Skip to main content
This page covers adding access to more workspaces and channels, and how access stacks when several bundles apply to the same place. It assumes you have already paired a workspace and created an Access bundle. You must be an Owner in your Claude organization, or a Claude Tag admin, to attach a bundle to the organization, a workspace, or a channel. Attaching a bundle by channel name needs an Owner. A scope is where a bundle applies: Default Slack access (the organization-wide root), a workspace, or a single channel. Bundles inherit downward through those scopes, and when credentials overlap, the narrowest scope wins.

How scopes inherit

Bundles stack downward. A channel gets whatever is attached at Default Slack access, plus its workspace, plus anything attached to the channel itself. Nested boxes. The outermost box is the Default Slack access scope: a bundle attached here is the baseline every channel gets. Inside it, two examples. Outside the workspace box, a channel called another-team in a different workspace gets only the default bundle. Inside the workspace box, which adds an optional bundle for channels inside it, two channel boxes: a public channel called general, with no channel bundle, gets the default plus the workspace bundle; a private channel, marked with a lock, with its own channel bundle, gets all three, the default, workspace, and channel bundles. Nested boxes. The outermost box is the Default Slack access scope: a bundle attached here is the baseline every channel gets. Inside it, two examples. Outside the workspace box, a channel called another-team in a different workspace gets only the default bundle. Inside the workspace box, which adds an optional bundle for channels inside it, two channel boxes: a public channel called general, with no channel bundle, gets the default plus the workspace bundle; a private channel, marked with a lock, with its own channel bundle, gets all three, the default, workspace, and channel bundles. The same stacking applies in reverse. Detaching a bundle from a channel removes only that channel’s additions, and bundles attached at the workspace or Default Slack access still apply there. Memory is also scoped, but differently: there is no organization-wide memory, each channel keeps its own notes, workspace notes saved from public channels are read across the workspace, and a private channel reads the workspace notes but writes only to its own store. See What Claude Tag remembers. One-to-one DMs from members who have connected a Claude account run under the member’s own claude.ai account, so bundles attached here don’t apply to them. See how DMs work in this model. A DM from a member who hasn’t connected a Claude account does reach access bundles. A group DM gets the bundles on the workspace’s scope and on Default Slack access.

Attach the bundle

Attaching binds the bundle to a workspace scope, to a single channel under it, or to every channel whose name matches a pattern. The binding takes full effect in new threads only. A thread already running keeps the skills, plugins, and custom instructions it started with. A connection added after a thread started still works there if you ask Claude to use the service by name, but Claude doesn’t announce it, so test with a new top-level thread after attaching a bundle. See What survives between replies. At the channel’s top level, outside any thread, Claude works from a single long-lived channel session. After a configuration change, Claude replaces that session on the next channel message, so top-level replies pick up the change from then on.

Attach to a workspace

Each paired workspace already has a scope; bind a bundle in the scope’s Access bundles section. On the Access bundles page in the left navigation, each bundle’s card shows how many places it’s used in. To see which scopes those are, open the bundle’s Manage dialog and hover over the usage count in its footer. To add another workspace, pair it first.

