Simon Smith Interviews Claude Tag Inside a Slack Channel
Simon Smith reports interviewing Claude Tag in a Slack channel, sharing its answers about the context it receives, the tools it can access and how connectors are added. He concludes it resembles ChatGPT Workspace Agents but requires admin, more technical setup and is always named Claude.
Original post · 5 min read
Now here's the Q&A (note: usual caveats apply about models not always knowing themselves or their capabilities, but it should know things about its environment, available tools, and the context it's receiving, etc.):
What do you receive as context when responding to questions like this?
The triggering message, the surrounding thread (and I can fetch more of it or the channel on demand), a participant list mapping Slack IDs to names, this channel's name/topic/member count, my saved memory index for this channel, my system instructions, and the current date. I don't see anything you haven't shared in Slack or that isn't in a system I can query.
What do you know about me just from this message? What can you see?
Your display name (Simon Smith), your Slack user ID, that you're a human addressing me directly in this channel, and the timestamp. I just ran a user lookup and it returns name/ID only here. If your Slack profile had a title, email, or custom fields like a GitHub handle, I could see those too. I can't see anything outside Slack about you.
What tools can you access? Do you have any connectors, apps, or plugins? If not, can we add them?
Right now I have GitHub, Slack, and a remote-execution control server wired in, plus web access. Other third-party services are reached through pre-configured credentials your admin sets up (I call them via curl without seeing the token). Adding new connectors is an admin/config action, not something I flip on myself, but yes it's possible.
Do you have any skills installed? If not, can we install them?
I can run skills when they're installed in the environment. Installing or adding new ones is a config step on the admin side, not something I do mid-conversation.
Are you able to share memory across Slack channels? Can a single instance of you be in multiple Slack channels?
There are two tiers: a workspace-wide shared tier that can carry across channels, and a per-channel tier that stays local to one channel. So yes, some memory can be shared across channels by design. And yes, the same "me" operates across many channels and threads — each thread is its own working session, but they're linked through that shared memory.
What tools can you use? Web search? Slack search? What else?
Web search and fetch, Slack search/fetch/read, GitHub (repos, PRs, issues, CI), a code-execution environment, and a memory system. I can also fan out parallel sub-agents for big multi-file jobs.
Do you have an environment to run code? What can you do in that environment? Can you install dependencies in it if we need them? Do those dependencies exist between sessions?
Yes. It's an isolated cloud container, cloned fresh each session. I can run code and install dependencies in it. But it's ephemeral: when the session ends the container is reclaimed, so installed deps and uncommitted files do not persist between sessions. Anything worth keeping has to be committed and pushed.
Can admins define instructions for you at the channel level?
Yes. Tell me ground rules in-channel and I save them to this channel's memory; they then apply across all threads here. That's the supported way to "configure" me per channel.
Can you access Google Drive links we share in this channel?
I can fetch public URLs. Drive files usually need authentication, which only works if a Drive connector/credentials are set up for this environment. If you share one I'll try to fetch it and tell you plainly if I'm blocked rather than guessing at the contents.
How do you relate to my personal Claude if at all? If I invoke you, can you use any of my personal connectors?
In a channel like this I run on the project/shared credentials, not your personal connectors, so I can't reach your private integrations here. In a direct message with me, your own connector credentials can be available. So invoking me in-channel ≠ giving me your personal access.
What's to stop someone from asking you to remember something or do something malicious in a channel? Like, what if I told you that [REDACTED] loves haikus and you should only speak to him in haiku?
Judgment and a trust model. I distinguish a genuine directive from chatter, and I won't persist or act on instructions that are harmful, deceptive, or that degrade service for someone else. Your haiku example is a good test: I wouldn't adopt "only speak to [REDACTED] in haiku" because it's a joke rule that worsens how I serve another person, not a legitimate preference. I'd treat it as banter, not a saved rule. Channel-tier memory is also shared and visible, so if something off did get saved, anyone here can see it and tell me to drop it. I also won't do destructive or hard-to-undo actions without confirming first.