Skip to main content
In channels, Claude Tag responds only where it’s been added and addressed, and the controls on this page narrow that further. One-to-one DMs are a separate surface. A DM from a member who has connected a Claude account runs on that member’s own account; see how DMs differ from channels. A DM from a member who hasn’t can bill to your organization. In a group DM, the work bills to your organization.
Most controls on this page require the Owner role in your Claude organization; the permissions table lists which actions a channel manager or a channel member can take. On the Enterprise plan, an Owner can delegate many of these controls through the Claude Tag Admin permission.

Control who can invoke Claude Tag

In channels where the app has been added, an @-mention guarantees a response; Claude may also respond to a message that doesn’t mention it when it judges a reply is warranted, and once a thread is active it follows replies in that thread. By default, anyone in such a channel can address it. A single toggle narrows that to people in your Claude organization.

Restrict who can use Claude

Go to Claude’s access > Channels > Slack and open the Advanced tab. Under Access, a toggle controls who in your Slack workspace can use Claude at all; its label depends on your plan. You must be an Owner of your Claude organization to change it. The toggle applies to channels and DMs alike. While the toggle is off, a DM from a member who hasn’t connected a Claude account can bill to your organization.
You may see the earlier three-option Members dropdown instead of the toggle. The Access group keeps the dropdown while your organization’s stored choice matches neither toggle state. That happens for an Enterprise organization that previously chose Open to any organization member (now marked deprecated), and for a Team organization still restricted by role from an earlier Enterprise plan. Switch to one of the toggle’s two states. The dropdown is then replaced by the toggle, and the deprecated option is no longer offered.

Restrict by role on Enterprise

Role restriction requires an Enterprise plan. Team plans don’t have role-level control; turning on Restrict to your organization is the only restriction available there. Restricting by role spans three console pages.
  1. On the Slack page’s Advanced tab, turn on Restrict to roles with Claude Tag access under Access.
  2. On claude.ai/admin-settings/groups, create groups and add the relevant members.
  3. On claude.ai/admin-settings/roles, create a custom role with the Claude Tag in Slack capability turned on or off, and choose which groups hold the role in the role editor.
Three rules govern how role restrictions resolve.
  • The toggle gates the capability. The Claude Tag in Slack capability on a role has no effect until Restrict to roles with Claude Tag access is on. While the toggle is off, every member can use Claude regardless of what their role grants.
  • Built-in roles always grant access. Every built-in role, including User, Owner, and Primary owner, grants Claude Tag in Slack automatically, so the restriction only blocks members on a custom role that doesn’t grant it.
  • Any grant wins. A member in more than one group keeps access if any of their roles grants it.
A member whose roles don’t grant the capability is excluded everywhere Claude works, in three ways:
  • @-mentions and DMs get a private notice. Claude doesn’t act on the request. The member sees a notice only they can see, saying their role doesn’t allow Claude Tag and to ask their admin for access.
  • Automatic replies skip them. In channels where Claude responds without being tagged, a restricted member’s messages never trigger a response.
  • Their thread replies aren’t treated as requests. In a thread an allowed member started, a restricted member’s replies reach Claude marked as coming from someone who can’t use it. Claude can read them as context and doesn’t act on them.
On a Slack Enterprise Grid, each workspace follows the access settings of the Claude organization it’s paired to. For a channel shared between workspaces that are paired to different organizations, see Channels shared across workspaces in your Enterprise Grid. On Enterprise plans, if your organization belongs to a parent enterprise organization, you see one more toggle in the same Access group on the Slack page’s Advanced tab, Restrict to your verified domains. It needs an Owner to change. The check uses the enterprise’s verified domains, which every organization under the enterprise shares. When the toggle is on, a Slack user whose profile email isn’t on one of the enterprise’s verified domains can’t link a Claude account to this organization; the sign-in is refused.
Turning this on in any one organization also stops Slack users on a verified domain from linking a Claude account to any organization outside the enterprise.

Control where Claude Tag operates

The restriction toggle decides who can use Claude. The controls in this section decide where it works at all, from one channel up to a workspace, and which generation answers in each scope (a scope is a channel, a workspace, or your whole organization). Each scope has its own page under Claude’s access > Channels, and the Slack page there holds the settings for your whole organization. If the Slack page’s General tab shows a Respond in channels switch rather than Respond in all channels, your organization has a single on-or-off switch in place of the per-scope switches and version settings. The other controls in this section work the same way either way.

