Restrict where Claude Tag operates changedclaude-tag/admins/restrict-access
Nearest release: v2.1.288, published an hour before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 2 Oct 2026 19:35 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 2 Oct 2026 19:37 UTC.
Upstream edited
Recorded here
Lines+34added
Lines−9removed
From line
6
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits41to this page, all time
### Group DMs
The whole hunk
from line 6, old and new numbered
/
from line 6
66
77<BetaNote />
88
9In channels, Claude Tag responds only where it's been added and addressed, and the controls on this page narrow that further. DMs are a separate surface. A DM from a member who has connected a Claude account runs on that member's own account; see [how DMs differ from channels](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A [DM from a member who hasn't](#direct-messages-from-members-without-a-claude-account) can bill to your organization.
9In channels, Claude Tag responds only where it's been added and addressed, and the controls on this page narrow that further. One-to-one DMs are a separate surface. A DM from a member who has connected a Claude account runs on that member's own account; see [how DMs differ from channels](/docs/claude-tag/concepts/agent-identity#direct-message-channels). A [DM from a member who hasn't](#direct-messages-from-members-without-a-claude-account) can bill to your organization. In a [group DM](#group-dms), the work bills to your organization.
1010
1111<Note>Most controls on this page require the Owner role in your Claude organization; the [permissions table](#permissions-by-role) below lists which actions a channel manager or a channel member can take. On the Enterprise plan, an Owner can delegate many of these controls through the [**Claude Tag Admin** permission](#delegate-claude-tag-administration).</Note>
1212
from line 93
9393
9494### Limit Claude Tag to specific channels
9595
96To let Claude respond only in channels you choose, for example during a pilot confined to one channel, turn Claude off everywhere with the [**Enable Claude Tag in Slack** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) on **Default Slack access**, then turn each chosen channel's **Enable Claude Tag in this channel** switch on. Both changes happen in the **Claude Tag's access** section at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). DMs, guest channels, and shared channels need more than the **Enable Claude Tag** switches; each gets its own treatment after the steps.
96To let Claude respond only in channels you choose, for example during a pilot confined to one channel, turn Claude off everywhere with the [**Enable Claude Tag in Slack** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) on **Default Slack access**, then turn each chosen channel's **Enable Claude Tag in this channel** switch on. Both changes happen in the **Claude Tag's access** section at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag). One-to-one DMs, guest channels, and shared channels need more than the **Enable Claude Tag** switches; each gets its own treatment after the steps.
9797
9898These steps need the per-scope switches. If you have the single [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-on-the-team-plan) instead, you can't limit Claude this way. Use [blocked channel patterns](#block-or-auto-join-channels-by-name) to keep it out of specific channels.
9999
from line 117
117117
118118If someone invites the app into another channel afterward, Claude stays silent there. Mentioning `@Claude` in that channel gets a notice that Claude is disabled in the channel, not a reply.
119119
120DMs, guest channels, and shared channels sit outside the per-scope switches:
120One-to-one DMs, guest channels, and shared channels sit outside the per-scope switches:
121121
122* **DMs.** The per-scope switches don't cover DMs from members who have connected a Claude account. To close those off too, turn off the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle. For members who haven't connected an account, see [Stop direct messages from members without a Claude account](#stop-direct-messages-from-members-without-a-claude-account).
122* **One-to-one DMs.** The per-scope switches don't cover one-to-one DMs from members who have connected a Claude account. To close those off too, turn off the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle. For members who haven't connected an account, see [Stop direct messages from members without a Claude account](#stop-direct-messages-from-members-without-a-claude-account).
123123* **Guest channels.** By default Claude is off in any channel that includes a Slack guest. If a chosen channel has guests, also set [**How should Claude work in channels with guests**](#restrict-guest-channels) to **Full access** or **Channel only** on its scope.
124124* **Shared channels.** A [channel shared across workspaces in your Enterprise Grid](#channels-shared-across-workspaces-in-your-enterprise-grid) takes its settings from **Default Slack access** only and can't serve as a chosen channel. Claude doesn't work in a [Slack Connect channel](#slack-connect-channels), one shared with another company.
