Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
One change · claude-docs

Admin controls changed

claude-science/admin-controls

Nearest release: v2.1.252, published 7 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Recorded here
Lines+221added
Lines−78removed
From line 1 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits10to this page, all time

## Organization settings ### Defaults by plan ### How changes reach members ### Featured connectors and skills ### Custom connectors ### Custom skills ### Network allowlist ### Organization package mirror ### SSH hosts ### Modal ### Scientific model endpoints ### Memory ## How other admin settings apply to Claude Science ### Identity and access ### Capability toggles ### Connectors ### Data and privacy ### Audit and compliance ### Usage, models, and billing ### Offboarding and local data ## Identity and access ## Capability toggles ## Connectors ## Data and privacy ## Audit and compliance ## Usage, models, and billing ## Offboarding and local data

The whole hunk

from line 1, old and new numbered
/
lines
from line 1
11# Admin controls
22 
3> Members sign in to Claude Science with their Claude account, so your identity and billing controls apply automatically.
3> Organization settings for Claude Science on Team and Enterprise plans (Featured connectors and skills, custom connectors and skills, the network allowlist, package mirror, SSH hosts, Modal, scientific model endpoints, and memory) and which other claude.ai admin controls apply to the app.
44 
5Members sign in to Claude Science with their Claude account, so your identity and billing controls apply automatically. Because the app stores conversations on each member's computer, most of the data-handling controls Anthropic provides don't reach that data today. The tables show, for each admin setting, whether it governs Claude Science in beta. Status values describe Claude Science specifically; other Claude products may differ.
5Members sign in to Claude Science with their Claude account, so your identity and billing controls apply automatically. Because the app stores conversations on each member's computer, most of the data-handling controls Anthropic provides don't reach that data today. [Organization settings](#organization-settings) describes the controls on the claude.ai **Organization settings** > **Claude Science** page itself, which govern the connectors, skills, compute, network access, and memory that members can use in the Claude Science app. [How other admin settings apply to Claude Science](#how-other-admin-settings-apply-to-claude-science) lists every other claude.ai admin setting and whether it applies to Claude Science today. Status values describe Claude Science specifically; other Claude products may differ.
66 
7Legend: Supported / Partial / Not available / Not applicable
7## Organization settings
88 
9## Identity and access
9The [**Organization settings** > **Claude Science**](https://claude.ai/admin-settings/claude-science) page in claude.ai holds the controls that apply to every member of your Team or Enterprise organization who uses the app. An Owner or Primary Owner turns Claude Science on there (see [Enable Claude Science](/docs/claude-science/enable-claude-science)), and the other controls unlock once Claude Science is on. Each section below covers one control: what it governs, its default, and what changes for members when you turn it off.
1010 
11| Admin setting | Status in Claude Science beta | Note |
12| --------------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
13| SSO (SAML / OIDC) | Supported | Sign-in goes through claude.ai, so your SSO policy applies automatically. |
14| SCIM / Directory Sync | Supported | Deprovisioning a member revokes their access. |
15| Domain capture | Supported | Inherited from claude.ai account creation. |
16| Members management | Supported | Adding or removing org members controls who can sign in. |
17| Built-in roles | Supported | All built-in roles get access once the product is enabled for the org. |
18| Custom roles | Supported | Custom roles can grant or deny access to the app. |
19| Groups | Supported | Roles assigned through groups carry through. |
20| IP allowlisting | Partial | Claude inference is IP-gated. Gating remote compute (running code on the member's own SSH hosts or cloud accounts) is on the roadmap. Custom connectors and local operation are outside this setting's scope. |
21| Session duration | Partial | Limits the browser sign-in step only; the app stays signed in after that. |
11### Defaults by plan
2212 
23## Capability toggles
13Each control starts at a default that depends on your plan and on whether HIPAA compliance is enabled for your organization. The page always shows the value in force for your organization.