Quiet or remove Claude Tag

Six ways to stop Claude Tag from responding, ordered from quietest to most complete:
  1. Ask it to stay quiet. Saying “stay quiet in this thread unless tagged” stops Claude following an active thread.
  2. Remove it from the channel. Run /remove @Claude. It can no longer read or post there.
  3. Turn off the scope’s switch.
    • Stop Claude in one workspace or channel: open the workspace’s or channel’s page on the Channels tab and turn off the Enable Claude Tag in this workspace or Enable Claude Tag in this channel switch at the top of its General tab. Claude stops responding in that scope even if someone invites it back; an @-mention gets a disabled notice instead of a reply. Only an Owner or a Claude Tag admin can change it.
    • Stop Claude in every channel: turn off the Respond in all channels switch at the top of the Slack page’s General tab. Claude stops responding in every channel except in workspaces and channels whose own switch is on. If the Slack page shows Respond in channels instead, turning it off stops Claude in every channel of every connected workspace.
  4. Remove the channel’s scope. If the ⋯ menu on the channel’s page lists Remove this scope, choose it. Claude deletes the channel’s sessions, memory, routines, and published artifacts; see what each action deletes. Where the channel’s workspace has its own setting on, or has no setting of its own and the Slack page’s setting is on, Claude keeps answering in the channel with the access it inherits from its workspace. To stop it answering in that case, run /remove @Claude first.
  5. Delete the bundle. On the bundle’s page, choose Delete bundle from its menu. This revokes its credentials everywhere it applied (the credentials are removed; memory, routines, and transcripts are not). Running sessions may keep a revoked credential for a short window before the change propagates. An Owner or a Claude Tag admin can delete a bundle, except that only an Owner can delete one a channel rule names.
  6. Uninstall the app. This removes Claude from the workspace and deletes the workspace’s Claude data the same way disconnecting the workspace does.
To keep Claude out of channels by name ahead of time, add a blocked channel pattern instead. Steps 1–3 do not delete any data. Removing Claude from a channel stops it responding there; the channel’s memory and routines stay on record, and re-adding Claude restores them. Steps 4 through 6, and disconnecting the workspace, each delete something different:
  • Remove the channel’s scope (step 4): deletes the channel’s sessions, memory, routines, and published artifacts; see what each action deletes.
  • Delete the bundle (step 5): removes the credentials in that bundle. Memory, routines, and session transcripts stay.
  • Uninstall the app (step 6): Anthropic deletes the workspace’s Claude data, the same set as disconnecting the workspace, plus the app’s installation credential; see what each action deletes.
  • Disconnect the workspace at claude.ai/admin-settings/claude-tag: Anthropic deletes the workspace’s sessions and transcripts, memory, routines and artifacts, scopes, and members’ account links, and the app stays installed so a workspace admin can pair again; see what each action deletes.
Bundles belong to your organization, not to a workspace, so uninstalling or disconnecting keeps them; only the places they apply in that workspace go. To delete one channel’s data while Claude stays in the workspace, remove that channel’s scope (step 4) rather than uninstalling.

Limit Claude Tag to specific channels

To let Claude respond only in channels you choose, for example during a pilot confined to one channel, turn off Respond in all channels on the Slack page, then turn on each chosen channel’s Enable Claude Tag in this channel switch. Both pages are on the Channels tab under Claude’s access. One-to-one DMs, guest channels, and shared channels need more than these switches; each gets its own treatment after the steps. These steps need the per-scope switches. If the Slack page shows Respond in channels instead, you can’t limit Claude this way. Use blocked channel patterns to keep it out of specific channels.
Turning Claude off in a scope silences the earlier Claude in Slack there too. If you’re in the middle of migrating from the earlier app, decide which scopes stay on Legacy before you start; the earlier app keeps answering in those channels.
1

Turn Claude Tag off in every channel

Go to Claude’s access > Channels > Slack and turn off the Respond in all channels switch at the top of the General tab.
2

Reset the scopes that override it

Open each workspace’s or channel’s page that has its own setting, except the ones you’re keeping on Legacy. Its switch shows Set for this workspace or Set for this channel underneath. Click the Use inherited setting link beside that line. The scope then follows the off state on the Slack page.
3

