Skip to content

What can Claude see through a connector, and how do you scope it down?

Last updated 2026-08-17 · Confidence: documented — Anthropic’s help center, connector pages, and Slack announcement; the no-folder-scoping-after-the-August-release check is reported, the second-account lever inferred.

A connector sees everything the connected account sees — the whole Drive, your Slack DMs — and prompts don’t narrow that. The real scoping levers are a limited second account and the permission settings, not instructions.

What a connector reaches: the whole account

Section titled “What a connector reaches: the whole account”

Google Workspace: Claude accesses “the Gmail, Calendar, and Drive data for the Google account you’ve connected” and “mirrors your existing permissions”, per Anthropic’s help center. No folder or label scoping exists; a mid-August 2026 check confirmed the Gmail/Drive write release changed none of this.

Slack: the connector searches “your workspace’s channels, direct messages, and shared files”, limited to “channels and conversations you have permission to view”, per Anthropic’s announcement. Private channels you belong to are in scope.

“Leave the safeguarding folder out of context” is a request the model usually honors, not a boundary — nothing stops a broad search from returning those files. Keep data Claude must never touch in a place the connected account cannot reach; save prompt-level exclusions for data that is merely noise.

- A second, limited account. Because Claude mirrors account permissions, an account shared only into approved folders or shared drives bounds Claude exactly. The cost: Gmail and Calendar bind to that same account — see Two Google accounts.

  • Per-tool permissions. Connectors split read from write tools; write actions ask “for your approval by default” (Gmail connector). See Permission modes.
  • Org controls. On Team/Enterprise, owners enable each connector and set each permission category to Always allow, Needs approval, or Blocked — org-wide, “individual users can’t override it” (connectors overview). An account that seems to lack always-allow usually has it blocked there, not missing from the product — see Team data.

Can Claude read my private Slack messages once connected? Yes — the connector searches DMs and private channels you’re in, and pulls whatever looks relevant to the query, so DMs can surface unasked. It can’t see conversations your Slack account can’t.