2414 
25| Admin setting | Status in Claude Science beta | Note |
26| -------------------------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
27| Org enable toggle | Supported | Off by default for Team and Enterprise; an Owner or Primary Owner turns it on under Organization settings > Claude Science. Assigning seats doesn't turn it on. |
28| Completion feedback (thumbs) | Supported | The org toggle hides the feedback buttons, same as Chat. |
29| Organization custom instructions | Supported | The org's custom instructions are applied to the app's model calls, the same as Chat. |
30| Skills allowlist | Partial | Org-published skills appear, but members can also install local skills without restriction. Adding admin control is on the roadmap. |
31| Web search | Not available | The app offers web search regardless of this setting. Adding admin control is on the roadmap. |
32| Code execution | Not available | This setting controls Chat's hosted code sandbox only. Claude Science runs code locally regardless of this setting; that's core to the product. |
33| Code execution network allowlist | Not available | This setting controls Chat's hosted code sandbox only and is not yet available for Claude Science in Organization settings. Claude Science's local sandbox keeps its own allowlist, which members manage in the app and administrators can extend per device with the sandbox network keys in the [configuration file reference](/docs/claude-science/configuration-file-reference). |
34| Location metadata | Not applicable | The app doesn't derive, store, or send any geolocation data. |
35| Memory | Not applicable | The claude.ai Memory setting doesn't control memory in Claude Science. The app keeps its own memory locally on the member's device. |
36| Projects | Not applicable | No Projects integration; the app uses local workspaces instead. |
15| Control | Default for Team | Default for Enterprise¹ |
16| ----------------------------------------------------------- | ------------------------------ | ------------------------------ |
17| Featured connectors and Featured skills | All on | All on |
18| Allow custom connectors | On | Off |
19| Allow custom skills | On | On |
20| Manage network allowlist | Off (members manage their own) | Off (members manage their own) |
21| Organization package mirror | Not set | Not set |
22| Allow members to connect SSH hosts | On | On |
23| Allow members to connect to Modal | On | Off |
24| Show scientific model endpoint providers on the Compute tab | On | On |
25| Turn on memory for your team | On | On |
3726 
38## Connectors
27¹ For HIPAA-eligible organizations, note that Claude Science (beta) is not covered under your Business Associate Agreement (BAA) and should not be used with protected health information (PHI). Administrators who enable Claude Science are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. Featured and custom connectors, SSH hosts, Modal, scientific model endpoints, and memory are all off by default for HIPAA-eligible organizations.
3928 
40| Admin setting | Status in Claude Science beta | Note |
41| ---------------------------------- | ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
42| Org-published Directory connectors | Supported | Connectors the admin publishes are available in the app. |
43| Per-role connector restrictions | Partial | Enforced for Directory connectors, not for connectors members add locally. |
44| Org plugin allowlist | Partial | Org-published plugins appear automatically; members can still add their own local skills and connectors. Adding admin control to restrict local skills and connectors is on the roadmap. |
45| Connector tunnels | Partial | Directory connectors the admin publishes reach the app through tunnels. Local connectors the member adds run on their own computer, so tunnels don't apply. Custom remote connectors the member adds don't route through tunnels. |
46| Custom connector restrictions | Not available | Members can add their own custom connectors regardless of the organization allowlist. Adding admin control is on the roadmap. |
47| Desktop Extension allowlist | Not applicable | Desktop Extension directory isn't available in the app. |
29### How changes reach members
4830 
49## Data and privacy
31Changes you save reach each member's running app within a few minutes and apply on the member's next turn or request. An app that is closed picks up your changes when it next starts, and an app that can't reach claude.ai keeps applying the last settings it received.
5032 
51| Admin setting | Status in Claude Science beta | Note |
52| ------------------------- | ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
53| CMEK | Supported | Applies to the product's model traffic the same as Chat. Compliance API session transcripts are also encrypted under your key. |
54| Data processing geography | Partial | Covers Anthropic-hosted processing, not remote compute you configure (code the member runs on their own SSH hosts or cloud accounts) or the member's computer (same as Claude Code). |
55| HIPAA | Partial | Organizations with HIPAA compliance enabled can turn on the Claude Science beta, but usage isn't covered under the BAA. |
56| Custom Data Retention | Partial | The auto-delete window doesn't cover data on members' computers or the model-call logs Anthropic keeps for this product. For Enterprise organizations with the Compliance API enabled, the window does apply to the session transcripts it returns. |
33The settings apply to members running version 0.1.41 or later of the Claude Science app. A member still on an earlier version isn't governed by these settings until the member updates (see [Required updates](/docs/claude-science/manage-on-devices#required-updates)). For Team and Enterprise organizations, Claude Science enforces a minimum version of 0.1.41. A member on an older version sees a notice that the version is no longer supported, with an **Update now** button. If the update doesn't complete after a second try, the member can install the current version from the [Claude Science download page](https://claude.com/product/claude-science) (on Linux, rerun the install command in [Get started](/docs/claude-science/get-started#install)); projects and settings on the computer are kept.
5734 
58## Audit and compliance
35Each member's app also has to reach claude.ai regularly to confirm these settings. If an app can't reach claude.ai for 72 hours, it pauses memory, custom connectors, SSH hosts, Modal, model endpoints, and adding custom skills until it reconnects, and keeps applying the network allowlist, package mirror, and Featured connector and skill choices it last received.
