Engineering
Claude Tag: what an agent living in Slack changes
Claude Tag installs an agent as a member of a Slack channel, with an ambient mode that speaks unprompted. What it changes, and what it does not do.
Claude Tag installs Claude as a member of a Slack channel, summonable by anyone with @Claude, and the change is not the conversation, it is the location. The agent sits where the work is discussed instead of waiting in a tab somebody has to remember to open, and that difference of position produces another one, more interesting still: it can speak first.
Announced on 23 June 2026 in beta for Team and Enterprise customers, it runs on Opus 4.8 and replaces the previous Claude for Slack app, with thirty days to migrate. We build an agent that also lives in team messaging, which gives this article a bias I would rather declare, and an experience of the same problems that is probably worth more than a commentary on a press release.
What is Claude Tag, concretely?
It is an agent added to specific channels, with one identity shared by everyone in them. Anthropic uses the word “multiplayer” and it is well chosen: this is not one assistant each, it is the same interlocutor for the whole team, which sees the exchanges go by and therefore does not need briefing on every request.
It breaks a request into steps, calls the tools and sources it has been granted, works asynchronously while you do something else, and can schedule a task for later. Administrators set access channel by channel, private channels are out of reach, and the activity log records who asked for what.
That architecture deserves to be taken seriously even if you do not use Slack, because it publicly validates a hypothesis we have held from the start: enterprise software does not need a new interface, it needs to come into the one people are already in. That is the movement we described in the end of interfaces, not the end of software, and seeing it ship at Anthropic is better evidence than anything we could write about it.
Ambient mode is the real subject, and the real difficulty
The setting that separates Claude Tag from a conventional assistant is the one letting it step in without being summoned: flagging a thread left unanswered, chasing an unresolved task, surfacing information at the moment it becomes relevant. That is the good idea in the product, and it is also the one that decides whether it gets adopted or switched off.
We have built this function and I can say where the difficulty sits, because it is not where you expect. Deciding to speak is easy, a trigger is enough. Deciding to stay quiet is the real work, and an agent that flags everything it notices becomes, within a week, one more notification the team learns to skim and then to mute. An agent silenced by excess of zeal is strictly less useful than an agent you summon, because it has also spent the trust.
The criterion we ended up with is blunt and fits in one sentence: the agent speaks only if it brings something finished. Not “this thread looks stuck”, but the follow-up already drafted, with the context explaining why it is going out now. The difference between the two is what separates a colleague from a calendar reminder, and it is paid for in design work rather than in settings exposed to the user.
Where does the approval line sit when the agent acts alone?
An agent that steps in by itself makes the question of control more urgent, and the answer does not lie in the opposition between autonomous and supervised. It lies in the direction of the action: what stays inside the company can happen without approval, what leaves it goes through a person.
Flagging a stalled thread, summarising a channel, preparing a document, none of that deserves any ceremony. Writing to a client, replying to a candidate, publishing anything under the company’s name belongs to the other category, whatever level of trust has accumulated. That is the rule we apply without exception and set out in who approves what when an AI writes to your candidates, and its main virtue is that it is not negotiated case by case.
What makes that line hold is that it is written into the product rather than into the instructions. A rule written in plain language is worked around by another sentence in plain language, whereas a permission never granted cannot be negotiated, and it is the only limit that holds once the content being read can itself contain instructions.
Billing the organisation rather than the seat, at last
Here is the point on which I side with Anthropic without reservation, because it runs against the immediate commercial interest of any software vendor.
Claude Tag spend is capped by the administrator, globally and channel by channel, and it is charged to the organisation rather than to the user who typed the request. That is the right model for an agent, and the opposite of the per-seat price we explain elsewhere is broken: when you charge for access, a vendor gains from as many people as possible opening the product, whereas the buyer gains from the work being done by as few as possible. Charging for the work realigns the two.
The counterpart is a variable invoice, which has to be learned, and launch credits that make the first months deceptively quiet. The right question is not what the first quarter costs, it is what the month costs once the credits are exhausted and usage has settled in.
