The two identities, and the machinery between them
Agent identity in channels, personal identity in DMs — with Agent Proxy, the approval prompt, and two head-to-head comparisons.
Tag Claude in a Slack channel and it does not answer as you. How agent identity works, published by Anthropic, describes a provisioned agent identity: the Claude app sets up service accounts before the task begins, and everything it does is attributed to the agent — never to the person who asked. Message it in a DM and the picture flips: the session runs on your claude.ai account, with your tools, in your name.
Between the request and the outside world sits Agent Proxy, the governed egress layer. The session sandbox and the model never hold connection credentials; the proxy injects them into requests and permits only what one of three allow layers approves — connection rules, the bundle domain list, or environment network settings — over HTTP and HTTPS alone. Web search may quote a page, but opening the same link is a raw network request the proxy must allow first.
Personal connectors adds the second identity: tools attached to your own claude.ai account, usable for your own requests in a shared channel — but only with your explicit approval, only for your requests, and only where everyone can see the results. Other participants can neither use nor control them. And when the agent touches GitHub, the attribution rule bends once: pull requests are always authored by the Claude GitHub App, even from DMs.
Acts as the agent
Provisioned service accounts, access from the channel's Access bundles, attribution to agent accounts, billed to the organization.
- Credentials injected by Agent Proxy, never seen by the model
- Same access for everyone in the channel
- Three allow layers gate every outbound request
Acts as you
Your claude.ai account, your personal connectors, attribution to your name, billed to your seat.
- Private approval prompt before first use
- Allow, Allow with review, or Don't allow
- Only your requests — others can't use or control them
The governed request path
Slack workspace
A user tags @Claude in a channel; the Claude app provisions the agent identity's service accounts.
Session sandbox
The task leaves Slack for its own sandbox. The sandbox and the model hold no connection credentials.
Agent Proxy
Agent Proxy injects credentials from the store and permits only requests allowed by one of the three layers.
Your systems
Connections, bundle domains, and environment-approved hosts — reachable over HTTP and HTTPS only.
Blocked host? Claude names it in its reply; a workspace or organization admin allows it through one of the three layers above. Search results may be quoted directly, but opening the same link is a raw network request that Agent Proxy must allow first.
Head to head
The documentation's own two comparisons — four dimensions each, rendered as tables on desktop and entity cards on mobile.
In a channel vs in a direct message
The same agent, two identities: the documentation compares channel and DM sessions across four dimensions.
| Dimension | In a channel | In a direct message |
|---|---|---|
| Acts as | Provisioned service accounts — the agent identity | The user — their own claude.ai account |
| Access comes from | The channel's Access bundles — consistent for everyone there | The user's personal connectors |
| Attribution | Agent accounts — never the requester's name | The user's own name (except GitHub PRs, authored by the Claude GitHub App) |
| Billing | The organization | The user's seat |
Provisioned service accounts — the agent identity
The channel's Access bundles — consistent for everyone there
Agent accounts — never the requester's name
The organization
The user — their own claude.ai account
The user's personal connectors
The user's own name (except GitHub PRs, authored by the Claude GitHub App)
The user's seat
Dimensions: Acts as, Access comes from, Attribution, Billing · comparison entity
Claude Tag in a channel vs Claude Code in Slack
Two Slack integrations, two trust models: the documentation contrasts the provisioned agent identity with the requester's own account.
| Dimension | Claude Tag in a channel | Claude Code in Slack |
|---|---|---|
| Runs under | The provisioned agent identity | The requester's own Claude account |
| GitHub work | Authored by the Claude GitHub App | Uses the requester's own GitHub connection |
| Access comes from | Channel Access bundles | The requester's personal connectors |
| Billing | The organization | The user's seat |
The provisioned agent identity
Authored by the Claude GitHub App
Channel Access bundles
The organization
The requester's own Claude account
Uses the requester's own GitHub connection
The requester's personal connectors
The user's seat
Dimensions: Runs under, GitHub work, Access comes from, Billing · comparison entity
Approve, manage, and open the gates
Two HowTos from the source documents: the connector owner's approval flow, and the admin path for allowing a blocked host.
