Claude Tag Now Remembers Your Slack Channels. Who Can See And Delete It?

August 4, 2026

Claude Tag keeps channel and workspace memory, uses admin-granted tools, and follows separate Slack and Claude deletion rules. Here is what teams should check.

Yes. Claude Tag can retain channel and workspace memory across Slack tasks, use tools and repositories granted by an organization owner, and keep working after the person who tagged it leaves. Admins can review, edit, and delete that memory. But deleting a Slack message, disconnecting the integration, and deleting Claude Tag memory are not documented as one automatic action.

Watch The 30-Second Summary

Watch this video on YouTube

Last updated: August 4, 2026

The Short Answer

Anthropic switched the former Claude in Slack experience to Claude Tag on August 3, 2026. The change turns Claude from a mostly request-and-response Slack app into a shared agent with persistent context, its own organization identity, inherited permissions, connected tools, schedules, and audit records.

The key privacy distinction is this:

Anthropic says commercial Claude for Work data is not used to train its generative models. That is important, but "not used for training" does not mean "not processed," "not retained as memory," or "deleted everywhere when one Slack message disappears."

Who This Is For

This guide is for:

The migration matters most when Slack contains customer conversations, legal work, incident response, source code, unreleased plans, employee matters, financial data, support tickets, or credentials embedded in old messages and files.

What Is Confirmed

1. The older Claude in Slack experience switched to Claude Tag on August 3

Anthropic's official Claude Tag help page says the existing Claude in Slack integration would switch to Claude Tag on August 3, 2026. Claude Tag is available in beta for Claude Team and Enterprise customers.

The new experience is materially broader than a one-off chatbot reply. In a channel, Claude:

Anthropic's launch announcement describes Claude Tag as a Slack teammate that can join selected channels, connect to tools, data, and codebases, and build context from the work it observes there.

2. Claude Tag memory persists across tasks

Anthropic says Claude Tag keeps context per channel and per workspace. Admins can view, edit, and delete that memory.

The company's best-practices guide adds several practical details:

This means a short prompt can activate more context than the text visible in the current thread. Claude may use retained preferences, earlier corrections, past channel decisions, shared workspace memory, connected documents, or the channel's conversation history.

3. Permissions and memory can inherit across three scopes

Anthropic documents three access levels:

Scope What it can grant Memory boundary described by Anthropic
Organization Credentials and repositories available wherever Claude Tag is installed Can be inherited by workspaces and channels
Workspace Access applying to public channels in one Slack workspace Inherits organization permissions and memory
Private channel Additional credentials or repositories for a smaller group Private-channel memory stays separate from other channels

This hierarchy is easy to misread. A tool added for organization-wide or workspace-wide use is not necessarily limited to the one Slack thread where an employee first notices it. The important control is the scope an owner chose when provisioning Claude Tag.

Anthropic recommends using a private channel for sensitive connections, such as legal tools or repositories. A private channel can add narrower credentials, but it still inherits broader organization and workspace access documented for the levels above it.

4. Channel work and direct messages use different identities and connections

In a Slack channel, Claude Tag acts under the organization's identity and uses admin-managed tools. In a direct message or Slack's assistant panel, Claude uses the capabilities enabled in the individual user's Claude account, such as personal web search or connected tools.

Anthropic says personal tools are not supposed to spill into a shared channel accidentally because the identities and connection sets are separate. That is a useful design boundary. It does not remove the need to inspect what the organization identity can access or what a user intentionally copies from a personal source into a shared thread.

5. Slack history and Claude history remain separate

Anthropic says conversations initiated in Slack do not appear in a user's Claude web chat history, and Claude web conversations are not accessible from Slack. Each platform keeps a separate conversation history.

Separate does not mean ephemeral. It means there are at least two records to reason about:

  1. the Slack messages, files, and thread history controlled by the organization's Slack settings
  2. the data Claude processes and retains to provide the integration, including persistent Claude Tag memory

Slack's current retention documentation says paid workspaces keep messages and files for the lifetime of the workspace by default unless owners configure a custom deletion policy. Enterprise exports can also follow controls that differ from what a member sees in the ordinary interface.

6. Disconnecting starts a documented Claude-side conversation deletion window

Anthropic says conversations are automatically deleted from Claude within 30 days after an organization disconnects the integration or uninstalls the app. The Slack copies continue to follow the organization's Slack retention policy.

This is a connector-level rule, not a promise that every message is deleted from every system as soon as someone removes a Slack post. An employee deleting one message, an admin deleting Claude Tag memory, a Slack retention job expiring a thread, and an owner uninstalling the integration are four different actions.

7. Commercial data is not used to train Anthropic's generative models

Anthropic's current commercial privacy guidance says a Claude for Work customer is the controller of data submitted by its users, Anthropic acts as a processor, and Anthropic does not use that commercial data to train generative models.

