How scopes inherit
Bundles stack downward. A channel gets whatever is attached at Default Slack access, plus its workspace, plus anything attached to the channel itself.
The same stacking applies in reverse. Detaching a bundle from a channel removes only that channel’s additions, and bundles attached at the workspace or Default Slack access still apply there.
Memory is also scoped, but differently: there is no organization-wide memory, public-channel entries are shared across the workspace, and a private channel reads workspace memory but writes only to its own store. See What Claude Tag remembers.
DMs run under the user’s own claude.ai account, so bundles attached here apply only in channels. See how DMs work in this model.
Attach the bundle
Attaching binds the bundle to a workspace scope or to a single channel under it. The binding takes full effect in new threads only. A thread already running keeps the skills, plugins, and custom instructions it started with. A connection added after a thread started still works there if you ask Claude to use the service by name, but Claude doesn’t announce it, so test with a new top-level thread after attaching a bundle.Attach to a workspace
Each paired workspace already has a scope; bind a bundle in the scope’s Access bundles section. On the Access bundles page in the left navigation, each bundle’s card shows how many places it’s used in. To see which scopes those are, open the bundle’s Manage dialog and hover over the usage count in its footer. To add another workspace, pair it first.Attach to a channel
Channels Claude was added to appear on the Slack tab automatically, each as a scope under its workspace. To give one of these channels access beyond the workspace baseline, select its row and bind bundles in the scope’s Access bundles section. A channel row shows the name an admin gave the scope, the channel’s name in Slack, or the raw channel ID. To find a channel, use the Search channels field. It matches channel names and channel IDs (pasting a channel link copied from Slack also works), and searching a workspace’s name shows that workspace’s channels. To bind one bundle to several channels in one pass, open the bundle from a scope’s Access bundles section on the Slack tab and select Add to channels. The dialog lists channel scopes grouped by workspace, with a search field and a checkbox per channel. Check the channels you want and select Add. The bundle binds to each checked channel, and channels it’s already bound to directly are marked Already added. A channel that doesn’t appear in the list yet needs a scope created for it:- On
claude.ai/admin-settings/claude-tag, find the workspace on the Slack tab under Claude Tag’s access and select Add channel. - Paste the channel’s ID into the Channel ID field. Channel IDs start with
C, or withGfor some older private channels. Copy the ID from the channel’s details in Slack. - Save, then bind bundles in the new scope’s Access bundles section, the same as for a workspace.
Attach a single repository or connector
To grant a single repository or connector without opening a bundle first, use the Repositories and Connectors sections on the scope’s own panel and select the + button (Add repo or Add connector). When you save the repository or finish connecting, the item is attached to that scope. The grant still lives in a bundle. The item is added to the bundle that was created for that scope, or to the scope’s only bundle when that bundle is bound nowhere else, and otherwise a new bundle is created for the scope. If the bundle created for the scope is now bound to other scopes too, the add is refused with a message telling you to manage that bundle’s repositories and connectors in Access bundles instead, so adding here never widens another scope’s access.Precedence when bundles overlap
A channel sees the union of every bundle bound at the channel itself, its workspace, and Default Slack access. Narrower scopes don’t replace wider ones; they add to them. When two bundles in the resolved set carry rules for the same host, the rule from the narrower scope wins. Within that union, fixed rules decide which credential and which instructions apply.Which credential wins
When two bundles each carry a credential for the same host:- The credential from the narrowest scope is used: channel beats workspace, which beats Default Slack access.
- Within the same scope, the order isn’t admin-configurable. Avoid binding overlapping credentials at the same scope; if you can’t predict which key acts, neither can a security review.
- There is no fallback. If the winning credential gets a
401or403, Claude does not retry with the next one.
Repositories and plugins
Repository grants and plugins from every bound bundle are combined as a union; a channel gets every repo and plugin from any bundle in its chain. The Access summary section, shown when a scope you select on the Slack tab has any resolved connections or repositories, lists them with the bundle each one comes from. Plugins aren’t listed there. The scope’s Plugins section shows only the plugins attached at that scope, and plugins inherited from wider scopes and from bundles apply without appearing in it.Custom instructions
Per-scope custom instructions are concatenated, Default Slack access first, then workspace, then channel. A channel’s instructions add to, rather than replace, what’s set above it.Instruction layers
Three kinds of standing instruction can apply in a channel, written by different people:
Channel members can shape how Claude responds in their channel through memory, but they can’t change which credentials or repositories it has; that’s bundle configuration. See who controls what for the full split.
Custom instructions are read ahead of the conversation and take priority in practice, but they’re guidance, not an enforced guardrail. Don’t rely on them to block actions; use access controls for that.
Add custom instructions
Each scope can carry custom instructions, which are standing guidance Claude reads in every session there, like team conventions or where to file tickets. The Custom instructions field is on the scope’s panel, shown when you select the scope on the Slack tab in admin settings. Channel members reach the same field for the channel scope through the Configure page, linked in the footer of any Claude reply in the channel, without going through admin settings. Both entry points write the same instructions, so a change from either place is visible in the other. The field is plain text, inserted as written; there is no include or template syntax, and{{include:...}} is passed through literally. To give Claude a repository’s CLAUDE.md, grant the repository and name it in the request; its CLAUDE.md loads after the clone completes.
Restrict who can set channel instructions
By default, anyone in a channel who is also a member of your Claude organization can edit that channel’s instructions from the Configure link in Claude’s reply footer. The Channel member edits setting in a scope’s Advanced settings controls this.
A chain of scopes that all inherit resolves to Allow. Set Block at the workspace or Default Slack access scope to lock channel instructions across every channel beneath it. A channel manager can still edit instructions in a channel assigned to them when Block is set.
Verify the bundle is live
- The bundle card’s usage count includes the new scope. To see it named, open the bundle’s Manage dialog and hover over the count in its footer.
- A test task in the pilot channel uses the bundle’s connections, and the action appears in the connected service’s audit log under your service account.
Related resources
- Getting started for users: what your team does once the bundle is live
- Restrict where Claude Tag operates: narrow where it responds