IA3 MIN

Claude can use your private files in Slack. The team may still see its answer

Claude Tag now lets people use personal connectors inside Slack channels. The access remains theirs, but any answer posted to the channel becomes visible to its members.

Two coworkers look at a laptop together in an office
Image: Vitaly Gariev / Unsplash
01

Your access follows your request

Anthropic has updated Claude Tag, its assistant for Slack channels, so it can use the personal services connected to the account of the person asking. Previously, it was limited to tools an administrator had attached to the channel. A user can now ask it to compare a private Drive planning document with work recorded in the channel’s GitHub integration, without giving every teammate access to that document.

The personal login does not become a shared channel credential. Claude uses that person’s permissions for the request, and activity through the connector is logged under their account. It is a practical example of AI agents working across tools, with an important boundary around who owns the access.

Several people work with laptops at a shared table
Image: Compagnons / Unsplash
02

The answer is a separate disclosure decision

A teammate may be unable to open the original file yet still see the summary Claude posts to Slack. Anthropic offers a review mode that lets the requester approve the response before it appears. Auto mode posts without that step unless Claude decides the content is sensitive enough to require review.

That automatic check is not a promise to catch every detail your organization considers private. If a request involves customer information or an unpublished plan, reviewing the proposed message is safer than relying on the filter. Anthropic says Enterprise administrators will be able to require review. Personal connectors are rolling out to Team now, with Enterprise support to follow.

03

Unattended work still needs shared connectors

Personal connectors apply to requests a person makes in a channel. Scheduled routines and actions Claude starts on its own continue to use admin-managed shared connectors. Those run under a different identity, so connecting your account does not silently give an unattended workflow your permissions.

Anthropic says Claude will ask the first time a channel request needs one of your connected services, and that you can disconnect it later. Check what the service can read or change before approving it. Our guide to prompt injection explains why outside content deserves particular care once an assistant also has permission to act.

Team gathered around laptops and documents
Image: George Dagerotip / Unsplash
00

The conversation starts here

Sign in with a supporter account to comment. Sign in

Nobody has commented yet. Want to go first?

YOUR NEXT ROUTE

Keep following AI models and agents

If this story interests you, these three pieces are the best place to carry on.

OPEN THE FULL TOPIC
  1. 01Meta wants Muse to see what you see and help book your next night outIA · 3 MIN
  2. 02Opus 5.5 looks stronger than GPT-6 Sol at preserving what already worksIA · 5 MIN
  3. 03GPT-6 Sol and Luna arrive, but you won’t find them in regular ChatGPT chatsIA · 2 MIN

KEEP READING

You may also like

FRONT PAGE