Anthropic assigns independent permission packages to each channel to completely block AI leak backdoors.
Anthropic has rolled out a new agent identity security mechanism for its team collaboration product, Claude Tags. Instead of borrowing human credentials, the AI now gets its own dedicated account in each channel, closing the privilege escalation loopholes that plague multi-user setups.
The old way was a security nightmare: AI tools used shared employee accounts, meaning anyone could trick the bot into revealing private files or system keys by asking the right malicious questions. Under the new architecture, the AI automatically mounts different permission packages depending on the channel. A development channel might let it write to the database, while a public channel can only read. Memory is physically isolated too — the finance channel’s sensitive secrets never bleed into the development channel. All network requests get credentials injected dynamically by a gateway; the AI itself never knows the keys, making password leaks impossible.
Future updates will add just-in-time authorization — a human pop-up confirmation for sensitive actions, with the requester’s own permissions also checked. Only when both the human and the AI have clearance will the system allow the operation, locking down privilege escalation at the foundation.