When multiple people share a single AI assistant for work, it's easy for sensitive data to leak across channels. Anthropic has unveiled a new security architecture for its team collaboration feature, Claude Tags, that completely changes how AI handles credentials. Instead of letting AI act on behalf of a human employee's account, the system now assigns each AI its own independent identity. That means when Claude posts in Slack, commits code on GitHub, or queries a data warehouse, it does so under its own account.
Enterprise administrators can centrally control which tools and repositories the AI can access, and fine-tune permissions on a per-channel basis. For example, only a specific development channel might be allowed to write to a database, while public channels are read-only. Because the AI has a unique identity in every private channel, sensitive conversations and accumulated memory in legal or finance channels never leak elsewhere in the workspace. For direct messages, Claude falls back to the personal account system to securely handle private tasks like writing emails.
During runtime, security credentials are loaded dynamically only when a network request is made. If the AI tries to reach an external server that an admin has blocked, the request is intercepted immediately. Administrators can also track AI-specific audit logs in the connected system's logs. In the future, the system will support just-in-time authorization — a human pop-up confirmation for sensitive operations — and will also cross-check the initiating user's permissions, so an action only goes through if both the human and the AI are authorized, minimizing the risk of privilege abuse.