Personal access enters the channel

Anthropic has added personal connectors to Claude Tag, its beta feature for bringing Claude into a Slack channel. The Anthropic announcement, dated 24 September, says a person can now ask Claude to use services connected to their own account for a request made in the channel. Previously, Claude could only use connectors an administrator had attached to the channel itself.

That distinction reflects how teams actually work. A project channel may share a repository, while a member alone can open a private planning document or see their own calendar and assigned customer accounts. Anthropic’s example combines channel GitHub information with a document available through the requesting person’s Google Drive connector. The access is not handed to every other channel member.

However, the output may be posted where everyone in the channel can see it. Connector access and disclosure are separate questions. A user may be permitted to read a document without being authorised to summarise it to an entire team. The new control surface therefore needs a deliberate review step, especially for sensitive information.

A choice before Claude posts

Anthropic offers a review mode that lets the requesting person inspect Claude’s response before it appears in the channel. Auto mode can post without that review unless Claude determines that content is sensitive. On Enterprise plans, administrators will be able to require review for everyone. Organisations should decide which mode fits the data involved rather than defaulting to convenience.

The company says activity through a personal connector appears in that service’s log under the person’s account. Channel connector work remains under the shared service account. This separation helps investigators understand who supplied a particular tool context, but only if the organisation retains and can correlate the relevant logs.

Anthropic says first use prompts the person when a request needs one of their connectors. They can later disconnect it. An admin should still inspect connector scopes and the service’s own permission model. A personal identity is not automatically least privilege if a user’s account can reach far more than the immediate task requires.

Shared connectors still have a job

Personal connectors do not run unattended, according to Anthropic. Scheduled routines and work Claude starts independently use connectors an administrator attached to the channel. That boundary prevents a background process from depending on an individual’s private login after the person has left the conversation or changed roles.

An on-call channel, for example, may need a shared connection to a runbook, monitoring system and deployment history so a routine can operate at any hour. A supervised drafting channel may instead use personal connections so contributors consult only what they themselves can open. Neither pattern is universally better; the nature of the work determines the identity and review model.

The new option also makes governance more granular. An administrator can choose shared agent identity for some tools, personal identity for others, or a mixture. A team should document that design so members know when Claude is acting as the channel and when it is acting through their own account.

A measured rollout

Anthropic says personal connectors are rolling out on Team plans now, with Enterprise to follow. This is not a statement that every organisation can enable it immediately. Before building a workflow around it, check the plan, admin settings and connected service behaviour in the actual tenant.

A safe pilot could ask Claude to compare a non-sensitive personal document with a shared project record, then inspect the prompt, connector logs and proposed response. Test whether review mode catches a private detail that should not be posted. Repeat with an expired or revoked connector to see whether Claude clearly explains the limitation instead of inventing an answer.

The update lets a team use richer individual context without turning every private tool into a channel-wide credential. Its value depends on preserving that boundary all the way to the posted reply. Done carefully, it can make channel assistance more useful while keeping identity, logging and human judgment visible.

Consider an employee who asks for a meeting time from a personal calendar. The safe answer may be a proposed slot, not a list of private appointments. Similarly, a CRM summary can be helpful without exposing every customer note in a broad channel. Testing should assess the content Claude reveals, not merely whether the connector obeyed its own access rules.

Teams should also plan for a person changing jobs or leaving a project. Their personal connection should not become a hidden dependency for a channel routine. Anthropic’s unattended-work boundary helps, but admins still need a clear owner for every shared connector and a process to remove access that is no longer needed.

The channel remains a social workspace. Colleagues may assume a reply from Claude is based on information available to everyone, when it could have drawn on one member’s private sources. A clear disclosure in the interaction or an internal convention can help people understand the provenance and decide whether the answer may be reused elsewhere.