Skip to content
Work with meSpeakingInsightsAbout Book a call

Setting up your Claude Team account

A step-by-step guide for small law firms.

You bought a Claude Team plan. Now what? This guide walks through every screen in the admin console that matters for a law firm, in the order the console shows them, with my recommendation for each setting. No technical background required. Plan on about an hour for a clean first setup, plus a few minutes per person for the apps.

I first published this guide in May 2026. I rebuilt it on September 28, 2026 by walking through the live Team admin console screen by screen, because the console has moved ahead of Anthropic's own help articles: settings have been renamed, moved between pages, and added. Where the console marks a switch "Default," I tell you what the default is. Where it doesn't, I tell you to check yours. Everything I describe from the console is what I observed on September 28, 2026 in the Team account I reviewed. Anthropic rolls changes out gradually, so yours may not match exactly. Where a claim rests on Anthropic's documentation instead, I link to the source next to it. If your firm also uses ChatGPT, I wrote the same walkthrough for ChatGPT Business.

A note before you start: the person doing the setup should be the Primary Owner or an Owner of the account. The Primary Owner is usually the person who signed up and entered the credit card. Admins can manage members, but only Owners can change capabilities, connectors, and data settings. If that isn't you, find that person before going further.

If you set up Claude Team from the May edition

Revisit these nine things. Each links to the step that covers it.

  1. Agent features now start switched on: Cowork, Cowork in the cloud, the built-in browser, Claude in Chrome, remote control of Cowork, and automatic approval (Part 5 and Part 7).
  2. Approvals have their own section, including a switch for "Skip all approvals" mode. Turn that one off (Step 5.3).
  3. Memory is on by default, with a firm-wide switch. Turning it off later deletes everyone's memory (Step 5.6).
  4. Sharing got its own tab, with separate switches for sharing chats, sharing chats outside the firm, and letting members download their own data (Part 6).
  5. Two outside-sharing paths start on: emailing artifacts to people outside the firm, and public links in Claude Design (Step 7.4 and Step 7.5).
  6. Single sign-on works on Team once you verify a domain (Step 4.3).
  7. Organization instructions exist: 3,000 characters, and members can't see them (Step 4.2).
  8. The Microsoft 365 connector can now send email, set inbox rules, change calendars, and edit SharePoint files (Step 8.3).
  9. The minimum is now two seats, and Anthropic's top model, Fable 5.1, is included only with Premium seats (Step 4.6).

Settings at a glance

Every setting in this guide, grouped the way the admin console groups them, with my call. "On" means turn it on or leave it on. "Off" means turn it off or leave it off. "Your call" means it depends on your firm, and the step that covers it explains how to decide. The middle column shows the console's default where it labels one.