5936 
60| Admin setting | Status in Claude Science beta | Note |
61| --------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
62| Audit log | Not available | Claude Science doesn't write events to the audit log. For Enterprise organizations with the Compliance API enabled, changes to your Claude Science organization settings are recorded in its Activity Feed instead. |
63| Compliance API | Partial | Enterprise plans only. The [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) returns read-only transcripts of members' Claude Science sessions (this coverage is in beta) and records changes to your Claude Science organization settings in its Activity Feed. Sessions in organizations with HIPAA compliance enabled aren't captured. See [Compliance API coverage](/docs/claude-science/how-claude-science-works-with-your-data#compliance-api-coverage). |
64| Org data export | Not available | The export doesn't include data stored on members' computers (same as Claude Code). |
37Turning a control off doesn't delete anything on the members' computers. What members set up under that control (custom connectors, SSH hosts, their Modal connection, saved memories, and their own choices) stays on their computer, and that feature cannot be used inside the Claude Science app while the control is off. The setting shows grayed out in the app with a note that an admin turned it off, and everything works again as before if you turn the control back on. A control that is off by your plan's default instead shows a note that an admin can turn it on. When the **Allow custom skills** switch is off, skills a member added earlier keep working (see [Custom skills](#custom-skills)).
6538 
66## Usage, models, and billing
39### Featured connectors and skills
6740 
68| Admin setting | Status in Claude Science beta | Note |
69| --------------------- | ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
70| Usage limits | Supported | Usage counts toward the same 5-hour and weekly limits as Claude Code and Cowork. |
71| Billing and seats | Supported | Uses the same seat as the rest of claude.ai. |
72| Model access controls | Supported | Uses the standard model API, so the org's allowed-model list and model access grants apply to both the model picker and the calls themselves. |
73| Usage analytics | Supported | Open Analytics from the user menu; the Claude Science tab shows usage, and spend is filterable by product on the Overview tab. |
41Featured connectors and Featured skills come with Claude Science, and admins can control whether they are enabled or disabled for your members (see [Connectors and skills](/docs/claude-science/connectors-and-skills)). The **Featured connectors** and **Featured skills** sections list them with one switch per item, so you can choose which ones members can use. Every item is on by default for Team and Enterprise organizations. In an organization with HIPAA compliance enabled, every Featured connector and skill starts disabled; turn on the ones you have reviewed.
7442 
75## Offboarding and local data
43Each section shows how many items are enabled. Expand it to see the list, and select an item to see its tools or instructions, author, license, and third-party terms.
7644 
77| Admin setting | Status in Claude Science beta | Note |
78| ------------------------ | ----------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
79| Offboarding (local data) | Not available | Removing a member doesn't wipe data already on their computer. |
80| Local deletion signal | Not available | Deleting local data doesn't notify Anthropic to drop the matching server-side model-call logs early; this is on the roadmap. Compliance API session transcripts, where captured, remain until their retention period ends. |
45Besides switching every current item in that list, **Enable all** and **Disable all** set how items added in later versions of Claude Science start: on after **Enable all**, off after **Disable all**. If you use neither, new items start on (off in an organization with HIPAA compliance enabled). The individual switches affect only that item, so to keep today's items on while new ones start off, choose **Disable all** and then turn on the items you want.
46 
47In the **Featured connectors** list, the rows marked **Web** (PubMed, Clinical Trials, ChEMBL, and bioRxiv) are connectors Anthropic hosts in the Claude connector directory rather than locally as part of the app. The switches for those four add or remove the connector for your whole organization on **Organization settings** > **Connectors**, need a role that can manage your organization's connectors, and aren't changed by **Enable all** or **Disable all**. For organizations with HIPAA compliance enabled, manage those four on the **Connectors** page instead.
48 
49When you turn a connector or skill off, Claude can no longer use it for any member. A connector is no longer offered to Claude, and a skill is left out of the skills Claude can load, from the member's next turn. The item stays listed in the member's settings, grayed, with a note that it's disabled by your admin.
50 
51Members can still turn off, in their own app, any item you leave on. The app remembers each member's choice, so it applies again if you turn an item off and later back on. Turning a Featured skill off doesn't stop a member from writing a skill of their own; whether members can add their own skills is governed by [Custom skills](#custom-skills).
52 
53When you turn Claude Science on, the [**Turn on Claude Science** dialog](/docs/claude-science/enable-claude-science#turn-on-claude-science) notes: "By continuing, you authorize your team to let Claude use the optional enabled resources on their behalf. These resources and content they reach may be subject to third-party terms (viewable in Settings), and your users are solely responsible for compliance."
54 
55### Custom connectors
56 
57Custom connectors are Model Context Protocol (MCP) servers a member adds under **Settings** > **Connectors** in the Claude Science app, either a remote server at an HTTPS URL or a local command on their computer (see [Custom connectors](/docs/claude-science/custom-connectors)). The **Allow custom connectors** switch decides whether members can add and use them. It's on by default for Team organizations and off by default for Enterprise organizations. Organizations with HIPAA compliance enabled can't turn it on.
