Organization settings
The Organization settings > Claude Science page in claude.ai holds the controls that apply to every member of your Team or Enterprise organization who uses the app. An Owner or Primary Owner turns Claude Science on there (see Enable Claude Science), and the other controls unlock once Claude Science is on. Each section below covers one control: what it governs, its default, and what changes for members when you turn it off.Defaults by plan
Each control starts at a default that depends on your plan and on whether HIPAA compliance is enabled for your organization. The page always shows the value in force for your organization.
¹ For HIPAA-eligible organizations, note that Claude Science (beta) is not covered under your Business Associate Agreement (BAA) and should not be used with protected health information (PHI). Administrators who enable Claude Science are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. Featured and custom connectors, SSH hosts, Modal, scientific model endpoints, memory, and access to previously saved Claude Science work are all off by default for HIPAA-eligible organizations.
How changes reach members
Changes you save reach each member’s running app within a few minutes and apply on the member’s next turn or request. An app that is closed picks up your changes when it next starts, and an app that can’t reach claude.ai keeps applying the last settings it received. The settings apply to members running version 0.1.41 or later of the Claude Science app. A member still on an earlier version isn’t governed by these settings until the member updates (see Required updates). For Team and Enterprise organizations, Claude Science enforces a minimum version of 0.1.41. A member on an older version sees a notice that the version is no longer supported, with an Update now button. If the update doesn’t complete after a second try, the member can install the current version from the Claude Science download page (on Linux, rerun the install command in Get started); projects and settings on the computer are kept. Each member’s app also has to reach claude.ai regularly to confirm these settings. If an app can’t reach claude.ai for 72 hours, it pauses memory, custom connectors, SSH hosts, Modal, model endpoints, adding custom skills, and accessing previously saved Claude Science work until it reconnects, and keeps applying the network allowlist, package mirror, and Featured connector and skill choices it last received. Turning a control off doesn’t delete anything on the members’ computers. What members set up under that control (custom connectors, SSH hosts, their Modal connection, saved memories, and their own choices) stays on their computer, and that feature cannot be used inside the Claude Science app while the control is off. The setting shows grayed out in the app with a note that an admin turned it off, and everything works again as before if you turn the control back on. A control that is off by your plan’s default instead shows a note that an admin can turn it on. When the Allow custom skills switch is off, skills a member added earlier keep working (see Custom skills).Featured connectors and skills
Featured connectors and Featured skills come with Claude Science, and admins can control whether they are enabled or disabled for your members (see Connectors and skills). The Featured connectors and Featured skills sections list them with one switch per item, so you can choose which ones members can use. Every item is on by default for Team and Enterprise organizations. In an organization with HIPAA compliance enabled, every Featured connector and skill starts disabled; turn on the ones you have reviewed. Each section shows how many items are enabled. Expand it to see the list, and select an item to see its tools or instructions, author, license, and third-party terms. Besides switching every current item in that list, Enable all and Disable all set how items added in later versions of Claude Science start: on after Enable all, off after Disable all. If you use neither, new items start on (off in an organization with HIPAA compliance enabled). The individual switches affect only that item, so to keep today’s items on while new ones start off, choose Disable all and then turn on the items you want. In the Featured connectors list, the rows marked Web (PubMed, Clinical Trials, ChEMBL, and bioRxiv) are connectors Anthropic hosts in the Claude connector directory rather than locally as part of the app. The switches for those four add or remove the connector for your whole organization on Organization settings > Connectors, need a role that can manage your organization’s connectors, and aren’t changed by Enable all or Disable all. For organizations with HIPAA compliance enabled, manage those four on the Connectors page instead. When you turn a connector or skill off, Claude can no longer use it for any member. A connector is no longer offered to Claude, and a skill is left out of the skills Claude can load, from the member’s next turn. The item stays listed in the member’s settings, grayed, with a note that it’s disabled by your admin. Members can still turn off, in their own app, any item you leave on. The app remembers each member’s choice, so it applies again if you turn an item off and later back on. Turning a Featured skill off doesn’t stop a member from writing a skill of their own; whether members can add their own skills is governed by Custom skills. When you turn Claude Science on, the Turn on Claude Science dialog notes: “By continuing, you authorize your team to let Claude use the optional enabled resources on their behalf. These resources and content they reach may be subject to third-party terms (viewable in Settings), and your users are solely responsible for compliance.”Custom connectors
Custom connectors are Model Context Protocol (MCP) servers a member adds under Settings > Connectors in the Claude Science app, either a remote server at an HTTPS URL or a local command on their computer (see Custom connectors). The Allow custom connectors switch decides whether members can add and use them. It’s on by default for Team organizations and off by default for Enterprise organizations. Organizations with HIPAA compliance enabled can’t turn it on. When the switch is off, members can’t add, change, or authorize custom connectors, and Claude no longer sees the custom connectors members may have added earlier. Those connectors stay listed in the member’s settings, grayed, with a note that custom connectors are disabled by your admin. Featured connectors and the Directory connectors you publish from Organization settings > Connectors aren’t affected by this switch.Custom skills
Skills are instructions, sometimes with helper code, that Claude loads when a task calls for them (see Skills). Members add their own by writing one, uploading one, importing one from a public GitHub repository (or a private repo if a GitHub credential is stored), or asking Claude to create one from a session. The Allow custom skills switch decides whether members can add skills of their own, including creating one from the Claude Science app so it’s also available to them in claude.ai. It’s on by default for Team and Enterprise organizations, including those with HIPAA compliance enabled. When the switch is off, members can’t add new skills of their own or publish them, and the app notes that custom skills are disabled by your admin. Skills a member added earlier still work and can still be edited, and Featured skills aren’t affected. Custom skills are how members teach Claude their own workflows and analysis pipelines, so Anthropic recommends leaving this switch on.Organization skills
Add skills for everyone in your organization in claude.ai, under Organization settings > Skills > Organization skills. Upload each skill as a .zip file. Members see it in the Claude Science app under Settings > Skills, in the Organization section. Organization skills go to every member. To update a skill, upload a new version in claude.ai. To let members manage their own skills, host them in a GitHub repository. Put oneskills/<name>/SKILL.md folder per skill in the repository and share the link. Members import them in the Claude Science app under Settings > Skills > Add skill > Import from GitHub. Claude Science records the commit each skill came from. Check for updates flags skills that are behind the repository’s latest commit; each member chooses when to import again. Private repositories work after a member adds a GitHub token in the Claude Science app under Settings > Credentials.