SettingDefaultMy call
Organization and access
Team name and logoOn set both
Organization instructionsEmptyOn
Domains: verify your firm's domainUnverifiedOn
Domains: DiscoverableOff
Single sign-onNot set upOn if you use Microsoft 365, Google, or Okta
User provisioningInvite onlyInvite only
Invite linkOff
Member invitesOff
New member approvalRequire admin approval
Billing, usage, and members
Seat types (Members > Tier)Standard for most; Premium for heavy users and Fable
Turn on usage creditsOffYour call set limits first
Usage credit requestsOn
Capabilities: data sources
Web searchOn
Interactive content (maps, images)OnOn
Ask [your organization] (enterprise search)OnYour call
Built-in browserOnYour call limit the sites first
Capabilities: visuals
Enable artifact connectorsOff until you have a use
Inline visualizationsOnOn
Capabilities: tool approvals
Allow "Automatically approve" modeOnOff for the first 30 days
Allow "Skip all approvals" modeOff
Allow "Always allow" for connector toolsOff
Capabilities: code execution
Cloud code execution and file creationOnOn
Allow network egressOnOn
Domain allowlistPackage managers only
Capabilities: remote sessions and memory
Remote Control (Cowork)OnYour call
Require trusted devicesOffOn
Routines (also runs cloud scheduled tasks)OnOn
Enable memory for your teamOnOn with client work in projects
Sensitive topics in memoryOff
Data and privacy
Share chatsOn
Share chats that use connectorsOn
Share chats externallyOff
Share cloud sessions (Claude Code)OnYour call
Share projectsOnOn
Public projects (firm-wide)Off unless you want firm-wide reference projects
Allow members to export their own dataOffOff
Rate chats (feedback to Anthropic)Off
Location metadataOnYour call
Monitoring (OpenTelemetry)Not set upOff unless you run a SIEM
Products
Cowork: Enable for your organizationOnOn
Cowork in the cloudOnOn
Enable DispatchOff
Claude in Chrome: Enable for your teamOnYour call
Claude in Chrome: Password managersOff
Site permissions: Default for all sitesBlock by default; allow listed sites
Artifacts and organization-wide sharingOnOn
Artifacts: External sharingOffOff
Artifacts: Email invitations outside your organizationOnOff
Templates: Slides, Design, Design systems, DocsOnOn
Claude Design: Allow public linksOff
Office Agents: Let Claude work across appsOnYour call pilot first
Claude Tag (Slack)Not set upYour call no client matters yet
Claude Code: Desktop and Cloud sessionsOnYour call on only if someone builds
Claude Code: Remote Control and ChannelsOff
Claude ScienceOffOff
Claude AcademyOn
Plugins
SkillsOnOn
User-created skillsOnOn
Skill sharingOnOn
PublishingOpenRequires review
Connectors: Microsoft 365 or GoogleNone addedOn read first
Connector write toolsYour call off in the pilot
Custom connectorsOff unless IT has vetted them
Desktop extension allowlistOffOn
GitHubNot connectedOnly if someone builds

Part 1: Confirm your foundation

Step 1.1: Make sure you're in the Team account, not a personal one

If you used Claude before the firm bought Team, you may have a personal Free, Pro, or Max account on the same email. These are separate accounts with separate data.

  1. Go to claude.ai and sign in
  2. Click your initials or name in the bottom-left corner
  3. Select the firm's organization
  4. Confirm the screen shows your firm's name, not just your own

Why this matters: a personal account runs under Anthropic's Consumer Terms, where chats can be used to train Anthropic's models unless the user opts out. The Team account runs under Anthropic's Commercial Terms, with no training on your content by default. Client work belongs in the Team account every time.

Step 1.2: Decide what happens to personal accounts

When someone joins, Claude offers to fold their personal account into the firm's. The choices are Keep both accounts, or Use your organization account only, and with the second, Bring your data with you or Delete your data. Moving is one-way.

  • What moves: chats, projects, uploaded files, and memory (unless the firm has memory off).
  • What doesn't: custom skills, connected-app sign-ins, public share links (which stop working), and Cowork sessions.

Anything a lawyer brings in becomes firm data that the Primary Owner can export. My recommendation: keep both accounts by default, and bring data in only when someone has already been doing firm work in a personal account.

Step 1.3: Find Organization settings

This is the control panel for everything that follows.

  1. Click your initials or name in the bottom-left corner
  2. Select Organization settings (or go to claude.ai/admin-settings)

The left sidebar is the map for the rest of this guide:

  • Top: Notifications, Organization and access, Billing, Usage, Data and privacy, Capabilities
  • People: Members
  • Products: Claude Code, Claude in Chrome, Claude Tag, Cloud environments, Cowork, Artifacts, Claude Design, Office Agents, Claude Science, Claude Academy
  • Plugins: Plugins & skills, Connectors, GitHub, and a link to the Directory

Several settings have moved in recent weeks, and the old pages now carry a "moved to" note with a button that takes you to the new home. Follow those buttons; the older help articles often point to the old location. If you don't see Organization settings at all, you're a User. Stop and get the Primary Owner involved.