Switch each chosen channel back on

On the Channels tab, find the channel with the search field; channels Claude was added to are already listed. If it isn’t listed, set it up as described in Attach to a channel. Open the channel’s page and turn on the Enable Claude Tag in this channel switch at the top of its General tab.A channel’s own setting wins over the off setting above it, so Claude responds in the chosen channels and nowhere else.
If someone invites the app into another channel afterward, Claude stays silent there. Mentioning @Claude in that channel gets a notice that Claude is disabled in the channel, not a reply. One-to-one DMs, guest channels, and shared channels sit outside the per-scope switches: The Enable Claude Tag switch covers group DMs, and a group DM can’t serve as a chosen channel. While the switch that covers a workspace is off, Claude doesn’t answer in that workspace’s group DMs. To control who can use Claude in the allowed channels, turn on the restriction toggle; to cap what a channel spends, set a per-channel spend limit.

Block or auto-join channels by name

Channel name rules steer where Claude works by channel name instead of channel by channel. The rules sit on the Advanced tab of the Slack page and of each workspace’s page under Claude’s access > Channels, in the Channels group, as a Blocked channel patterns list and an Auto-join channels table:
  • Blocked channel patterns: Claude won’t read or respond in a channel whose name matches, even if someone invites it there. When it’s added to such a channel or @-mentioned in one, it posts a notice that an admin has blocked it there, and otherwise stays silent.
  • Auto-join channels: Claude joins a public channel whose name matches one of its patterns when the channel is created or renamed. Private channels still need an invite. To add Claude to an existing channel, invite it as usual.
Each row of the Auto-join channels table is one pattern, added with Add pattern. A row can also carry bundles, which attach in every matching channel Claude is in; a row with no bundles is marked Auto-join only, and Claude joins matching channels whether or not a row carries bundles. A channel rule added with Add a channel rule… on the Channels tab shows up as a row here too. Editing the patterns or the bundles on a row needs an Owner of your Claude organization. Removing a pattern row also detaches the row’s bundles. A row marked Not auto-joined shows a pattern that still has bundles attached but that the auto-join list no longer carries. Claude joins no new channels for it, but its bundles still attach in matching channels Claude is already in; remove the bundles from the row to end that. A pattern is written in lowercase, like Slack channel names, plus two wildcards: * matches any run of characters and ? matches exactly one. inc-* matches every channel whose name starts with inc-, and *-confidential-* matches any name containing -confidential-. The blocked list and the auto-join table each hold up to 50 patterns of up to 80 characters. A channel that matches a blocked pattern stays off-limits even when it also matches an auto-join pattern. Patterns on the Slack page apply in every connected workspace. A workspace scope can add its own patterns but can’t remove the organization’s. About once a week, Claude sends the person who connected the workspace a direct message suggesting public channels to add it to. To stop those messages, select Stop these suggestions in any of them.

Restrict guest channels

By default, Claude is disabled in any channel that includes a Slack guest. You can change this default per scope with the How should Claude work in channels with guests setting. It’s in the Access group on the Advanced tab of the Slack page and of each workspace’s and channel’s page under Claude’s access > Channels. The setting has three values: A channel without its own value shows Inherit and takes the value from its workspace, or from the Slack page. An Owner or a Claude Tag admin can choose Restrict or Channel only. Only an organization Owner can choose Full access or set a scope back to Inherit. The setting applies to every guest channel the scope covers. To open one channel rather than a whole workspace, set it on the channel’s own page. Under every value, guests in the channel can read what Claude posts there. Under Restrict and Channel only, Claude posts a short notice in the channel when the first guest joins a channel where it had been replying, saying how it responds while guests are present, and another when the last guest leaves, saying it’s back to the channel’s usual setup. Members don’t have to work out from silence or a changed answer that the guest setting took effect. Claude doesn’t post these notices in a channel shared across workspaces. In any channel that includes a guest, even under Full access, Claude won’t search the workspace, look up people or channels, or read channels other than the one it’s in. The results could include content the guests can’t see in Slack, which is also why Claude doesn’t search private channels. To have Claude search, look someone up, or read another channel, ask from a channel without guests.

