Most controls on this page require the Owner role in your Claude organization; the permissions table below lists which actions a channel manager or a channel member can take.
Control who can invoke Claude Tag
In channels where the app has been added, an @-mention guarantees a response; Claude may also respond to a message that doesn’t mention it when it judges a reply is warranted, and once a thread is active it follows replies in that thread. By default, anyone in such a channel can address it. A single toggle narrows that to people in your Claude organization.Restrict who can use Claude
Open Manage on the Slack entry under Where Claude Tag works atclaude.ai/admin-settings/claude-tag. The dialog shows a toggle that controls who in your Slack workspace can use Claude at all; its label depends on your plan. You must be an Owner of your Claude organization to change it.
The toggle applies to channels and DMs alike.
You may see the earlier three-option Members dropdown instead of the toggle. The dialog keeps the dropdown while your organization’s stored choice matches neither toggle state. That happens for an Enterprise organization that previously chose Open to any organization member (now marked deprecated), and for a Team organization still restricted by role from an earlier Enterprise plan. Switch to one of the toggle’s two states. The dropdown is then replaced by the toggle, and the deprecated option is no longer offered.
Restrict by role on Enterprise
Role restriction requires an Enterprise plan. Team plans don’t have role-level control; turning on Restrict to your organization is the only restriction available there. Restricting by role spans three console pages.- On
claude.ai/admin-settings/claude-tag, turn on Restrict to roles with Claude Tag access. - On
claude.ai/admin-settings/groups, create groups and add the relevant members. - On
claude.ai/admin-settings/roles, create a custom role with the Claude Tag in Slack capability turned on or off, and choose which groups hold the role in the role editor.
- The toggle gates the capability. The Claude Tag in Slack capability on a role has no effect until Restrict to roles with Claude Tag access is on. While the toggle is off, every member can use Claude regardless of what their role grants.
- Built-in roles always grant access. Every built-in role, including User, Owner, and Primary owner, grants Claude Tag in Slack automatically, so the restriction only blocks members on a custom role that doesn’t grant it.
- Any grant wins. A member in more than one group keeps access if any of their roles grants it.
- @-mentions and DMs get a private notice. Claude doesn’t act on the request. The member sees a notice only they can see, saying their role doesn’t allow Claude Tag and to ask their admin for access.
- Automatic replies skip them. In channels where Claude responds without being tagged, a restricted member’s messages never trigger a response.
- Their thread replies aren’t read. In a thread an allowed member started, a restricted member’s replies don’t reach Claude as content. Claude sees that a message arrived, but the message body is withheld.
Control where Claude Tag operates
The restriction toggle decides who can use Claude. The controls in this section decide where it works at all, from one channel up to a workspace, and which generation answers in each scope (a scope is a channel, a workspace, or your whole organization).Quiet or remove Claude Tag
Six ways to stop Claude Tag from responding, ordered from quietest to most complete:- Ask it to stay quiet. Saying “stay quiet in this thread unless tagged” stops Claude following an active thread.
- Remove it from the channel. Run
/remove @Claude. It can no longer read or post there. - Set the scope’s Claude Tag version to Off. Claude stops responding in that scope even if someone invites it back; an @-mention gets a disabled notice instead of a reply. The control is on the scope’s panel at
claude.ai/admin-settings/claude-tag, and only an Owner can change it. - Detach the scope. The channel loses its elevated access and falls back to inherited baselines.
- Delete the bundle. This revokes its credentials everywhere it was attached (the credentials are removed; memory, routines, and transcripts are not). Running sessions may keep a revoked credential for a short window before the change propagates.
- Uninstall the app. This removes Claude from the workspace entirely.
claude.ai/admin-settings/claude-tag rather than removal alone.
Limit Claude Tag to specific channels
To let Claude respond only in channels you choose, for example during a pilot confined to one channel, turn the version setting Off everywhere and switch the chosen channels back to New. Both changes happen in the Claude Tag’s access section atclaude.ai/admin-settings/claude-tag. DMs, guest channels, and shared channels need more than the version setting; each gets its own treatment after the steps.
Off silences the earlier Claude in Slack too. If you’re in the middle of migrating from the earlier app, decide which scopes stay on Legacy before you start; the earlier app keeps answering in those channels.
1
Turn Claude Tag off everywhere
Set the Claude Tag version on Default Slack access to Off. Then set any workspace or channel scope whose version is something other than Inherit to Off or Inherit too, leaving alone the scopes you’re keeping on Legacy.