That narrows one important risk. It does not answer every retention or access question. Data can still be processed to provide the service, retained in histories or memory, used by connected tools under the organization's authority, included in audit records, or preserved under the customer's Slack policy.

8. Admins get an audit trail for tasks and network calls

Anthropic says the Claude Tag Audit view lists scheduled and one-time tasks plus network calls made using the agent identity. Actions can also be attributed inside connected tools: Slack posts come from the Claude app, while commits and pull requests can identify the Claude GitHub App and link back to the initiating thread.

That is stronger than a generic "the AI did it" record. It gives administrators a way to review which identity acted, which task started the work, and which network calls occurred. Teams should still decide how long those audit records are retained, who can read them, and whether they contain sensitive URLs, repository names, or task details.

What Is Still Unclear

Anthropic's documentation is unusually specific about identity, memory, and deletion, but several user-facing questions remain unanswered.

Does deleting a Slack message delete a fact Claude Tag already saved as memory?

The published docs say Slack conversations follow Slack retention and that admins can separately delete Claude Tag memory. They do not state that deleting or expiring one Slack message automatically finds and removes every fact derived from that message in channel or workspace memory.

Until Anthropic documents that linkage, administrators should treat message deletion and memory deletion as separate checks.

How long is Claude Tag memory retained while the integration stays connected?

Anthropic says memory is retained rather than discarded after each task, but the public help page does not provide a default time limit for that memory while Claude Tag remains active.

The 30-day statement is tied to disconnecting or uninstalling the integration and explicitly refers to conversations. It should not be stretched into a universal 30-day memory-retention claim.

Does disconnecting remove every derived memory item automatically?

Anthropic says integration conversations are deleted from Claude within 30 days after disconnect. The same page says admins can review or delete memory, but it does not explicitly say whether disconnecting purges all derived channel and workspace memory on the same schedule.

An organization planning offboarding or incident response should ask Anthropic to confirm the exact deletion scope and retain evidence of the admin action.

What happens when public-channel memory is useful in another channel?

Anthropic's best-practices guide says what Claude learns in a public channel is available across the workspace, while the help page describes per-channel and per-workspace memory. The high-level boundary is clear, but the public docs do not expose a field-by-field view of what gets promoted from one channel to workspace memory or when.

Admins can review and edit memory, but users should not assume that a detail is confined to the thread where it first appeared merely because that thread is the visible source.

Which connected-tool records survive after Claude forgets?

Deleting Claude Tag memory does not automatically delete a pull request, ticket, CRM update, email, document, or Slack message created by the agent. Each connected system has its own history, retention, backup, and audit controls.

This is the same source-versus-reference problem that appears when disconnecting an AI app from old chats: stopping future access and deleting already-created copies are separate jobs.

The Five-Layer Claude Tag Data Path

Use this map before deciding whether a sensitive workflow belongs in Claude Tag.

Layer Data or authority Primary control Common mistake
Slack record Messages, files, threads, edits, channel membership Slack retention, deletion, export, and legal-hold settings Assuming the integration controls Slack's copy
Claude conversation Content sent through the Slack integration Disconnect or uninstall, then the documented 30-day deletion window Assuming removal from Slack deletes Claude's copy immediately
Claude Tag memory Saved channel and workspace context, corrections, preferences Admin review, edit, and delete controls Assuming memory expires with the source message
Agent authority Organization, workspace, channel, and personal tool connections Owner-defined identity, credentials, repositories, and channel scope Assuming one thread limits a workspace-scoped credential
Downstream records Pull requests, tickets, emails, CRM changes, files, network calls, audit events Controls in every connected system plus Claude Tag audit review Assuming deleting memory reverses completed actions

Privacy reviews often stop at the first layer because Slack is where the user can see the conversation. Claude Tag makes the other four layers equally important.

What Admins Should Check Before Enabling Claude Tag

1. Inventory every identity and connection

List all organization-, workspace-, private-channel-, and personal-level connections. Record the credential owner, scopes, repositories, writable resources, expiration, and revocation path.

Ask Claude in each enabled channel what it can access, then verify that answer against the admin configuration. An agent's self-report is useful discovery evidence, not the authoritative permission record.

2. Separate sensitive workflows by channel

Use private channels for narrower legal, security, HR, customer, and financial connections. Do not place a sensitive connector at the organization or workspace level merely because several teams might occasionally need it.

Channel separation is not a complete privacy solution. It is one way to reduce who can steer the shared agent and which memory can be reused outside the intended group.

3. Review both Slack retention and Claude Tag memory

Document:

If a policy says "delete after 30 days," specify which layer it means.