How Channel only works

Use Channel only to keep Claude available in a channel shared with contractors, clients, or agency partners without exposing the rest of the organization’s setup to that conversation. While a guest is in the channel, Claude has:
  • No bundles inherited from the workspace or the organization. A bundle attached directly to the channel still applies.
  • No connections inherited from the workspace or the organization. A connection set directly on the channel still applies.
  • No repositories from the workspace or the organization.
  • No instructions set on the workspace or the organization. Instructions set on the channel itself still apply.
  • No memory, including this channel’s own, and no skills.
  • No environment set on the scope. The session runs on the standard environment, so the setup script, environment variables, and network access level of the environment you chose don’t apply while a guest is present.
Claude decides which access applies when a conversation starts. When no guest is in the channel, new conversations get the same access as under Full access. A conversation that was underway before the first guest joined doesn’t keep its full access. The next message from a workspace member in that thread starts the conversation over with channel-only access. A guest who writes there before a member does gets the same notice as under Restrict. The channel’s Respond automatically setting works the same while a guest is present, and it’s on by default. While it’s on, messages from workspace members that don’t mention Claude still reach it, and Claude may reply to some of them on its own. Outside the threads Claude is part of, a guest’s messages that don’t mention Claude reach it only as context, not as requests. To have Claude reply only to @-mentions and in threads it’s already part of, turn Respond automatically off for that channel. While a guest is present, Claude doesn’t publish artifacts, the web pages hosted on claude.ai. To have Claude publish a page, ask from a channel without guests. A guest can talk to Claude by mentioning @Claude or by replying in a thread Claude is part of, and Claude answers them. A guest can’t approve a tool or permission request, and can’t restart, mute, fork, or stop the session. If a guest clicks approve, nothing is granted. Treat a channel’s instructions, and the instructions in any bundle attached directly to the channel, as visible to everyone in that channel, including guests. Under Channel only, Claude follows them in replies that guests can read and respond to. Channel only takes effect where the New Claude Tag version answers. On a scope where Legacy answers, a channel that includes a guest is treated as Restrict. By default, workspace search covers public channels across the workspace, including ones Claude hasn’t been added to. The Channels Claude can search setting narrows workspace search to channels Claude is in. You set it per scope in the Channels group on the Advanced tab of the Slack page or of a workspace’s or channel’s page under Claude’s access > Channels. Changing it needs an Owner of your Claude organization. The setting has two values: Most organizations can leave this on All public channels. Under Only channels Claude is in, Claude can’t find messages in your other public channels, so its answers can miss context your team expects it to have. On a workspace’s or channel’s page the setting also offers Inherit, which takes the value from the workspace or from the Slack page. The most specific scope that sets a value decides, in this order:
  1. The channel’s own value
  2. The workspace’s value
  3. The value on the Slack page, which is All public channels until you change it
A value on a channel or workspace replaces the value it would inherit, in either direction. In a channel set to All public channels, workspace search covers public channels across the workspace even when the channel’s workspace is set to Only channels Claude is in. Neither value adds private channels to workspace search. In a channel that includes a guest, workspace search is unavailable whichever value applies.

Slack Connect channels

A Slack Connect channel is a channel your Slack workspace shares with another company. Claude doesn’t work in Slack Connect channels, and no setting at claude.ai/admin-settings/claude-tag turns it on there. When someone mentions @Claude in one, Claude posts a notice that it isn’t turned on for Slack Connect channels and doesn’t answer. If a channel Claude already works in becomes a Slack Connect channel, Claude stops answering there, including in threads it was already part of.

Channels shared across workspaces in your Enterprise Grid

What happens in a channel shared across more than one workspace inside your Enterprise Grid depends on whether every workspace in it is connected to the same Claude organization. When the workspaces all belong to your one Claude organization, Claude replies in the channel, but only with the access and settings on your organization’s Slack page. Bundles, instructions, and memory set on a workspace or on that channel don’t reach it. Claude posts a notice in the thread explaining these limits, but not on every reply. Where guest access is at its default Restrict, the guest check still runs first and can refuse the reply. When the workspaces belong to different Claude organizations, each with its own settings and plan, Claude won’t reply and posts a refusal message instead. There is no per-channel override for either case.

Migrate from the earlier Claude in Slack

If your organization used the earlier Claude in Slack app, the Claude Tag version setting on the Advanced tab of each scope’s page chooses which generation answers @Claude there. Bundles only apply where the New version answers. See Turn Claude Tag on or off and set the version for a scope for the values and Migrate from the earlier Claude in Slack for the switch.

