Claude Tag: a shared Claude Code identity in Slack
Claude Tag runs @Claude in Slack as an organization-owned agent identity on Claude Team and Enterprise plans. A tagged thread starts a Claude Code session in a cloud sandbox, reaches only the repositories and services an admin granted to that channel, and returns answers, files, or draft pull requests authored by the Claude GitHub App.
This page is for the tech lead who has to decide what @Claude may touch from the team’s channels, and for the developers who will tag it. A bug lands in #payments-bugs at 16:40, three people agree on the cause, and nobody has time to open a branch. With the earlier Slack app, whoever tagged Claude lent it their own account, repositories, and plan limits. With Claude Tag, the channel owns the work, so the questions change: which repositories should this channel reach, who approves what Claude opens, and where is the audit trail?
Facts on this page were checked on 2026-09-26 against Anthropic’s Claude Tag documentation, the Claude Code in Slack page, and the Claude release notes, which list the launch on June 23, 2026. Claude Tag is labelled public beta, so admin page names can move; the setup page itself stays at claude.ai/admin-settings/claude-tag.
What a Claude Tag rollout gives your team
Section titled “What a Claude Tag rollout gives your team”- A per-channel access design: which Access bundle and which repositories each channel gets, and why.
- A
CLAUDE.mdblock that makes a fresh sandbox install dependencies and run your gates before it opens a pull request. - Four copy-paste Slack prompts with a definition of done Claude can check itself against.
- A GitHub rule that stops the person who asked for a change from approving Claude’s pull request alone.
- A map of the four audit trails, and a list of failures with their recovery steps.
Claude Tag or the earlier Claude Code in Slack?
Section titled “Claude Tag or the earlier Claude Code in Slack?”Both answer to the same @Claude handle, because they are two versions of one Slack app. What differs is whose identity does the work.
| Claude Tag (the New version) | Claude Code in Slack (the Legacy version) | |
|---|---|---|
| Plans | Team and Enterprise, on Anthropic’s first-party service only | Pro and Max; retiring on Team and Enterprise |
| Acts as | The organization’s agent identity, set up once by an Owner | The Claude account of whoever tagged it |
| Repositories | Those granted to the channel’s Access bundle | Those the requester personally connected |
| Pull request author | The Claude GitHub App | The requester |
| Bills to | The organization’s usage balance, under a monthly spend limit | The requester’s seat |
| Sessions | One per thread, shared with the whole channel | One per request |
| Memory and standing work | Channel memory, routines, pull request subscriptions | None |
Three constraints decide eligibility before anything else. Claude Tag is not available to organizations with Zero Data Retention or a customer-managed encryption (CMEK) policy, because it stores channel memory and session transcripts. It is not offered through third-party deployments. And routines must be enabled for the organization, or Claude answers every mention by saying it is unavailable.
If your workspace already runs the earlier app, pairing switches channels to the New version. On Enterprise, each scope’s Claude Tag version setting (New, Legacy, or Inherit) lets you migrate channel by channel. The Team plan has one Enable Claude Tag switch instead, so there is nothing to migrate. Anthropic has not published the date the Legacy version stops answering; your account team has it.
How does a tagged thread become a pull request?
Section titled “How does a tagged thread become a pull request?”Every request follows the same loop, and knowing it explains most surprises:
- Someone tags
@Claudewith a task. A routine can start a session too. - A fresh sandbox builds for that thread, with no repository checked out. It runs on the same infrastructure as Claude Code on the web.
- Claude clones a repository only when the message names one that the channel’s Access bundle grants. After the clone,
CLAUDE.md,.claude/CLAUDE.md,.claude/rules/*.md, and the skills in.claude/skills/load on the next turn. - For longer tasks, Claude’s first reply is a checklist it edits in place. Slack sends no notification for edits, so a thread that looks frozen is usually still moving.
- The result lands in the thread: a reply, a file or chart, a hosted page, or, for code, a draft pull request authored by the Claude GitHub App that links back to the thread.
- After a quiet period the sandbox is released. The thread, the transcript, and anything pushed or posted persist; files that lived only in the sandbox do not.
Anyone in the channel can steer a running session by replying in its thread. Editing an earlier message reaches Claude only as a note, and deleting a reply does not reach it at all, so corrections go in a new reply.
