|
|
|
|
|
by disillusioned
34 days ago
|
|
This sounds lovely, and ideal, but my read on this situation for, say, Google Drive, is a bit more nuanced: Anthropic's docs say that its permissions are scoped to the folders you grant access to the _user_ you create for Claude. This creates an unfortunate situation where, for example, I can't scope a given channel's Claude Tag to _only_, say, a project's shared drive or specific folders, because I'm using a custom claude@ Google account in my org, and its permissions have to be all-encompassing. It also means I can't escalate privilege and expose certain documents that I would like to: say I have a private #hr channel that I would like to have access to our HR shared drive docs with proprietary information. My understanding is that any user in any channel with @claude tag in it would be able to interrogate Claude about any file that the Claude Google user has access to, regardless of which channel they're in. I'm trying to determine if the way around this is the alternate Google service account option, but that mentions domain-wide delegation in such a manner that it makes me think it would replicate the problem, and I obviously don't want to create custom Google accounts for each project scope in my org... |
|