What Claude Tag does not do, and does not claim to
It learns from its channels and from the sources it is granted, not from your business systems. The distinction is decisive for a services firm or an agency, because the raw material of the work is not in the conversation: it is in the ATS, the CRM, the staffing tracker, and a large part of the job consists precisely of writing into them.
An agent that summarises a thread and drafts a message renders a real service. An agent that updates the record, produces the list of consultants available in three weeks and prepares the skills dossier in the client’s format is doing another job, one that assumes write permissions, business connectors and a memory whose forgetting has been decided. This is not a criticism of Anthropic’s product, which does not claim that ground, it is the border to know before concluding you are equipped.
The other limit is one of surface. Claude Tag exists on Slack only at launch, with Anthropic announcing its intention to expand, so a European company running on Microsoft 365 is not concerned for now. That is a scheduling constraint rather than a weakness, but it plans like a real one.
Which settings should you make on day one?
Three decisions matter more than all the others, and they are taken before the internal announcement rather than after the first complaints.
Channel scope. The temptation is to add the agent everywhere so it learns fast, and that is the mistake that costs most, because a channel added is a channel whose history becomes readable. Start with two or three team channels where the work is genuinely discussed, leaving aside those carrying information about people.
The ambient threshold. If a frequency setting exists, put it at minimum for a month and raise it only if somebody complains about the silence. The reverse order cannot be recovered: a team that has muted an agent’s notifications does not turn them back on, and you will have burnt the most interesting function of the product to gain two weeks.
The spend cap. Set it per channel from the start, at a figure that would make you shrug rather than one that strikes you as generous. An asynchronous agent that triggers itself is a cost line with real variance, and the cap serves as much to detect abnormal usage as to limit it.
One agent identity, or several?
Administrators can create separate identities with scoped memories, and that option raises a question we had to settle on our side, without a clean solution.
Scoping is right from a security standpoint, since a memory crossing a team boundary is a leak waiting to happen. Scoping is expensive from a usefulness standpoint, since each identity restarts with its own view of you and the two diverge without ever announcing it. It is the same trade-off faced by companies discovering they run twelve agents, half of which do not talk to each other, and the wording we use to settle it is this: an agent holding context about you must be unique, an agent holding an expertise can be called as often as you like.
Applied to Claude Tag, it gives a simple rule of use. One identity per real confidentiality boundary, never one per team or per project, on pain of rebuilding the silo the agent was meant to remove.
Which leaves the question that comes straight after, once several agents genuinely coexist: how do you tell the one that really works from the one rebranded for the occasion? That is the subject of agent washing and the grid that detects it.
Frequently asked questions
What is Claude Tag?
It is how Anthropic installs Claude inside Slack since 23 June 2026: an agent added to specific channels, summoned by anyone typing @Claude, which accumulates context from the conversations it follows. It replaces the previous Claude for Slack app, with a thirty-day migration window.
Does Claude Tag work on Microsoft Teams?
No, not at launch. Claude Tag is available on Slack only, with Anthropic stating it intends to expand to the other places teams work. For a European company running on Microsoft 365 that limit matters, since team messaging there is overwhelmingly Teams.
What is Claude Tag’s ambient mode?
It is the setting that lets the agent step in without being summoned: flagging a thread left unanswered, chasing an unresolved task, surfacing a relevant piece of information. It is what most clearly separates it from a conventional assistant, and it is also the setting that decides whether it becomes a useful colleague or a source of noise.
Does an administrator keep control of what the agent sees?
Yes. Access is set channel by channel, private channels are excluded, and administrators can create separate identities with scoped memories, cap token spend both organisation-wide and per channel, and review an activity log naming who requested each task.
Sources
Read next
Engineering
An AI agent’s memory: what it has to forgetA memory that swells unfiltered drops accuracy from 39 to 13 %. What an agent forgets matters as much as what it keeps, and that is settled at design time.Vision
The end of interfaces, not the end of softwareAt Supabase, 60% of new databases are launched by an agent, and probably 90%. What is dying is not the software: it is the access layer.Product
Twelve agents that do not talk to each otherA company runs twelve agents on average and half of them work alone. The right criterion is not how many you have, it is how many contexts you duplicate.