Part 2: Privacy and confidentiality (do this first)

This is the most important part for a law firm. Your duty of confidentiality under ABA Model Rule 1.6, and your state's version of it, doesn't pause because you're using AI. ABA Formal Opinion 512 (July 2024) is the starting point for the ethics analysis, and many state bars have issued their own guidance since. Anthropic also published an article for lawyers in August 2026 on privilege, confidentiality, and configuration; it's worth reading, with one caution I note in Step 2.4. Get this part right before anyone touches a client matter.

Step 2.1: Know which terms govern the account

  • Team runs under Anthropic's Commercial Terms. Your firm is the controller of the data your people submit, and Anthropic is the processor.
  • Anthropic doesn't train its models on your content by default.
  • Anthropic's Data Processing Addendum, with Standard Contractual Clauses, is built into the Commercial Terms. There's nothing separate to sign.
  • Anthropic lists ISO 27001, ISO 42001, and SOC 2 Type I and Type II. The reports are on its Trust Center at trust.anthropic.com.

A lawyer's personal Pro account runs under different terms, different privacy treatment, and different retention. Make "client work only in the firm's account" part of day one.

Step 2.2: Understand what the firm can see

Claude Team is a firm-managed account. The firm, not the lawyer, is the customer.

  • The Primary Owner can export the organization's data from Data and privacy: conversations, uploaded files, usage information, memory, incognito chats, and the data of people who have since left.
  • Members can't download their own data unless you turn on Allow members to export their own data (Step 6.2).
  • Owners see usage analytics: who's active, project names, which connectors get used, and spend. Not the content of chats.
  • No admin screen lets an Owner browse a person's memory, but memory is included in the Primary Owner's export. Private from colleagues is not the same as private from the firm.

This is the opposite of ChatGPT Business, where the firm can't export anything. It matters for lateral moves, internal investigations, malpractice claims, partner disputes, and employment matters. If you wouldn't write it in firm email, don't type it into the firm's Claude account. Personal questions ("help me draft a wedding toast") belong in a personal account. Tell everyone this before their first chat.

Step 2.3: Set sensible data minimization rules

Configuration alone will not protect you. Before anyone uses Claude on real matters, document and circulate firm rules. A workable starting set:

  • Minimize regulated identifiers. Leave out Social Security numbers, financial account numbers, medical record identifiers, and other regulated data unless the task needs them, the firm's privacy posture and client agreements permit it, and you've cut them down to the smallest amount needed. Sometimes employment, tax, PI, med-mal, immigration, or financial work genuinely needs them. Often a redacted version is enough. Make the question conscious, not automatic.
  • Be careful about pairing identity with strategy. Don't put client names next to candid case strategy in a project shared more widely than the matter team.
  • Treat Claude inputs like vendor inputs. Anything typed or uploaded should be treated the same as anything sent to an outside vendor: subject to your engagement letter, your privacy policy, and your AI use disclosure. Confirm whether your engagement letters and outside counsel guidelines permit AI assistance, and update them if not.

Step 2.4: Manage retention

On Team, chats stay until someone deletes them. There's no retention period to set; custom retention is an Enterprise feature. Anthropic's article for lawyers says retention is configurable, but that refers to Enterprise. Don't repeat it to a client about a Team account.

  • A deleted chat leaves your history immediately and Anthropic's back-end systems within 30 days.
  • Deleting a chat doesn't delete memories Claude formed from it. Delete those separately under Settings > Memory.
  • Incognito chats aren't saved to history or memory, but on Team they're kept for 30 days for safety and are included in the Primary Owner's export. They don't work inside projects.
  • Cowork sessions that run locally on a lawyer's computer keep their history on that computer, outside Anthropic's retention and outside anything an admin can manage.
  • Team has no legal hold. Nothing stops a user from deleting a chat, and a deleted chat won't be in the next export. If a hold reaches AI use, run the export promptly and tell the people involved not to delete anything.

Write a deletion rule before rollout that fits your records policy and any litigation holds. For example: delete chats that contain client confidences once the work product is saved to the document management system. Some firms want a record of AI-assisted work; some don't. Decide once, not case by case.