Allow or disable direct messages

The Allow direct messages toggle controls whether members can message Claude in a one-to-one DM or in a group DM. When it’s off, Claude is reachable only in channels, and no DM from a member without a Claude account bills to your organization. The default is on, and you must be an Owner of your Claude organization to change it. To change it, go to claude.ai/admin-settings/claude-tag, select Edit on the Direct messages row, and turn Allow direct messages on or off in the dialog. The change saves as soon as you flip the toggle. Edit is unavailable while Enable Claude Tag in Slack, the switch on the same page, is off. Turning off Respond in all channels (or Respond in channels) on the Slack page doesn’t affect direct messages from members who have connected a Claude account. For members who haven’t, see Stop direct messages from members without a Claude account.

Group DMs

A group DM is a Slack direct message among several people. When members add Claude to one, Claude acts with its own service accounts, and the work bills to your organization’s usage balance. Use Claude Tag in a group DM covers what members can do there. A group DM has no scope of its own, so you can’t attach a bundle to one group DM or turn Claude off in one. You control every group DM in a workspace together:
  • Access. Claude works with the bundles, instructions, and repositories on the workspace’s page and on the Slack page.
  • Stop Claude from answering in group DMs. Use either control. No setting covers group DMs alone.
  • Who can ask. If you restrict who can use Claude, the restriction applies in group DMs too. With no restriction, a member who hasn’t connected a Claude account can ask in a group DM, and the limits on one-to-one DMs from those members don’t apply.
  • Spend. The organization-wide spend limit caps group DM work along with channel work, and the Default spend limit applies to each group DM.
  • Version. Where the Legacy Claude Tag version answers for the workspace, Claude doesn’t respond in group DMs.
Who is in a group DM, and how Slack shares it, can change whether Claude answers:
  • A Slack guest is in the group DM. In a workspace outside Enterprise Grid, Claude follows the How should Claude work in channels with guests value on the workspace’s page or on the Slack page. Under the default, Restrict, Claude posts its guest notice instead of an answer. Under Channel only, Claude runs with channel-only access. Under Full access, Claude answers.
  • Someone from another company is in the group DM, through Slack Connect. Claude doesn’t answer, and no setting changes that.
  • On Enterprise Grid, the people in the group DM share no workspace. Claude doesn’t answer.

Direct messages from members without a Claude account

A Slack workspace member who hasn’t connected a Claude account can use Claude in a one-to-one DM for a limited time, billed to your organization’s usage balance. When that member uses Claude in a channel, the work bills to your organization the same way, and the same restriction toggle governs both. Where the conditions in this section aren’t met, Claude doesn’t act on that member’s DM and nothing bills to your organization. The limited time runs once for each member and starts with their first DM that Claude answers on your organization’s bill. A member’s DMs bill to your organization when every one of these is true:
  • The workspace is connected to your organization. The DMs bill the Claude organization the Slack workspace is paired to.
  • Anyone in the workspace can use Claude. The restriction toggle is off, which is its default.
  • Direct messages are allowed. The Allow direct messages toggle is on, which is its default.
  • Claude is on for the workspace. The workspace’s Enable Claude Tag in this workspace switch is on, or Respond in all channels on the Slack page is on when the workspace follows it. If the Slack page has the single Respond in channels switch instead, that switch is on.
  • The member is a full member of the Slack workspace. A Slack guest’s DMs don’t bill to your organization.

Limits on direct messages from members without a Claude account

Claude stops answering a member’s DMs on your organization’s bill when the member reaches any one of three limits. The Default spend limit is the one at claude.ai/admin-settings/usage/claude-tag that applies to each channel without a limit of its own. When it’s below $50, each member’s DMs stop at that amount. When it’s 0, none of these DMs bill to your organization. This usage also counts toward your organization’s spend limit. The usage page’s per-channel breakdown lists channels only, so this usage doesn’t appear in it. Claude checks the limits when each message arrives, so work already running when a limit is reached can finish past it. After a member reaches a limit, their next DM gets a prompt to connect a Claude account, and after connecting, their DMs run on their own Claude account and bill to their own seat.

Access in a direct message from a member without a Claude account

A DM session for a member without a Claude account runs as Claude’s own identity, the way a channel session does. Two facts decide what it can reach:
  • Bundles. The session reaches the same bundles as a channel the member creates in that workspace.
  • Personal connectors. The member has no Claude account, so the session has no personal connectors.

