Claude (Anthropic)
What Claude’s own help pages, docs and terms said on 1 October 2026, by the same six questions we ask of every agent. We didn’t test it for this page. “Not documented” means we didn’t find it on the vendor’s pages; it doesn’t mean the feature is missing.
Assistant
- Can you limit it?
- Per tool: allow, approve, block
- Does it ask first?
- Three modes; a fixed never list in Chrome
- Can you stop it?
- Stop any time
- Is there a record someone outside can check?
- Not documented
- What about sub-agents?
- In plugins; scope not stated
- Can you test it yourself?
- Custom MCP from the Free plan
What the vendor’s pages say
Every connector tool can be set to "Always allow", "Needs approval" or "Blocked", and Team and Enterprise owners can set this for the whole organisation (connectors). Claude in Chrome has three modes; in "Skip", "nothing checks its actions automatically". Anthropic also lists actions Claude in Chrome won't take: purchases, creating accounts, trades, permanent deletions, and completing "instructions from emails or web content" (Chrome permissions). "You can stop Claude at any point" (computer use). Enterprise audit logs keep 180 days; the event list doesn't include tool calls (audit logs). Plugins can bundle sub-agents; their scope isn't stated (Cowork safety). Custom MCP servers by URL work from the Free plan, which allows one (custom connectors).
Every statement above was checked on the vendor’s own page on 1 October 2026; each links to its source.
Run this test on yours
Delegus Check gives your agent a permission and a one-hour test server, then shows every action it tries and what was refused. It works today with agents that accept a custom MCP server, including Claude on any plan.
Corrections
Vendors and readers: if anything here is out of date, write to hello@delegus.ai and we’ll fix it. Each change is listed here with its date.
- 1 October 2026: first published. All vendor statements checked that day.