
Your team just hired someone who never sleeps, reads everything, and takes work from whoever asks. That’s the elevator pitch for Claude Tag, and on the face of it, it’s hard to see why anyone would push back on the new hire. Enterprises will want this in every workspace. On-demand status updates, first drafts, streamlined triage; the work that quietly eats a week now collapses into the team conversation.
But, look at the other half: the new colleague acts on what it receives, trusts the source by default (if you’re in the workspace, you’re trusted) and doesn’t question the intent behind a request. One crafted sentence buried in a customer’s support ticket doesn’t hijack a chat session; it hijacks the agent working for everyone in the channel.
Anthropic introduced Claude Tag as a teammate rather than a tool: multiplayer by design, wired to the team's tools, data, and codebases, and delegated to by anyone in the room. This represents a new layered risk we broke down when it first shipped. And the failure modes we documented for rogue coding agents land harder when the blast radius is a channel rather than a laptop.
Zenity Now Secures Claude Tag: So You Can Turn It On Everywhere
A shared agent holding the team's standing access is not something a security team can wave through, so enterprise adoption usually stalls after an in-house security test.
At Zenity, we built a dedicated Claude Tag plugin to close exactly this security gap. From the moment it’s installed, every channel where @Claude is invoked begins building an inventory, a policy, and an evidence trail. Teams move at the speed they want, and security keeps its controls and audit trail without being the gate.
Surface. Claude Tag appears as one entity per Slack workspace with everything it’s wired to in a single record: the channels it works in, the people using it, the connectors and credentials it’s seen using, the MCP servers and skills it actively invokes. Activity is a single timeline - scheduled runs included - with each step carrying its channel and the Slack author who triggered it.
Enforce. Boundaries apply here exactly as they do to every other agent, scoped per agent (‘per channel’ in this case): restrict @Claude in a given channel to the skills, MCP servers, and connectors that have been reviewed, and stop mutating or irreversible tool calls inline.
Protect. When Claude Tag reads a crafted instruction from a malicious Jira ticket, Zenity taints the session on ingest, and the Boundary evaluates the next action before it completes. And that holds even when nothing in the chain looks inherently wrong; the connector worked as intended, the teammate did nothing unusual, and the identity held permission. Blocking the request contains the blast radius and gives security teams the full picture: what happened, and how a data breach or business disruption was averted.
Where This Is Going
Anthropic is already bringing Claude Tag to Microsoft Teams. Agents are moving into the direct messaging tools organizations already run on, and support for more of them is coming. What stays constant is the agent layer: where access concentrates, and where intent becomes action. Get that layer right, and every new agent stops being a risk review and starts being capacity you can deploy the week it ships. That is the difference between an organization that adopts this at the speed it arrives and one that spends the next year waiting for approval.
All ArticlesRelated blog posts

From Triage to Full Coverage: The Shift AI Agent Security Took in August
Security teams evaluating an AI agent security platform tend to ask the same question after the first demo: will...

Introducing Guardian Agents: Meet Blue Agent, Your AI Security Analyst
AI agents are moving into production faster than security teams can govern them. And unlike traditional applications,...

Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace
Cursor has become one of the primary AI coding environments for development teams, and its agents increasingly...
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo