Navigation

Agent identity × Personal connectors · a knowledge-graph edition

Two Identities, One Agent.
Yours, on approval.

Claude Tag gives an AI agent two different identities depending on where it is asked to work. In a Slack channel it acts through provisioned service accounts, its access bounded by the channel's Access bundles and enforced by Agent Proxy's three allow layers — with the sandbox and model never seeing connection credentials. In direct messages it acts as the user, on their claude.ai account, with their personal connectors, subject to explicit approval before first use. This collection models both identities, their two native comparisons, the approval machinery, and the governed request path as a queryable knowledge graph.

In a channel

The agent identity

  • Provisioned service accounts
  • Access from channel Access bundles
  • Attribution to agent accounts
  • Billed to the organization
In a direct message

Your identity

  • Your claude.ai account
  • Your personal connectors
  • Attribution to your name
  • Billed to your seat

Distilled from How agent identity works and Personal connectors · KG built 25 September 2026

Overview

The two identities, and the machinery between them

Agent identity in channels, personal identity in DMs — with Agent Proxy, the approval prompt, and two head-to-head comparisons.

Tag Claude in a Slack channel and it does not answer as you. How agent identity works, published by Anthropic, describes a provisioned agent identity: the Claude app sets up service accounts before the task begins, and everything it does is attributed to the agent — never to the person who asked. Message it in a DM and the picture flips: the session runs on your claude.ai account, with your tools, in your name.

Between the request and the outside world sits Agent Proxy, the governed egress layer. The session sandbox and the model never hold connection credentials; the proxy injects them into requests and permits only what one of three allow layers approves — connection rules, the bundle domain list, or environment network settings — over HTTP and HTTPS alone. Web search may quote a page, but opening the same link is a raw network request the proxy must allow first.

Personal connectors adds the second identity: tools attached to your own claude.ai account, usable for your own requests in a shared channel — but only with your explicit approval, only for your requests, and only where everyone can see the results. Other participants can neither use nor control them. And when the agent touches GitHub, the attribution rule bends once: pull requests are always authored by the Claude GitHub App, even from DMs.

Channel identity

Acts as the agent

Provisioned service accounts, access from the channel's Access bundles, attribution to agent accounts, billed to the organization.

  • Credentials injected by Agent Proxy, never seen by the model
  • Same access for everyone in the channel
  • Three allow layers gate every outbound request
Personal identity

Acts as you

Your claude.ai account, your personal connectors, attribution to your name, billed to your seat.

  • Private approval prompt before first use
  • Allow, Allow with review, or Don't allow
  • Only your requests — others can't use or control them

The governed request path

Where the request starts

Slack workspace

A user tags @Claude in a channel; the Claude app provisions the agent identity's service accounts.

Per-thread execution

Session sandbox

The task leaves Slack for its own sandbox. The sandbox and the model hold no connection credentials.

Governed egress

Agent Proxy

Agent Proxy injects credentials from the store and permits only requests allowed by one of the three layers.

Connected tools

Your systems

Connections, bundle domains, and environment-approved hosts — reachable over HTTP and HTTPS only.

L1Connection rules and allowed websites — credential attachedL2Bundle domain list — no credentialsL3Environment network-access settings — no credentials

Blocked host? Claude names it in its reply; a workspace or organization admin allows it through one of the three layers above. Search results may be quoted directly, but opening the same link is a raw network request that Agent Proxy must allow first.

Head to head

The documentation's own two comparisons — four dimensions each, rendered as tables on desktop and entity cards on mobile.

In a channel vs in a direct message

The same agent, two identities: the documentation compares channel and DM sessions across four dimensions.

DimensionIn a channelIn a direct message
Acts asProvisioned service accounts — the agent identityThe user — their own claude.ai account
Access comes fromThe channel's Access bundles — consistent for everyone thereThe user's personal connectors
AttributionAgent accounts — never the requester's nameThe user's own name (except GitHub PRs, authored by the Claude GitHub App)
BillingThe organizationThe user's seat
Acts as

Provisioned service accounts — the agent identity

Access comes from

The channel's Access bundles — consistent for everyone there

Attribution

Agent accounts — never the requester's name

Billing

The organization

Acts as

The user — their own claude.ai account

Access comes from

The user's personal connectors

Attribution

The user's own name (except GitHub PRs, authored by the Claude GitHub App)

Billing

The user's seat

Dimensions: Acts as, Access comes from, Attribution, Billing · comparison entity

Claude Tag in a channel vs Claude Code in Slack

Two Slack integrations, two trust models: the documentation contrasts the provisioned agent identity with the requester's own account.