What carries over from your Claude Code setup
Section titled “What carries over from your Claude Code setup”The repository travels; your machine does not. Hand this table to developers who already use Claude Code in the terminal.
| Your local Claude Code setup | In a Claude Tag session |
|---|---|
CLAUDE.md, .claude/rules/*.md, .claude/skills/ in the repo | Load after the clone |
Hooks in the repo’s .claude/settings.json | Do not run |
.mcp.json, even when committed | Never loaded; services come only from the channel’s connections |
~/.claude, personal settings.json, shell environment | Not loaded |
/model | Channel default set by an admin; you can switch in a thread |
| Permission prompts | Auto mode; an admin pre-approves routine actions with auto mode allow rules |
| Secrets in environment variables | Admin-provisioned connections; Agent Proxy injects the credential outside the sandbox |
The hooks row matters most: gates that live in Claude Code hooks are silent in Claude Tag sessions, so move every gate you depend on into CI. See hooks automation for what those hooks do locally.
Set up Claude Tag for one pilot channel
Section titled “Set up Claude Tag for one pilot channel”Setup needs an Owner in the Claude organization and a Slack workspace admin, and they should be online together: the pairing code expires 15 minutes after Claude posts it. On a Team plan, nothing runs until the organization’s usage balance is funded.
-
Check eligibility. Confirm the plan is Team or Enterprise, that the organization has neither ZDR nor CMEK, and that Admin settings > Capabilities > Remote sessions > Routines is on. Claude Tag’s standing work is built on routines, so read Claude Code routines first if your organization has never used cloud sessions.
-
Link GitHub first. At
claude.ai/admin-settings/github, connect the Claude GitHub App to your GitHub organization. The person who does this must own the GitHub organization and be an Owner in Claude. The connection is shared with Claude Code, and Claude Tag ignores rows whose type is Personal. -
Pair the workspace. A Slack admin runs
/invite @Claudein a channel, then sends@Claude connectwith no other text. The Owner pastes the returned code onclaude.ai/admin-settings/claude-tagand chooses Specific channel with the pilot channel’s ID, rather than the whole workspace. For a private pilot channel, invite@Claudeto it before you enter the ID. -
Create a narrow Access bundle. On the bundle’s Repositories tab, grant only the repositories the pilot needs; avoid Connect all. For every other tool, create a dedicated account for Claude (for example
claude@yourcompany.example.com) with the narrowest role the tool offers, and paste that account’s key. Attach the bundle to the pilot channel only, and keep the channel private: a bundle on a public channel reaches anyone who joins it. -
Restrict who can invoke it. By default anyone in the connected Slack workspace can use Claude in channels, even without a Claude account. Turn on Restrict to your organization (Team) or Restrict to roles with Claude Tag access (Enterprise) under Member access. The toggle covers DMs too, and an Owner can also disable DMs organization-wide if you want all work to stay in visible channels.
-
Set a spend limit and launch. Pick a monthly limit at launch, or later at
claude.ai/admin-settings/usage/claude-tag. Channel work bills to the organization. A DM from a member with a connected Claude account bills to that member’s seat and is not capped by this limit; a DM from a member without one can bill to the organization. -
Verify from the channel. Send
@Claude what can you access from this channel?. The reply lists the connections and the repositories this channel can reach. Then run the first prompt below against a test repository.
Sessions run in auto mode, where Claude’s permission checker reviews each action and can stop it. If the checker keeps stopping a routine action, such as deploying to staging, an admin adds an auto mode allow rule on the scope’s Advanced section: one plain sentence, up to 50 rules per scope, inherited by every channel below. Put a rule on the narrowest scope that needs it, because it applies to everyone who can post there.
Repository grants, skills, plugins and custom instructions apply to new threads only; edits to connections and Domains entries reach running threads within about a minute. After you change a bundle, start a fresh thread and name the repository in the first message.