To stop members from adding their own skills, turn off the Allow custom skills switch on the Organization settings > Claude Science page (see Custom skills).
Previously saved Claude Science work
A member who used Claude Science under another sign-in on the same computer (for example, a personal plan before joining your organization) can access the projects, sessions, and artifacts from that sign-in and move it into the app’s folder for your organization on that computer (see Access work from another sign-in on your computer). The Allow members to access Claude Science work previously saved on their computer switch decides whether the app offers this access. It’s on by default for Team organizations and off by default for Enterprise organizations, and organizations with HIPAA compliance enabled can’t turn it on. The access happens on the member’s computer and uploads nothing. Claude Science work the app accesses will follow your organization’s settings from then on. Content your organization doesn’t allow isn’t copied or moved and stays in its original folder, and credentials such as API keys and connector sign-ins are never copied or moved. When the switch is off, the app doesn’t offer the access, and its Access previously saved Claude Science work on this computer setting is grayed out with a note that it’s off for your organization.Network allowlist
When Claude runs code for a member, that code can reach only the domains on the analysis sandbox’s network allowlist: the package hosts, the scientific databases behind the Featured connectors, and hosts the member approved. See Sandbox and the domain tables in Network requirements. By default, each member manages that list on their own computer. The Manage network allowlist switch transfers control of the list from members to you. While it’s on, every member’s app uses the organization’s list instead of the member’s own, and members see the list in their Network settings read-only, apart from domains they have blocked themselves, with a note that the domain allowlist is controlled by their admin. It’s off by default for Team and Enterprise organizations, and on for organizations with HIPAA compliance enabled, which can’t turn it off. Turning the switch on sets aside what members allowed themselves, including the domains a deployed configuration file adds with its[sandbox.network] keys; those settings are kept and apply again when you turn the switch off. Domains the file denies stay denied.
Your list is enforced by the app’s sandbox (see Sandbox). On a computer where the sandbox is turned off or can’t start, the app pauses new sessions and messages and tells the member the computer doesn’t meet the organization’s security requirements, until the member restarts the app with the sandbox on or you turn the switch off. Turning the switch off keeps your saved list, which applies again the next time you turn it on.
With the switch on, Claude Science domains shows the Featured domains in the same groups as the app, such as Package management, Literature & citations, and NCBI / NIH, with one switch per domain. A group switch turns all of its domains on or off. Below it, Custom domains adds your own. The rules for an entry are:
- An exact name such as
data.example.org, or a wildcard such as*.example.org - A wildcard covers subdomains only, so
*.example.orgdoesn’t coverexample.orgitself; add both if you need both - No IP addresses and no single-label names such as
intranet - The list holds up to 600 domains, counting built-in and custom ones together
- There’s no Save button: each change is saved as soon as you make it
Organization package mirror
Analysis environments install Python and conda packages from the public hosts unless a mirror is set. Members or IT can set a mirror per computer under Settings > Network > Package mirror or in the configuration file. See Point package installs at an internal mirror for the mirror layout and credentials. The Organization package mirror section sets the same two addresses once for every member: a Conda channel URL and a Python package index URL (PyPI). The section applies whether or not you manage the network allowlist, and there is no organization mirror by default. Addresses must start withhttps://, name a host rather than an IP address (an intranet name such as https://artifactory:8443 works), use the standard port or 8443, and carry no sign-in details. To test an address before you save it, open Claude Science on a computer inside your network, go to Settings > Network > Package mirror > Configure, paste the address, and select Check. An address that breaks these rules is ignored for that registry, the member’s own mirror setting applies instead, and the member’s app notes it in its log. An address that passes them but can’t be reached isn’t ignored, and package installs fail with an error that names the mirror.