58 
59When the switch is off, members can't add, change, or authorize custom connectors, and Claude no longer sees the custom connectors members may have added earlier. Those connectors stay listed in the member's settings, grayed, with a note that custom connectors are disabled by your admin. Featured connectors and the Directory connectors you publish from **Organization settings** > **Connectors** aren't affected by this switch.
60 
61### Custom skills
62 
63Skills are instructions, sometimes with helper code, that Claude loads when a task calls for them (see [Skills](/docs/claude-science/connectors-and-skills#skills)). Members add their own by writing one, uploading one, importing one from a public GitHub repository (or a private repo if a [GitHub credential](/docs/claude-science/connectors-and-skills#skills) is stored), or asking Claude to create one from a session. The **Allow custom skills** switch decides whether members can add skills of their own, including creating one from the Claude Science app so it's also available to them in claude.ai. It's on by default for Team and Enterprise organizations, including those with HIPAA compliance enabled.
64 
65When the switch is off, members can't add new skills of their own or publish them, and the app notes that custom skills are disabled by your admin. Skills a member added earlier still work and can still be edited, and Featured skills aren't affected. Custom skills are how members teach Claude their own workflows and analysis pipelines, so Anthropic recommends leaving this switch on.
66 
67### Network allowlist
68 
69When Claude runs code for a member, that code can reach only the domains on the analysis sandbox's network allowlist: the package hosts, the scientific databases behind the Featured connectors, and hosts the member approved. See [Sandbox](/docs/claude-science/core-concepts#sandbox) and the domain tables in [Network requirements](/docs/claude-science/network-requirements#analysis-sandbox-domains).
70 
71By default, each member manages that list on their own computer. The **Manage network allowlist** switch transfers control of the list from members to you. While it's on, every member's app uses the organization's list instead of the member's own, and members see the list in their **Network** settings read-only, apart from domains they have blocked themselves, with a note that the domain allowlist is controlled by their admin. It's off by default for Team and Enterprise organizations, and on for organizations with HIPAA compliance enabled, which can't turn it off.
72 
73Turning the switch on sets aside what members allowed themselves, including the domains a deployed configuration file adds with its `[sandbox.network]` keys; those settings are kept and apply again when you turn the switch off. Domains the file denies stay denied.
74 
75Your list is enforced by the app's sandbox (see [Sandbox](/docs/claude-science/core-concepts#sandbox)). On a computer where the sandbox is turned off or can't start, the app pauses new sessions and messages and tells the member the computer doesn't meet the organization's security requirements, until the member restarts the app with the sandbox on or you turn the switch off. Turning the switch off keeps your saved list, which applies again the next time you turn it on.
76 
77With the switch on, **Claude Science domains** shows the Featured domains in the same groups as the app, such as **Package management**, **Literature & citations**, and **NCBI / NIH**, with one switch per domain. A group switch turns all of its domains on or off. Below it, **Custom domains** adds your own. The rules for an entry are:
78 
79* An exact name such as `data.example.org`, or a wildcard such as `*.example.org`
80* A wildcard covers subdomains only, so `*.example.org` doesn't cover `example.org` itself; add both if you need both
81* No IP addresses and no single-label names such as `intranet`
82* The list holds up to 600 domains, counting built-in and custom ones together
83* There's no **Save** button: each change is saved as soon as you make it
84 
85Until you change the list, members use Claude Science's Featured list, including domains added in later versions of Claude Science. Once you change it, the list is saved exactly as you left it, so a domain added in a later version stays off until you turn it on. **Reset** returns to the Featured list and removes your custom domains, for all members.
86 
87You can also turn off the **Package management** domains (PyPI, conda, CRAN and Bioconductor, npm, and GitHub), with limits. The PyPI and conda domains can be turned off only while the [organization package mirror](#organization-package-mirror) covers them. Turning the CRAN and Bioconductor, npm, or GitHub domains off means members can't install packages from them, and the page asks you to confirm. The domains the sandbox always blocks (see [Network requirements](/docs/claude-science/network-requirements#domains-the-sandbox-always-blocks)) stay blocked whichever list is in force.
88 
89The allowlist governs the network connections of code Claude runs in the sandbox on the member's computer, the local-command connectors that run inside it, and, while you manage it, the [model endpoints](#scientific-model-endpoints) members connect by host name. Jobs on SSH hosts use the host's own network, so the allowlist doesn't apply to them, and the [**Allow members to connect SSH hosts**](#ssh-hosts) switch is the control for those.