DimensionClaude Tag in a channelClaude Code in Slack
Runs underThe provisioned agent identityThe requester's own Claude account
GitHub workAuthored by the Claude GitHub AppUses the requester's own GitHub connection
Access comes fromChannel Access bundlesThe requester's personal connectors
BillingThe organizationThe user's seat
Runs under

The provisioned agent identity

GitHub work

Authored by the Claude GitHub App

Access comes from

Channel Access bundles

Billing

The organization

Runs under

The requester's own Claude account

GitHub work

Uses the requester's own GitHub connection

Access comes from

The requester's personal connectors

Billing

The user's seat

Dimensions: Runs under, GitHub work, Access comes from, Billing · comparison entity

HowTo

Approve, manage, and open the gates

Two HowTos from the source documents: the connector owner's approval flow, and the admin path for allowing a blocked host.

Approve and manage personal connector use in a channel

Seven steps for a connector owner: the private approval prompt, the three choices, saving and changing a choice, reviewing held results, and stopping a task.

1

Tag @Claude with your request

In a Slack channel, tag the Claude app and describe the task that needs one of your personal tools.

2

Read the private approval prompt

Claude shows the approval only to you, listing exactly which connector it wants to use and what it will do with it.

3

Choose Allow, Allow with review, or Don't allow

Allow runs the task; Allow with review holds each result for your check before it posts; Don't allow blocks this request.

4

Optionally save the choice

Check 'Use this choice for future requests' to switch that connector to Auto mode, Ask every time, or Allow with review.

5

Review held results

With Allow with review, inspect each held result before it posts. Remember: anything posted to the channel stays visible to everyone there.

6

Change a saved choice from the Home tab

Open the Claude app's Home tab in Slack to review and adjust your saved connector choices at any time.

7

Stop a task with the Stop button

Click Stop in the Claude app's reply to halt a running task immediately.

Get a blocked host allowed for a channel scope

Three steps for the admin path: Claude names the blocked host, an admin allows it through one of the three layers, and the task retries.

1

Note the blocked host Claude names

When Agent Proxy blocks a request, Claude tells you which host was denied.

2

Ask an admin to allow the host

A workspace or organization admin can attach a connection whose rules list the host, add the domain to the bundle domain list, or adjust the environment's network-access settings.

3

Retry the task

Once the host is allowed through one of the three layers, the task can call it and Claude completes the work.

FAQ

Frequently asked questions

Fifteen reader questions, answered strictly from the two source documents.

F01What is Claude Tag's agent identity in a Slack channel?

In a channel, Claude Tag acts as an agent identity — not as the user who tagged it. Before work starts, the Claude app provisions service accounts or uses existing ones, and the task runs under those accounts. This keeps every action tied to a recognizable agent rather than masquerading as the requester.

F02How is a channel session's access bounded?

Three boundaries. First, the sandbox and the model never receive connection credentials — Agent Proxy injects them into requests. Second, Agent Proxy only permits outbound traffic through the channel's Access bundles, applied consistently for everyone in the channel. Third, Agent Proxy carries HTTP and HTTPS only — no SSH, no native database protocols.

F03What are the three Agent Proxy allow layers?

Connection rules and allowed websites, where requests pass with the connection credential attached; the bundle domain list, where requests pass without credentials; and environment network-access settings, where requests pass without credentials. A task can only call a host allowed by one of these layers.

F04How does a blocked host get allowed?

When Agent Proxy blocks a host, Claude names the host in its reply. A workspace or organization admin then grants access by attaching a connection whose rules list the host, adding the domain to the bundle domain list, or adjusting the environment's network-access settings. Every egress decision stays in admin hands.

F05Why can Claude quote a web page from search but not open the same link?

Web search is a governed tool that returns page content directly, so quoting it stays inside the tool's boundary. Opening the same link would be a raw network request, which Agent Proxy must allow for that host first. If it is not allowed, Claude quotes the search result and names the host so an admin can allow it.

F06What are personal connectors?

Personal connectors are tools attached to an individual's claude.ai account — email, calendar, and similar services the user has connected themselves. They travel with the person, not the workspace, and in supported organizations they can be used for requests the connector owner makes in a shared channel.

F07When can Claude use my personal connectors in a channel?

Four rules: the request must come from the connector owner; direct messages can always use them; in a channel, the task must run under the owner's identity and carry out the owner's request; and other participants can see the results.

F08What choices does the approval prompt offer?