Step 2.5: Know the rules that come with Fable

Fable 5.1, the most capable model on Team, comes with two strings. The first is cost: Premium seats can spend up to half their weekly usage on Fable models, while Standard seats can only use Fable with usage credits, billed at API rates. The second is retention: Anthropic designates Fable and its sibling Mythos as "covered models," and says prompts and outputs sent to them are kept for at least 30 days and reviewed by automated safety systems, on every surface where the models run.

For a Team account that changes little in practice, because Team already keeps chats until someone deletes them. Anthropic's more detailed retention article is written for customers with zero data retention, so I wouldn't read more into it for Team without confirmation from Anthropic. If a matter calls for it, Opus 5.5 (which Anthropic says performs at Fable 5.1's level on most work) keeps you outside the covered-model policy; it still runs under Team's standard retention and Anthropic's usual safety systems.

Step 2.6: Know that Claude's text carries a watermark

Anthropic signed the EU's code of practice on marking AI-generated content. Text from Opus 5.5, Fable 5.1, and Opus 5 carries an invisible watermark that travels with the words when they're copied and may survive some editing, and files Claude creates carry Content Credentials. Anthropic plans to extend watermarks to its older models by December 2, 2026. There's no setting to turn this off, and for now detection is limited to regulators and certain other organizations. It's one more reason to settle your AI disclosure position before a court or client asks.

Step 2.7: PHI and HIPAA

Team plans can't be configured for HIPAA. Enterprise plans can, and the Business Associate Agreement there still doesn't cover Cowork, the Office add-ins, or Docs, Slides, and Design.

Holding medical records doesn't by itself make a firm a HIPAA business associate; that depends on whose records they are and for whom you're working. A firm that represents a health plan or provider may be one. Other firms handle medical records in personal injury, workers' compensation, med-mal, disability, and elder law matters without being business associates, but still owe confidentiality. Have counsel determine the firm's role. My conservative recommendation is a firm policy that keeps medical records out of Team unless counsel has cleared a specific use.

Step 2.8: Decide what clients need to know

ABA Formal Opinion 512 says a lawyer may need a client's informed consent before putting information about the representation into an AI tool, and that boilerplate in an engagement letter isn't enough when consent is required. Decide, for each tool and each kind of use, whether consent is needed, and get it specifically when it is. Check your state bar's guidance too, and any outside counsel guidelines that restrict AI use.

Step 2.9: Know where your data is

Anthropic stores Team data in the United States and may route traffic through the US, Europe, Asia, and Australia. Processing restricted to the US is an Enterprise option.


Part 3: Four firm decisions before you invite anyone

Before you bring people in, write down where the firm lands on four questions. Doing it now saves a hundred small arguments later.

  1. What data may go into Claude? Be specific. Pleadings? Discovery? Medical records? Privileged communications? Trust account information? Write it as a one-page firm policy, not a verbal understanding.
  2. Who may create projects, and who's in them? In Claude, sharing a project shares its files and instructions, not anyone's chats. Opening a project to the whole firm puts its documents in front of everyone. Decide who can do that.
  3. What may Claude do on its own? Cowork runs multi-step tasks, drives a browser, can be controlled remotely from a phone, and can act in Outlook, SharePoint, Gmail, and Drive. Decide whether automatic approval is allowed, which connectors may write, and whether the browser tools are on. Parts 5, 7, and 8 show the settings that enforce your answer.
  4. What must be verified before output leaves the firm? Part 11 gives you a starting protocol. This one isn't optional; courts have sanctioned lawyers for unverified AI output.

Get the four answers signed off by the partners before you send a single invitation.


Part 4: Organization, members, and billing

Step 4.1: Set the team name and logo

Where: Organization and access > Team nameWho: OwnersMy call: On

The top of Organization and access shows a Team overview: your allowed email domains, total seats (with a Manage link for buying seats), and total members. Below it, set the team name and upload the firm's logo so people know at a glance they're in the firm's account.