Prepare the repository for a fresh sandbox
Section titled “Prepare the repository for a fresh sandbox”Each session starts from a clean sandbox with a standard set of tools, and Claude treats CLAUDE.md as guidance, not a setup script. Anthropic’s advice is to write each install as a precondition of the work it supports. This block is written for that:
## Working in a fresh sandbox (Claude Tag, cloud sessions)
- Before building or running tests, install dependencies with `pnpm install --frozen-lockfile`. If `pnpm` is missing, run `corepack enable` first. Use the default npm registry; other download hosts may be blocked.- Before opening or updating a pull request, run and pass, in this order: `pnpm typecheck`, `pnpm lint`, `pnpm test`. Paste each command's last line and exit code into the pull request description.- Open pull requests as drafts. Never merge, and never push to `main`.- If a test needs a service the sandbox cannot reach, say so in the thread and stop. Do not skip or delete the test.For tools every channel needs, such as a language runtime, an admin adds the install to the setup script of the environment the channel’s sessions run on. Registries other than the default ones need a host on the bundle’s Domains tab, because outbound traffic from the sandbox is default-deny.
Prompts that give Claude Tag a finish line
Section titled “Prompts that give Claude Tag a finish line”Every prompt below names the repository in the first message, so the clone happens before work starts, and ends with a definition of done that Claude can check. Replace acme/billing-api with a repository your channel’s bundle grants.
Repository conventions belong in CLAUDE.md, where they follow the code into every channel. Channel memory is for how this team wants work reported. Both are guidance; a rule that must hold, such as “never merge”, has to be enforced in GitHub.
A few ! commands help when a thread misbehaves. They must follow the mention directly: @Claude !status reports whether Claude is still working, visible only to you; @Claude !restart archives the thread’s session and starts a fresh one that rereads the thread; @Claude !routines lists the channel’s scheduled jobs and subscriptions; and @Claude !fork #payments-team <prompt> moves a public thread into the owning team’s channel.
How do you verify what Claude Tag ships without reading every line?
Section titled “How do you verify what Claude Tag ships without reading every line?”Claude’s work reaches main only through a pull request, so the pull request gates are the verification. Four controls make that true.
Require a second approver. Claude authors its pull requests, so GitHub’s rule against approving your own pull request applies to Claude, not to the person who asked. On a branch that needs one approval, the requester can approve and merge Claude’s work alone. Either require two approvals in the branch ruleset, or add a required status check that only Claude’s pull requests must pass. Also turn on dismissal of stale approvals when new commits are pushed. This workflow is one way to build that check:
# Add "second-approval" as a required status check on main.name: second-approvalon: pull_request: types: [opened, synchronize, reopened] pull_request_review: types: [submitted, dismissed]permissions: pull-requests: readjobs: second-approval: runs-on: ubuntu-latest steps: - name: Require two approvals on pull requests authored by Claude if: github.event.pull_request.user.login == 'claude[bot]' env: GH_TOKEN: ${{ github.token }} PR: ${{ github.event.pull_request.number }} REPO: ${{ github.repository }} run: | approvals=$(gh api "repos/$REPO/pulls/$PR/reviews?per_page=100" \ --jq '[.[] | select(.state != "COMMENTED")] | group_by(.user.login) | map(last) | map(select(.state == "APPROVED")) | length') echo "Distinct approvers: $approvals" test "$approvals" -ge 2GitHub runs this workflow from the pull request’s own branch, so a pull request that edits it changes the check. Add .github/workflows/ to CODEOWNERS and turn on Require review from Code Owners in the ruleset, or prefer the simpler control: require two approvals in the branch ruleset. Test the workflow on a scratch repository before you make it required. On GitHub Enterprise Server, Claude’s login is your own app’s <slug>[bot].
Keep the gates in CI. Type checks, linters, tests, and automated review run on Claude’s pull requests exactly as on a person’s.
Know what Claude can do in GitHub Actions. As the Claude GitHub App, Claude can read runs and logs, re-run or cancel runs, dispatch workflow_dispatch workflows, delete runs and artifacts, enable or disable workflows, and edit files under .github/workflows/ in a pull request. It cannot send repository_dispatch or approve a held run or pending deployment. Put deployments behind a GitHub environment with required reviewers.
Sign-off. The second approver owns the merge. For what that reviewer should look at when the diff is too large to read, see agent PR review and the evidence bundle.
Where is the audit trail for Claude Tag?