90 
91Modal jobs run in Modal's cloud. While you manage the list, a member's Modal jobs run only if the member has set **Network restrictions** for Modal in the app to **Allowlist** or **No network**. Unrestricted Modal jobs are refused.
92 
93### Organization package mirror
94 
95Analysis environments install Python and conda packages from the public hosts unless a mirror is set. Members or IT can set a mirror per computer under **Settings** > **Network** > **Package mirror** or in the [configuration file](/docs/claude-science/configuration-file-reference#package-download-keys). See [Point package installs at an internal mirror](/docs/claude-science/corporate-networks#point-package-installs-at-an-internal-mirror) for the mirror layout and credentials.
96 
97The **Organization package mirror** section sets the same two addresses once for every member: a **Conda channel URL** and a **Python package index URL (PyPI)**. The section applies whether or not you manage the [network allowlist](#network-allowlist), and there is no organization mirror by default.
98 
99Addresses must start with `https://`, name a host rather than an IP address (an intranet name such as `https://artifactory:8443` works), use the standard port or 8443, and carry no sign-in details. To test an address before you save it, open Claude Science on a computer inside your network, go to **Settings** > **Network** > **Package mirror** > **Configure**, paste the address, and select **Check**. An address that breaks these rules is ignored for that registry, the member's own mirror setting applies instead, and the member's app notes it in its log. An address that passes them but can't be reached isn't ignored, and package installs fail with an error that names the mirror.
100 
101An organization mirror takes precedence over a mirror a member set in Settings or in their configuration file. The member's values are kept but not used, and their Settings show that the package mirror is controlled by their admin. The mirror host is allowed automatically and the public hosts it replaces are removed from the allowlist, as for a member-set mirror. While you manage the network allowlist, those hosts stay removed even if they are switched on in your list.
102 
103Mirror credentials stay with each member. A member signs in to your mirror once per mirror host under **Settings** > **Network** > **Package mirror** > **Mirror credentials**, and the organization settings never store a credential.
104 
105### SSH hosts
106 
107Members can register a machine they reach over SSH, such as a lab workstation or an HPC login node, so Claude can run jobs on it (see [Remote compute clusters](/docs/claude-science/remote-compute-clusters)). The **Allow members to connect SSH hosts** switch decides whether they can. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
108 
109When the switch is off, members can't add SSH hosts, and hosts they added earlier are kept but refuse new commands and file transfers; the app shows that SSH host setup is disabled by your admin. A job that is already running can still be stopped and its results collected.
110 
111Jobs on an SSH host run outside the sandbox, as the member's own user on that machine, with access to everything that account can read and write there. The app uses the member's existing SSH configuration and keys and installs nothing on the host. Job scripts and inputs travel directly from the member's computer to the host, and outputs come back the same way, without passing through Anthropic. Code on the host uses the host's network, so the [network allowlist](#network-allowlist) doesn't apply to it.
112 
113### Modal
114 
115[Modal](https://modal.com/) is a third-party cloud computing service. Members can connect a Modal account they own so Claude can run jobs that need a GPU or more memory than their computer has. Modal bills that account directly, and Anthropic never sees a payment method (see [Compute providers](/docs/claude-science/compute-providers#connecting-modal)). The **Allow members to connect to Modal** switch decides whether members can connect Modal in the Claude Science app in **Settings** > **Compute**. It's on by default for Team organizations, off by default for Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
116 
117When the switch is off, members can't set up Modal or start new Modal jobs, and the app shows that Modal setup is disabled by your admin. A job that is already running can still be stopped, and the member's Modal settings are kept.
118 
119With the switch on, **Modal workspaces** lets you limit which Modal workspaces members can connect to. By default members can connect to any workspace. Select **Restrict to a workspace** and enter each workspace name as Modal shows it; capitalization doesn't matter.
120 
121The app checks the workspace that Modal reports for the member's token when the member uses it, and a member on another workspace sees that their Modal workspace is not allowed by their admin. Turning the **Allow members to connect to Modal** switch off hides the workspace list, which is kept and applies again when you turn Modal back on.
122 
123Modal jobs run in Modal's cloud, not on the member's computer. There is no spend ceiling in Claude Science; to limit spend, use the controls in your Modal account (see [Modal's documentation](https://modal.com/docs/guide/budgets)). Members approve jobs on a card that shows the machine and the maximum billable time, per job or for a whole conversation or project, and a job keeps running and billing after the app closes.
