Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
242 changes: 121 additions & 121 deletions content/.metadata.json

Large diffs are not rendered by default.

39 changes: 23 additions & 16 deletions content/claude/claude-science/admin-controls.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,9 @@

# Admin controls

> Organization settings for Claude Science on Team and Enterprise plans (Featured connectors and skills, custom connectors and skills, the network allowlist, package mirror, SSH hosts, Modal, scientific model endpoints, and memory) and which other claude.ai admin controls apply to the app.
> Organization settings for Claude Science on Team and Enterprise plans (Featured connectors and skills, custom connectors and skills, access to Claude Science work previously saved on the computer, the network allowlist, package mirror, SSH hosts, Modal, scientific model endpoints, and memory) and which other claude.ai admin controls apply to the app.

Members sign in to Claude Science with their Claude account, so your identity and billing controls apply automatically. Because the app stores conversations on each member's computer, most of the data-handling controls Anthropic provides don't reach that data today. [Organization settings](#organization-settings) describes the controls on the claude.ai **Organization settings** > **Claude Science** page itself, which govern the connectors, skills, compute, network access, and memory that members can use in the Claude Science app. [How other admin settings apply to Claude Science](#how-other-admin-settings-apply-to-claude-science) lists every other claude.ai admin setting and whether it applies to Claude Science today. Status values describe Claude Science specifically; other Claude products may differ.
Members sign in to Claude Science with their Claude account, so your identity and billing controls apply automatically. Because the app stores conversations on each member's computer, most of the data-handling controls Anthropic provides don't reach that data today. [Organization settings](#organization-settings) describes the controls on the claude.ai **Organization settings** > **Claude Science** page itself, which govern the connectors, skills, compute, network access, and memory that members can use in the Claude Science app, and whether members can access previously saved Claude Science work. [How other admin settings apply to Claude Science](#how-other-admin-settings-apply-to-claude-science) lists every other claude.ai admin setting and whether it applies to Claude Science today. Status values describe Claude Science specifically; other Claude products may differ.

## Organization settings

Expand All @@ -16,27 +16,28 @@ The [**Organization settings** > **Claude Science**](https://claude.ai/admin-set

Each control starts at a default that depends on your plan and on whether HIPAA compliance is enabled for your organization. The page always shows the value in force for your organization.

| Control | Default for Team | Default for Enterprise¹ |
| ----------------------------------------------------------- | ------------------------------ | ------------------------------ |
| Featured connectors and Featured skills | All on | All on |
| Allow custom connectors | On | Off |
| Allow custom skills | On | On |
| Manage network allowlist | Off (members manage their own) | Off (members manage their own) |
| Organization package mirror | Not set | Not set |
| Allow members to connect SSH hosts | On | On |
| Allow members to connect to Modal | On | Off |
| Show scientific model endpoint providers on the Compute tab | On | On |
| Turn on memory for your team | On | On |

¹ For HIPAA-eligible organizations, note that Claude Science (beta) is not covered under your Business Associate Agreement (BAA) and should not be used with protected health information (PHI). Administrators who enable Claude Science are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. Featured and custom connectors, SSH hosts, Modal, scientific model endpoints, and memory are all off by default for HIPAA-eligible organizations.
| Control | Default for Team | Default for Enterprise¹ |
| ------------------------------------------------------------------------------ | ------------------------------ | ------------------------------ |
| Featured connectors and Featured skills | All on | All on |
| Allow custom connectors | On | Off |
| Allow custom skills | On | On |
| Allow members to access Claude Science work previously saved on their computer | On | Off |
| Manage network allowlist | Off (members manage their own) | Off (members manage their own) |
| Organization package mirror | Not set | Not set |
| Allow members to connect SSH hosts | On | On |
| Allow members to connect to Modal | On | Off |
| Show scientific model endpoint providers on the Compute tab | On | On |
| Turn on memory for your team | On | On |

¹ For HIPAA-eligible organizations, note that Claude Science (beta) is not covered under your Business Associate Agreement (BAA) and should not be used with protected health information (PHI). Administrators who enable Claude Science are responsible for ensuring their workforce uses it in compliance with applicable legal obligations. Featured and custom connectors, SSH hosts, Modal, scientific model endpoints, memory, and access to previously saved Claude Science work are all off by default for HIPAA-eligible organizations.

### How changes reach members

Changes you save reach each member's running app within a few minutes and apply on the member's next turn or request. An app that is closed picks up your changes when it next starts, and an app that can't reach claude.ai keeps applying the last settings it received.

The settings apply to members running version 0.1.41 or later of the Claude Science app. A member still on an earlier version isn't governed by these settings until the member updates (see [Required updates](/docs/claude-science/manage-on-devices#required-updates)). For Team and Enterprise organizations, Claude Science enforces a minimum version of 0.1.41. A member on an older version sees a notice that the version is no longer supported, with an **Update now** button. If the update doesn't complete after a second try, the member can install the current version from the [Claude Science download page](https://claude.com/product/claude-science) (on Linux, rerun the install command in [Get started](/docs/claude-science/get-started#install)); projects and settings on the computer are kept.

