JOURNAL

Claude Tag can now use your own connectors. The whole channel sees the answer

Claude in Slack can pull from your calendar, your drive and your CRM. That turns the channel's shared access into a choice you make tool by tool.

25 September 2026·9 min read·Claude · Anthropic · Claude Tag · Slack · Claude integration

Claude Tag can now use your own connectors when you ask Claude something in a Slack channel. The first time it happens, a message appears in the thread that only you can see. It has three buttons: Allow, Allow with review and Don't allow. The rest of the channel never sees the three buttons.

Anthropic launched the feature on 24 September 2026. It's rolling out on the Team plan first, with Enterprise to follow. Claude Tag is still in public beta, and Anthropic's own documentation says not every organisation has the feature yet.

TL;DR: Until now, Claude in a channel could only use the tools an admin had attached to that channel. Now it can also use your calendar, your drive or your slice of the CRM for a task you asked for yourself, and the answer lands in the channel where everyone can read it. Anthropic's own sensitive-content check doesn't consider who else is in the channel. That turns your Claude integration in Slack into a decision you make tool by tool: does the tool belong in the channel's shared access, or should it follow the person?

What Claude Tag can reach now depends on who's asking

In a channel, Claude Tag works under its own service accounts, not as you. An admin attaches the tools to the channel, and everyone who writes to @Claude in there gets the same access. Anthropic spells out the benefit in its documentation on Claude's identity: "What Claude can do never changes based on who asked."

That still holds for the channel's own work. It no longer holds for your task. Ask for something that needs one of your own tools, and Claude can now fetch it through your connector, with your permissions, and put the result in the thread.

Animated drawing on a light ground of the same Slack thread seen from two seats side by side. On the left, the person who asked sees a message with three buttons that only she can see. On the right, a colleague sees the same thread without that message. When the answer is posted, it appears in both views at once.
The same thread from two seats. The three-button message reaches one person; the answer reaches everyone in the channel.

Two things don't change. Nobody else in the channel can use your connectors. If a colleague writes in your thread, their request runs on the channel's own access, and Anthropic says Claude is designed to take direction from you and to read other people's messages as information about the task.

And routines, the tasks Claude runs on a schedule or starts on its own, always use the channel's tools. Never yours.

Your Claude integration: does the tool stay in the channel or follow the person?

Everyone in a channel can use whatever an admin attaches to it. Anthropic says so in its security documentation: whatever the connected account can read or write is "available to every member of those channels". That's why Anthropic recommends a dedicated account for Claude in each tool rather than someone's personal login.

In the blog post about the feature, Anthropic also says most organisations keep the channel's list short on purpose, because they want access to follow the person, not the channel. Until now that was all or nothing. Either the tool went into the channel for everyone, or Claude couldn't use it there at all.

Now there's a middle way, and Anthropic lists the options itself: a shared set of tools under Claude's own identity, personal connectors only, or a decision tool by tool.

Light infographic. On the left, a box labelled the channel's shared access. Inside it, monitoring and the runbook are pinned in place, with a moon symbol because unattended routines use them. Calendar and drive have moved out of the box along gold arrows and follow a person on the right. The CRM sits on the box's wall with a question mark.
The channel's shared access, sorted tool by tool. Anything that runs unattended can only use the channel's own tools.

Take a sales channel at a 30-person company. The example is mine. The calendar has no reason to sit in the channel, because everyone has their own. The same goes for the drive, where each person can already open only what they have access to.

The CRM is harder. If the channel runs on one login that can see every customer, anyone in the channel can get Claude to pull every customer. Move the CRM onto each person's own connector, and every salesperson sees only their own accounts, exactly as they do in the CRM itself.

You can empty the channel's shared access completely. But then routines have nothing to work with, because personal connectors don't run unattended. Anthropic says a channel that relies only on personal connectors "suits closely supervised work".

Three buttons only the person asking can see

According to Anthropic's guide, you get three choices:

  • Allow starts the task in auto mode. Claude uses your connectors as needed and only checks with you before posting something that looks sensitive.
  • Allow with review shows you every single result before it's posted to the channel.
  • Don't allow turns down this one request. A later request can ask you again.

Below the buttons there's a checkbox, "Use this choice for future requests". Tick it and the choice is saved for every channel, and Claude stops asking. You can change it later on the Home tab of the Claude app in Slack, which offers Auto mode, Ask every time and Allow with review. Ask every time is what you have until you save something.

Light infographic with two grids of the same six channels. On the left, labelled saved Allow, all six channels carry the same tag, auto. On the right, labelled Ask every time, each channel carries its own choice: review in leadership, HR, quotes and customers, auto in the others.
A saved choice applies in every channel. Ask every time lets you choose channel by channel.

My advice is to leave the box unticked. Ask every time lets you decide channel by channel: auto in your own project channel, review in the channel with the leadership team. A saved Allow also applies in the channel you weren't thinking about when you ticked the box. If you do want to save something, save Allow with review.