124 
125### Scientific model endpoints
126 
127Members can connect a scientific model server, such as NVIDIA BioNeMo NIM, that Claude calls directly from analyses (see [Scientific model endpoints](/docs/claude-science/compute-providers#scientific-model-endpoints)). The **Show scientific model endpoint providers on the Compute tab** switch decides whether members can connect the providers listed on the app's **Compute** tab. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
128 
129When the switch is off, members can't connect these providers or use the endpoints they set up earlier, and the app shows that scientific model endpoint setup is disabled by your admin; the settings they entered are kept. The switch governs third-party model endpoints only and has no effect on which Claude models members can use.
130 
131While members manage their own network allowlist, an endpoint a member connected is reachable without being on that list. While you manage the [network allowlist](#network-allowlist), an endpoint at a public or internal host name works only if your network allowlist also includes that host, so add `health.api.nvidia.com` (NVIDIA's hosted endpoint) or your own server's name under **Custom domains** on the **Organization settings** > **Claude Science** page. Endpoints at a private IP address or on localhost aren't affected.
132 
133### Memory
134 
135Memory lets Claude save short facts about a member, their projects, and their files across sessions, stored in the app's local database on the member's computer (see [Memory](/docs/claude-science/core-concepts#memory)). Each member chooses whether their own memory is on, during first-time setup or later in **Settings** > **Memory**. The **Turn on memory for your team** switch decides whether members can use memory at all. It's on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on.
136 
137When the switch is off, memory is off for every member, whatever they chose in their own settings; Claude neither recalls nor saves facts, first-time setup skips its memory step, and the **Memory** setting shows that memory is disabled by your admin. Facts a member saved earlier stay on their computer, the member can still review and delete them, and Claude uses them again if you turn the switch back on.
138 
139When Claude recalls saved facts for a session, those facts are sent to Anthropic as part of that session's conversation and handled like the rest of the conversation (see [How Claude Science works with your data](/docs/claude-science/how-claude-science-works-with-your-data)). The **Capabilities** > **Memory** setting in claude.ai **Organization settings** doesn't control memory in Claude Science.
140 
141## How other admin settings apply to Claude Science
142 
143In the tables below, each setting is named by its page in claude.ai **Organization settings** and, where it has one, its label there (for example, **Capabilities** > **Web search**). Apart from the **Enable for your organization** toggle, the controls on the **Claude Science** page itself are described under [Organization settings](#organization-settings).
144 
145The status column in each table shows one of four values:
146 
147* **Supported in Claude Science**: you can govern this for Claude Science, through the claude.ai setting itself or through the named control on the **Claude Science** page.
148* **Partially supported in Claude Science**: you can govern only part of this for Claude Science through either place, and the note says which part.
149* **Not available in Claude Science**: the setting doesn't cover Claude Science, and Claude Science has no equivalent control.
150* **Not applicable in Claude Science**: Claude Science has nothing for the setting to govern.
151 
152### Identity and access
153 
154| Setting in claude.ai | Status for Claude Science | Note |
155| ----------------------------------------------------------------------------- | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
156| Organization and access > Single sign-on (SSO) | Supported in Claude Science | Members sign in to Claude Science through claude.ai, so your SSO configuration and the **Require SSO for Claude** setting apply to the app. |
157| Organization and access > User provisioning (SCIM directory sync, Enterprise) | Supported in Claude Science | Provisioning and deprovisioning act on claude.ai membership, which Anthropic checks on every request the app makes, so a deprovisioned member's app stops working. |
158| Organization and access > Domains | Supported in Claude Science | Domain verification, and the **Migrate accounts using your domains** and **Restrict organization creation** settings that build on it, act on claude.ai accounts before anyone reaches the app, so they apply unchanged. |
159| Members | Supported in Claude Science | Adding or removing members controls who can sign in to Claude Science. |
160| Roles (built-in) | Supported in Claude Science | Every built-in role (User, Admin, Owner, and Primary Owner) can use Claude Science once it's turned on for the organization. |
161| Roles > Claude Science permission in custom roles (Enterprise) | Supported in Claude Science | Add the Claude Science permission to a custom role to give the app to that role's members. Members whose custom roles don't include it can't use the app. Team plans don't have custom roles, so everyone gets access when Claude Science is on. |
162| Groups (Enterprise) | Supported in Claude Science | Members get the Claude Science access of the roles their groups assign. |
163| IP allowlist (Enterprise) | Partially supported in Claude Science | The app's sign-in, its requests to Claude, and its Directory connector calls are checked against your allowlist (see [Restrict access to Claude with IP allowlisting](https://support.claude.com/en/articles/13200993-restrict-access-to-claude-with-ip-allowlisting)). Traffic that doesn't go to Anthropic isn't checked, which covers code on the member's computer, SSH hosts, or Modal account, and custom connectors. You can turn SSH hosts, Modal, and custom connectors off under [Organization settings](#organization-settings). |