Attach to a channel

Channels Claude was added to appear on the Slack tab automatically, each as a scope under its workspace. To give one of these channels access beyond the workspace baseline, select its row and bind bundles in the scope’s Access bundles section. A channel row shows the name an admin gave the scope, the channel’s name in Slack, or the raw channel ID. To find a channel, use the Search channels field. It matches channel names and channel IDs (pasting a channel link copied from Slack also works), and searching a workspace’s name shows that workspace’s channels. To bind one bundle to several channels in one pass, open the bundle from a scope’s Access bundles section on the Slack tab and select Add to channels. The dialog lists channel scopes grouped by workspace, with a search field and a checkbox per channel. Check the channels you want and select Add. The bundle binds to each checked channel, and channels it’s already bound to directly are marked Already added. A channel that doesn’t appear in the list yet needs a scope created for it:
  1. On claude.ai/admin-settings/claude-tag, find the workspace on the Slack tab under Claude Tag’s access and select Add channel.
  2. Pick the channel in the Channel field. Type a name to search public channels, or paste a channel ID or channel link copied from Slack. Private channels don’t appear in the search results, so for a private channel, paste its ID from the channel’s details in Slack. Channel IDs start with C, or with G for some older private channels.
  3. Save, then bind bundles in the new scope’s Access bundles section, the same as for a workspace.
In a channel shared across more than one workspace in your Enterprise Grid, bundles bound to the channel or its workspace don’t apply. See Channels shared across workspaces in your Enterprise Grid for what Claude does there instead.
A bundle attached to a public channel grants its access to anyone who joins that channel. In most Slack workspaces, anyone can join a public channel, so the channel’s join policy becomes the effective access control for whatever the bundle grants. Keep elevated credentials in private-channel scopes.

Attach a bundle to channels by name

A bundle attach rule binds a bundle to every channel whose name matches a pattern, instead of channel by channel. Rules are listed in the Auto-join channels table, the same table that holds the auto-join patterns, in the collapsed Advanced section of the Default Slack access panel and of each workspace scope’s panel at claude.ai/admin-settings/claude-tag. A rule on Default Slack access covers matching channels in every connected workspace; a rule on a workspace scope covers only that workspace’s matching channels. Adding or removing a bundle on a pattern, or editing the patterns themselves, needs an Owner of your Claude organization. Each table row is one channel-name pattern. To create a rule, select Add bundle on the pattern’s row and pick the bundle; if the pattern isn’t listed yet, add it with Add pattern first. A pattern added here is also an auto-join pattern, so Claude starts joining matching public channels when they’re created or renamed. For example, if your incident channel names start with inc-, add inc-* with Add pattern and attach your incident-response bundle to its row. Claude then joins each new public incident channel and has the bundle’s access there. The rule grants the bundle in every matching channel Claude is in under the scope, including channels it was invited to before the rule existed. The rule itself doesn’t add Claude to any channel; only the auto-join patterns, or an invite, do that. A channel whose name matches a blocked pattern stays off-limits even when a rule matches it. After adding or changing a rule, test with a new thread in a matching channel. A rule’s pattern follows the same syntax as the other channel name patterns, lowercase with * matching any run of characters and ? matching exactly one. Each scope holds up to 20 bundle attach rules. On a workspace scope, the table also lists the organization’s patterns, marked Org-wide. You can attach a bundle to an Org-wide pattern from the workspace’s table, and that rule covers only the workspace’s matching channels; you edit the pattern itself on Default Slack access.
A bundle attach rule grants its bundle in every matching channel Claude is in, now or in the future, and anyone who can rename a channel can move it into or out of a pattern. Keep elevated credentials out of broad patterns, and add a blocked channel pattern for name shapes that should never carry access; a blocked channel stays off-limits whatever rules match it.

Where rule-attached bundles appear

When bundle attach rules cover a channel, the channel scope’s panel lists their bundles under Attached here by rule. The list is read-only, because a channel scope doesn’t take rules of its own; to change it, edit the rule on Default Slack access or the workspace scope. Rules on Default Slack access and rules on the channel’s workspace apply together.

Attach a single repository or connector

To grant a single repository or connector without opening a bundle first, use the Repositories and Connectors sections on the scope’s own panel and select the + button (Add repo or Add connector). When you save the repository or finish connecting, the item is attached to that scope. Each connector or repository row in these sections carries an origin line that says which scope or bundle gave the scope that item. Select the scope name to open that scope, or the bundle name to open the bundle. An item you add with the + button is still stored in a bundle, chosen in this order:
  1. The bundle that was created for that scope, if it exists
  2. The scope’s only bundle, if that bundle is bound nowhere else
  3. A new bundle created for the scope
When the receiving bundle is bound to other scopes too, the picker shows a note that the addition applies in every scope the bundle is bound to.

