Customize Claude Tag changedclaude-tag/admins/customize
Nearest release: v2.1.290, published under an hour before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 5 Oct 2026 18:53 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 5 Oct 2026 19:07 UTC.
Upstream edited
Recorded here
Lines+28added
Lines−24removed
From line
10
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits35to this page, all time
### Claude Tag connectors are separate from personal connectors ### Channel connections are separate from personal connectors
The whole hunk
from line 10, old and new numbered
/
from line 10
1010
1111| Layer | What it is | Who sets it | Where |
1212| :- | :- | :- | :- |
13| **Connections** | Credentials for the systems Claude can reach (GitHub, Drive, Datadog, your APIs) | Owner or [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | [Access bundles](/docs/claude-tag/admins/add-connections), or the channel's Configure page for a channel manager |
14| **Plugins and skills** | Instructions that teach Claude how to use a tool or follow a process. A plugin bundles one or more [skills](https://code.claude.com/docs/en/skills). | Owner or [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); channel members can add plugins to their channel unless an admin restricts editing | [Bundle Plugins tab](/docs/claude-tag/admins/add-connections#attach-plugins), a [skills repository](/docs/claude-tag/admins/skills-repo), or the channel's Configure page |
13| **Connectors** | The systems Claude can reach and the credentials it uses for each (GitHub, Drive, Datadog, your APIs) | Owner or [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) for their assigned channels | The **Connectors** tab and [bundles](/docs/claude-tag/admins/add-connections) under **Claude's access**, or the channel's Configure page for a channel manager |
14| **Plugins and skills** | Instructions that teach Claude how to use a tool or follow a process. A plugin bundles one or more [skills](https://code.claude.com/docs/en/skills). | Owner or [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); channel members can add plugins to their channel unless an admin restricts editing | The **Skills and plugins** tab under **Claude's access**, a [bundle](/docs/claude-tag/admins/add-connections#attach-plugins), a [skills repository](/docs/claude-tag/admins/skills-repo), or the channel's Configure page |
1515| **Custom instructions** | Standing guidance read in every session at a scope (team conventions, output formats). Outranks channel memory. | Owner for any scope; [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) for workspace and channel scopes; channel members for the channel scope, from the [Configure page](/docs/claude-tag/users/good-habits#configure-claude-for-a-channel) | [Per-scope instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions) |
1616| **Channel memory** | Facts Claude saves while working in a channel | Anyone in the channel | By [telling Claude](/docs/claude-tag/users/memory) |
1717
18Connections and plugins decide what Claude *can do*; instructions and memory shape *how it does it*.
18Connectors and plugins decide what Claude *can do*; instructions and memory shape *how it does it*.
1919
2020## Settings admins control
2121
22Access and organization-wide behavior are set at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), per scope (a scope is a channel, a workspace, or your whole organization), so the same agent can work differently in different channels. Most controls below need the Owner role or, on the Enterprise plan, the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration).
22Access and organization-wide behavior are set at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), per scope (a scope is a channel, a workspace, or your whole organization), so the same agent can work differently in different channels. Each scope has its own page on the **Channels** tab under **Claude's access**, and the **Slack** page there covers your whole organization. Most controls below need the Owner role or, on the Enterprise plan, the [**Claude Tag Admin** permission](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration); the [permissions table](/docs/claude-tag/admins/restrict-access#permissions-by-role) lists each action and who can take it.
