What Claude can read in Slack
Claude reads Slack with the same visibility a member of your workspace has. In a Slack workspace connected to your Claude organization, Claude can:- Read and post in the channels it has been added to
- Search every public channel by keyword, including public channels it hasn’t been added to. No admin setting turns this search off. An Owner can limit it to channels Claude is in.
- Read a private channel only after someone in that channel invites it
Plan and organization requirements
Limiting Claude to approved channels needs an Enterprise plan, in addition to the general prerequisites for Claude Tag. Only the Enterprise plan has a setting that turns Claude on or off for an individual channel. If your Claude organization has Zero Data Retention (ZDR) or customer-managed encryption keys, Claude Tag isn’t available in that organization. Ask your account team about creating a separate Claude organization without those policies and connecting your Slack workspace to the separate organization instead.Limit Claude to PHI-free channels
An Owner turns Claude off everywhere by default, turns it on only in channels approved as PHI-free, turns off direct messages, and blocks channel names that signal PHI. Every setting in these steps is atclaude.ai/admin-settings/claude-tag.
1
Turn Claude off by default
Go to Claude Tag’s access → Slack → Default Slack and turn off the Enable Claude Tag in Slack switch at the top of the panel. Limit Claude Tag to specific channels has the full procedure.
2
Reset workspace and channel entries that have their own setting
A workspace or channel entry’s own Enable Claude Tag setting takes precedence over Default Slack, so an entry switched on during an earlier pilot keeps Claude active there. Under Claude Tag’s access → Slack, open each workspace and channel entry that has its own setting and click Use inherited setting under the switch.
3
Turn Claude on in each approved channel
Go to Claude Tag’s access → Slack, select the entry for the approved channel, and turn on its Enable Claude Tag in this channel switch. If the channel isn’t listed under Slack, add the channel with Add channel first.
4
Turn off direct messages
On the same
claude.ai/admin-settings/claude-tag page, turn off the Allow direct messages toggle. Claude is then reachable only in channels.5
Block channel names that signal PHI
Go to Claude Tag’s access → Slack → Default Slack → Advanced → Blocked channel patterns and add the naming patterns your workspace uses for clinical or patient channels, for example
*-patient-*. Claude won’t read or respond in a matching channel even if someone invites it. See Block or auto-join channels by name.@Claude to a channel that isn’t approved. Claude stays silent there, and an @-mention gets a notice that Claude is disabled in that channel instead of a reply.
Only an Owner of your Claude organization or a Claude Tag admin can change an Enable Claude Tag switch, and only an Owner can change the Allow direct messages toggle. Give the Claude Tag Admin permission only to people you trust to approve a channel as PHI-free.
Connect only PHI-free tools
In a channel, Claude signs in to tools outside Slack only through the connections an Owner adds, and each connection is attached to specific channels through an access bundle. For a healthcare organization, apply these rules when deciding what to connect:- Connect only tools that never hold PHI, such as your code host, issue tracker, and internal documentation
- Leave electronic health record systems, clinical systems, and patient communication tools unconnected
- Treat email and calendar as PHI-bearing unless your compliance team has confirmed otherwise, and leave them unconnected until then
- Attach each bundle to the approved channels that need it, not to Default Slack (the entry whose settings apply to every channel in every connected workspace), so a connection never reaches a channel it wasn’t reviewed for
- Block a connector for everyone. A connector you restrict for your organization on the Connectors admin page stays restricted when Claude uses a member’s connectors in a channel.
- Require human review. On the Enterprise plan, turn on Require human review of every message in the Personal connectors section at
claude.ai/admin-settings/claude-tag, so a member reviews every result before it posts to the channel. - Treat the rest as PHI-bearing. Include members’ remaining claude.ai connectors in the tools that must stay PHI-free.
Train your workspace and monitor approved channels
Settings keep Claude out of unapproved channels and tools. They don’t stop a person from typing PHI where Claude can read it. Train everyone in the workspace that patient information never goes in a public channel, in a channel Claude has been added to, or in a tool Claude is connected to. Run your data loss prevention tooling on the approved channels to catch mistakes.What Claude Tag stores
Anthropic stores two things for the conversations Claude works in. The first is a transcript of each conversation, which includes everything Claude read while working. The second is the memory notes Claude keeps for each channel. Claude keeps separate notes for each channel. From a public channel it can also save workspace notes, and those inform its replies in every channel in the workspace. Notes from a private channel stay in that channel’s own store and aren’t read anywhere else. Anyone in a channel can ask Claude what it remembers there and tell it to correct or delete a note. An Owner can view, edit, and delete the memory notes of a channel or of the workspace atclaude.ai/admin-settings/claude-tag → Claude Tag’s access → Slack → the channel’s or workspace’s entry → options menu → View memory files.
By default, your Slack conversations with Claude aren’t used to train Anthropic’s models. Anthropic’s model training policy describes when data is used. Claude Tag data is kept until one of the admin actions in Data lifecycle and deletion deletes it, and during the beta you can’t set a shorter retention period.
For the full list of what is stored and what each admin action deletes, see Data lifecycle and deletion and What Claude Tag remembers.
If PHI is posted where Claude can read it
Anthropic keeps a transcript of each conversation Claude works in, including the messages Claude read. Deleting a message in Slack doesn’t remove it from a transcript that already includes it. If PHI is posted in a channel where Claude is turned on, in any public channel of the connected workspace, or in a private channel Claude has been invited to:- Report it to your organization’s HIPAA privacy officer and follow your incident process.
- Delete the message in Slack.
- If the message was posted in a channel where Claude is turned on, have an Owner delete that channel’s transcripts and memory immediately by removing the channel’s entry under Claude Tag’s access → Slack.
- If that channel is public, have an Owner also check the workspace’s memory, because workspace notes Claude saved from that channel are stored with the workspace and aren’t deleted with the channel’s entry. Go to Claude Tag’s access → Slack → your workspace’s entry → options menu → View memory files, and delete any note that contains the information. Deleting a note removes it from what Claude reads in every channel right away.
- Email privacy@anthropic.com to request deletion of the data Claude Tag retained that the admin controls in steps 3 and 4 don’t delete, including the workspace’s stored memory and any transcript in another channel whose session found the message through search. Include the workspace, the channel, and the time of the message.
Related resources
- Restrict where Claude Tag operates: every control that narrows where Claude responds and who can use it
- Security and data handling: sandbox isolation, credential handling, and network egress
- Data lifecycle and deletion: what Anthropic stores and how to delete it