Daily brief offer for members without a Claude account

The first time a member opens Claude’s DM, Claude’s greeting can offer a short brief each morning and a wrap at the end of each day, with Start and No thanks buttons.
  • Start sets up the two scheduled messages, which read Slack only and bill to your organization inside the same limits. If the member’s 7 days haven’t started, they start.
  • No thanks sets up nothing and starts nothing. A message the member sends Claude later starts the 7 days.
  • After the member reaches a limit, they get “Your daily briefs are paused. Connect your Claude account to keep them going.”

Stop direct messages from members without a Claude account

Three controls stop Claude from answering these DMs on your organization’s bill. Each one applies to members who have already started and changes something beyond these DMs. To confirm the change, have a member who hasn’t connected a Claude account send Claude a DM. With Allow direct messages off, Claude answers “Your Claude admin has disabled sending direct messages to Claude.” With either of the other two controls, Claude answers with a prompt to connect a Claude account. In both cases nothing bills to your organization. After you turn a control back on, a member who hasn’t reached a limit can use Claude in DMs again, and their daily briefs resume. The 7 days keep counting while the control is off.

Set spend limits

Spend limits live at claude.ai/admin-settings/usage/claude-tag, a different page than the main Claude Tag settings; see when the usage page is available. Spend trends and per-channel reports live on a separate analytics page; see Usage analytics below. A spend limit is a cap on how much of your organization’s usage balance Claude Tag can draw each billing period. Setting a limit doesn’t fund the balance; on a Team plan, fund the usage balance first or Claude won’t respond in channels regardless of the limit.
  • Organization-wide limit. Caps total Claude Tag spend across every channel.
  • Default spend limit. A default limit applied to each channel that doesn’t have its own.
  • Per-channel limits. Set on any channel from its row in the per-channel spend table, in addition to the organization limit. A channel doesn’t need its own scope to take a limit.
  • Per-channel spend. How much each channel has spent against its limit in the current billing period, at list price, on the same page. Usage covered by a promotional credit isn’t counted here and shows as $0.00. The Spend by channel table at claude.ai/analytics/claude-tag shows list-price spend including covered usage.
Work that would exceed a limit is declined rather than silently truncated. A user blocked by a limit can request more usage from their admin in Slack, and the admin notification names whether the usage balance or the limit caused the block.

Usage analytics

Spend trends live at claude.ai/analytics/claude-tag, the Claude Tag section of the Analytics dashboard, refreshed once a day. It shows total and projected month-end spend for the period you pick, spend by channel with a CSV export, DM versus channel spend, spend by kind of work, and any promotional credit. Billed figures are shown after your discount. Anyone with permission to view your organization’s Analytics dashboard can open it; it has no controls, so use the usage page to change a limit. The two pages link to each other. When the period you pick falls within the current month, the Spend by channel table shows a Billed column and a List price column. Usage covered by a promotional credit shows as $0.00 under Billed and at its list price under List price.

Delegate Claude Tag administration

On the Enterprise plan, the Claude Tag Admin permission lets a member of your Claude organization administer Claude Tag without the Owner role. It’s a permission in custom roles, listed under Product admin in the role editor; an Owner sets it up. To delegate the setup of one channel instead, add a channel manager. A member whose custom role includes the permission is a Claude Tag admin. A Claude Tag admin can:
  • Create and edit bundles, including their credentials, domain entries, and repository grants, and attach bundles to the organization, a workspace, or a channel
  • Edit workspace and channel settings at claude.ai/admin-settings/claude-tag, such as custom instructions and the default model
  • Turn Claude on or off for a workspace or a channel with its Enable Claude Tag switch, or for every channel with the Respond in all channels switch on the Slack page
  • Add and remove channel managers, if the role also sets Identity & Access to Can manage
  • Set up Managed by for a channel, on the Admin tab of the channel’s Configure page
  • Open on-call setup at claude.ai/oncall
  • Set a scope’s How should Claude work in channels with guests setting to Restrict or Channel only; choosing Full access or setting a scope back to Inherit stays with Owners
Some actions stay outside the permission:

Give a member the Claude Tag Admin permission

1

Create a role

Go to Organization settings > Roles, select Add role, and give the role a name.
2

Grant the permission

On the role’s Admin permissions tab, set Claude Tag Admin, under Product admin, to Can manage. Changing the member’s role type to Custom takes them off the built-in Admin role, so if the member is an Admin today, also set User Management to Can manage and Analytics to Can view, both under Organization admin. Leave the Capabilities and Connectors tabs as they are, then select Save.
3

