working (see [Custom skills](#custom-skills)).
3939 
40### Capabilities in custom roles
41 
42On Enterprise plans, seven of the controls on this page also have a capability in custom roles, so you can leave a control on for the organization and, among members with custom roles, limit it to certain roles. Go to [**Organization settings > Roles**](https://claude.ai/admin-settings/roles), open a custom role, and go to its **Capabilities** tab. In the **Claude Science** section, the seven are listed under the **Claude Science** capability.
43 
44The table shows each capability and the control on the **Claude Science** page that it goes with.
45 
46| Capability in a custom role | Control on the **Claude Science** page |
47| - | - |
48| **Access previously saved work** | [**Allow members to access Claude Science work previously saved on their computer**](#previously-saved-claude-science-work) |
49| **Connect to SSH hosts** | [**Allow members to connect SSH hosts**](#ssh-hosts) |
50| **Custom connectors** | [**Allow custom connectors**](#custom-connectors) |
51| **Custom skills** | [**Allow custom skills**](#custom-skills) |
52| **Memory** | [**Turn on memory for your team**](#memory) |
53| **Modal** | [**Allow members to connect to Modal**](#modal) |
54| **Scientific model endpoint providers** | [**Show scientific model endpoint providers on the Compute tab**](#scientific-model-endpoints) |
55 
56The control on the **Claude Science** page is the upper limit, and roles narrow it:
57 
58* **Control off**: the feature is off for every member, whatever their roles include. In the role, the capability's row says that it's turned off at the organization level.
59* **Control on, built-in role**: members whose role is User, Admin, Owner, or Primary Owner can use the feature, because custom roles affect only members whose role is set to **Custom**. On Team plans, which don't have custom roles, that's every member.
60* **Control on, custom roles**: a member whose role is set to **Custom** can use the feature only if at least one of their custom roles has the capability turned on.
61 
62Turning on the **Claude Science** capability in a role also turns on the seven under it, and you can then turn off the ones that role shouldn't have. Any capability whose control your organization can't turn on stays off. Turning the **Claude Science** capability off turns them all off. A role whose **Capability access** setting is **All capabilities** already includes all seven. A role set to **All generally available** gets them when you turn on its **Claude Science** capability (see [Who gets access after you enable](/docs/claude-science/enable-claude-science#who-gets-access-after-you-enable)).
63 
64For a member whose custom roles don't include a capability, the feature behaves as it does when you turn its control off (see [How changes reach members](#how-changes-reach-members)). The setting is grayed out in the Claude Science app, and what the member set up earlier is kept. To give that member the feature, turn on the capability in one of their roles. A change to a role's capabilities can take up to 15 minutes to reach members, and then applies on the member's next turn or request.
65 
66The network allowlist, the package mirror, Modal workspaces, and the switches for Featured connectors and skills aren't set by role and apply to the whole organization. To create custom roles and assign them to groups, see [Manage custom roles on Enterprise plans](https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans).
67 
4068### Featured connectors and skills
4169 
4270Featured connectors and Featured skills come with Claude Science, and admins can control whether they are enabled or disabled for your members (see [Connectors and skills](/docs/claude-science/connectors-and-skills)). The **Featured connectors** and **Featured skills** sections list them with one switch per item, so you can choose which ones members can use. Every item is on by default for Team and Enterprise organizations. In an organization with HIPAA compliance enabled, every Featured connector and skill starts disabled; turn on the ones you have reviewed.
from line 87
5987 
6088If a connector needs a sign-in, each member signs in with their own account; the app opens claude.ai for them to do it. Connector permissions in Enterprise custom roles apply the same way; see [Connectors](#connectors) under How other admin settings apply to Claude Science.
6189 
62Two kinds of connectors are controlled on **Organization settings > Claude Science** instead: the Featured connectors that run on members' computers (see [Featured connectors and skills](#featured-connectors-and-skills)), and connectors members add in the app themselves (see [Custom connectors](#custom-connectors)).
90Two kinds of connectors are controlled on **Organization settings > Claude Science** instead: the Featured connectors that run on members' computers (see [Featured connectors and skills](#featured-connectors-and-skills)), and connectors members add in the app themselves (see [Custom connectors](#custom-connectors)). On Enterprise plans, a custom role's **Custom connectors** capability can also limit the second kind to certain roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)).
