Anthropic shipped something this week that looks small and is actually a big governance move. It is called Claude Tag, a Slack-based agent for Team and Enterprise plans. You summon it by typing @claude in a channel or thread, and it works with Opus 4.8. It replaces the older Claude in Slack app, with admins getting 30 days to opt in before the prior experience switches over on August 3 (9to5Mac).
On the surface that is just "chatbot in Slack, version two." Ignore the surface. The important word is identity.
What changed under the hood
Claude Tag runs under what Anthropic calls an "agent identity" model. Instead of borrowing one user’s login to do its work, Claude acts through its own service accounts. That unlocks channel-scoped permissions, separate memory between private workspaces, audit logs for the network calls and actions it takes, and admin controls over who is even allowed to use it (TestingCatalog).
If you have ever had to answer to an auditor or a security team, those four things are the whole ballgame. Let me explain why.
Why borrowing a login is the original sin
Most AI assistants bolted onto a workplace tool today run on a human’s credentials. The bot acts as you. That is convenient and it is a governance nightmare. When the agent does something, the audit log says you did it. When it has access, it has all of your access, not a scoped subset. When it remembers something from a private channel, that memory can bleed into places it should not. There is no clean line between what the human did and what the machine did.
Agent identity draws that line. The agent is its own actor with its own service account, its own permissions, and its own audit trail. You can scope it to one channel. You can see exactly what it touched. You can shut it off for specific people. That is the difference between a fun demo and something a regulated company can actually turn on.
This is not happening in isolation. Anthropic has been building the same idea across its stack — Managed Agents that run in a sandbox you control and connect to your private MCP servers, plus enterprise-managed connector access starting with Okta so admins provision once and users get zero-touch access (TestingCatalog). Claude Tag is the Slack-shaped piece of a bigger control-plane strategy.
What this means for you
If you are an enterprise IT leader, this is the kind of feature that should move an AI tool from "blocked by security" to "let’s pilot it." The objection to AI agents in a governed environment has never really been about model quality. It has been "I cannot tell what it did, I cannot scope what it can reach, and it is acting as a named employee." Agent identity answers all three. If your org runs Slack and you have been holding the line on AI agents, the ground just shifted. Go read the audit-log and permission-scoping details before your business units start asking why the answer is still no.
If you run a small business, the direct feature is gated behind Team and Enterprise tiers, so you may not flip it on tomorrow. But pay attention to the pattern, because it is going to define the next year of AI tools. The agents worth trusting are the ones that act as themselves, with their own limited keys and their own paper trail — not the ones quietly wearing your badge. When you evaluate any AI tool that takes actions on your behalf, ask one question: does it act as me, or as itself with scoped permissions? The answer tells you how much you should trust it with.
My take
I run Claude Cowork every day, and one thing I have consistently respected is that it makes the friction visible — it will not quietly log into things as me. Claude Tag is that same philosophy turned into enterprise plumbing. Giving an agent its own identity is not a flashy feature. There is no benchmark to brag about. But it is exactly the unglamorous governance work that has to happen before AI agents can be trusted with anything that matters. The companies that get identity, scoping, and audit right are the ones whose agents will still be running in production a year from now. The ones still borrowing a human’s login are building a liability. This week, Anthropic picked the right side of that line.
News commentary by Brad Rowland — IT Infrastructure and Operations leader, automation builder, and AI implementer. Sources are linked inline.
![Head-to-Head: Claude Cowork vs Microsoft Copilot Cowork — Where Each One Actually Wins [Updated June 2026] Head-to-Head: Claude Cowork vs Microsoft Copilot Cowork — Where Each One Actually Wins [Updated June 2026]](https://aitechtoolkit.com/wp-content/plugins/contextual-related-posts/default.png)