Three: Allow, Allow with review, or Don't allow. A checkbox can save the choice — future requests then run in Auto mode, ask every time, or allow with review — and a saved choice can be changed at any time from the Claude app's Home tab in Slack.

F09What does the sensitive-content check look for — and what are its limits?

Before results post, Claude screens for secrets, personal data, financial information, and sensitive internal content, withholding or summarizing anything sensitive. The documentation states this check explicitly as a screen, not a guarantee — it cannot catch everything.

F10How do I stop a task that is using my connectors?

Click the Stop button in the Claude app's reply to halt the task immediately. For a broader change, open the Claude app's Home tab and review your connector choices — Auto mode, Ask every time, or Allow with review — and adjust them there.

F11What do other people in the channel see?

Anything Claude posts to the channel remains visible to everyone in it. Other participants cannot control or use your personal connectors — only you approve, review, and stop them.

F12How do direct messages differ from channels?

In a DM the session uses your own claude.ai account and personal connectors: it acts as you, attributes results to your name, and bills your user seat. In a channel it acts as provisioned service accounts, draws access from the channel's Access bundles, attributes work to agent accounts, and bills the organization. The one exception: GitHub pull requests are always authored by the Claude GitHub App, even from DMs.

F13How is Claude Tag different from Claude Code in Slack?

Claude Tag runs under a provisioned agent identity, with access from channel Access bundles and organization billing. Claude Code in Slack runs under the requester's own Claude account, with access from their personal connectors and billing to their user seat. GitHub work differs too: Claude Tag authors pull requests via the Claude GitHub App, while Claude Code uses the requester's own GitHub connection.

F14What can the Enterprise 'Delegated task results' setting do?

Workspace or organization owners can set delegated task results to 'Review before posting' or 'Post automatically', at workspace, organization, or individual-user level. Personal connectors stay outside delegated scope — the setting governs the agent's own results, not someone else's personal tools.

F15Which protocols can Agent Proxy carry?

HTTP and HTTPS only. Agent Proxy does not carry SSH or native database protocols — a task can call a REST or HTTPS API, but cannot open an SSH session or a direct database connection.

Glossary

The vocabulary of agent identity

Fourteen terms as a schema:DefinedTermSet and skos:ConceptScheme — each term links to its entity in the companion Turtle.

Service account

An account provisioned for an agent rather than a person. In a channel, Claude Tag acts through provisioned service accounts, so its actions are attributed to the agent identity instead of the user who tagged it.

Agent identity

The identity Claude Tag acts under in a channel: provisioned service accounts managed by the Claude app, separate from any human user's identity.

Channel session

A Claude Tag task started by tagging @Claude in a channel. It runs under the agent identity and draws access from the channel's Access bundles, consistently for everyone there.

Direct message session

A Claude Tag conversation in DMs, which uses the individual's claude.ai account and personal connectors instead of the agent identity.

Access bundle

A packaged set of connections, domains, and settings that a channel scope grants. Channel sessions derive all their access from the scope's Access bundles.

Agent Proxy

The governed egress layer between the session sandbox and connected systems. It injects connection credentials the model never sees, enforces the three allow layers, and carries HTTP and HTTPS only.

Session sandbox

The per-thread execution environment where a channel task runs after leaving Slack. The sandbox and the model hold no connection credentials.

Connection credential store

Where connection credentials live. Agent Proxy draws credentials from the store and injects them into allowed requests; they are never exposed to the sandbox or the model.

Personal connector

A tool attached to an individual's claude.ai account, such as email or calendar. Personal connectors travel with the person and can be used for the owner's own requests in shared channels.

Scope

A channel, workspace, or organization boundary that determines which Access bundles — and therefore which systems — a session may reach.

Sensitive-content check

A screen Claude runs before results post: it looks for secrets, personal data, financial information, and sensitive internal content, withholding or summarizing anything sensitive. The documentation describes it explicitly as a screen, not a guarantee.

Allow with review

An approval option that lets a task use a personal connector while holding each result for the owner's review before it posts.

Prompt injection

Text that looks like an instruction — in another participant's message, a document, or a web page — which Claude must treat as information, not as a direction to follow.

Delegated task results

An Enterprise setting letting workspace or organization owners choose 'Review before posting' or 'Post automatically' for delegated task results, at workspace, organization, or per-user level. Personal connectors stay outside its scope.

Laboratory

KG Explorer & SPARQL Workbench

Graph the curated knowledge graph and query it with SPARQL. Drag nodes, double-click to pin, resize the pane, switch density.

Open ▾Close ▴
KG Explorer

Explore the graph

Core shows the backbone identity entities; Full loads the whole graph including FAQ, glossary, and HowTo entities. Click any node to open it in the resolver.

