claude.ai/admin-settings/claude-tag says when they turn on for your organization. A channel also keeps working with the connections an admin attached to it, as described in how agent identity works.
Where your connectors apply
Claude can use your personal connectors for the requests you make in a channel.- Approval: Claude asks you before it starts using your connectors in a channel.
- Access: Claude works with your permissions and reaches only what your account can reach.
- Attribution: Claude records what it does under your name.
- Review: Before results post to the channel, you can review every result, or only the ones a sensitive-content check flags.
- You ask in a channel. When your task needs one of your own tools, Claude can use your connector for it. The channel also uses the connections an admin attached to it, and everyone who asks there gets the same access.
- Someone else asks in a channel. Your connectors serve only you. Their request doesn’t control or use your connectors, even in a shared channel.
- Claude starts work on its own. Routines and other work Claude starts on its own in a channel use the channel’s connections, never your connectors.
- You ask in a direct message (DM). Your connectors apply on their own, because a DM runs on your own claude.ai account.
Control connector use
Approve connector use
By design, Claude asks before it starts using your connectors in a channel. The first time a task calls for one of your connectors, Claude shows you a prompt in the thread that only you can see, with three choices:- Allow starts the work in auto mode. Claude uses your connectors as the task needs them and checks with you before posting anything that looks sensitive.
- Allow with review starts the work and shows you every result to approve before it posts to the channel.
- Don’t allow declines this request, and Claude doesn’t use your connectors. A later request can prompt you again.
Review results before posting
Claude can hold a result and show it to you before anything posts to the channel. When you chose Allow with review, Claude holds every result. When you chose Allow, Claude holds a result when the content looks sensitive and posts the rest directly. Before a result posts directly, Claude checks it for private or sensitive content and holds anything the check flags so you can review it first. The check looks for content such as:- Credentials and secret keys
- Personal identifiers
- Compensation, HR, and performance records
- Personnel changes, including layoffs, offboarding, hiring, and candidates
- Customer, deal, and other commercial information
- Privileged legal material
- Company strategy, unannounced plans, and in-flight projects
- Protected-class information
- Medical and health information
- Security incidents
Admin controls for personal connectors
Admins manage personal connectors for the whole organization in the Personal connectors section atclaude.ai/admin-settings/claude-tag. The settings there apply to every workspace and channel.
- Require human review of every message. On the Enterprise plan, an admin can turn this switch on so that Claude holds every result for the requester’s review, not only the ones the sensitive-content check flags. With it on, the prompt no longer offers Allow and the Home tab no longer offers Auto mode. With it off, and on the Team plan, which has no such switch, each member’s own choice decides which results Claude holds.
- Sensitive information requiring review. Shows examples of what the check looks for. An Owner can add topics of their own under Additional topics, for example “Board meeting notes are confidential”, and Claude holds results that touch them.
Stop connector use
To stop a task that’s using your connectors, select Stop under the message in the task’s thread where Claude says it’s going to use your connectors. Only you can see the Stop button.How Claude protects your connectors
Other people can’t use your connectors. Requests other people make to Claude in your task’s thread run with the connections an admin attached to the channel, not with your connectors. While Claude works on your connector task, it is designed to take direction from you. Other people’s messages in the thread reach Claude as information about the task, not as instructions. A message that tells Claude to change course or share what it found can’t use your connectors, and Claude is designed not to let it redirect your task. Claude treats anything else it reads while it works the same way. A web page it visits, a comment on a GitHub pull request, or a Slack conversation you ask it to summarize can all contain text written to look like instructions for Claude, a technique called prompt injection. Claude is designed to treat what it reads as material to weigh rather than commands to follow.What other people in the channel see
Results stay visible in the channel. What Claude posts back to a channel thread is readable by everyone there, like any other work Claude does in a channel. Claude’s detailed work on a task you approved lives in a session only you can open. The work runs with your permissions and is recorded under your name.Related resources
- How agent identity works: whose identity and access Claude uses in channels and DMs
- Connectors: set up and manage connectors on your claude.ai account
- Get started: hand Claude your first task in a channel