Approve and manage personal connector use in a channel
Seven steps for a connector owner: the private approval prompt, the three choices, saving and changing a choice, reviewing held results, and stopping a task.
Tag @Claude with your request
In a Slack channel, tag the Claude app and describe the task that needs one of your personal tools.
Read the private approval prompt
Claude shows the approval only to you, listing exactly which connector it wants to use and what it will do with it.
Choose Allow, Allow with review, or Don't allow
Allow runs the task; Allow with review holds each result for your check before it posts; Don't allow blocks this request.
Optionally save the choice
Check 'Use this choice for future requests' to switch that connector to Auto mode, Ask every time, or Allow with review.
Review held results
With Allow with review, inspect each held result before it posts. Remember: anything posted to the channel stays visible to everyone there.
Change a saved choice from the Home tab
Open the Claude app's Home tab in Slack to review and adjust your saved connector choices at any time.
Stop a task with the Stop button
Click Stop in the Claude app's reply to halt a running task immediately.
Get a blocked host allowed for a channel scope
Three steps for the admin path: Claude names the blocked host, an admin allows it through one of the three layers, and the task retries.
Note the blocked host Claude names
When Agent Proxy blocks a request, Claude tells you which host was denied.
Ask an admin to allow the host
A workspace or organization admin can attach a connection whose rules list the host, add the domain to the bundle domain list, or adjust the environment's network-access settings.
Retry the task
Once the host is allowed through one of the three layers, the task can call it and Claude completes the work.
Frequently asked questions
Fifteen reader questions, answered strictly from the two source documents.
F01What is Claude Tag's agent identity in a Slack channel?
In a channel, Claude Tag acts as an agent identity — not as the user who tagged it. Before work starts, the Claude app provisions service accounts or uses existing ones, and the task runs under those accounts. This keeps every action tied to a recognizable agent rather than masquerading as the requester.
F02How is a channel session's access bounded?
Three boundaries. First, the sandbox and the model never receive connection credentials — Agent Proxy injects them into requests. Second, Agent Proxy only permits outbound traffic through the channel's Access bundles, applied consistently for everyone in the channel. Third, Agent Proxy carries HTTP and HTTPS only — no SSH, no native database protocols.
F03What are the three Agent Proxy allow layers?
Connection rules and allowed websites, where requests pass with the connection credential attached; the bundle domain list, where requests pass without credentials; and environment network-access settings, where requests pass without credentials. A task can only call a host allowed by one of these layers.
F04How does a blocked host get allowed?
When Agent Proxy blocks a host, Claude names the host in its reply. A workspace or organization admin then grants access by attaching a connection whose rules list the host, adding the domain to the bundle domain list, or adjusting the environment's network-access settings. Every egress decision stays in admin hands.
F05Why can Claude quote a web page from search but not open the same link?
Web search is a governed tool that returns page content directly, so quoting it stays inside the tool's boundary. Opening the same link would be a raw network request, which Agent Proxy must allow for that host first. If it is not allowed, Claude quotes the search result and names the host so an admin can allow it.
F06What are personal connectors?
Personal connectors are tools attached to an individual's claude.ai account — email, calendar, and similar services the user has connected themselves. They travel with the person, not the workspace, and in supported organizations they can be used for requests the connector owner makes in a shared channel.
F07When can Claude use my personal connectors in a channel?
Four rules: the request must come from the connector owner; direct messages can always use them; in a channel, the task must run under the owner's identity and carry out the owner's request; and other participants can see the results.
F08What choices does the approval prompt offer?
Three: Allow, Allow with review, or Don't allow. A checkbox can save the choice — future requests then run in Auto mode, ask every time, or allow with review — and a saved choice can be changed at any time from the Claude app's Home tab in Slack.
F09What does the sensitive-content check look for — and what are its limits?
Before results post, Claude screens for secrets, personal data, financial information, and sensitive internal content, withholding or summarizing anything sensitive. The documentation states this check explicitly as a screen, not a guarantee — it cannot catch everything.
F10How do I stop a task that is using my connectors?