Each member's app also has to reach claude.ai regularly to confirm these settings. If an app can't reach claude.ai for 72 hours, it pauses memory, custom connectors, SSH hosts, Modal, model endpoints, and adding custom skills until it reconnects, and keeps applying the network allowlist, package mirror, and Featured connector and skill choices it last received.
Each member's app also has to reach claude.ai regularly to confirm these settings. If an app can't reach claude.ai for 72 hours, it pauses memory, custom connectors, SSH hosts, Modal, model endpoints, adding custom skills, and accessing previously saved Claude Science work until it reconnects, and keeps applying the network allowlist, package mirror, and Featured connector and skill choices it last received.

Turning a control off doesn't delete anything on the members' computers. What members set up under that control (custom connectors, SSH hosts, their Modal connection, saved memories, and their own choices) stays on their computer, and that feature cannot be used inside the Claude Science app while the control is off. The setting shows grayed out in the app with a note that an admin turned it off, and everything works again as before if you turn the control back on. A control that is off by your plan's default instead shows a note that an admin can turn it on. When the **Allow custom skills** switch is off, skills a member added earlier keep working (see [Custom skills](#custom-skills)).

Expand Down Expand Up @@ -76,6 +77,12 @@ To let members manage their own skills, host them in a GitHub repository. Put on

To stop members from adding their own skills, turn off the **Allow custom skills** switch on the **Organization settings** > **Claude Science** page (see [Custom skills](#custom-skills)).

### Previously saved Claude Science work

A member who used Claude Science under another sign-in on the same computer (for example, a personal plan before joining your organization) can access the projects, sessions, and artifacts from that sign-in and move it into the app's folder for your organization on that computer (see [Access work from another sign-in on your computer](/docs/claude-science/multiple-computers#access-work-from-another-sign-in-on-your-computer)). The **Allow members to access Claude Science work previously saved on their computer** switch decides whether the app offers this access. It's on by default for Team organizations and off by default for Enterprise organizations, and organizations with HIPAA compliance enabled can't turn it on.

The access happens on the member's computer and uploads nothing. Claude Science work the app accesses will follow your organization's settings from then on. Content your organization doesn't allow isn't copied or moved and stays in its original folder, and credentials such as API keys and connector sign-ins are never copied or moved. When the switch is off, the app doesn't offer the access, and its **Import work on this computer** setting is grayed out with a note that it's off for your organization.

### Network allowlist

When Claude runs code for a member, that code can reach only the domains on the analysis sandbox's network allowlist: the package hosts, the scientific databases behind the Featured connectors, and hosts the member approved. See [Sandbox](/docs/claude-science/core-concepts#sandbox) and the domain tables in [Network requirements](/docs/claude-science/network-requirements#analysis-sandbox-domains).
Expand Down
14 changes: 14 additions & 0 deletions content/claude/claude-science/changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,20 @@

> Release notes for Claude Science, including new features, improvements, and bug fixes by version.

<Update label="0.1.49" description="September 16, 2026">
* Saved credentials now reach Claude's code only when it asks for them and you approve. They're no longer present in every cell
* Access Claude Science work saved on your computer from other sign-ins, from Home or Settings. Admins control it on Team and Enterprise plans
* Claude can send you a short message, such as a link to a file, while it keeps working on a task
* Mac: Apple silicon Macs with the Intel version installed can now update, and then run natively
* Mac: if Claude's tools can't start after an Xcode update, the error now says how to accept the Xcode license
* You can comment on and bookmark the short summaries of Claude's progress notes
* Sessions moved to a model with a smaller context window keep going instead of failing
* Turning Auto-review off now applies to agents that are already running; turning it back on resumes their reviews
* Settings > Connectors shows "Not set" for tools without a permission, and saves "Ask each time"
* Windows: `claude-science install` now reports the step that failed instead of reporting success
* Faster search of a long session's history; clearer wording in model settings
</Update>

<Update label="0.1.48" description="September 14, 2026">
* On Windows, environment setup now handles user folders with accented or non-Latin names, tries again if Windows briefly refuses to start the environment installer, and no longer needs the Microsoft Visual C++ Redistributable
* The app now warns you a few days before your sign-in expires and offers a "Sign in again" button
Expand Down
4 changes: 2 additions & 2 deletions content/claude/claude-science/cloud-storage.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ Connect Amazon S3, Google Cloud Storage, or Azure Blob Storage so Claude can rea

In **Settings > Credentials**, choose **AWS**, **Google Cloud**, or **Microsoft Azure**, then Connect. Provide the credential (access key, service-account JSON, HMAC key, service principal, or connection string) and list the bucket names (AWS, GCP) or **Blob containers** (Azure) this credential covers. S3-compatible stores use the AWS form with the **S3-compatible endpoint** field; you'll need to allowlist that endpoint host separately.