164| Organization and access > Shortened session length (Enterprise) | Partially supported in Claude Science | Applies to the browser sign-in a member completes to connect the app. It doesn't shorten the app's own sign-in after that, so members aren't asked to sign in again on your schedule. Turning Claude Science off for the organization or removing a member still stops their app within a few minutes. |
165 
166### Capability toggles
167 
168| Setting in claude.ai | Status for Claude Science | Note |
169| -------------------------------------------------------------------------------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
170| Claude Science > Enable for your organization | Supported in Claude Science | Off by default for Team and Enterprise. An Owner or Primary Owner turns it on under **Organization settings** > **Claude Science** (see [Enable Claude Science](/docs/claude-science/enable-claude-science)). Assigning seats doesn't turn it on. |
171| Data and privacy > Rate chats | Supported in Claude Science | When you turn this off, the app hides its response rating buttons and feedback form, as claude.ai does. |
172| Organization and access > Organization instructions | Supported in Claude Science | Anthropic adds your organization instructions to the app's requests to Claude, as it does for claude.ai chat, so members don't need to update the app for a change to apply. |
173| Skills > Organization skills and Policy | Supported in Claude Science | Skills you add under **Organization skills**, and members' own claude.ai skills, appear in Claude Science while **Skills** is on, and **User-created skills** decides whether a member can save a skill from the app to their own claude.ai account. The skills that come with the app and the skills members add in it are controlled on the **Claude Science** page: one switch per Featured skill, and **Allow custom skills** for skills members add themselves (see [Featured connectors and skills](#featured-connectors-and-skills) and [Custom skills](#custom-skills)). |
174| Capabilities > Web search | Not applicable in Claude Science | This setting governs claude.ai chat. Claude Science can search the web regardless of it, and the **Claude Science** page has no switch for web search. |
175| Capabilities > Code execution and file creation | Not applicable in Claude Science | This setting governs the code sandbox Anthropic hosts for claude.ai chat. Running code on the member's computer, or on compute the member connects, is the core of Claude Science and can't be turned off; you govern what that code can reach with the [network allowlist](#network-allowlist), [SSH hosts](#ssh-hosts), and [Modal](#modal) controls. |
176| Capabilities > Allow network egress and Domain allowlist | Supported in Claude Science | These settings govern the hosted sandbox for claude.ai chat. Claude Science's sandbox has its own allowlist: manage it for the whole organization with the **Manage network allowlist** switch on the **Claude Science** page (see [Network allowlist](#network-allowlist)), or leave it off and let members manage their own. Administrators can also extend a member's list per device with the sandbox network keys in the [configuration file reference](/docs/claude-science/configuration-file-reference). |
177| Data and privacy > Location metadata | Not applicable in Claude Science | Claude Science doesn't send location data with requests to Claude, so there is nothing for this setting to govern. |
178| Capabilities > Memory (Enable memory for your team) | Supported in Claude Science | This setting governs memory in claude.ai chat. Claude Science keeps a separate memory on each member's computer, which you turn on or off for everyone with the **Turn on memory for your team** switch on the **Claude Science** page (see [Memory](#memory)). |
179| Settings for claude.ai projects (Public projects, Retention period for projects) | Not applicable in Claude Science | Claude Science doesn't use claude.ai projects. Its projects are folders on the member's computer. |
180 
181### Connectors
182 
183| Setting in claude.ai | Status for Claude Science | Note |
184| ---------------------------------------------------------- | ------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
185| Connectors > Directory connectors you publish | Supported in Claude Science | Directory connectors you publish on the **Connectors** page are available to members in the app, as in claude.ai. The app reaches them through Anthropic's hosted connector service with the member's own account. |
186| Roles > connector permissions in custom roles (Enterprise) | Partially supported in Claude Science | Apply to the connectors on your **Connectors** page, which the app reaches through Anthropic. They don't apply to Featured connectors or custom connectors added via the Claude Science app; the **Claude Science** page controls those for every member rather than per role (see [Organization settings](#organization-settings)). |
187| Plugins > plugins you add for the organization | Partially supported in Claude Science | Plugins you set to **Installed by default** or **Required** are synced to members' Claude Science app, which loads their skills and connectors. Plugins left as **Available to install** aren't offered in the app, and plugin commands don't apply there. Which Featured connectors and skills members can use, and whether they can add their own, are separate controls on the **Claude Science** page (see [Featured connectors and skills](#featured-connectors-and-skills), [Custom connectors](#custom-connectors), and [Custom skills](#custom-skills)). |
188| Connectors > Tunnels API (Enterprise) | Partially supported in Claude Science | A connector your organization serves through a tunnel works in the app the same way it does in claude.ai, because the app reaches Directory connectors through Anthropic's hosted connector service. Custom connectors a member adds in the Claude Science app connect directly from the member's computer and never use a tunnel (admins can restrict this in [Custom connectors](#custom-connectors)). |