2323
2424| Setting | What it does | More |
2525| :- | :- | :- |
from line 27
2727| Managed by | Which other Slack channels' members can write a channel's standing instructions by asking Claude, including from a private channel. On the Enterprise plan, an Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) sets it on the **Admin** tab of the channel's Configure page. | [Manage a channel's instructions from another channel](/docs/claude-tag/admins/managed-by) |
2828| Respond automatically | Whether Claude replies to a channel's messages without an @-mention. **Respond automatically** exists only on channels, not on workspaces or your whole organization. Channel members can change it too, from Slack or the channel's Configure page, unless the scope's [**Channel member edits**](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**. | [Turn automatic replies on or off](/docs/claude-tag/users/when-claude-responds#turn-automatic-replies-on-or-off) |
2929| Plugins | Bundles of skills that teach Claude how to use a specific tool | [Attach plugins](/docs/claude-tag/admins/add-connections#attach-plugins) |
30| Connections | Which systems it can reach from each channel | [Add connections](/docs/claude-tag/admins/add-connections) |
31| Default model | Which Claude model handles sessions in a scope | [Choose the model for a scope](#choose-the-model-for-a-scope) |
30| Connectors | Which systems Claude can reach from each channel | [Add a connector](/docs/claude-tag/admins/add-connections) |
31| Model | Which Claude model handles sessions in a scope | [Choose the model for a scope](#choose-the-model-for-a-scope) |
3232| Auto mode allow rules | Actions pre-approved in a scope's sessions that Claude's permission checker would otherwise flag or stop | [Auto mode allow rules](#auto-mode-allow-rules) |
3333| Environment | Which cloud environment a scope's sessions run in | [Configure the environment for a scope](#configure-the-environment-for-a-scope) |
34| Enable Claude Tag | Turns Claude on or off in a scope | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
34| Enable Claude Tag | Turns Claude on or off in a scope. On the **Slack** page, the switch is labeled **Respond in all channels** or **Respond in channels** | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
3535| Claude Tag version | Which generation answers in a scope (**New** or **Legacy**) | [Turn Claude Tag on or off and set the version for a scope](/docs/claude-tag/admins/workspaces#turn-claude-tag-on-or-off-and-set-the-version-for-a-scope) |
3636
37### Channel connections are separate from personal connectors
37<a id="channel-connections-are-separate-from-personal-connectors" />
3838
39An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) configures Claude's connections, plugins, and skills, and they apply per scope. They are separate from the connectors, skills, or MCP servers an individual user has set up in their own claude.ai or Claude Desktop account. A user's personal connectors are not part of a channel's configuration, and the channel's connections are not listed among that user's personal connectors in claude.ai. Claude can [use a user's personal connectors in a channel](/docs/claude-tag/concepts/personal-connectors) for that user's own tasks, after the user allows it. That work runs with the user's permissions and is recorded under their name. Projects in claude.ai are separate too. Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project. Put standing guidance for a channel in its [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
39### Claude Tag connectors are separate from personal connectors
4040
41To give Claude access to a tool that is not in the built-in connection list, including a custom MCP server, see [add a custom connection](/docs/claude-tag/admins/connections/custom).
41An Owner or a [Claude Tag admin](/docs/claude-tag/admins/restrict-access#delegate-claude-tag-administration) configures Claude Tag connectors, plugins, and skills, and they apply per scope. They are separate from the personal connectors, skills, or MCP servers an individual user has set up in their own claude.ai or Claude Desktop account. A user's personal connectors are not part of a channel's configuration, and the channel's connectors are not listed among that user's personal connectors in claude.ai. Claude can [use a user's personal connectors in a channel](/docs/claude-tag/concepts/personal-connectors) for that user's own tasks, after the user allows it. That work runs with the user's permissions and is recorded under their name. Projects in claude.ai are separate too. Claude doesn't read a Project's instructions or knowledge in Slack, and a channel can't be pointed at a Project. Put standing guidance for a channel in its [custom instructions](/docs/claude-tag/admins/attach-to-scope#add-custom-instructions).
4242
43To give Claude access to a tool that isn't in the **Add a connector** list, including a custom MCP server, see [Connect a service that isn't in the list](/docs/claude-tag/admins/connections/custom).
44
4345## Change behavior from the channel
4446
4547Everything in the table below is open to channel members, with no admin involved.
from line 64
6264
6365## Choose the model for a scope
6466
65Each scope carries a **Default model** setting in its **Advanced** section, alongside the [environment](/docs/claude-tag/concepts/glossary#environment) and guest controls. It sets the model new channel sessions in that scope start on. The options are the models your organization allows, such as Opus and Sonnet models, regardless of any individual member's own model access. The picker also lists model families. A scope set to a family option starts sessions on the newest model of that family your organization allows, and moves to a newer one when your organization gets it, without you changing the setting. A scope without its own setting inherits from its parent, and a channel's setting overrides its workspace's. The **Inherit** option shows which model the scope resolves to.
