Skip to main content

Access bundle

A named set of connections, domain entries, repository access, and rules that an Owner or a Claude Tag admin creates for Claude to use. Bundles attach to scopes, and one bundle can serve many scopes. See Give Claude access.

Agent identity

The service accounts Claude acts with: the Claude app in Slack, the Claude GitHub App on code, and the credentials an admin provisions for every other tool. See How agent identity works.

Agent Proxy

The network layer that injects credentials into Claude’s outbound requests. The model and the sandbox are not given the key; Agent Proxy adds the credential at the network boundary when a request matches the rules an admin set. See How agent identity works.

Channel manager

A member of your Claude organization named to set up specific channels. For each channel assigned to them, a channel manager sets the default model, adds repositories their own GitHub account is an admin of, and manages credentials and plugins in the channel’s own bundle, without holding the Owner role. See Delegate channel setup to channel managers.

Channel memory

Facts Claude retains while working in a channel, including facts you told it to remember and notes it writes itself. Each channel keeps its own entries. From a public channel Claude can also save workspace notes, which it reads in every channel in the workspace. See What Claude Tag remembers.

Claude Tag admin

A member of your Claude organization whose custom role includes the Claude Tag Admin permission, available on the Enterprise plan. A Claude Tag admin manages Access bundles, attaches them to scopes, and edits workspace and channel settings, without holding the Owner role. A Claude Tag admin whose role also sets Identity & Access to Can manage can add and remove channel managers. See Delegate Claude Tag administration.

The earlier Claude in Slack

Claude Tag is the second generation of the Claude app in Slack: Your admin chooses which generation answers @Claude in a given channel, so two channels in the same workspace can work differently. See Migrate from the earlier Claude in Slack.

Connection

A credential for one external service that Claude uses on the channel’s behalf, like a Datadog API key or a GitHub App installation. Connections belong to the agent identity, not to any user, and are grouped into Access bundles by an admin. A connection is not a connector. A connector belongs to your personal claude.ai account. A channel session uses the channel’s connections. Claude can also use your connectors there for your own tasks, after you allow it. A one-to-one DM uses your own account instead, as how DMs work in this model describes.

Connector

A tool you add to your own claude.ai account, like Gmail, Google Drive, or a custom MCP server, listed under Customize > Connectors. Connectors are personal. In Slack they apply in one-to-one DMs. Claude can also use them in a channel for your own tasks, after you allow it. For the agent-side equivalent that works in channels, see Connection.

Environment

The sandboxed compute configuration a session runs in, including its network access setting. Environments used here must be scoped to the organization, not to an individual account, because channel sessions run with no user account attached.

Plugin

A bundle of skills an Owner or a Claude Tag admin attaches to an Access bundle or scope, teaching Claude how to use a specific tool or follow a specific process. Anthropic provides plugins for common tools; you can add your own. See Attach plugins.

Routine

A scheduled or run-once task Claude runs on its own, such as a daily digest or a channel watch. Anyone in a channel can ask Claude to set one up, list what’s scheduled, or disable one. Routines run with the channel’s connections, not the creator’s. Claude Code also has a feature named routines. Those run under an individual user’s account; Claude Tag routines run under the agent identity.

Rule

The match conditions Agent Proxy checks against each outbound request. A connection pairs one credential with the rule that decides when to inject it, and a request that matches the rule gets the credential attached at the boundary. A request that nothing allows (no rule, no domain entry, no environment network access setting) is blocked. See Agent Proxy.

Scope

One of three levels Claude’s settings can target: Default Slack access (the organization-wide root), one Slack workspace, or one channel (public or private). Scopes inherit downward, so a channel gets its workspace’s settings plus any of its own. An Owner or a Claude Tag admin attaches Access bundles and instructions at a scope. See Attach the bundle to a scope.

Session

The unit of work behind one conversation. Each Slack thread binds to one persistent session, and anyone in the channel can continue it by replying in the thread. A channel where Claude works at the top level, outside threads, also carries one session for the channel itself, separate from every thread’s. See How Claude Tag works and Restart a stuck or wrong-context session.