4. Test offboarding before a real incident

Create harmless test data, let Claude Tag save a correction, have it create a reversible downstream record, then run the planned cleanup:

  1. delete the source Slack message
  2. check what Claude Tag still remembers
  3. delete the memory item
  4. revoke a connector credential
  5. inspect the downstream tool and audit trail
  6. disconnect the integration in a test environment if possible

The goal is to learn which cleanup steps are automatic and which require separate administrator action.

5. Keep high-impact actions approval-gated

Anthropic's guide encourages scheduled work and proactive follow-up. Those features can be useful for digests and monitoring, but tasks that send external messages, change customer records, merge code, delete data, spend money, alter permissions, or deploy systems should keep explicit human approval at the action boundary.

An audit trail explains what happened. It does not prevent an overbroad or mistaken action by itself.

6. Review memory as a living record

Stale context can be a privacy and accuracy problem. A customer classification, employee role, incident status, or access assumption can become wrong while remaining useful-looking to the agent.

Schedule periodic reviews of saved channel and workspace memory. Delete obsolete sensitive details, correct facts that changed, and record the source and date for high-impact instructions.

What This Does Not Mean

Claude Tag's August 3 migration is not evidence that Anthropic is secretly training models on every Slack workspace. Anthropic says commercial Claude for Work data is not used to train its generative models.

It also does not prove that Claude Tag ignores channel boundaries, exposes private channels to the whole company, or bypasses the access configured by an owner. Anthropic documents separate private-channel and direct-message boundaries plus organization-managed identities and audit records.

The defensible conclusion is narrower: Claude Tag creates a persistent shared-memory and tool-authority layer on top of Slack, so teams must manage conversation retention, memory deletion, permissions, and downstream records as separate controls.

Where OpenVeil Fits

Claude Tag is designed for collaborative workplace automation. OpenVeil serves a different need: a paid privacy-focused AI chat workspace with browser-local history and no server-side chat-history record for normal private chat sessions.

OpenVeil may fit when a person wants a narrower hosted chat workflow without giving an agent persistent Slack channel memory, organization-wide tool credentials, scheduled workplace tasks, or authority to act inside code and business systems. OpenVeil supports web search, uploads, voice, and image tools where enabled, but active requests can still be processed by OpenVeil and necessary AI, search, upload, hosting, routing, security, and infrastructure providers.

Browser-local history is also not the same as fully local inference. Read what browser-local AI chat history protects and what no server chat history does not mean before choosing a workflow.

For shared, persistent, tool-connected teamwork, Claude Tag may be the better product. For focused private AI chat where a normal server-stored conversation history is unwanted, review OpenVeil's privacy policy and decide whether its narrower boundary fits the task.

FAQ

Does Claude Tag read every Slack channel?

No. Anthropic says an owner chooses the channels where Claude Tag can work. Its access also depends on organization, workspace, private-channel, and personal connection scopes. Teams should verify the configured scopes rather than infer access from where one task appears.

Can anyone in a channel continue another person's Claude Tag task?

Yes. Anthropic says everyone in an enabled channel works with the same Claude and can steer or continue the shared task. That collaboration is intentional, which is why channel membership is part of the security boundary.

Does Claude Tag remember Slack conversations?

Claude Tag keeps channel and workspace context across tasks. Anthropic says public-channel learning can be available across a workspace, while private-channel and direct-message memory stays within those spaces.

Can an admin delete Claude Tag memory?

Yes. Anthropic says admins can view, edit, and delete Claude Tag memory. The public documentation does not say that deleting a Slack message automatically deletes every related memory item.

What happens after Claude Tag is disconnected?

Anthropic says integration conversations are automatically deleted from Claude within 30 days after disconnecting or uninstalling the app. Slack messages continue to follow the organization's Slack retention rules. The public documentation does not explicitly state whether every derived memory item follows that same 30-day path.

Is Claude Tag data used to train Anthropic models?

Anthropic says data submitted through its commercial Claude for Work products is not used to train generative models. Training use, service processing, conversation retention, memory, audit records, and connected-tool actions are separate questions.

Is a Claude Tag direct message private from the whole Slack channel?

Anthropic says direct messages use the individual's Claude account and personal connections, while shared channels use the organization's identity and admin-managed connections. A DM is not visible to the channel merely because the same Claude app is present there, but the individual's account and organization policies still govern the data.

Does deleting Claude Tag memory undo its actions?

No. Deleting memory does not automatically reverse a sent message, pull request, ticket, CRM update, file, email, or other record created in a connected tool. Those records must be reviewed and removed in the systems where they were created.

Bottom Line

Claude Tag's Slack migration creates a more capable shared agent—and a larger privacy boundary. Treat Slack history, Claude conversation copies, persistent memory, organization credentials, direct-message connections, downstream actions, and audit records as distinct objects.

Before using it for sensitive work, verify who can steer the agent, what it can access, what it remembers, how each layer is deleted, and which actions still require a human decision.

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.