Assign the role through a group

A custom role applies to the members of the groups it’s assigned to. Go to Organization settings > Groups and select Add group. Name the group and pick the new role under Roles. Add the member under Members, then select Add group. To use a group the member is already in, open the role on the Roles page instead and add that group on its Details tab.
4

Change the member's role to Custom

On the Members page, change the member’s role to Custom. Custom roles apply only to members whose role type is Custom. If member roles are managed through your identity provider, make the change in the identity provider instead.
5

Confirm the member's access

The member can now open Claude Tag under Products in Organization settings. If it isn’t listed for them yet, have them refresh the page.

Delegate channel setup to channel managers

A channel manager is a member of your Claude organization who can set up Claude in specific channels without the Owner role. Channel managers are available on the Enterprise plan. An Owner can add or remove them, and so can a Claude Tag admin whose role also sets Identity & Access to Can manage. You name channel managers one channel at a time. For that channel, a channel manager sets the default model, adds repositories, manages credentials and plugins in the channel’s bundle, and edits channel instructions. Every other setting at claude.ai/admin-settings/claude-tag stays with Owners; on the Enterprise plan, an Owner can delegate most of them through the Claude Tag Admin permission. A channel manager is a person. To let the members of another Slack channel write a channel’s instructions, see Manage a channel’s instructions from another channel.

What a channel manager can do on the Configure page

A channel manager has to be a member of the channel in Slack. The channel’s Configure page, which opens on claude.ai from the Configure link in any Claude reply, is split into tabs. In a channel you assigned to them, a channel manager sees the Default model card on the General tab and the repository and access bundle cards on the Tools and access tab. Members without the role don’t see those cards. Owners and Claude Tag admins also see an Admin tab, whose Channel settings card holds some of the channel scope’s settings from admin settings. When a channel manager adds a credential, Claude also allows the host that credential uses. Channel managers can’t change the bundle’s domains or rules in any other way. A channel manager can’t add, change, or rotate credentials that use Claude’s own identity (mutual TLS, AWS or GCP service identity, and IAP), but can delete one from the channel’s bundle, including one an Owner added. If that happens, Claude loses access to that service until an Owner or a Claude Tag admin adds the credential back. If you detach the channel’s own bundle from the channel, its channel managers can’t save settings for the channel; they see an error saying the channel’s configuration was suspended by an administrator. They don’t get a new bundle. Attach the bundle again to restore their access. A channel manager can edit channel instructions even when the scope’s Channel member edits setting is Block. Channel managers see their assigned channels at claude.ai/admin-settings/claude-tag; organization and workspace settings are read-only for them. Tell them when you add them.

Add a channel manager

Channel managers are built on custom roles. When you add the first manager to a channel, you create a custom role for it, named Channel managers plus the channel’s name and ID, with the Claude Tag channel setup permission. A custom role works only for members on the Custom roles access level, so the last step below checks each manager’s level.
1

Open the channel's page

Go to Claude’s access > Channels and open the channel’s page. The channel must be a public or private channel. If it isn’t listed, add Claude to the channel in Slack first.
2

Add people or a group

In the page’s header, select Add managers. Search for people and groups, and select each one to add. People you add join the channel’s default group. A group you pick comes from claude.ai/admin-settings/groups, and the same group can manage several channels.
3

Check each manager's access level

When you add a member on the User or Claude Code user level, you move them to the Custom roles level in the same step; if they already hold other custom roles, you confirm the move first. For a member on any other level, you see Not in effect until you change their level on the Members page. Adding a group changes nobody’s level.If you’re a Claude Tag admin, the move also needs User Management set to Can manage on your role. Without it, the member is still added but shows Not in effect until their access level is changed on the Members page.If your identity provider manages access levels, you can’t change a level on the Members page, and the move doesn’t happen. Put the channel managers in an identity provider group and map that group to the Custom roles level instead. If you turn on identity provider management after adding channel managers, the next sync sets every member’s level from your group mappings, so managers you moved by hand show Not in effect until a mapped group covers them. The role and its group are kept; you don’t need to add the managers again.
Owners can already configure every channel, so you see them as Already has full access and can’t add them. Leave the role as it was created: assigned to its channel, with Claude Tag channel setup as its only permission. If the role’s permissions are changed on the Roles page, the channel’s Add managers list stops recognizing the role and refuses to add or remove any, with a notice that points you to the Roles page. To recover, set the role’s permissions back to exactly Claude Tag channel setup; the group and its members are kept. To give channel managers any other permission, create a separate role for it.