67The **Model** setting sets the model new channel sessions in a scope start on. For your whole organization, it's the **Model** row on the main [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) page. For a workspace or channel, it's on the **General** tab of that scope's page on the **Channels** tab under **Claude's access**. The options are the models your organization allows, such as Opus and Sonnet models, regardless of any individual member's own model access. The picker also lists model families. A scope set to a family option starts sessions on the newest model of that family your organization allows, and moves to a newer one when your organization gets it, without you changing the setting.
6668
67To keep sessions on a model you chose, set a specific model at the organization scope rather than leaving the setting unset; every scope without an override then follows it.
69A workspace or channel without its own setting shows **Inherit** and takes the model from its parent, and a channel's setting overrides its workspace's. The line under the setting names the model the scope uses and which scope it comes from.
6870
71To keep sessions on a model you chose, set a specific model in the organization's **Model** row rather than leaving it unset; every scope without an override then follows it.
72
6973When you change the setting, new sessions start on the new model. A thread already underway switches to it at the next message anyone posts there, unless someone in that thread has already had Claude switch models. The footer of each Claude reply in Slack names the model that handled it, so you can confirm what a scope is running.
7074
7175Channel members can also change the model from Slack. Asking Claude in a thread switches that thread, and asking it to make a model the channel default changes this setting for the channel, unless the scope's [Channel member edits](/docs/claude-tag/admins/attach-to-scope#restrict-who-can-set-channel-instructions) setting is **Block**. See [choose the model Claude Tag uses](/docs/claude-tag/users/models).
from line 78
7478
7579On the Team plan, Claude Tag doesn't apply the [`availableModels` allowlist](https://code.claude.com/docs/en/model-config#restrict-model-selection) from your Claude Code [server-managed settings](https://code.claude.com/docs/en/server-managed-settings), and on the Enterprise plan it applies the allowlist in only some organizations.
7680
77* **Where the allowlist doesn't apply**: Claude offers your organization's full Claude Tag model list, both when someone asks it to switch and in the model selector for direct messages. It starts sessions on a scope's **Default model** without checking that model against the allowlist. The **Default model** picker in admin settings still lists only allowed models.
81* **Where the allowlist doesn't apply**: Claude offers your organization's full Claude Tag model list, both when someone asks it to switch and in the model selector for direct messages. It starts sessions on a scope's **Model** setting without checking that model against the allowlist. The **Model** picker in admin settings still lists only allowed models.
7882* **Where the allowlist applies**: sessions in a channel run as the [agent identity](/docs/claude-tag/concepts/agent-identity) you provisioned and without your server-managed settings. When someone in a channel asks Claude to switch models, Claude may decline a model outside the allowlist, though that check doesn't always run. In one-to-one direct messages from a member whose linked Claude account belongs to your organization, Claude runs on that member's own account, which receives your allowlist; see [Restrict model selection](https://code.claude.com/docs/en/model-config#restrict-model-selection) for what happens to a model the allowlist blocks.
7983
8084In either case, Claude Tag offers only the models it supports, so a model your allowlist includes can be absent in Slack.
8185
82On the Enterprise plan, turning a model off for the whole organization on your **Models** page removes it from the lists in Slack, and Claude declines requests to switch to it. If you turn off the model a scope's **Default model** is set to, Claude still starts sessions there on a fallback model that's still on, and declines only when every fallback is off too. The footer of the first reply names the model that served it.
86On the Enterprise plan, turning a model off for the whole organization on your **Models** page removes it from the lists in Slack, and Claude declines requests to switch to it. If you turn off the model a scope's **Model** setting names, Claude still starts sessions there on a fallback model that's still on, and declines only when every fallback is off too. The footer of the first reply names the model that served it.