6391 
6492### Custom connectors
6593 
from line 99
7199 
72100Connectors are built on an open standard called the Model Context Protocol (MCP). When your organization needs a connector it doesn't have yet, what to do depends on where the data lives:
73101 
74* **Your own systems and data**, such as an internal database or lab system: have your developers build a connector for it, then add its web address for everyone under **Organization settings > Connectors > Add > Custom** (see [Third party connectors with remote MCP](/docs/connectors/custom/remote-mcp)). Claude connects to it from Anthropic's servers, so it must be reachable from the internet. For a system that isn't, Enterprise organizations can request an MCP tunnel, a secure link from their own network to Anthropic (in research preview; see [MCP tunnels](/docs/connectors/mcp-tunnels/overview)).
75* **Another company's product**: the company that makes the product usually builds and runs its connector, not Anthropic. Check the [Connectors Directory](/docs/connectors/directory) first. If the company offers a connector that isn't listed there, add its web address under **Organization settings > Connectors > Add > Custom**; a connector doesn't need to be in the directory to work (see [Connector verification](/docs/connectors/verification)). If the company doesn't offer one, ask them to build one. They can [submit it to the Connectors Directory](/docs/connectors/building/submission#submit-your-connector) for review; if Anthropic accepts it, any Claude user can find it there.
102* **Your own systems and data**, such as an internal database or lab system: have your developers build a connector for it, then add its web address for everyone under **Organization settings > Connectors > Add > Custom** (see [Add a connector by URL](/docs/connectors/custom/add-unlisted#add-a-connector-by-url)). Claude connects to it from Anthropic's servers, so it must be reachable from the internet. For a system that isn't, Enterprise organizations can request an MCP tunnel, a secure link from their own network to Anthropic (in research preview; see [MCP tunnels](/docs/connectors/mcp-tunnels/overview)).
103* **Another company's product**: the company that makes the product usually builds and runs its connector, not Anthropic. Check the [Connectors Directory](/docs/connectors/directory) first. If the company offers a connector that isn't listed there, add its web address under **Organization settings > Connectors > Add > Custom**; a connector doesn't need to be in the directory to work (see [Connector verification](/docs/connectors/verification)). If the company doesn't offer one, ask them to build one. They can [submit it to the Connectors Directory](/docs/connectors/building/submission) for review; if Anthropic accepts it, any Claude user can find it there.
76104* **Public scientific databases and tools**: Claude may not need a connector at all. Code that Claude runs on members' computers can reach any site on Claude Science's list of allowed sites, so adding the site to that list is often enough. By default, members allow a new site themselves when Claude asks. If you turn on **Manage network allowlist** on **Organization settings > Claude Science**, you add sites for them under **Custom domains** instead (see [Network allowlist](#network-allowlist)). If a connector would still help, look for one in the [Connectors Directory](/docs/connectors/directory) and add it on **Organization settings > Connectors**.
77105 
78106### Custom skills
from line 163
135163 
136164### SSH hosts
137165 
138Members can register a machine they reach over SSH, such as a lab workstation or an HPC login node, so Claude can run jobs on it (see [Remote compute clusters](/docs/claude-science/remote-compute-clusters)). The **Allow members to connect SSH hosts** switch decides whether they can. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
166Members can register a machine they reach over SSH, such as a lab workstation or an HPC login node, so Claude can run jobs on it (see [Remote compute clusters](/docs/claude-science/remote-compute-clusters)). The **Allow members to connect SSH hosts** switch decides whether they can. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on. On Enterprise plans, you can also limit SSH hosts to certain custom roles with the **Connect to SSH hosts** capability (see [Capabilities in custom roles](#capabilities-in-custom-roles)).
139167 
140168When the switch is off, members can't add SSH hosts, and hosts they added earlier are kept but refuse new commands and file transfers; the app shows that SSH host setup is disabled by your admin. A job that is already running can still be stopped and its results collected.
141169 
from line 195
167195 
168196When the switch is off, memory is off for every member, whatever they chose in their own settings; Claude neither recalls nor saves facts, first-time setup skips its memory step, and the **Memory** setting shows that memory is disabled by your admin. Facts a member saved earlier stay on their computer, the member can still review and delete them, and Claude uses them again if you turn the switch back on.
