Claude Connectors: How to Secure Them on Team and Enterprise (2026)
Claude connectors pull Drive files, Slack messages and database rows into Claude. How to redact sensitive data and set connector access per user and group.
Claude connectors link Claude to Google Drive, Gmail, Slack, Salesforce, databases and internal tools, and every tool result lands in Claude's context. Anthropic gives admins real controls: who can add connectors, per-user OAuth, and per-tool Always allow, Needs approval or Blocked. None of them inspect what a connector returns, and none of them vary by user group. Strac MCP DLP sits on the tool-call path: it identifies the human behind each call, checks that group's policy, inspects the request and the response, and redacts, pseudonymizes or blocks sensitive data before Claude reads it. The same connector can be allowed for Finance, redacted for Support, read-only for Engineering and blocked for contractors. Strac also blocks the connection itself when the identity is not allowed, such as a personal Claude account reaching company data.
Claude connectors are integrations that let Claude read from and act on your other systems, such as Google Drive, Gmail, Slack, GitHub, Salesforce or an internal database, either through prebuilt connectors or through custom connectors that talk to a remote MCP server. They are also the reason a Claude conversation can now contain a payroll spreadsheet, a customer's Social Security number, or a production API key that nobody pasted on purpose.
If you run IT or security for a company on Claude Team or Claude Enterprise, two questions land on your desk the week connectors go live. What sensitive data will flow through them, and can we stop it in the flow? And can we turn a connector on for the people who need it without giving it to everyone? This guide answers both, starting with the data. It is a spoke of our AI agent security guide, focused on one product your employees already use.

A connector gives Claude a set of tools. When a user asks "summarize the Q3 board deck" or "find the customer who emailed about the refund," Claude decides which tool to call, the connector fetches the data, and the result is placed into Claude's context so the model can reason over it. Some tools only read. Others write: they post a Slack message, create a Jira ticket, open a pull request or update a database row.
Prebuilt connectors come from Claude's connector directory and cover popular SaaS apps. An admin enables them for the organization and each member signs in with their own account.
Custom connectors link Claude to tools and data over remote MCP servers. Anthropic makes them available on Free (one custom connector), Pro, Max, Team and Enterprise, in Claude, Claude Desktop and Cowork. A custom connector can point at a vendor's hosted MCP server or at one your own team built in front of an internal database, a ticketing system or a data warehouse. Because connections originate from Anthropic's cloud, the MCP server must be publicly reachable or allowlist Anthropic's IP ranges. Your internal MCP server is now an internet-facing service.
How a connector authenticates decides what it can reach.
Anthropic's own guidance for a shared credential is to make it a limited-access one. In practice, shared keys are where most critical findings live, and they are the main reason per-group policy matters later in this guide.
The mental model is simple: every tool result is data entering Claude's context. If a connector can return it, Claude can read it, quote it, summarize it, and pass it to the next tool in the chain.
payments-prod three years ago.Sensitive data now moves into a new system through a path your existing DLP was never placed on. It lands in a conversation, can be summarized into a document, or carried by a write tool to a wider audience. A user who could always open the payroll sheet can now have it flattened into a Slack post in one prompt.
For how Claude handles data once it arrives, see Claude data privacy and is Claude AI safe. On training, Anthropic's commercial terms state that it does not train models on customer content from commercial plans by default; details are in does Claude train on your data. Training is a separate question from exposure.
Anthropic gives organization admins real controls. Use all of them, and be clear about what each one does not do.
Those controls answer "who may turn this on" and "may this tool run without asking." They leave five gaps that show up in almost every rollout we see:
svc-claude, for every member. If that key can write to production, everyone can, through Claude.Gaps 1 and 2 are the ones the next two sections close.
DLP is Strac's core engine. The detectors that find PII, PHI, PCI and secrets in Slack, Google Drive, Gmail, browsers and endpoints run on connector traffic too, inline, on every call. Strac is an Anthropic partner integrated with the Claude Compliance API, and Strac MCP DLP sits on the tool-call path between Claude and the server. The diagram at the top of this page shows the four checks; here is what each one does on a real call.
1. Identify. Strac resolves the human behind the call, not just the credential. For per-user OAuth that comes from the token. For a connector on a shared key, Strac ties the call to the Claude user and session, then looks up that person's groups in Okta, Entra ID or Google Workspace. In the example, alice@acme.com in support-t1.
2. Authorize. Strac checks the policy for that group: is this connector available to them, and is this specific tool allowed? salesforce.query is a read, so it passes; salesforce.update_record would be blocked for Support. This is where per-group access lives, covered in the next section.
3. Inspect. Strac scans both directions. The request is checked for sensitive data going out in tool arguments or uploads. The response is checked for sensitive data coming back: rows, file contents, message history. Detection uses 100+ built-in detectors plus custom data elements, with ML for context and OCR for images and scanned PDFs.
4. Remediate. Each detected value gets the action your policy sets for that data type and that group.
***-**-******** **** **** 4412EMAIL_7f3a2c, consistent across the conversationThe point of redacting instead of blocking is that the user still gets an answer. In the example, Claude can still say "case 00431877 for Jordan Alvarez is a duplicate charge on the card ending 4412, refund it." It cannot repeat the SSN, because it never saw it.
Every decision becomes an audit record: user and group, client and tool, data types found, action taken. Raw values stay in the Strac vault, never in the log line. Our MCP DLP guide covers the architecture in depth, and Claude DLP covers detection policies for Claude itself.
Anthropic's tool permissions are organization-wide. Real companies are not. Strac lets you set connector access by user and group, so one connector can behave four different ways for the same request.