2
Switch the chosen channels back on
Set each chosen channel’s version to New. A channel’s own setting wins over the Off above it, so Claude responds in the chosen channels and nowhere else. Channels Claude was added to already appear in the Claude Tag’s access section, and the version control is on each channel scope’s panel; use Search channels to find each one. For a channel that isn’t listed, create a scope with Add channel as described in Attach to a channel.
@Claude in that channel gets a notice that Claude is disabled in the channel, not a reply.
DMs, guest channels, and shared channels sit outside the version setting:
- DMs. The version setting doesn’t cover them. To close those off too, turn off Allow direct messages.
- Guest channels. By default Claude is off in any channel that includes a Slack guest. If a chosen channel has guests, also set Allow Claude to work in channels with guests to Allow or Channel only on its scope.
- Shared channels. A channel shared across workspaces in your Enterprise Grid takes its settings from Default Slack access only, and Claude doesn’t operate in Slack Connect channels at all; neither can serve as a chosen channel.
Block or auto-join channels by name
Channel name rules steer where Claude works by channel name instead of channel by channel. The rules sit in the Advanced section of the Default Slack access panel and of each workspace scope’s panel atclaude.ai/admin-settings/claude-tag, as two pattern lists:
- Blocked channel patterns: Claude won’t read or respond in a channel whose name matches, even if someone invites it there. When it’s added to such a channel or @-mentioned in one, it posts a notice that an admin has blocked it there, and otherwise stays silent.
- Auto-join channel patterns: Claude joins a public channel whose name matches when the channel is created or renamed. Private channels still need an invite. To add Claude to an existing channel, invite it as usual.
* matches any run of characters and ? matches exactly one. inc-* matches every channel whose name starts with inc-, and *-confidential-* matches any name containing -confidential-. Each list holds up to 50 patterns of up to 80 characters.
A channel that matches a blocked pattern stays off-limits even when it also matches an auto-join pattern. Patterns on Default Slack access apply in every connected workspace. A workspace scope can add its own patterns but can’t remove the organization’s.
Restrict guest channels
By default, Claude is disabled in any channel that includes a Slack guest. The Allow Claude to work in channels with guests setting changes that per scope. It’s atclaude.ai/admin-settings/claude-tag, on the Slack tab under Claude Tag’s access, in the scope’s collapsed Advanced section, and it has three values:
A channel without its own value shows Inherit and takes the value from its workspace, or from Default Slack access. Changing this setting requires an organization owner. The setting applies to every guest channel the scope covers; to open one channel rather than a whole workspace, set it on the channel’s own scope.
Under every value, guests in the channel can read what Claude posts there. In any channel that includes a guest, even under Allow, Claude won’t search the workspace, look up people or channels, or read channels other than the one it’s in, because the results could include content the guests can’t see in Slack. That is the same reason Claude doesn’t search private channels. To do any of that, ask from a channel without guests.
How Channel only works
Channel only lets a team keep using Claude in a channel shared with contractors, clients, or agency partners without exposing the rest of the organization’s setup to that conversation. While a guest is in the channel, Claude keeps what is set on the channel itself and drops what it would inherit:- No access bundles from the workspace or from Default Slack access. A bundle attached directly to this channel’s scope still applies, with its connections, instructions, and plugins, so attach to a guest channel only what you’re comfortable having used in front of guests.
- No repositories, including any in a bundle attached to the channel, and no connectors set directly on the channel.
- No instructions set on the workspace or the organization. Instructions set on the channel itself still apply.
- No memory, including this channel’s own, and no skills.
@Claude or by replying in a thread Claude started after a guest was in the channel, and Claude answers them. In a thread Claude began before the first guest joined, Claude stops replying while a guest is present, and a guest who writes there gets the same notice as under Restrict; start a new thread instead. While a guest is present, Claude replies only to mentions and to threads it’s already part of; it doesn’t pick up other channel messages on its own, even where Respond automatically is on. A guest can’t approve a tool or permission request, or restart, mute, fork, or stop the session. If a guest clicks approve, nothing is granted and a workspace member has to ask Claude again.
Treat a channel’s instructions, and the instructions in any bundle attached to the channel, as visible to everyone in that channel, including guests. Under Channel only they shape replies that guests read and take part in.
Channel only takes effect where the New version answers. On a scope where Legacy answers, a channel that includes a guest is treated as Restrict.