169197 
170When Claude recalls saved facts for a session, those facts are sent to Anthropic as part of that session's conversation and handled like the rest of the conversation (see [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data)). The **Capabilities** > **Memory** setting in claude.ai **Organization settings** doesn't control memory in Claude Science.
198When Claude recalls saved facts for a session, those facts are sent to Anthropic as part of that session's conversation and handled like the rest of the conversation (see [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data)). The **Capabilities** > **Memory** setting in claude.ai **Organization settings** doesn't control memory in Claude Science. In a custom role, the **Memory** row under **Claude Science** is the capability for the app's memory, and the **Memory** row under **Chat** is for claude.ai chat (see [Capabilities in custom roles](#capabilities-in-custom-roles)).
171199 
172200## How other admin settings apply to Claude Science
173201 
from line 217
189217| Organization and access > Domains | Supported in Claude Science | Domain verification, and the **Migrate accounts using your domains** and **Restrict organization creation** settings that build on it, act on claude.ai accounts before anyone reaches the app, so they apply unchanged. |
190218| Members | Supported in Claude Science | Adding or removing members controls who can sign in to Claude Science. |
191219| Roles (built-in) | Supported in Claude Science | Every built-in role (User, Admin, Owner, and Primary Owner) can use Claude Science once it's turned on for the organization. |
192| Roles > Claude Science permission in custom roles (Enterprise) | Supported in Claude Science | Add the Claude Science permission to a custom role to give the app to that role's members. Members whose custom roles don't include it can't use the app. Team plans don't have custom roles, so everyone gets access when Claude Science is on. |
220| Roles > Claude Science permission in custom roles (Enterprise) | Supported in Claude Science | Add the Claude Science permission to a custom role to give the app to that role's members. Members whose custom roles don't include it can't use the app. On the role's **Capabilities** tab, seven capabilities under **Claude Science** decide which of the app's features that role's members can use (see [Capabilities in custom roles](#capabilities-in-custom-roles)). Team plans don't have custom roles, so everyone gets access when Claude Science is on. |
193221| Groups (Enterprise) | Supported in Claude Science | Members get the Claude Science access of the roles their groups assign. |
194222| IP allowlist (Enterprise) | Partially supported in Claude Science | The app's sign-in, its requests to Claude, and its Directory connector calls are checked against your allowlist (see [Restrict access to Claude with IP allowlisting](https://support.claude.com/en/articles/13200993-restrict-access-to-claude-with-ip-allowlisting)). Traffic that doesn't go to Anthropic isn't checked, which covers code on the member's computer, SSH hosts, or Modal account, and custom connectors members add in the app. You can turn SSH hosts, Modal, and custom connectors off under [Organization settings](#organization-settings). |
195223| Organization and access > Shortened session length (Enterprise) | Partially supported in Claude Science | Applies to the browser sign-in a member completes to connect the app. It doesn't shorten the app's own sign-in after that, so members aren't asked to sign in again on your schedule. Turning Claude Science off for the organization or removing a member still stops their app within a few minutes. |
from line 234
206234| Capabilities > Code execution and file creation | Not applicable in Claude Science | This setting governs the code sandbox Anthropic hosts for claude.ai chat. Running code on the member's computer, or on compute the member connects, is the core of Claude Science and can't be turned off; you govern what that code can reach with the [network allowlist](#network-allowlist), [SSH hosts](#ssh-hosts), and [Modal](#modal) controls. |
207235| Capabilities > Allow network egress and Domain allowlist | Supported in Claude Science | These settings govern the hosted sandbox for claude.ai chat. Claude Science's sandbox has its own allowlist: manage it for the whole organization with the **Manage network allowlist** switch on the **Claude Science** page (see [Network allowlist](#network-allowlist)), or leave it off and let members manage their own. Administrators can also extend a member's list per device with the sandbox network keys in the [configuration file reference](/docs/claude-science/configuration-file-reference). |
208236| Data and privacy > Location metadata | Not applicable in Claude Science | Claude Science doesn't send location data with requests to Claude, so there is nothing for this setting to govern. |
209| Capabilities > Memory (Enable memory for your team) | Supported in Claude Science | This setting governs memory in claude.ai chat. Claude Science keeps a separate memory on each member's computer, which you turn on or off for everyone with the **Turn on memory for your team** switch on the **Claude Science** page (see [Memory](#memory)). |