189| Connectors > connectors members add themselves | Supported in Claude Science | In claude.ai, members use only the connectors on your **Connectors** page. In Claude Science, members can also add custom connectors (a server URL or a local command) while the **Allow custom connectors** switch is on, which it is by default for Team and not for Enterprise, and the **Connectors** page and its restrictions don't apply to those. Turn off the **Allow custom connectors** switch under **Organization settings** > **Claude Science** to limit members to Featured connectors and the Directory connectors you publish (see [Custom connectors](#custom-connectors)). |
190| Connectors > Desktop extension allowlist | Not applicable in Claude Science | Claude Science doesn't install desktop extensions, so there is nothing for this setting to govern. |
191 
192### Data and privacy
193 
194| Setting in claude.ai | Status for Claude Science | Note |
195| -------------------------------------------------------------------------------------------------------- | ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
196| Data and privacy > Encryption keys (customer-managed keys) | Supported in Claude Science | Anthropic handles Claude Science requests to Claude under your key the same way it handles claude.ai chat requests. Compliance API session transcripts are also encrypted under your key. |
197| Data and privacy > Data residency (US-only inference), or the regional processing terms in your contract | Supported in Claude Science | Governs where Anthropic processes Claude Science requests to Claude, as for your other Claude products. It doesn't cover code that runs on the member's computer, SSH hosts, or Modal account (the same boundary as Claude Code). |
198| Data and privacy > HIPAA Compliance | Not applicable in Claude Science | Organizations with HIPAA compliance enabled can turn Claude Science on, but its use isn't covered under your BAA and members must keep protected health information out of it. These organizations start from stricter defaults, listed under [Defaults by plan](#defaults-by-plan). |
199| Data and privacy > Retention period for chats and projects | Partially supported in Claude Science | The auto-delete window doesn't cover data on members' computers or the model-call logs Anthropic keeps for this product. For Enterprise organizations with the Compliance API enabled, the window does apply to the session transcripts it returns. |
200 
201### Audit and compliance
202 
203| Setting in claude.ai | Status for Claude Science | Note |
204| ------------------------------------ | ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
205| Data and privacy > Export audit logs | Not available in Claude Science | Claude Science doesn't write events to the audit log. For Enterprise organizations with the Compliance API enabled, changes to your Claude Science organization settings are recorded in its Activity Feed instead. |
206| Data and privacy > Compliance API | Supported in Claude Science | Enterprise plans only. The [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) returns read-only transcripts of members' Claude Science sessions (this coverage is in beta) and records changes to your Claude Science organization settings in its Activity Feed. Sessions in organizations with HIPAA compliance enabled aren't captured. See [Compliance API coverage](/docs/claude-science/how-claude-science-works-with-your-data#compliance-api-coverage). |
207| Data and privacy > Export data | Not available in Claude Science | The organization export doesn't include Claude Science conversations and files, which are stored on members' computers (the same as Claude Code). |
208 
209### Usage, models, and billing
210 
211| Setting in claude.ai | Status for Claude Science | Note |
212| ---------------------------------------------------- | --------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
213| Usage > Extra usage and Spend limits | Supported in Claude Science | Claude Science usage counts toward each member's 5-hour and weekly usage limits, in the same pool as Claude Code and Cowork. |
214| Billing | Supported in Claude Science | Claude Science uses the same seat as the rest of claude.ai, so there is nothing separate to purchase. |
215| Models > Model access and Default model (Enterprise) | Supported in Claude Science | Turning a model off on the **Models** page, for the whole organization or for a custom role, stops those members from using it in Claude Science because requests for that model are refused. A model you turned off can still appear in the app's model picker, where choosing it returns an error, and the **Default model** setting doesn't set the app's default. Team plans don't have the **Models** page. |
216| Analytics (from the user menu) | Supported in Claude Science | Analytics has a **Claude Science** tab with adoption and session metrics, and the spend charts on the **Overview** tab can be filtered to Claude Science (see [Monitor usage](/docs/claude-science/monitor-usage)). |
217 
218### Offboarding and local data
219 
220| Setting in claude.ai | Status for Claude Science | Note |
221| ------------------------------ | ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
222| Removing a member (local data) | Not available in Claude Science | Removing a member ends their access to Claude Science but doesn't delete data already on their computer. Use your device management software for that (see [Manage on devices](/docs/claude-science/manage-on-devices)). |
223| Deleting local data | Not available in Claude Science | When a member deletes Claude Science data on their computer, Anthropic isn't notified, so the matching server-side model-call logs keep their standard retention period. Compliance API session transcripts, where captured, remain until their retention period ends. |
81224