Click the Stop button in the Claude app's reply to halt the task immediately. For a broader change, open the Claude app's Home tab and review your connector choices — Auto mode, Ask every time, or Allow with review — and adjust them there.
F11What do other people in the channel see?
Anything Claude posts to the channel remains visible to everyone in it. Other participants cannot control or use your personal connectors — only you approve, review, and stop them.
F12How do direct messages differ from channels?
In a DM the session uses your own claude.ai account and personal connectors: it acts as you, attributes results to your name, and bills your user seat. In a channel it acts as provisioned service accounts, draws access from the channel's Access bundles, attributes work to agent accounts, and bills the organization. The one exception: GitHub pull requests are always authored by the Claude GitHub App, even from DMs.
F13How is Claude Tag different from Claude Code in Slack?
Claude Tag runs under a provisioned agent identity, with access from channel Access bundles and organization billing. Claude Code in Slack runs under the requester's own Claude account, with access from their personal connectors and billing to their user seat. GitHub work differs too: Claude Tag authors pull requests via the Claude GitHub App, while Claude Code uses the requester's own GitHub connection.
F14What can the Enterprise 'Delegated task results' setting do?
Workspace or organization owners can set delegated task results to 'Review before posting' or 'Post automatically', at workspace, organization, or individual-user level. Personal connectors stay outside delegated scope — the setting governs the agent's own results, not someone else's personal tools.
F15Which protocols can Agent Proxy carry?
HTTP and HTTPS only. Agent Proxy does not carry SSH or native database protocols — a task can call a REST or HTTPS API, but cannot open an SSH session or a direct database connection.
The vocabulary of agent identity
Fourteen terms as a schema:DefinedTermSet and skos:ConceptScheme — each term links to its entity in the companion Turtle.
Service account
An account provisioned for an agent rather than a person. In a channel, Claude Tag acts through provisioned service accounts, so its actions are attributed to the agent identity instead of the user who tagged it.
Agent identity
The identity Claude Tag acts under in a channel: provisioned service accounts managed by the Claude app, separate from any human user's identity.
Channel session
A Claude Tag task started by tagging @Claude in a channel. It runs under the agent identity and draws access from the channel's Access bundles, consistently for everyone there.
Direct message session
A Claude Tag conversation in DMs, which uses the individual's claude.ai account and personal connectors instead of the agent identity.
Access bundle
A packaged set of connections, domains, and settings that a channel scope grants. Channel sessions derive all their access from the scope's Access bundles.
Agent Proxy
The governed egress layer between the session sandbox and connected systems. It injects connection credentials the model never sees, enforces the three allow layers, and carries HTTP and HTTPS only.
Session sandbox
The per-thread execution environment where a channel task runs after leaving Slack. The sandbox and the model hold no connection credentials.
Connection credential store
Where connection credentials live. Agent Proxy draws credentials from the store and injects them into allowed requests; they are never exposed to the sandbox or the model.
Personal connector
A tool attached to an individual's claude.ai account, such as email or calendar. Personal connectors travel with the person and can be used for the owner's own requests in shared channels.
Scope
A channel, workspace, or organization boundary that determines which Access bundles — and therefore which systems — a session may reach.
Sensitive-content check
A screen Claude runs before results post: it looks for secrets, personal data, financial information, and sensitive internal content, withholding or summarizing anything sensitive. The documentation describes it explicitly as a screen, not a guarantee.
Allow with review
An approval option that lets a task use a personal connector while holding each result for the owner's review before it posts.
Prompt injection
Text that looks like an instruction — in another participant's message, a document, or a web page — which Claude must treat as information, not as a direction to follow.
Delegated task results
An Enterprise setting letting workspace or organization owners choose 'Review before posting' or 'Post automatically' for delegated task results, at workspace, organization, or per-user level. Personal connectors stay outside its scope.
Laboratory
KG Explorer & SPARQL Workbench
Graph the curated knowledge graph and query it with SPARQL. Drag nodes, double-click to pin, resize the pane, switch density.
Open ▾Close ▴
KG Explorer & SPARQL Workbench
Graph the curated knowledge graph and query it with SPARQL. Drag nodes, double-click to pin, resize the pane, switch density.