8387
8488### Allow fast mode
8589
from line 101
97101
98102## Configure the environment for a scope
99103
100Claude runs every channel session in a sandbox that starts with a standard set of tools. When a channel's work needs something that sandbox doesn't have, such as a language runtime, a database client, a set of environment variables, or broader web access, give the channel an environment. An environment is an [organization-shared cloud environment](https://code.claude.com/docs/en/cloud-environments#organization-shared-environments): you create it once, then choose it on a scope, meaning a channel, a workspace, or **Default Slack access**. Both steps take an Owner; a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can't change a channel's environment.
104Claude runs every channel session in a sandbox that starts with a standard set of tools. When a channel's work needs something that sandbox doesn't have, such as a language runtime, a database client, a set of environment variables, or broader web access, give the channel an environment. An environment is an [organization-shared cloud environment](https://code.claude.com/docs/en/cloud-environments#organization-shared-environments): you create it once, then choose it on a scope, meaning a channel, a workspace, or the **Slack** page for your whole organization. Both steps take an Owner; a [channel manager](/docs/claude-tag/admins/restrict-access#delegate-channel-setup-to-channel-managers) can't change a channel's environment.
101105
102106### Decide what goes in the environment
103107
from line 112
108112| A tool installed before Claude starts, such as a runtime or a database client | The environment's setup script, a Bash script whose installs are on disk before Claude starts work |
109113| A value every session should see, such as a deployment target or a feature flag | The environment's environment variables, as `KEY=value` pairs, one per line |
110114| Web access without a credential | The environment's network access level; see [broad web access through the environment](/docs/claude-tag/admins/add-connections#broad-web-access-through-the-environment) |
111| An API key, token, or other credential | A [connection](/docs/claude-tag/admins/add-connections), never an environment variable |
115| An API key, token, or other credential | A [connector](/docs/claude-tag/admins/add-connections), never an environment variable |
112116| Setup for one repository, such as installing its dependencies | That repository's `CLAUDE.md`; see [install project dependencies](/docs/claude-tag/admins/configure-github#install-project-dependencies) |
113117
114Keep credentials out of environment variables because every session on the environment reads them and Claude can print them. There is no separate secrets store. A connection stores the credential outside the sandbox and attaches it to matching requests at the network layer, so Claude uses the service without holding the raw value. [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) describes how. A connection also travels with the access bundle, so you choose channel by channel which sessions can use it. Repository-specific setup goes in `CLAUDE.md` so the people who maintain the repository keep it current. Claude reads it when it starts work in that repository.
118Keep credentials out of environment variables because every session on the environment reads them and Claude can print them. There is no separate secrets store. A connector stores the credential outside the sandbox and attaches it to matching requests at the network layer, so Claude uses the service without holding the raw value. [Agent Proxy](/docs/claude-tag/concepts/agent-identity#agent-proxy) describes how. A connector in a bundle also travels with that bundle, so you choose channel by channel which sessions can use it. Repository-specific setup goes in `CLAUDE.md` so the people who maintain the repository keep it current. Claude reads it when it starts work in that repository.
115119
116120### Create the environment and choose it on a scope
117121
118Creating the environment and choosing it on a scope happen on two different admin pages. Choose it on a channel to change only that channel's sessions, on a workspace to cover every channel in the workspace where you haven't chosen one, or on **Default Slack access** to cover every workspace.
122Creating the environment and choosing it on a scope happen on two different admin pages. Choose it on a channel to change only that channel's sessions, on a workspace to cover every channel in the workspace where you haven't chosen one, or on the **Slack** page to cover every workspace.
119123
120124<Steps>
121125 <Step title="Create the environment">
from line 127
123127 </Step>
124128
125129 <Step title="Set the scope's environment">
126 The picker is at [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag) > **Claude Tag's access** > **Slack** > the scope (**Default Slack** is the organization-wide scope) > **Advanced** > **Environment**. Pick the environment there.