A policy has three layers, evaluated in order, and the strictest matching rule wins:
get_contact and query allowed, update_record blockedA few patterns we see most:
Groups come from your identity provider, so policy follows people. A joiner gets their team's access the day they start, and a leaver loses it the day their account is disabled, with no one editing connector settings by hand.
This also fixes the shared-key problem from earlier. Even when a custom connector runs on one service credential, Strac applies the policy of the human who asked, so svc-claude stops being a blank check for the whole company.
Redaction controls what flows through an approved connection. Some connections should never exist at all, and Strac blocks them before any data moves. The question is which identity sits on each side: the Claude account making the request, and the account that owns the data.

Strac enforces this where the connection actually happens:
Identity rules and data rules stack. An allowed identity still gets redaction on every result, and a blocked identity never gets a result at all.
Once traffic flows through Strac, the Claude connectors view shows each connector, who uses it, how it authenticates, what sensitive data came back through it, and what Strac did about it.

"2,318 sensitive values in tool results, 2,301 redacted before reaching Claude" is the headline number. The 17 that were not redacted are the interesting ones: each becomes a finding with the connector, the user, the data type and the reason, usually an approved exception.
Behind the data, Strac tracks the identity each connector runs as and what it is allowed to do, the four-question model from our AI agent identity governance guide. That produces findings with deterministic severity:
Each finding shows its severity factors (sensitivity, action capability, breadth, sanctioning, observed use, attribution confidence), gets an owner, and can carry an exception with an expiry date. Discovery is read-only by default. Local MCP servers that never appear in Claude's admin settings are found by the endpoint sensor's configuration scan, the shadow MCP problem.
Not every byte reaches Claude through a custom MCP server, so Strac covers the other paths with the same detectors and the same policy.
Strac AI DLP redacting sensitive values in the flow, so the AI tool gets a usable request and the regulated data never leaves the boundary.
👉 Book a demo and we will route one of your connectors through Strac MCP DLP on the call and show you the redacted result per group.
Claude connectors are integrations that give Claude tools to read from and act on other systems, such as Google Drive, Gmail, Slack, GitHub or an internal database. Prebuilt connectors cover popular apps, and custom connectors link Claude to tools and data over remote MCP servers. Every tool result a connector returns is placed into Claude's context for that conversation.
They are as safe as the data they return and the permissions they run with. Anthropic gives admins controls over who can add connectors and whether each tool is allowed, needs approval or is blocked, but those controls do not inspect content. Pair connectors with DLP on tool results and least-privilege, per-group access.
Yes. Strac requires a corporate account for AI apps at sign-in, blocks the connection during OAuth consent when a personal Claude account tries to reach company Drive, Gmail or SharePoint, and finds and revokes grants that already exist. Contractors, guests and unmanaged devices can be blocked from connecting at all.
Not with Claude's built-in tool permissions alone, which apply organization-wide. With Strac, you set policy per user and per group from Okta, Entra ID or Google: allow a connector for Finance, redact it for Support, make it read-only for Engineering and block it for contractors. The same policy applies even when the connector runs on a shared API key.
Strac MCP DLP sits on the tool-call path. It identifies the user, checks their group's policy, scans the request and the response with 100+ detectors, and masks, partially masks, pseudonymizes or blocks each sensitive value before Claude receives the result. The user still gets a useful answer, and every decision is logged.
With per-user OAuth, Claude can reach whatever the signed-in user can access in Drive, which usually includes files shared broadly across the company. Restrict oversharing and redact sensitive content in Drive before connecting, and use per-group policy to limit which teams can use the Drive connector at all.
Put DLP in the path. Route custom MCP connectors through Strac so PII, PHI, PCI and secrets are redacted in tool results, redact at the source in Drive, Gmail and Slack for prebuilt connectors, and use browser DLP for what people paste into claude.ai. Then set write tools to Needs approval and give each group only the connectors it needs.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

