Restrict where Claude Tag operates changedclaude-tag/admins/restrict-access
Nearest release: v2.1.288, published 5 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 2 Oct 2026 23:33 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 2 Oct 2026 23:37 UTC.
Upstream edited
Recorded here
Lines+3added
Lines−5removed
From line
242
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits46to this page, all time
The whole hunk
from line 242, old and new numbered
/
from line 242
242242
243243A group DM is a Slack direct message among several people. When members add Claude to one, Claude acts with its own [service accounts](/docs/claude-tag/concepts/agent-identity), and the work bills to your organization's [usage balance](/docs/claude-tag/admins/set-spend-limit). [Use Claude Tag in a group DM](/docs/claude-tag/users/group-dms) covers what members can do there.
244244
245Claude works in group DMs on the Team plan, and for some organizations on the Enterprise plan. No admin setting makes Claude work in group DMs for an organization. If Claude doesn't work in group DMs for your organization, it answers a top-level `@Claude` mention in a group DM with the notice ["Group DMs aren't supported yet"](/docs/claude-tag/users/troubleshooting#group-dms-aren%E2%80%99t-supported-yet).
246
247245A group DM has no [scope](/docs/claude-tag/concepts/glossary#scope) of its own, so you can't attach an [Access bundle](/docs/claude-tag/admins/attach-to-scope) to one group DM or turn Claude off in one. You control every group DM in a workspace together:
248246
249247* **Access.** Claude works with the Access bundles, instructions, and repositories on the workspace's scope and on **Default Slack access**.
from line 254
256254
257255Who is in a group DM, and how Slack shares it, can change whether Claude answers:
258256
259* **A Slack guest is in the group DM.** In a workspace outside Enterprise Grid, Claude follows the [**How should Claude work in channels with guests**](#restrict-guest-channels) value on the workspace's scope or on **Default Slack access**. Under the default, **Restrict**, Claude posts its guest notice instead of an answer. Under **Channel only**, Claude runs with [channel-only access](#how-channel-only-works) and can't set up [routines](/docs/claude-tag/users/proactivity). Under **Full access**, Claude answers.
257* **A Slack guest is in the group DM.** In a workspace outside Enterprise Grid, Claude follows the [**How should Claude work in channels with guests**](#restrict-guest-channels) value on the workspace's scope or on **Default Slack access**. Under the default, **Restrict**, Claude posts its guest notice instead of an answer. Under **Channel only**, Claude runs with [channel-only access](#how-channel-only-works). Under **Full access**, Claude answers.
260258* **Someone from another company is in the group DM, through Slack Connect.** Claude doesn't answer, and no setting changes that.
261* **Slack shares the group DM across the workspaces of an Enterprise Grid.** Claude doesn't answer, whoever is in the group DM.
259* **On Enterprise Grid, the people in the group DM share no workspace.** Claude doesn't answer.
262260
263261### Direct messages from members without a Claude account
264262
from line 477
479477* **Third-party deployment.** Claude Tag runs on Anthropic's first-party service; it isn't available through third-party deployments.
480478* **Renaming or rebranding the app.** The Claude app's name, @-handle, and avatar in Slack are fixed; there is no per-workspace rename setting.
481479* **Per-user spend caps on channel work.** Spend limits apply at the organization and channel level. There's no way to cap what one member can spend in channels; one-to-one DM usage from a member who has connected a Claude account bills to that member's own seat and follows the seat's usual limits.
482* **A switch for group DMs alone, or settings for one group DM.** You can't attach a bundle to one group DM, turn Claude off in one, or stop group DMs without also stopping one-to-one DMs or the workspace's channels. See [Group DMs](#group-dms).
480* **A switch for group DMs alone, or settings for one group DM.** You can't attach a bundle to one group DM, turn Claude off in one, or stop Claude from answering in group DMs without also stopping it in one-to-one DMs or the workspace's channels. See [Group DMs](#group-dms).
483481* **Per-channel responder allowlist.** The restriction toggle governs who can invoke Claude across the workspace; you can't narrow it to a list of people for one channel only.
484482* **An open-internet switch in Claude Tag settings.** A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner or a [Claude Tag admin](#delegate-claude-tag-administration) adds that hostname on a [bundle's Domains tab](/docs/claude-tag/admins/add-connections#allow-a-host-without-a-credential); for broad web access, an Owner pins an [environment](/docs/claude-tag/concepts/glossary#environment) whose network access level is Full access on the scope. [Allow-all egress](/docs/claude-tag/admins/add-connections#allow-all-hosts), a `*` entry on the Domains tab, admits any host on the ports it lists.
485483* **A web search toggle for channels.** No setting turns web search off for channel sessions; the web search capability setting in claude.ai admin settings governs claude.ai chat, not channels. Web search runs on Anthropic's servers rather than from the channel sandbox, so Domains entries and egress settings don't govern it, and a search opens no new path out of the sandbox; search requests travel to Anthropic the same way the session's model traffic already does. See [Web search vs. network requests](/docs/claude-tag/concepts/agent-identity#web-search-vs-network-requests).
No line in this hunk matches that.