130 Go to [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels) and open the scope's page (**Slack** for the whole organization). On its **Advanced** tab, pick the environment in **Environment** under **Sessions**.
127131 </Step>
128132
129133 <Step title="Confirm the environment in a new thread">
from line 141
137141
1381421. The channel's **Environment** setting
1391432. The workspace's **Environment** setting
1403. The **Environment** setting on **Default Slack access**
1443. The **Environment** setting on the **Slack** page
1411454. The [organization's default environment](https://code.claude.com/docs/en/cloud-environments#the-default-environment), which an Owner chooses under **Cloud sessions** at [`claude.ai/admin-settings/claude-code`](https://claude.ai/admin-settings/claude-code)
142146
143If you haven't chosen an environment on a scope, its picker shows **Organization default**, but sessions there may still run on an environment you chose on the workspace or on **Default Slack access**. In a channel where Claude runs with [channel-only access](/docs/claude-tag/admins/restrict-access#how-channel-only-works) because a guest is present, sessions run on the standard environment regardless of these settings. If a channel's sessions aren't on the environment you expect, see [channel sessions use the wrong environment](/docs/claude-tag/admins/troubleshooting#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one).
147If you haven't chosen an environment on a scope, its picker shows **Organization default**, but sessions there may still run on an environment you chose on the workspace or on the **Slack** page. In a channel where Claude runs with [channel-only access](/docs/claude-tag/admins/restrict-access#how-channel-only-works) because a guest is present, sessions run on the standard environment regardless of these settings. If a channel's sessions aren't on the environment you expect, see [channel sessions use the wrong environment](/docs/claude-tag/admins/troubleshooting#channel-sessions-use-the-wrong-environment-or-can%E2%80%99t-find-one).
144148
145149## Auto mode allow rules
146150
from line 152
148152
149153A rule is a plain sentence that describes work you approve in the scope, such as "Deploying to our staging cluster from a session in this channel is a normal, approved workflow." To add one:
150154
1511. On [`claude.ai/admin-settings/claude-tag`](https://claude.ai/admin-settings/claude-tag), open the **Slack** tab under **Claude Tag's access** and find the scope you want to change (the organization-wide **Default Slack** row, a workspace, or a channel). The **Default Slack** row opens as **Default Slack access**.
1522. Open the scope's **Advanced** section and find **Auto mode allow rules**, below the [**Default model**](#choose-the-model-for-a-scope) setting.
1551. Go to [**Claude's access > Channels**](https://claude.ai/admin-settings/claude-tag?access=channels) and open the page of the scope you want to change: **Slack** for the whole organization, a workspace, or a channel.
1562. Open the page's **Advanced** tab and find **Auto mode allow rules** under **Sessions**.
1531573. Select **Add rule** and write the rule as one plain sentence.
154158
155159The rules list has three properties:
156160
157161* **Limits:** a scope holds up to 50 rules, and each rule can be up to 1,024 characters
158* **Inheritance:** rules you set on a workspace or on [Default Slack access](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit) (the organization-wide root) carry down to the channels beneath, the way [custom instructions](/docs/claude-tag/admins/attach-to-scope#custom-instructions) stack. A channel's own rules add to those and never replace them, so put a rule on a single channel's scope to pre-approve an action there without changing any other channel.
162* **Inheritance:** rules you set on a workspace or on the [**Slack** page](/docs/claude-tag/admins/attach-to-scope#how-scopes-inherit) (the organization-wide root) carry down to the channels beneath, the way [custom instructions](/docs/claude-tag/admins/attach-to-scope#custom-instructions) stack. A channel's own rules add to those and never replace them, so put a rule on a single channel's scope to pre-approve an action there without changing any other channel.
159163* **Access:** you edit the list with the same admin access as the scope's other **Advanced** settings
160164
161165<Warning>Once you add an allow rule, Claude runs the actions it names in every channel the scope covers without anyone approving them in the moment. Keep each rule narrow: name the tool, the action, and the environment it allows, and put rules that unlock sensitive systems on the narrowest scope that needs them.</Warning>
No line in this hunk matches that.