125125
126The **Enable Claude Tag** switch covers [group DMs](#group-dms), and a group DM can't serve as a chosen channel. While the switch that covers a workspace is off, Claude doesn't answer in that workspace's group DMs.
127
126128To control who can use Claude in the allowed channels, turn on the [restriction toggle](#restrict-who-can-use-claude); to cap what a channel spends, [set a per-channel spend limit](#set-spend-limits).
127129
128130### Block or auto-join channels by name
from line 234
232234
233235### Allow or disable direct messages
234236
235The **Allow direct messages** toggle controls whether members can message Claude directly. When it's off, Claude is reachable only in channels, and no [DM from a member without a Claude account](#direct-messages-from-members-without-a-claude-account) bills to your organization. The default is on, and you must be an Owner of your Claude organization to change it.
237The **Allow direct messages** toggle controls whether members can message Claude in a one-to-one DM or in a [group DM](#group-dms). When it's off, Claude is reachable only in channels, and no [DM from a member without a Claude account](#direct-messages-from-members-without-a-claude-account) bills to your organization. The default is on, and you must be an Owner of your Claude organization to change it.
236238
237239On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), the toggle appears in one of two places: directly on the Claude Tag settings page, or in the **Manage** dialog on the Slack entry under **Where Claude Tag works**. It's the same setting in both places, so change it wherever it appears for your organization.
238240
241### Group DMs
242
243A group DM is a Slack direct message among several people. When members add Claude to one, Claude acts with its own [service accounts](/docs/claude-tag/concepts/agent-identity), and the work bills to your organization's [usage balance](/docs/claude-tag/admins/set-spend-limit). [Use Claude Tag in a group DM](/docs/claude-tag/users/group-dms) covers what members can do there.
244
245Claude works in group DMs on the Team plan, and for some organizations on the Enterprise plan. No admin setting makes Claude work in group DMs for an organization. If Claude doesn't work in group DMs for your organization, it answers a top-level `@Claude` mention in a group DM with the notice ["Group DMs aren't supported yet"](/docs/claude-tag/users/troubleshooting#group-dms-aren%E2%80%99t-supported-yet).
246
247A group DM has no [scope](/docs/claude-tag/concepts/glossary#scope) of its own, so you can't attach an [Access bundle](/docs/claude-tag/admins/attach-to-scope) to one group DM or turn Claude off in one. You control every group DM in a workspace together:
248
249* **Access.** Claude works with the Access bundles, instructions, and repositories on the workspace's scope and on **Default Slack access**.
250* **Stop Claude from answering in group DMs.** Use either control. No setting covers group DMs alone.
251 * Turn off the [**Enable Claude Tag** switch](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) that covers the workspace. Claude also stops answering in the channels that follow that switch.
252 * Turn off the [**Allow direct messages**](#allow-or-disable-direct-messages) toggle. Claude also stops answering one-to-one DMs.
253* **Who can ask.** If you [restrict who can use Claude](#restrict-who-can-use-claude), the restriction applies in group DMs too. With no restriction, a member who hasn't connected a Claude account can ask in a group DM, and the [limits on one-to-one DMs from those members](#limits-on-direct-messages-from-members-without-a-claude-account) don't apply.
254* **Spend.** The organization-wide [spend limit](#set-spend-limits) caps group DM work along with channel work, and the **Default spend limit** applies to each group DM.
255* **Version.** Where the **Legacy** [Claude Tag version](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) answers for the workspace, Claude doesn't respond in group DMs.
256
257Who is in a group DM, and how Slack shares it, can change whether Claude answers:
258
259* **A Slack guest is in the group DM.** In a workspace outside Enterprise Grid, Claude follows the [**How should Claude work in channels with guests**](#restrict-guest-channels) value on the workspace's scope or on **Default Slack access**. Under the default, **Restrict**, Claude posts its guest notice instead of an answer. Under **Channel only**, Claude runs with [channel-only access](#how-channel-only-works) and can't set up [routines](/docs/claude-tag/users/proactivity). Under **Full access**, Claude answers.
260* **Someone from another company is in the group DM, through Slack Connect.** Claude doesn't answer, and no setting changes that.
261* **Slack shares the group DM across the workspaces of an Enterprise Grid.** Claude doesn't answer, whoever is in the group DM.