Listing a bucket adds its address to the sandbox network allowlist so code can reach it without a per-call card. Access within the bucket is still limited to the credential's permissions. Credentials are encrypted on your computer and sent only to the provider they belong to.
Listing a bucket adds its address to the sandbox network allowlist so code can reach it without a network permission card. Access within the bucket is still limited to the credential's permissions. Credentials are encrypted on your computer and sent only to the provider they belong to.

Claude reads and writes objects with ordinary code using the provider's Python library (`boto3`, Azure SDK). **Settings > Storage** lists connected credentials and lets you browse and import objects (up to 100 GB) or export artifacts.

Expand All @@ -19,5 +19,5 @@ Claude reads and writes objects with ordinary code using the provider's Python l
</Note>

<Warning>
Any code Claude writes can use credentials you add here. If a bucket should never be reachable from an analysis session, don't add its credential.
Code that Claude writes can use a credential you add here only after you approve a **Credentials** card that names it. By default the approval lasts for the conversation. If a bucket should never be reachable from an analysis session, don't add its credential.
</Warning>
1 change: 1 addition & 0 deletions content/claude/claude-science/core-concepts.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@ A permission card appears in the conversation each time Claude needs a new kind
| Run code | Run Python code? / Run a shell command? / Install packages? | Once or Always |
| Reach a network host | Connect to `<target>`? | Persists until revoked |
| Use a connector tool | Use `<tool>`? | Once, This conversation, This project, or Global |
| Use a saved credential | Credentials | Once, This conversation, This project, or Global |
| Run a remote job | Run this job on `<host>`? / Start a Modal job? | Once, This conversation, This project, or Global |

All standing grants are listed in Settings > Permissions and can be revoked there.
Expand Down
2 changes: 1 addition & 1 deletion content/claude/claude-science/custom-connectors.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ Remote servers that need login take you through the provider's sign-in page.

On Team and Enterprise plans, you can add and use custom connectors only if your organization allows them. When it doesn't, the **Remote** and **Local command** options under **Add connector** are grayed with a note that custom connectors are disabled by your admin. Custom connectors you added earlier stay listed and grayed, Claude can't use them, and they work again if your organization turns custom connectors back on. See [Custom connectors](/docs/claude-science/admin-controls#custom-connectors) in the admin controls.

Every tool from a custom connector starts at **Ask each time**. On the connector's page, set individual tools to **Always allow** or **Block** under **Tools**, or turn on Skip approvals for the whole connector.
Every tool from a custom connector starts as **Not set**, and Claude asks before using it. On the connector's page, set individual tools to **Always allow**, **Ask each time**, or **Block** under **Tools**, or turn on Skip approvals for the whole connector.

<Warning>
Skip approvals disables the per-call card for every tool on that connector. Only use connectors from developers you trust.
Expand Down
4 changes: 2 additions & 2 deletions content/claude/claude-science/enable-claude-science.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@

> Claude Science is a desktop app for scientific research.

Claude Science is a desktop app for scientific research. It's off by default for Team and Enterprise organizations. Turning it on in **Organization settings** > **Claude Science** opens a short dialog that covers who gets access and which connectors to turn on. You can change any of it later on the same page, which also holds the other [organization settings](/docs/claude-science/admin-controls#organization-settings) for Claude Science: which connectors, skills, compute, network access, and memory members can use.
Claude Science is a desktop app for scientific research. It's off by default for Team and Enterprise organizations. Turning it on in **Organization settings** > **Claude Science** opens a short dialog that covers who gets access and which connectors to turn on. You can change any of it later on the same page, which also holds the other [organization settings](/docs/claude-science/admin-controls#organization-settings) for Claude Science: which connectors, skills, compute, network access, and memory members can use, and whether members can access previously saved Claude Science work.

## Availability

Expand Down Expand Up @@ -69,7 +69,7 @@ Members who belong to more than one organization on claude.ai, such as a persona

Organizations with HIPAA compliance enabled can turn on Claude Science during the beta, but usage isn't covered under your BAA, so keep protected health information out of it. The **Turn on Claude Science** dialog opens with a step that says so. In its connectors step the local connectors start off, and you can turn on the ones you have reviewed. The Anthropic-hosted and directory connectors in that step are read-only because the dialog's quick-enable path doesn't include the per-connector HIPAA attestation, so add those from **Organization settings** > **Connectors** instead, where the attestation is required.

These organizations also start with stricter organization settings. Featured connectors and skills, SSH hosts, Modal, model endpoints, and memory are off until you turn them on (including for members who were already using them), custom connectors can't be turned on, and the organization always manages the network allowlist. See [Defaults by plan](/docs/claude-science/admin-controls#defaults-by-plan).
These organizations also start with stricter organization settings. Featured connectors and skills, SSH hosts, Modal, model endpoints, and memory are off until you turn them on (including for members who were already using them), custom connectors and access to previously saved Claude Science work can't be turned on, and the organization always manages the network allowlist. See [Defaults by plan](/docs/claude-science/admin-controls#defaults-by-plan).

## Turn off Claude Science

Expand Down
Loading
Loading