Externally shared channels
Claude doesn’t operate in Slack Connect channels, the ones shared with another company. It’s off in those channels regardless of scope or bundle, and this isn’t configurable.Channels shared across workspaces in your Enterprise Grid
What happens in a channel shared across more than one workspace inside your Enterprise Grid depends on whether every workspace in it is connected to the same Claude organization. When the workspaces all belong to your one Claude organization, Claude replies in the channel, but only with the access and settings on your organization’s Default Slack access scope. Bundles, instructions, and memory set on a workspace or on that channel don’t reach it. Claude posts a notice in the thread explaining this, about once a month per channel at most rather than on every reply. Where guest access is Restrict or Channel only, the guest check still runs first and can refuse the reply. When the workspaces belong to different Claude organizations, each with its own settings and plan, Claude won’t reply and posts a refusal message instead. There is no per-channel override for either case.Migrate from the earlier Claude in Slack
If your organization used the earlier Claude in Slack app, you choose which generation answers@Claude per scope. The control is the Claude Tag version setting on each workspace or channel scope at claude.ai/admin-settings/claude-tag, with the choices Off, Legacy, New, and Inherit, plus the Claude Tag version row on the Default Slack access scope above them.
Both generations answer through the same @Claude app, so Off turns off both. To opt out of Claude Tag but keep the earlier app answering in a scope, choose Legacy.
Access bundles only apply where the New version answers. The glossary covers how the two differ.
Allow or disable direct messages
The Allow direct messages toggle controls whether members can message Claude directly. When it’s off, Claude is reachable only in channels. The default is on, and you must be an Owner of your Claude organization to change it. Onclaude.ai/admin-settings/claude-tag, the toggle appears in one of two places: directly on the Claude Tag settings page, or in the Manage dialog on the Slack entry under Where Claude Tag works. It’s the same setting in both places, so change it wherever it appears for your organization.
Set spend limits
Spend limits live atclaude.ai/admin-settings/usage/claude-tag, a different page than the main Claude Tag settings. Spend trends and per-channel reports live on a separate analytics page; see Usage analytics below.
A spend limit is a cap on how much of your organization’s usage balance Claude Tag can draw each billing period. Setting a limit doesn’t fund the balance; on a Team plan, fund the usage balance first or Claude won’t respond in channels regardless of the limit.
- Organization-wide limit. Caps total Claude Tag spend across every channel.
- Default spend limit. A default limit applied to each channel that doesn’t have its own.
- Per-channel limits. Set on any channel from its row in the per-channel spend table, in addition to the organization limit. A channel doesn’t need its own scope to take a limit.
- Per-channel spend. How much each channel has spent against its limit in the current billing period, at list price, on the same page.
Usage analytics
Spend trends live atclaude.ai/analytics/claude-tag, the Claude Tag section of the Analytics dashboard. It shows total and projected month-end spend for the period you pick, spend by channel with a CSV export, DM versus channel spend, spend by kind of work, and any promotional credit, as billed after your discount. Anyone with permission to view your organization’s Analytics dashboard can open it; it has no controls, so use the usage page to change a limit. The two pages link to each other.
Delegate channel setup to channel managers
A channel manager is a member of your Claude organization who can set up Claude in specific channels without the Owner role. Channel managers are available on the Enterprise plan, and you must be an Owner to add or remove them. You name channel managers one channel at a time. For that channel, a channel manager adds repositories and credentials, sets the default model, and edits channel instructions. Every other setting atclaude.ai/admin-settings/claude-tag stays with Owners.
What a channel manager can do on the Configure page
A channel manager has to be a member of the channel in Slack. In a channel you assigned to them, they see a Channel manager settings section on the channel’s Configure page, reached from the Configure link in any Claude reply. Other members see the same values read-only.
When a channel manager adds a credential, Claude also allows the host that credential uses. Channel managers can’t change the bundle’s domains or rules in any other way. Credentials that use Claude’s own identity (mutual TLS, AWS or GCP service identity, and IAP) stay Owner-only: a channel manager can’t add, change, or rotate one, but can delete one from the channel’s bundle, including one an Owner added. If that happens, Claude loses access to that service until an Owner adds the credential back.
If you detach the channel’s own bundle from the channel, its channel managers can’t save settings for the channel; they see an error saying the channel’s configuration was suspended by an administrator. They don’t get a new bundle. Attach the bundle again to restore their access.
A channel manager can edit channel instructions even when the scope’s Channel member edits setting is Block.
Channel managers see their assigned channels at
claude.ai/admin-settings/claude-tag; organization and workspace settings are read-only for them. Tell them when you add them.