— nodes / — links
Click outside to release zoom
Types:
Classes
Instances
Channel-identity entities
Personal-connector entities

\u2699 Advanced Settings

-400
90px
Toggle predicates
SPARQL Workbench

Query the graph

Run the four query recipes, or write your own SPARQL, against the URIBurner SPARQL endpoint.

Query recipes

Entity type summary (canonical)

Count entities by type and sample one of each — the canonical collection-summary query. Projects the IRI-valued ?typeIri and ?sampleEntity.

Run live query (query entity)

PREFIX : <https://claude.com/docs/claude-tag/concepts/agent-identity#>
PREFIX schema: <http://schema.org/>
PREFIX cdx: <https://github.com/OpenLinkSoftware/ai-agent-skills/blob/main/agent-rdf-memory/entities/ontology-terms.ttl#>
SELECT ?typeIri (COUNT(?s) AS ?entityCount) (SAMPLE(?s) AS ?sampleEntity)
WHERE { ?s a ?typeIri } GROUP BY ?typeIri ORDER BY DESC(?entityCount)
Comparison dimensions: channel vs direct message

The four dimensions of the channel-vs-DM comparison, with the IRI of each dimension entity.

Run live query (query entity)

PREFIX : <https://claude.com/docs/claude-tag/concepts/agent-identity#>
PREFIX schema: <http://schema.org/>
PREFIX cdx: <https://github.com/OpenLinkSoftware/ai-agent-skills/blob/main/agent-rdf-memory/entities/ontology-terms.ttl#>
SELECT ?dimIri ?dim ?channel ?dm WHERE {
  ?dimIri a cdx:ComparisonDimension ; schema:name ?dim ;
          :channelValue ?channel ; :dmValue ?dm .
} ORDER BY ?dimIri
FAQ questions with answers (IRI-bound)

All fifteen reader questions with their accepted answers; each answer is bound to its IRI-valued ?aIri.

Run live query (query entity)

PREFIX : <https://claude.com/docs/claude-tag/concepts/agent-identity#>
PREFIX schema: <http://schema.org/>
PREFIX cdx: <https://github.com/OpenLinkSoftware/ai-agent-skills/blob/main/agent-rdf-memory/entities/ontology-terms.ttl#>
SELECT ?qIri ?q ?aIri ?a WHERE {
  ?qIri a schema:Question ; schema:name ?q ;
        schema:acceptedAnswer ?aIri .
  ?aIri schema:text ?a .
} ORDER BY ?qIri
Approval choices

The three personal-connector approval choices, each bound to its IRI-valued ?choiceIri.

Run live query (query entity)

PREFIX : <https://claude.com/docs/claude-tag/concepts/agent-identity#>
PREFIX schema: <http://schema.org/>
PREFIX cdx: <https://github.com/OpenLinkSoftware/ai-agent-skills/blob/main/agent-rdf-memory/entities/ontology-terms.ttl#>
SELECT ?choiceIri ?choice ?mode WHERE {
  ?choiceIri a :ConnectorApprovalChoice ; schema:name ?choice ;
         schema:description ?mode .
} ORDER BY ?choiceIri
About

About this collection

Source material

The two Claude documentation pages this collection distills: How agent identity works and Personal connectors (both fetched 25 September 2026; external entities cross-checked against DBpedia).

Companion files

The knowledge graph itself: claude-tag-agent-identity-connectors-muse.ttl — 694 triples, zero blank nodes, named answers, a distinct owl:Ontology entity, and four SPARQL recipe entities.

Skills used

KG curated by kg-generator and rdf-infographic-skill — the graph built by the former, this page by the latter — together with Muse Spark, on behalf of Kingsley Idehen.

Generation environment

Deterministic, script-assisted build (graph > 20 entities): same input → same output. No network access at build time; all evidence pre-verified. Built 25 September 2026.

Linked Data runtime

Graphs modeled for OpenLink Virtuoso and the URIBurner SPARQL endpoint — schema.org, SKOS, PROV-O, OWL, and RDFS.

Named graphs

One default graph per workbench recipe; the SPARQL Workbench scopes queries through its named-graph selector, defaulting to the companion Turtle.

Resolver pattern

Every entity resolves through https://linkeddata.uriburner.com/describe/?url={IRI} — node clicks, labels, and prose links all land in the resolver.

Extraction provenance

Template-engine extraction from the two source documents; prov:wasGeneratedBy on both article entities, with the three skills acting on behalf of the curator.