Remove a channel manager

To remove a channel manager, select Add managers on the channel’s page. The current managers are listed first, each with a check mark. Select a member you added directly, or a group you added, to remove it. The member keeps their access level and any other custom roles. The manager cards on the channel’s Configure page disappear for them.

Verify a channel manager’s access

In the list behind Add managers on the channel’s page, people added directly show Not in effect when their access level doesn’t support the role; the role works only on the Custom roles access level, so change the member’s level on the Members page to put it into effect. An active manager sees the Default model, repository, and access bundle cards on the channel’s Configure page, so asking them to open that page confirms the setup.

Audit channel manager activity

Channel manager activity is recorded in your organization’s audit log, which you read through the Compliance API. The log records:
  • Role channel assignments. When a channel is assigned to a channel manager role or removed from it, with the role and the number of channels before and after.
  • Credential changes. Each credential a channel manager creates, updates, rotates, or deletes, with the Slack workspace and channel it was for and the roles that granted the permission, so you can tell a channel manager’s change from an Owner’s. Secrets are never included.
  • Configure page changes. Which settings a channel manager saved from the Configure page, such as the default model, repositories, or channel instructions. The log records which fields changed, not the values entered.
The Activity page at claude.ai/admin-settings/claude-tag/audit doesn’t list these events; it covers scheduled work, memory, and network events.

Permissions by role

Creating bundles and binding them to scopes need an Owner or a Claude Tag admin. Pairing workspaces needs an Owner. Editing channel name patterns and changing which channels Claude can search need an Owner too. A channel manager configures only the channels assigned to them. Everything else happens inside the channel and is open to its members. The built-in Admin role doesn’t include the Claude Tag Admin permission. A member with that role can take the actions in the Channel member column, in channels they belong to. The table lists each action and who can take it, with no column for Claude Tag admins; the actions that permission covers are listed under Delegate Claude Tag administration. Scheduled jobs run with the channel’s credentials, so a member creating one can’t reach anything the channel itself can’t.

Controls that aren’t available

These are controls an admin might look for that Claude Tag doesn’t have.
  • Third-party deployment. Claude Tag runs on Anthropic’s first-party service; it isn’t available through third-party deployments.
  • Renaming or rebranding the app. The Claude app’s name, @-handle, and avatar in Slack are fixed; there is no per-workspace rename setting.
  • Per-user spend caps on channel work. Spend limits apply at the organization and channel level. There’s no way to cap what one member can spend in channels; one-to-one DM usage from a member who has connected a Claude account bills to that member’s own seat and follows the seat’s usual limits.
  • A switch for group DMs alone, or settings for one group DM. You can’t attach a bundle to one group DM, turn Claude off in one, or stop Claude from answering in group DMs without also stopping it in one-to-one DMs or the workspace’s channels. See Group DMs.
  • Per-channel responder allowlist. The restriction toggle governs who can invoke Claude across the workspace; you can’t narrow it to a list of people for one channel only.
  • An open-internet switch in Claude Tag settings. A channel sandbox reaches only allowed hosts. To let Claude reach a public site or API, an Owner or a Claude Tag admin adds that hostname to a bundle as a domain; for broad web access, an Owner pins an environment whose network access level is Full access on the scope. Allow-all egress, a * domain entry, admits any host on the ports it lists.
  • A web search toggle for channels. No setting turns web search off for channel sessions; the web search capability setting in claude.ai admin settings governs claude.ai chat, not channels. Web search runs on Anthropic’s servers rather than from the channel sandbox, so Domains entries and egress settings don’t govern it, and a search opens no new path out of the sandbox; search requests travel to Anthropic the same way the session’s model traffic already does. See Web search vs. network requests.
  • A switch to turn workspace search off. Claude can search public channels by keyword the same way any Slack user can; it can’t read a channel’s full history unless it’s been added there. No setting turns workspace search off. The Channels Claude can search setting narrows it to channels Claude is in. No setting enables search in channels that include guests, where it’s unavailable.
  • Session length enforcement. Your organization’s Slack session-length policy is not enforced on this surface.