Claude Gets a 'Staff Card' Now, From Anthropic

marsbitPublished on 2026-07-01Last updated on 2026-07-01

Abstract

"Claude now has an 'official position' as Anthropic introduces 'Claude Tag', an AI team member with its own identity in Slack. Unlike traditional AI assistants that borrow user permissions, Claude Tag operates with its own dedicated accounts and audit trails across systems like Slack, GitHub, and data warehouses—a model Anthropic calls 'agent identity'. This allows the AI to act as a shared colleague within a channel, learning from team context and even proactively addressing issues in 'eavesdrop mode'. The key shift is that permissions are tied to the channel, not individual users, enabling anyone in a channel (like a PM without repo access) to leverage Claude's capabilities. Anthropic reports using this internally, with AI generating most of their product team's code. As AI agents proliferate in enterprises, this dedicated identity model addresses the scaling and security challenges of managing non-human 'employees'."

From today onward, AI no longer borrows your work badge.

On June 23, Anthropic launched Claude Tag—an AI team member permanently residing in a Slack channel.

It doesn't use any human accounts or permissions; it has its own identity, its own account, and its own audit trail.

Anthropic calls this agent identity.

Three engineers and one PM are debugging in the same Slack channel. Someone @'s Claude, asking it to check the code repository, pull metrics from the data warehouse, and create a PR on GitHub.

So the question arises: whose permissions should the AI use?

The PM's? She doesn't have repo access. One of the engineers'? Maybe he doesn't have the necessary data warehouse permissions.

The answer is: none of the above.

When AI transitions from "a personal assistant for one person" to "a collaborative member of a team," the traditional permission model breaks down logically.

Anthropic's solution is: don't borrow anyone's permissions; issue the AI its own work badge.

An AI with a 'Staff Card' Joins Slack

Claude Tag is not a chatbot.

It's an AI colleague permanently residing in your Slack channel—with its own account, its own memory, and its own toolset.

There is only one Claude per channel, shared by everyone, and everyone can see what it's doing.

When you join, you don't need to explain the context from scratch, because it has already learned along the way from the team's conversations.

Even more impressive is the "Listen-Only Mode."

When activated, Claude monitors the channel on its own. If a thread goes unanswered or a problem isn't followed up on, it proactively steps in. No need to @ it.

For example, you open Slack on Monday morning, and Claude has already investigated the issue you left in the channel last Friday that no one picked up, waiting for your confirmation.

The AI's Own Work Badge

The core design of Claude Tag isn't a product feature; it's the permission architecture.

Anyone who has used AI assistants like ChatGPT knows they connect to your own Google Drive, GitHub, calendar, using your permissions.

But Claude Tag is multi-user—three to five people in a channel @ it in turn. Whose permissions should it use?

Anthropic's solution is called agent identity.

Claude has its own account in each system.

In Slack, it posts messages as the Claude App.

In GitHub, it creates PRs as the Claude GitHub App.

In your data warehouse, it queries using a service account configured by the administrator.

No human credentials are involved at any point.

Administrators define a baseline identity at the workspace level—Claude inherits this default configuration everywhere. Then, they can override it at the channel level:

The engineering channel gets GitHub and data warehouse access. The CRM tool is locked to the sales team's private channel. The legal channel has its own legal toolkit.

Private channels each have independent identities, while public channels share the workspace-level identity.

What Claude learns in the legal channel never appears in the engineering channel. What you discuss with Claude in DMs doesn't reach the team channels either, because DMs go through your personal claude.ai account.

Revoking permissions is simpler. Revoke one identity, and Claude is simultaneously disconnected from all access points. No need to audit dozens of user accounts one by one, because the AI never used them.

Currently, Claude Tag is in beta for Enterprise Edition ($125 per user/month) and Team Edition ($20 per user/month, annual billing) customers, with usage-based billing, using the Opus 4.8 model.

You Don't Have Repo Permissions, But the AI Does

For example, you are a product manager but don't have GitHub permissions and can't view code.

In this case, you just ask Claude in the engineering channel "why is this interface returning an error?" Claude then goes to investigate, because the channel's configuration gives Claude repo access.

Previously, this required walking over and tapping an engineer on the shoulder. Now, the AI goes to check for you.

In other words, permissions no longer follow the person; they follow the channel.

The engineering channel gives Claude repo access, so anyone in that channel can use Claude to check code—regardless of their own personal access.

Anthropic's assessment of this is: Counterintuitive, but necessary.

Counterintuitive, because it goes against a security professional's instincts.

Necessary, because in scenarios involving multi-person collaboration and increasing AI autonomy, the user-based permission model is logically untenable.

Of course, there are safeguards.

The Enterprise Edition supports RBAC, allowing administrators to decide who can @Claude and who cannot within a channel. Channel configurations can have caps set according to the least-privileged member.

Anthropic Does This Themselves

65% of the code produced by Anthropic's product team is generated by Claude, exceeding 80% as of May this year.

Engineers now merge eight times more code per day than in 2024.

"It feels like managing a team, not using a tool." This is what Boris Cherny said, and he hasn't written any code himself in half a year.

For the average worker, the feeling is more direct—

You say in the channel "this data looks wrong," and Claude goes off to check the data warehouse, locates the anomaly, writes the fix, and waits for your review. You didn't write a single line of code, but the task is done.

AI Bots Outnumber Employees 50 to 1. Who Manages Them?

Right now, many companies likely already have dozens of AI bots running. But who created them, who approved their permissions, whether they've "left the company"—probably no one can say for sure.