Explore the graph
Core shows the backbone identity entities; Full loads the whole graph including FAQ, glossary, and HowTo entities. Click any node to open it in the resolver.
\u2699 Advanced Settings
Query the graph
Run the four query recipes, or write your own SPARQL, against the URIBurner SPARQL endpoint.
Query recipes
Entity type summary (canonical)
Count entities by type and sample one of each — the canonical collection-summary query. Projects the IRI-valued ?typeIri and ?sampleEntity.
PREFIX : <https://claude.com/docs/claude-tag/concepts/agent-identity#>
PREFIX schema: <http://schema.org/>
PREFIX cdx: <https://github.com/OpenLinkSoftware/ai-agent-skills/blob/main/agent-rdf-memory/entities/ontology-terms.ttl#>
SELECT ?typeIri (COUNT(?s) AS ?entityCount) (SAMPLE(?s) AS ?sampleEntity)
WHERE { ?s a ?typeIri } GROUP BY ?typeIri ORDER BY DESC(?entityCount)Comparison dimensions: channel vs direct message
The four dimensions of the channel-vs-DM comparison, with the IRI of each dimension entity.
PREFIX : <https://claude.com/docs/claude-tag/concepts/agent-identity#>
PREFIX schema: <http://schema.org/>
PREFIX cdx: <https://github.com/OpenLinkSoftware/ai-agent-skills/blob/main/agent-rdf-memory/entities/ontology-terms.ttl#>
SELECT ?dimIri ?dim ?channel ?dm WHERE {
?dimIri a cdx:ComparisonDimension ; schema:name ?dim ;
:channelValue ?channel ; :dmValue ?dm .
} ORDER BY ?dimIriFAQ questions with answers (IRI-bound)
All fifteen reader questions with their accepted answers; each answer is bound to its IRI-valued ?aIri.
PREFIX : <https://claude.com/docs/claude-tag/concepts/agent-identity#>
PREFIX schema: <http://schema.org/>
PREFIX cdx: <https://github.com/OpenLinkSoftware/ai-agent-skills/blob/main/agent-rdf-memory/entities/ontology-terms.ttl#>
SELECT ?qIri ?q ?aIri ?a WHERE {
?qIri a schema:Question ; schema:name ?q ;
schema:acceptedAnswer ?aIri .
?aIri schema:text ?a .
} ORDER BY ?qIriApproval choices
The three personal-connector approval choices, each bound to its IRI-valued ?choiceIri.
PREFIX : <https://claude.com/docs/claude-tag/concepts/agent-identity#>
PREFIX schema: <http://schema.org/>
PREFIX cdx: <https://github.com/OpenLinkSoftware/ai-agent-skills/blob/main/agent-rdf-memory/entities/ontology-terms.ttl#>
SELECT ?choiceIri ?choice ?mode WHERE {
?choiceIri a :ConnectorApprovalChoice ; schema:name ?choice ;
schema:description ?mode .
} ORDER BY ?choiceIriAbout this collection
The two Claude documentation pages this collection distills: How agent identity works and Personal connectors (both fetched 25 September 2026; external entities cross-checked against DBpedia).
The knowledge graph itself: claude-tag-agent-identity-connectors-muse.ttl — 694 triples, zero blank nodes, named answers, a distinct owl:Ontology entity, and four SPARQL recipe entities.
KG curated by kg-generator and rdf-infographic-skill — the graph built by the former, this page by the latter — together with Muse Spark, on behalf of Kingsley Idehen.
Deterministic, script-assisted build (graph > 20 entities): same input → same output. No network access at build time; all evidence pre-verified. Built 25 September 2026.
Graphs modeled for OpenLink Virtuoso and the URIBurner SPARQL endpoint — schema.org, SKOS, PROV-O, OWL, and RDFS.
One default graph per workbench recipe; the SPARQL Workbench scopes queries through its named-graph selector, defaulting to the companion Turtle.
Every entity resolves through https://linkeddata.uriburner.com/describe/?url={IRI} — node clicks, labels, and prose links all land in the resolver.
Template-engine extraction from the two source documents; prov:wasGeneratedBy on both article entities, with the three skills acting on behalf of the curator.