What can Claude see through a connector, and how do you scope it down?
Last updated 2026-08-17 · Confidence: documented — Anthropic’s help center, connector pages, and Slack announcement; the no-folder-scoping-after-the-August-release check is reported, the second-account lever inferred.
A connector sees everything the connected account sees — the whole Drive, your Slack DMs — and prompts don’t narrow that. The real scoping levers are a limited second account and the permission settings, not instructions.
What a connector reaches: the whole account
Section titled “What a connector reaches: the whole account”Google Workspace: Claude accesses “the Gmail, Calendar, and Drive data for the Google account you’ve connected” and “mirrors your existing permissions”, per Anthropic’s help center. No folder or label scoping exists; a mid-August 2026 check confirmed the Gmail/Drive write release changed none of this.
Slack: the connector searches “your workspace’s channels, direct messages, and shared files”, limited to “channels and conversations you have permission to view”, per Anthropic’s announcement. Private channels you belong to are in scope.
Instructions are not access control
Section titled “Instructions are not access control”“Leave the safeguarding folder out of context” is a request the model usually honors, not a boundary — nothing stops a broad search from returning those files. Keep data Claude must never touch in a place the connected account cannot reach; save prompt-level exclusions for data that is merely noise.
The levers that do scope
Section titled “The levers that do scope”- A second, limited account. Because Claude mirrors account permissions, an account shared only into approved folders or shared drives bounds Claude exactly. The cost: Gmail and Calendar bind to that same account — see Two Google accounts.
- Per-tool permissions. Connectors split read from write tools; write actions ask “for your approval by default” (Gmail connector). See Permission modes.
- Org controls. On Team/Enterprise, owners enable each connector and set each permission category to Always allow, Needs approval, or Blocked — org-wide, “individual users can’t override it” (connectors overview). An account that seems to lack always-allow usually has it blocked there, not missing from the product — see Team data.
Q&A from calls
Section titled “Q&A from calls”Can Claude read my private Slack messages once connected? Yes — the connector searches DMs and private channels you’re in, and pulls whatever looks relevant to the query, so DMs can surface unasked. It can’t see conversations your Slack account can’t.
Sources
Section titled “Sources”- Use Google Workspace connectors — support.claude.com
- Use connectors to extend Claude’s capabilities — support.claude.com
- Claude and Slack — claude.com
- Gmail Connector — claude.com
- Slack Connector — claude.com
- Release notes — support.claude.com (no August entry alters connector scoping)