237| Capabilities > Memory (Enable memory for your team) | Supported in Claude Science | This setting governs memory in claude.ai chat. Claude Science keeps a separate memory on each member's computer, which you turn on or off with the **Turn on memory for your team** switch on the **Claude Science** page (see [Memory](#memory)). On Enterprise plans, a custom role's **Memory** capability under **Claude Science** can limit it to certain roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)). |
210238| Settings for claude.ai projects (Public projects, Retention period for projects) | Not applicable in Claude Science | Claude Science doesn't use claude.ai projects. Its projects are folders on the member's computer. |
211239 
212240### Connectors
from line 242
214242| Setting in claude.ai | Status for Claude Science | Note |
215243| - | - | - |
216244| Connectors > connectors you add for your organization | Supported in Claude Science | Connectors you add on the **Connectors** page, from the directory or by web address (custom connectors), are available to members in the app, as in claude.ai. Claude connects to them from Anthropic's servers, and members sign in with their own accounts where needed. |
217| Roles > connector permissions in custom roles (Enterprise) | Partially supported in Claude Science | Apply to the connectors on your **Connectors** page, which the app reaches through Anthropic. They don't apply to Featured connectors or custom connectors added via the Claude Science app; the **Claude Science** page controls those for every member rather than per role (see [Organization settings](#organization-settings)). |
245| Roles > connector permissions in custom roles (Enterprise) | Partially supported in Claude Science | Apply to the connectors on your **Connectors** page, which the app reaches through Anthropic. They don't apply to the Featured connectors that run on members' computers or to custom connectors members add in the Claude Science app. The **Claude Science** page controls those Featured connectors for every member. The **Allow custom connectors** switch there decides whether members can add and use custom connectors, and a separate capability in custom roles, **Custom connectors**, can limit that to certain roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)). |
218246| Plugins > plugins you add for the organization | Partially supported in Claude Science | Plugins you set to **Installed by default** or **Required** are synced to members' Claude Science app, which loads their skills and connectors. Plugins left as **Available to install** aren't offered in the app, and plugin commands don't apply there. Which Featured connectors and skills members can use, and whether they can add their own, are separate controls on the **Claude Science** page (see [Featured connectors and skills](#featured-connectors-and-skills), [Custom connectors](#custom-connectors), and [Custom skills](#custom-skills)). |
219247| Connectors > Tunnels API (Enterprise) | Partially supported in Claude Science | A connector your organization serves through a tunnel works in the app the same way it does in claude.ai, because the app reaches the connectors on your **Connectors** page through Anthropic's hosted connector service. Custom connectors a member adds in the Claude Science app connect directly from the member's computer and never use a tunnel (admins can restrict this in [Custom connectors](#custom-connectors)). |
220| Connectors > connectors members add themselves | Supported in Claude Science | In claude.ai, members use only the connectors on your **Connectors** page. In Claude Science, members can also add custom connectors (a server URL or a local command) while the **Allow custom connectors** switch is on, which it is by default for Team and not for Enterprise, and the **Connectors** page and its restrictions don't apply to those. Turn off the **Allow custom connectors** switch under **Organization settings** > **Claude Science** to limit members to Featured connectors and the connectors you add on your **Connectors** page (see [Custom connectors](#custom-connectors)). |
248| Connectors > connectors members add themselves | Supported in Claude Science | In claude.ai, members use only the connectors on your **Connectors** page. In Claude Science, members can also add custom connectors (a server URL or a local command) while the **Allow custom connectors** switch is on, which it is by default for Team and not for Enterprise, and the **Connectors** page and its restrictions don't apply to those. Turn off the **Allow custom connectors** switch under **Organization settings** > **Claude Science** to limit members to Featured connectors and the connectors you add on your **Connectors** page (see [Custom connectors](#custom-connectors)). On Enterprise plans, you can also leave the switch on and limit custom connectors to certain custom roles (see [Capabilities in custom roles](#capabilities-in-custom-roles)). |
221249| Connectors > Desktop extension allowlist | Not applicable in Claude Science | Claude Science doesn't install desktop extensions, so there is nothing for this setting to govern. |
222250 
223251### Data and privacy
Feedback