Claude for Slack · Four Ways · June 2026

Do you rent the agent,
or own the substrate?

Anthropic now ships two official Slack products; two open-source stacks answer them. They split on one axis: who owns the sandbox, the memory, and the audit log the agent runs on.

Claude Tag is the best agent you can rent — zero-setup, strong managed sandbox, compounding memory. CCSC + AGP make the opposite trade: you host it, you own the memory, and the audit is a signed record you verify with your own key. Both are legitimate — pick by who must own the substrate.

The matrix rent ◀ ▶ own

A — Claude in Slack
legacy · retires Aug 3 2026
B — Claude Tag / @Claude
launched Jun 23 2026
CCSC
governance kernel · Apache-2.0
AGP
sandboxed · Apache-2.0
HostingAnthropic (SaaS)Anthropic infraSelf-hostSelf-host
Agentic levelNon-agentic (Q&A / summarize)Fully agentic teammateAgentic, gated per callAgentic, gated + sandboxed
Approval modelN/ACoarse — channel scope + spend caps; no per-action approvalPer-tool-call HITL (allow/deny/require)Per-tool-call HITL (default-deny)
AuditVendor SaaS logsVendor log admins can viewSigned, offline-verifiable (hash-chain + Ed25519 + policy attestation)Signed + signed-HEAD checkpoint (closes truncation gap)
Memory & dataVendorVendor — memory is Anthropic's proprietary stateYours, on your infraYours, on your infra
Cost controlSubscriptionToken-spend caps (org + channel)Own the model bill; deny via policy (per-channel cap on roadmap)Own the model bill; gate/deny via policy
SandboxN/AStrong, managed — sandbox + Agent Proxy (deny-by-default egress, per launch coverage)None itself (delegated to AGP)Hardened container; preflight proves egress off (namespace/cgroup, not VM)
CredentialsVendor-managedModel never sees raw keysSecret values never sent"Gate, don't impersonate" — journals names, not values
HarnessesClaudeClaude (Opus 4.8)Claude CodeMulti-harness (Claude + Codex) live Codex provisional
LicenseProprietaryProprietaryApache-2.0Apache-2.0
Setup costLowLowest — tag & goHigher — you operate itHigher — you operate it
Best forQ&A / summaries (sunsetting)Teams wanting a zero-setup teammate on managed infraRegulated / security-conscious teams needing verifiable audit + HITL+ sandboxed multi-harness execution

What each side does that the other can't

What only Claude Tag does

  • Zero infrastructure / zero-ops — tag and go
  • Multiplayer memory that compounds automatically across a channel
  • Ambient / proactive + scheduled autonomous work, no orchestration to build
  • Fully-managed strong sandbox + Agent Proxy — no security engineering on your part
  • Built-in token-spend caps + central org governance on day one

What only CCSC + AGP do

  • A signed, offline-verifiable audit you check with your own public key — no vendor in the trust path
  • AGP's signed-HEAD checkpoint catches a truncated log — the gap CCSC documents as T8
  • Deterministic, fine-grained per-tool-call policy (default-deny in AGP), not channel scope + budget
  • Human-in-command approval per consequential call, with anti-self-approval a bot can't satisfy
  • The memory + audit are yours, portable — no context lock-in
  • A sandbox that proves egress is off (preflight fails closed)

Pros & cons honest — no FUD

Claude Tag / @Claude
The best agent you can rent
Zero infra, multiplayer memory, ambient + scheduled work
Genuinely strong managed security — sandbox + Agent Proxy (deny-by-default egress per launch coverage)
Token-spend caps + central admin governance out of the box
Substrate is Anthropic's — memory + audit live on their infra
Governance is coarse; audit is shown, not verifiable by you; context lock-in
Claude in Slack (legacy)
Retiring Aug 3, 2026
Dead-simple; good at summarize / answer; near-zero setup
Not agentic
Being retired — migration is effectively forced
CCSC
The governance kernel · Apache-2.0
Deterministic per-tool-call policy (allow/deny/require) + human-in-command approval
Signed, offline-verifiable audit — public-key-only verification; five injection-defense layers
You own the memory + audit on your infra
You host + operate it; no execution sandbox of its own (that's AGP)
Bare chain doesn't stop truncation (T8 — AGP fixes it); no host-OS-compromise protection
AGP
Sandboxed · multi-harness · Apache-2.0
CCSC's guarantees + a sandbox that proves egress off; signed-HEAD closes truncation
"Gate, don't impersonate" credentials; one gate across Claude Code + Codex
You host + operate it; sandbox is namespace/cgroup, not VM-grade
Live Codex interception provisional; self-assessed test grade B− (78/100)

Claude Tag is the best agent you can rent. If the agent — and its memory and its audit trail — must be yours and verifiable on your own infra, you host it. Both are legitimate. Pick by who must own the substrate.

Try it & stay in the loop

Get the code

Both stacks are open source (Apache-2.0). Run them on your own infrastructure.

★ CCSC — the governance kernel → ★ AGP — sandboxed, multi-harness →

Stay in the loop with Intent Solutions

Customer-owned, verifiable AI governance — new drops, deep-dives, and releases. No spam.