An organization mirror takes precedence over a mirror a member set in Settings or in their configuration file. The member’s values are kept but not used, and their Settings show that the package mirror is controlled by their admin. The mirror host is allowed automatically and the public hosts it replaces are removed from the allowlist, as for a member-set mirror. While you manage the network allowlist, those hosts stay removed even if they are switched on in your list.
Mirror credentials stay with each member. A member signs in to your mirror once per mirror host under Settings > Network > Package mirror > Mirror credentials, and the organization settings never store a credential.
SSH hosts
Members can register a machine they reach over SSH, such as a lab workstation or an HPC login node, so Claude can run jobs on it (see Remote compute clusters). The Allow members to connect SSH hosts switch decides whether they can. It’s on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on. When the switch is off, members can’t add SSH hosts, and hosts they added earlier are kept but refuse new commands and file transfers; the app shows that SSH host setup is disabled by your admin. A job that is already running can still be stopped and its results collected. Jobs on an SSH host run outside the sandbox, as the member’s own user on that machine, with access to everything that account can read and write there. The app uses the member’s existing SSH configuration and keys and installs nothing on the host. Job scripts and inputs travel directly from the member’s computer to the host, and outputs come back the same way, without passing through Anthropic. Code on the host uses the host’s network, so the network allowlist doesn’t apply to it.Modal
Modal is a third-party cloud computing service. Members can connect a Modal account they own so Claude can run jobs that need a GPU or more memory than their computer has. Modal bills that account directly, and Anthropic never sees a payment method (see Compute providers). The Allow members to connect to Modal switch decides whether members can connect Modal in the Claude Science app in Settings > Compute. It’s on by default for Team organizations, off by default for Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on. When the switch is off, members can’t set up Modal or start new Modal jobs, and the app shows that Modal setup is disabled by your admin. A job that is already running can still be stopped, and the member’s Modal settings are kept. With the switch on, Modal workspaces lets you limit which Modal workspaces members can connect to. By default members can connect to any workspace. Select Restrict to a workspace and enter each workspace name as Modal shows it; capitalization doesn’t matter. The app checks the workspace that Modal reports for the member’s token when the member uses it, and a member on another workspace sees that their Modal workspace is not allowed by their admin. Turning the Allow members to connect to Modal switch off hides the workspace list, which is kept and applies again when you turn Modal back on. Modal jobs run in Modal’s cloud, not on the member’s computer. There is no spend ceiling in Claude Science; to limit spend, use the controls in your Modal account (see Modal’s documentation). Members approve jobs on a card that shows the machine and the maximum billable time, per job or for a whole conversation or project, and a job keeps running and billing after the app closes.Scientific model endpoints
Members can connect a scientific model server, such as NVIDIA BioNeMo NIM, that Claude calls directly from analyses (see Scientific model endpoints). The Show scientific model endpoint providers on the Compute tab switch decides whether members can connect the providers listed on the app’s Compute tab. It’s on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on. When the switch is off, members can’t connect these providers or use the endpoints they set up earlier, and the app shows that scientific model endpoint setup is disabled by your admin; the settings they entered are kept. The switch governs third-party model endpoints only and has no effect on which Claude models members can use. While members manage their own network allowlist, an endpoint a member connected is reachable without being on that list. While you manage the network allowlist, an endpoint at a public or internal host name works only if your network allowlist also includes that host, so addhealth.api.nvidia.com (NVIDIA’s hosted endpoint) or your own server’s name under Custom domains on the Organization settings > Claude Science page. Endpoints at a private IP address or on localhost aren’t affected.
Memory
Memory lets Claude save short facts about a member, their projects, and their files across sessions, stored in the app’s local database on the member’s computer (see Memory). Each member chooses whether their own memory is on, during first-time setup or later in Settings > Memory. The Turn on memory for your team switch decides whether members can use memory at all. It’s on by default for Team and Enterprise organizations, and off by default for organizations with HIPAA compliance enabled, which can turn it on. When the switch is off, memory is off for every member, whatever they chose in their own settings; Claude neither recalls nor saves facts, first-time setup skips its memory step, and the Memory setting shows that memory is disabled by your admin. Facts a member saved earlier stay on their computer, the member can still review and delete them, and Claude uses them again if you turn the switch back on. When Claude recalls saved facts for a session, those facts are sent to Anthropic as part of that session’s conversation and handled like the rest of the conversation (see How Claude Science works with your data). The Capabilities > Memory setting in claude.ai Organization settings doesn’t control memory in Claude Science.How other admin settings apply to Claude Science
In the tables below, each setting is named by its page in claude.ai Organization settings and, where it has one, its label there (for example, Capabilities > Web search). Apart from the Enable for your organization toggle, the controls on the Claude Science page itself are described under Organization settings. The status column in each table shows one of four values:- Supported in Claude Science: you can govern this for Claude Science, through the claude.ai setting itself or through the named control on the Claude Science page.
- Partially supported in Claude Science: you can govern only part of this for Claude Science through either place, and the note says which part.
- Not available in Claude Science: the setting doesn’t cover Claude Science, and Claude Science has no equivalent control.
- Not applicable in Claude Science: Claude Science has nothing for the setting to govern.