Section titled “Where is the audit trail for Claude Tag?”There is no single log of every task and who asked for it. The record is spread across four places:
| Trail | What it shows | Who can see it |
|---|---|---|
Activity page, claude.ai/admin-settings/claude-tag/audit | Tabs for scheduled work (with Created by), memory files per scope, and an hourly JSON export of outbound requests through Agent Proxy; Git and MCP traffic are excluded | Owners |
| The Slack thread | The request, every steering reply, and the result | Channel members |
| GitHub | Commits and pull requests authored by the Claude GitHub App, each linking back to its Slack thread | Repository readers |
| Each connected service’s audit log | Actions under the dedicated account you created for Claude | That service’s admins |
Deleting a Slack message does not remove it from the session transcript, and archiving a session keeps its transcript with the channel’s Claude data. Tell your team before the pilot, and keep secrets out of tagged threads. To check a channel’s standing work, anyone can send @Claude what triggers do you have set up in this channel?.
What breaks when you roll out Claude Tag?
Section titled “What breaks when you roll out Claude Tag?”Claude says a repository isn’t available or isn’t configured, or GitHub returns 403. Either the GitHub organization is not Connected at claude.ai/admin-settings/github, or the repository is not on the Repositories tab of a bundle attached to this channel’s scope. Recovery: fix whichever is missing, then start a new thread and name the repository in the first message.
A 403 that says “repository_dispatch is not permitted for this session type.” That is the fixed GitHub Actions permission set, not a repository grant. Recovery: trigger the workflow with workflow_dispatch, or run it yourself.
Channel sessions fail immediately with “That environment or repo isn’t configured for Claude Code”, and retrying does not help. The environment pinned on the channel’s scope is not set up for channel sessions, usually because it belongs to someone’s personal account. Recovery: an Owner creates an organization-shared environment under Admin settings > Cloud environments (environments created at claude.ai/code belong to one person and never appear in the picker) and pins it on the channel’s scope under Advanced > Environment.
Every mention gets “Claude is disabled in this channel.” Either setup was saved but not launched, or the Enable Claude Tag switch is off for the channel, workspace, or organization. Recovery: finish Launch Claude Tag on the setup page, or turn Enable Claude Tag on for that channel’s scope on the admin page.
Claude answers that it is unavailable and does no work. Routines are off for the organization. Recovery: enable them under Capabilities > Remote sessions.
Claude still opens pull requests under a person’s name. That channel is answering with the Legacy version. Recovery: set the scope’s Claude Tag version to New.
The pull request passed locally configured checks but broke the build. Your hooks and local MCP servers never ran in the sandbox. Recovery: move the check into CI and make it required.
Claude stopped mid-task with a spend message. The monthly spend limit, which counts usage at list price, was reached. Recovery: an admin raises it on the usage page. A rate-limit reply is different; wait the few seconds it names and re-send.
A thread went quiet for a long time. Recovery: @Claude !status; if the session is stuck, @Claude !restart. Ask for branches to be pushed as work progresses, because files left only in a released sandbox are gone.
Someone outside the team steered a session. Anyone who can post in the thread can steer it, and the earlier Claude Code in Slack app’s documentation warns that Claude may follow directions from other messages it reads. For tasks that use your personal connectors, which reach beyond the channel’s grant once you approve them, Claude Tag’s security page says Claude is designed to take direction only from you and to treat others’ thread posts as information; that is a design goal, not a control. A thread is an input channel for prompt injection. Recovery: keep bundles with write access on private channels, turn on the member restriction (on Enterprise, replies from members whose role lacks access reach Claude as context, not as requests), and rely on branch protection rather than prompt wording to stop merges.
Claude refuses to answer in a channel with contractors. By default, Claude only posts a short notice that it does not work in channels with guests. Recovery: set How should Claude work in channels with guests to Channel only on that channel’s scope. While a guest is present, Claude keeps only what is attached to that channel directly and drops inherited bundles, repositories, memory, and skills. The other option is Full access (Owner only), which keeps the scope’s full access with guests present. Choose it only for channels whose bundle you would expose to those guests. Full access is also what lets Claude post into that channel when someone asks from another channel. Slack Connect channels, shared with another company, have no setting that turns Claude on.
How do Codex and Cursor handle Slack delegation?
Section titled “How do Codex and Cursor handle Slack delegation?”This page covers Claude Tag only. In Codex, you mention @Codex with a prompt and Codex “creates a cloud chat and replies with the results” (OpenAI’s Slack documentation, checked 2026-08-28); see Codex in Slack and Linear. Cursor lists Slack among its Automations triggers for cloud agents; see Cursor cloud agents and automations. Whichever tool you choose, the same four controls apply: a narrow grant, CI gates, a second approver, and an audit trail you can name.