Add a channel manager
Channel managers are built on custom roles. When you add the first manager to a channel, you create a custom role for it, named Channel managers plus the channel’s name and ID, with the Claude Tag channel setup permission. A custom role works only for members on the Custom roles access level, so the last step below checks each manager’s level.1
Open the channel's panel
At
claude.ai/admin-settings/claude-tag, select the channel’s row on the Slack tab under Claude Tag’s access. The channel must be a public or private channel. If it isn’t listed, add Claude to the channel in Slack first.2
Add people or a group
In the Channel managers section, select Add channel managers who can add connections and repos to this channel. Select Add users to add people, which also creates a group named after the channel, or Add groups to add a group from
claude.ai/admin-settings/groups. The same group can manage several channels.3
Check each manager's access level
When you add a member on the User or Claude Code user level, you move them to the Custom roles level in the same step; if they already hold other custom roles, you confirm the move first. For a member on any other level, you see Not in effect until you change their level on the Members page. Adding a group changes nobody’s level; group members who aren’t on the Custom roles level show Not in effect too.If your identity provider manages access levels, you can’t change a level on the Members page, and the move doesn’t happen. Put the channel managers in an identity provider group and map that group to the Custom roles level instead. If you turn on identity provider management after adding channel managers, the next sync sets every member’s level from your group mappings, so managers you moved by hand show Not in effect until a mapped group covers them. The role and its group are kept; you don’t need to add the managers again.
Remove a channel manager
To remove a channel manager, open the same Channel managers section on the channel’s panel. Remove a member you added directly, or detach a group you added. The member keeps their access level and any other custom roles. In the channel, they go back to seeing the Configure page’s values read-only, like any other member.Verify a channel manager’s access
The Channel managers section on the channel’s panel shows each manager’s status. A member whose access level doesn’t support the role appears as Not in effect; the role works only on the Custom roles access level, so change the member’s level on the Members page to put it into effect. An active manager sees the Channel manager settings section on the channel’s Configure page, so asking them to open that page confirms the setup.Audit channel manager activity
Channel manager activity is recorded in your organization’s audit log, which you read through the Compliance API. The log records:- Role channel assignments. When a channel is assigned to a channel manager role or removed from it, with the role and the number of channels before and after.
- Credential changes. Each credential a channel manager creates, updates, rotates, or deletes, with the Slack workspace and channel it was for and the roles that granted the permission, so you can tell a channel manager’s change from an Owner’s. Secrets are never included.
- Configure page changes. Which settings a channel manager saved from the Configure page, such as the default model, repositories, or channel instructions. The log records which fields changed, not the values entered.
claude.ai/admin-settings/claude-tag/audit doesn’t list these events; it covers scheduled work, memory, and network events.
Permissions by role
Creating bundles, binding them to scopes, and pairing workspaces need an Owner. A channel manager configures only the channels assigned to them. Everything else happens inside the channel and is open to its members. The table lists each action and who can take it.
Scheduled jobs run with the channel’s credentials, so a member creating one can’t reach anything the channel itself can’t.
Controls that aren’t available
These are controls an admin might look for that Claude Tag doesn’t have.- Third-party deployment. Sessions run on Anthropic’s first-party infrastructure; Claude Tag isn’t available through third-party deployments.
- Renaming or rebranding the app. The Claude app’s name, @-handle, and avatar in Slack are fixed; there is no per-workspace rename setting.
- Per-user spend caps on channel work. Spend limits apply at the organization and channel level. There’s no way to cap what one member can spend in channels; DM usage bills to that member’s own seat and follows the seat’s usual limits.
- Per-channel responder allowlist. The restriction toggle governs who can invoke Claude across the workspace; you can’t narrow it to a list of people for one channel only.
- An open-internet switch in Claude Tag settings. A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner adds that hostname on a bundle’s Domains tab; for broad web access, they pin an environment whose network access level is Full access on the scope. Allow-all egress, a
*entry on the Domains tab, is off by default and enabled per organization by Anthropic. - A web search toggle for channels. No setting turns web search off for channel sessions; the web search capability setting in claude.ai admin settings governs claude.ai chat, not channels. Web search runs on Anthropic’s servers rather than from the channel sandbox, so Domains entries and egress settings don’t govern it, and a search opens no new path out of the sandbox; search requests travel to Anthropic the same way the session’s model traffic already does. See Web search vs. network requests.
- Read-scope confinement. Claude can search public channels by keyword the same way any Slack user can; it can’t read a channel’s full history unless it’s been added there. There’s no setting to disable workspace search, and no setting to enable it in channels that include guests, where search is unavailable.
- Session length enforcement. Your organization’s Slack session-length policy is not enforced on this surface.
Related resources
- Configure per-channel access: change the scopes these controls apply to
- How agent identity works: the model these controls operate on
- Security and data handling: what these controls don’t cover (data flow, retention, where credentials are stored)