The whole hunk
from line 87, old and new numbered
/
lines
from line 87
87872. Keep the channel private. A bundle on a public channel [grants its access to anyone who joins](/docs/claude-tag/admins/attach-to-scope#attach-to-a-channel).
88883. Check the channel's **Connectors**, **Repositories**, and **Plugins** sections on the [Slack tab in admin settings](/docs/claude-tag/admins/attach-to-scope). They list the access the channel gets, including rows inherited from the workspace or from Default Slack access, each with an origin line naming where it comes from.
8989
90Claude [doesn't operate in externally shared channels](/docs/claude-tag/admins/restrict-access#externally-shared-channels), so a channel shared with another company never has a session to isolate.
90In a channel shared with another company through Slack Connect, Claude is off by default. If an Owner turns it on, Claude runs there with [channel-only access](/docs/claude-tag/admins/restrict-access#slack-connect-channels), and a bundle's credentials reach that channel only if an Owner has also turned the bundle on for Slack Connect channels.
9191
9292Isolating a credential doesn't isolate what Claude knows. What it learns in a public channel becomes [workspace memory](/docs/claude-tag/users/memory) that sessions in the workspace's other channels can read, and it can [search public channels by keyword](/docs/claude-tag/admins/restrict-access#controls-that-aren%E2%80%99t-available) without being added to them, the same way any workspace member can.
9393