In large enterprises, the number of such non-human identities is 50 to 80 times that of human employees.

Data from Ramp in May 2026 shows that 34.4% of US businesses are already using paid Claude subscriptions, surpassing OpenAI's 32.3%.

And once Claude settles into a channel for half a year, accumulating the entire team's context and work habits, switching to a different AI means starting from zero.

More and more teams will encounter the problem from the beginning—whose permissions should be used?

Anthropic's answer is already given: use no one's; the AI has its own work badge.

References:

https://claude.com/blog/agent-identity-access-model

This article is from the WeChat public account "Xin Zhi Yuan" (New Wisdom Era), Author: ASI Revelations

Related Questions

QWhat is Claude Tag, and how does it differ from traditional AI assistants?

AClaude Tag is an AI team member that resides permanently within a Slack channel, created by Anthropic. Unlike traditional AI assistants that borrow a user's permissions to access systems, Claude Tag has its own identity, account, and audit trail. This means it operates independently with its own set of permissions, making it a shared collaborator within a team channel.

QWhat is 'agent identity' according to the article, and why is it significant?

A'Agent identity' is Anthropic's term for the permission architecture where Claude Tag has its own accounts in systems like Slack, GitHub, and data warehouses. This is significant because in a multi-user team setting, it eliminates the logical problem of deciding which human user's permissions an AI should use. It allows the AI to act autonomously with permissions defined at the channel level.

QHow does the permission model for Claude Tag work in a team channel?

APermissions for Claude Tag are attached to the Slack channel, not individual users. Administrators define a baseline identity for the AI at the workspace level. These permissions can be overridden at the channel level. For example, an engineering channel can grant Claude Tag access to GitHub and data warehouses, allowing anyone in that channel, even users without repo access, to query code through the AI.

QWhat are some of the operational benefits of using Claude Tag mentioned in the article?

AThe article highlights several benefits: Claude Tag can work autonomously in 'eavesdropping mode' to follow up on unanswered threads. It maintains shared memory and context for the entire team in a channel. Anthropic's own product team reportedly generates 65-80% of its code with Claude, increasing engineer output. It simplifies permission revocation, as disabling the AI's single identity disconnects it from all systems at once.

QWhat problem in enterprise AI management does Claude Tag's 'agent identity' aim to solve?

AIt solves the growing problem of managing numerous non-human AI identities within large companies. These identities can outnumber human employees by 50-80 times, making it difficult to track their creation, permissions, and deactivation. The 'agent identity' model centralizes control, providing clear audit trails and allowing administrators to manage AI permissions separately from human user accounts.

Related Reads

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

Ray Dalio, founder of Bridgewater Associates, warns in an interview that the current AI boom shows classic bubble characteristics, which could lead to significant economic downturns as seen in past cycles like 1929 or 2000. He explains that speculative enthusiasm, fueled by debt and overvaluation, often precedes a crash when rising rates or taxation force asset sales, causing widespread losses and recession. Dalio also outlines his "Big Cycle" theory, describing an approximate 80-year pattern where widening wealth gaps, massive government deficits, and shifting geopolitical power (like China's rise) create internal conflict and global instability. He emphasizes that we are in a late-cycle, transitional phase where traditional powers like the US and UK face decline. For personal wealth protection, Dalio advises diversification beyond cash into assets like stocks, bonds, real estate, and particularly gold, which he prefers over Bitcoin. While he holds about 1% of his portfolio in Bitcoin as a non-printable hard asset, he views gold as more secure from technological or governmental threats. Regarding AI's impact, Dalio believes it will disproportionately benefit capital owners, worsening inequality by replacing both physical and cognitive labor. He suggests that human intuition and emotional intelligence, combined with AI, will be key for future workers. On taxation, Dalio argues that wealth taxes are impractical and risk triggering asset sell-offs, reducing productive investment. He points to the UK as a cautionary example of debt, low productivity, and political strife. Geopolitically, Dalio foresees a more regionalized world, with the US showing weakness in prolonged conflicts like with Iran, akin to past imperial declines. The ideal outcome, he suggests, is coexisting powerful blocs (e.g., Americas, China-Asia Pacific) without major war.

marsbit2h ago

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

marsbit2h ago

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

South Korean stock market sees a dramatic shift in fund flows. On July 31, foreign investors made a record net purchase of approximately KRW 7.2 trillion in KOSPI stocks, marking a fundamental reversal from the persistent large-scale net outflows seen in previous months. This contributed to a significant narrowing of foreign net selling in July to KRW 9.8 trillion, down sharply from KRW 48.4 trillion in June and KRW 44.5 trillion in May. Simultaneously, domestic institutional pressure eased. South Korean pension funds and asset managers turned to a net buying position in July, purchasing KRW 1.0 trillion worth of KOSPI shares, contrasting with net sales in May and June. Market volatility is expected to be dampened by new financial regulations. Effective July 31, the Financial Services Commission tightened access for retail investors to single-stock leveraged ETFs by raising the minimum cash deposit requirement. Trading volumes for these products subsequently dropped to about 50% of their monthly average. Citigroup Research maintains its year-end KOSPI target of 10,000 points. The firm cites several supportive factors: the substantial easing of headwinds from capital outflows, a robust fundamental outlook for the semiconductor sector, historically low market valuations, strong economic fundamentals, and the potential for policy support from financial authorities if needed.

marsbit2h ago

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

marsbit2h ago

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ru7h ago

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ru7h ago

Trading

Spot
活动图片