262
239263### Direct messages from members without a Claude account
240264
241A Slack workspace member who hasn't connected a Claude account can use Claude in a DM for a limited time, billed to your organization's usage balance. When that member uses Claude in a channel, the work bills to your organization the same way, and the same [restriction toggle](#restrict-who-can-use-claude) governs both. Where the conditions in this section aren't met, Claude doesn't act on that member's DM and nothing bills to your organization. The limited time runs once for each member and starts with their first DM that Claude answers on your organization's bill.
265A Slack workspace member who hasn't connected a Claude account can use Claude in a one-to-one DM for a limited time, billed to your organization's usage balance. When that member uses Claude in a channel, the work bills to your organization the same way, and the same [restriction toggle](#restrict-who-can-use-claude) governs both. Where the conditions in this section aren't met, Claude doesn't act on that member's DM and nothing bills to your organization. The limited time runs once for each member and starts with their first DM that Claude answers on your organization's bill.
242266
243267A member's DMs bill to your organization when every one of these is true:
244268
from line 309
285309| :- | :- | :- |
286310| Turn on the restriction toggle | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Where Claude Tag works** > **Member access** > **Manage** | Members without a Claude account in your organization can't use Claude in channels either. See [Restrict who can use Claude](#restrict-who-can-use-claude) |
287311| Turn off the **Allow direct messages** toggle | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), on the page or in the **Manage** dialog on the Slack entry under **Where Claude Tag works** | Members who have connected a Claude account can't DM Claude either |
288| Turn off the **Enable Claude Tag** switch for the workspace or at **Default Slack access** | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Claude Tag's access** > **Slack** > the scope | Claude stops responding in every channel that follows that scope's switch. DMs from members who have connected a Claude account keep working |
312| Turn off the **Enable Claude Tag** switch for the workspace or at **Default Slack access** | [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Claude Tag's access** > **Slack** > the scope | Claude stops responding in every channel that follows that scope's switch. One-to-one DMs from members who have connected a Claude account keep working |
289313
290314To confirm the change, have a member who hasn't connected a Claude account send Claude a DM. With **Allow direct messages** off, Claude answers "Your Claude admin has disabled sending direct messages to Claude." With either of the other two controls, Claude answers with a prompt to connect a Claude account. In both cases nothing bills to your organization.
291315
from line 478
454478
455479* **Third-party deployment.** Claude Tag runs on Anthropic's first-party service; it isn't available through third-party deployments.
456480* **Renaming or rebranding the app.** The Claude app's name, @-handle, and avatar in Slack are fixed; there is no per-workspace rename setting.
457* **Per-user spend caps on channel work.** Spend limits apply at the organization and channel level. There's no way to cap what one member can spend in channels; DM usage from a member who has connected a Claude account bills to that member's own seat and follows the seat's usual limits.
481* **Per-user spend caps on channel work.** Spend limits apply at the organization and channel level. There's no way to cap what one member can spend in channels; one-to-one DM usage from a member who has connected a Claude account bills to that member's own seat and follows the seat's usual limits.
482* **A switch for group DMs alone, or settings for one group DM.** You can't attach a bundle to one group DM, turn Claude off in one, or stop group DMs without also stopping one-to-one DMs or the workspace's channels. See [Group DMs](#group-dms).
458483* **Per-channel responder allowlist.** The restriction toggle governs who can invoke Claude across the workspace; you can't narrow it to a list of people for one channel only.
459484* **An open-internet switch in Claude Tag settings.** A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) adds that hostname on a [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential); for broad web access, an Owner pins an [environment](/docs/claude-tag/concepts/glossary#environment) whose network access level is Full access on the scope. [Allow-all egress](/docs/claude-tag/admins/add-connections#allow-all-hosts), a `*` entry on the Domains tab, admits any host on the ports it lists.
460485* **A web search toggle for channels.** No setting turns web search off for channel sessions; the web search capability setting in claude.ai admin settings governs claude.ai chat, not channels. Web search runs on Anthropic's servers rather than from the channel sandbox, so Domains entries and egress settings don't govern it, and a search opens no new path out of the sandbox; search requests travel to Anthropic the same way the session's model traffic already does. See [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests).
No line in this hunk matches that.