Precedence when bundles overlap

A channel sees the union of every bundle bound at the channel itself, its workspace, and Default Slack access. Narrower scopes don’t replace wider ones; they add to them. When two bundles in the resolved set carry rules for the same host, the rule from the narrower scope wins. Within that union, fixed rules decide which credential and which instructions apply.

Which credential wins

When two bundles each carry a credential for the same host:
  • The credential from the narrowest scope is used: channel beats workspace, which beats Default Slack access.
  • Within the same scope, the order isn’t admin-configurable. Avoid binding overlapping credentials at the same scope; if you can’t predict which key acts, neither can a security review.
  • There is no fallback. If the winning credential gets a 401 or 403, Claude does not retry with the next one.

Repositories and plugins

Repository grants and plugins from every bound bundle are combined as a union; a channel gets every repo and plugin from any bundle in its chain. To see what applies to a channel, select its scope on the Slack tab. The scope’s panel lists everything that applies there in its Connectors, Repositories, and Plugins sections, inherited items included. Each row’s origin line says Inherited from the wider scope or Attached from the bundle that carries it. Select the scope or bundle name in the origin line to open it.

Custom instructions

Per-scope custom instructions are concatenated, Default Slack access first, then workspace, then channel. A channel’s instructions add to, rather than replace, what’s set above it.

Instruction layers

The table lists the kinds of standing instruction that can apply in a channel and who writes each. Channel members can shape how Claude responds in their channel through memory, but they can’t change which credentials or repositories it has; that’s bundle configuration. See who controls what for the full split. Custom instructions are read ahead of the conversation and take priority in practice, but they’re guidance, not an enforced guardrail. Don’t rely on them to block actions; use access controls for that.

Add custom instructions

Each scope can carry custom instructions, which are standing guidance Claude reads in every session there, like team conventions or where to file tickets. The Custom instructions field is on the scope’s panel, shown when you select the scope on the Slack tab in admin settings. Channel members reach the same field for the channel scope through the Configure page, linked in the footer of any Claude reply in the channel, without going through admin settings. Both entry points write the same instructions, so a change from either place is visible in the other. The field is plain text, inserted as written; there is no include or template syntax, and {{include:...}} is passed through literally. To give Claude a repository’s CLAUDE.md, grant the repository and name it in the request; its CLAUDE.md loads after the clone completes. What Claude reads in a channel is the concatenated custom instructions of its scope chain, the channel’s managed instructions if another channel manages it, and the CLAUDE.md of any repository it clones. Projects in claude.ai don’t apply here; Claude doesn’t read a Project’s instructions or knowledge in Slack, and a channel can’t be pointed at a Project. A new instruction applies to sessions started after you save it. Claude reads it in every new thread right away, keeps the old text in a thread that’s already running, and picks it up at the channel’s top level on the next channel message, when it replaces the channel’s session (see Attach the bundle). Claude doesn’t read a channel’s instructions in another channel or in a DM. To confirm what a session is reading, start a new thread and ask Claude to repeat its admin instructions. To let a central team write a channel’s instructions from its own Slack channel, see Manage a channel’s instructions from another channel.

Restrict who can set channel instructions

By default, anyone in a channel who is also a member of your Claude organization can edit that channel’s instructions from the Configure link in Claude’s reply footer. The Channel member edits setting in a scope’s Advanced settings controls this. A chain of scopes that all inherit resolves to Allow. Set Block at the workspace or Default Slack access scope to lock channel instructions across every channel beneath it. A channel manager can still edit instructions, change the default model, and switch the Respond automatically toggle from the Configure page in a channel assigned to them when Block is set.

Verify the bundle is live

  • The bundle card’s usage count includes the new scope. To see it named, open the bundle’s Manage dialog and hover over the count in its footer.
  • A test task in the pilot channel uses the bundle’s connections, and the action appears in the connected service’s audit log under your service account.
Repeat the attach step for any additional scopes that need elevated access.