Anthropic now ships two official Slack products; two open-source stacks answer them. They split on one axis: who owns the sandbox, the memory, and the audit log the agent runs on.
| A — Claude in Slack legacy · retires Aug 3 2026 |
B — Claude Tag / @Claude launched Jun 23 2026 |
CCSC governance kernel · Apache-2.0 |
AGP sandboxed · Apache-2.0 |
|
|---|---|---|---|---|
| Hosting | Anthropic (SaaS) | Anthropic infra | Self-host | Self-host |
| Agentic level | Non-agentic (Q&A / summarize) | Fully agentic teammate | Agentic, gated per call | Agentic, gated + sandboxed |
| Approval model | N/A | Coarse — channel scope + spend caps; no per-action approval | Per-tool-call HITL (allow/deny/require) | Per-tool-call HITL (default-deny) |
| Audit | Vendor SaaS logs | Vendor log admins can view | Signed, offline-verifiable (hash-chain + Ed25519 + policy attestation) | Signed + signed-HEAD checkpoint (closes truncation gap) |
| Memory & data | Vendor | Vendor — memory is Anthropic's proprietary state | Yours, on your infra | Yours, on your infra |
| Cost control | Subscription | Token-spend caps (org + channel) | Own the model bill; deny via policy (per-channel cap on roadmap) | Own the model bill; gate/deny via policy |
| Sandbox | N/A | Strong, managed — sandbox + Agent Proxy (deny-by-default egress, per launch coverage) | None itself (delegated to AGP) | Hardened container; preflight proves egress off (namespace/cgroup, not VM) |
| Credentials | Vendor-managed | Model never sees raw keys | Secret values never sent | "Gate, don't impersonate" — journals names, not values |
| Harnesses | Claude | Claude (Opus 4.8) | Claude Code | Multi-harness (Claude + Codex) live Codex provisional |
| License | Proprietary | Proprietary | Apache-2.0 | Apache-2.0 |
| Setup cost | Low | Lowest — tag & go | Higher — you operate it | Higher — you operate it |
| Best for | Q&A / summaries (sunsetting) | Teams wanting a zero-setup teammate on managed infra | Regulated / security-conscious teams needing verifiable audit + HITL | + sandboxed multi-harness execution |
Claude Tag is the best agent you can rent. If the agent — and its memory and its audit trail — must be yours and verifiable on your own infra, you host it. Both are legitimate. Pick by who must own the substrate.
Both stacks are open source (Apache-2.0). Run them on your own infrastructure.
★ CCSC — the governance kernel → ★ AGP — sandboxed, multi-harness →Customer-owned, verifiable AI governance — new drops, deep-dives, and releases. No spam.