If a task is doing something you don't want, there's a Stop button under Claude's message in the thread. Only you can see it.

The check reads the answer, not who's in the channel

If you choose Allow, Claude checks every result before posting it. Anthropic lists ten kinds of content the check holds back for your approval. They include credentials and keys, personal identifiers, pay and HR records, customer and deal information, unannounced plans and health information.

In Anthropic's own words: "The check is a screen, not a guarantee, and it doesn't consider whether other people in the channel have the same access you do."

Animated drawing on a light ground. Lines from an answer slide down through a sieve. A price tag and a name get caught in the sieve and are marked. To the right, a box for #quotes holds twelve figures, three of them in gold because they're not in sales. Nothing connects them to the sieve.
The check sorts the content. The channel's members don't come into it.

Picture a salesperson in #quotes who uses her own CRM connector to ask Claude for last year's price for one customer. A price is commercial information, so the check should hold it back, and she sees it before it's posted. The number's right, so she approves it. The channel has twelve members, and three of them don't work in sales. Nothing in the message told her that, and she checked the number, not the audience.

So review only helps if you know who's reading.

If the answer contains personal data from your inbox or your slice of the CRM, it now has more readers than it had in the tool. That happens inside the company, but it's your name on it: Anthropic says everything Claude does through your connector is recorded in that tool's own log under your account, while the channel's work sits under the service account.

Who reads the answer?

By default the room is internal. According to Anthropic's guide to access, Claude is switched off in channels with guests until an admin changes the setting, and it doesn't work at all in a Slack Connect channel shared with another company. If an owner does allow Claude in a channel with guests, the guests can read what Claude posts.

Light infographic of rings around a dot. The dot in the centre is you. The first ring is everyone in the channel, drawn as twelve small heads. A dashed ring outside it is guests, off by default. Outermost is Slack Connect, struck through, because Claude doesn't work there.
Who reads the answer? By default, the channel's own members and nobody else.

So the readers to think about are the colleagues who are in the channel for entirely different reasons.

On the Team plan you have two tools that shape the room: a setting that restricts Claude Tag to your organisation, and channel name patterns that keep Claude out of particular channels, whoever invites it. The documentation also describes an Enterprise setting, Delegated task results, that lets an owner require review for everyone. Enterprise gets personal connectors after Team. I've written about how the two plans differ on settings like these in the article on Claude's memory and its defaults.

Whoever asks is now the editor

The three-button message reaches one person. The answer reaches the whole channel. That makes whoever asks the editor for the channel, whether they know it or not.

When you press Allow with review, you're approving two things at once: that the number is right, and that these particular people in the channel should see it. You've always checked the first. The second is new.

As an AI consultant and Claude specialist, I set up Claude Tag for Danish companies. The hard part is going through the channel's shared access tool by tool and deciding what stays and what follows the person, without taking away what the AI agents and routines that run overnight need. I can help you with that as part of an internal Claude setup.

FAQ

Frequently asked questions

Yes, if it's in the answer. Anything Claude posts in a channel thread can be read by everyone in the channel. The work Claude does along the way lives in a session only you can open.

No. Your connectors are only used for tasks you asked for yourself. If a colleague writes in your thread, their request runs on the channel's own access.

Allow starts the task in auto mode, where Claude only holds a result back if it looks sensitive. Allow with review shows you every result before it's posted to the channel.

Open the Claude app in Slack and go to the Home tab. There you can switch between Auto mode, Ask every time and Allow with review.

The documentation describes an Enterprise setting, Delegated task results, that lets an owner require review for everyone, or remove the review option. Personal connectors are rolling out on Team first, with Enterprise to follow.

By default Claude is switched off in channels with guests until an admin changes it. In Slack Connect channels shared with another company, Claude doesn't work at all.

No. Routines and anything Claude starts on its own use the channel's own tools. Personal connectors never run unattended.

The feature is rolling out gradually, and Anthropic says only a limited number of organisations have it so far. If Claude never offers, your organisation may not have it yet.

Sources

How this article was made. Claude read Anthropic's blog post and five pages of documentation, re-fetched every quote word for word and built every file with nobody at the screen. Three reviewers attacked the angle before a word was written and moved the piece away from a plain walkthrough of settings, because that sat too close to an earlier Brinvik article. A fourth found a factual error in the plan, which was fixed before the text was written. Kim wrote the rules, the voice and the checklists in advance, and they were enforced throughout.

Portrait banner on a light ground. The headline "Who did the work?", below it two numbers for AI and Kim, a bar divided in the same proportion, and eight phase bars with their own labels underneath.
The split is a qualified estimate over the finished task, not a measured log.

Get new essays by email.

Roughly twice a month. Same voice. No list rental, no retargeting.

Sign up for the Brinvik journal. Unsubscribe anytime. See our privacy policy.

Protected by Cloudflare Turnstile. No challenge, no CAPTCHA. Brinvik never shares your address.