Step 4.2: Write organization instructions

Where: Organization and access > Organization instructionsDefault: emptyMy call: On

Organization instructions apply to every conversation across the firm and take priority over people's personal preferences. The box holds 3,000 characters, and changes can take up to an hour to take effect. It's one of the highest-impact settings, and most firms leave it empty.

Two quirks. Members can't see the organization instructions, so anything lawyers must know also belongs in your written policy. And they're sent with every message, so keep them short. A workable starting set for a small law firm:

You are working for [Firm Name], a [practice area] law firm. Treat all uploaded documents and conversation content as confidential client information. When asked legal questions, cite primary sources (statutes, cases, court rules) rather than secondary commentary, and say plainly when you can't find authority. Flag any sentence where you are inferring rather than working from a cited source. Use Bluebook citation format unless the user specifies otherwise. Produce work product for an attorney to review and adopt, not advice to a client.

Step 4.3: Verify your domain and set up single sign-on

Where: Organization and access > Domains; AuthenticationWho: OwnersMy call: verify On; Discoverable Off; SSO On if you use Microsoft 365, Google, or Okta

The Domains table lists each allowed email domain with two columns that matter: Discoverable and Verification. New domains show as Unverified until you prove you own them.

  1. Click Verify next to your firm's domain (use Add or edit domains to add one)
  2. Copy the whole TXT value, which starts with anthropic-domain-verification-, and save it; the console won't show it again
  3. Have your IT vendor add it as a TXT record at the root of your domain
  4. Come back and refresh until the domain shows Verified

Discoverable lets people who sign up with that domain find your organization and ask to join. Turn it off for a small firm; you'll invite people yourself. Public domains such as gmail.com can be allowed (so you can invite a contractor who uses one) but can't be made discoverable.

Single sign-on sits under Authentication and stays grayed out until at least one domain is verified. Once it's available, set it up with your identity provider (Microsoft Entra ID, Google Workspace, Okta, and others) and require it. From then on, your identity provider's rules apply to Claude, including multi-factor authentication and cutting off a departing lawyer. Two cautions: people on your domain who aren't assigned to the Claude app in your identity provider lose access to their personal Claude accounts on that email, and an expired signing certificate with SSO required locks everyone out until Anthropic Support helps an Owner. Put the certificate renewal on a calendar. Anthropic's docs also describe a Restrict organization creation switch that appears after verification and stops new personal accounts on your domain; if you see it, turn it on.

Step 4.4: Close the side doors

Where: Organization and access > User provisioningWho: Admins and above

The User provisioning section decides how people get in:

  • Invite only: members are added by email invitation. The right choice for a small firm.
  • Just-in-time (JIT): people are added automatically the first time they sign in through SSO. It's grayed out until SSO is on. It never removes anyone; when someone leaves, remove them in your identity provider and in Claude.
  • Invite link: anyone with an allowed email domain who has the link joins and is approved automatically. Off.
  • Member invites: lets members invite others by email, subject to your approval setting. Off, or leave it on only with admin approval.
  • New member approval: Require admin approval, so you get a notification for each join request and approve them one at a time.

Anthropic's docs say new organizations can start with the invite link and member invites switched on, and an automatically approved join can add a paid seat. Check yours. You want to see who's asking, and what it will cost, before anyone gets in.

Step 4.5: Add members

  1. Go to Members
  2. Click Add member
  3. Enter the person's email, and choose their role and seat tier
  4. Send the invitation

The Members page has Active and Pending tabs, a role filter, and Export CSV for your records. A pending invitation takes a seat the moment you send it, so cancel the ones you don't need.

Step 4.6: Choose Standard or Premium seats

Where: Members > Tier; Organization and access > Total seats > ManageWho: Owners buy seats; Admins assign them

  • Standard: $25 per member per month, or $20 billed annually. About 1.25 times a personal Pro account's usage per session, with a weekly limit. Includes Claude Code and Cowork. Fable models run only on usage credits.
  • Premium: $125 per member per month, or $100 billed annually. About five times Standard's usage, with Fable included for up to half of the weekly limit.

The plan needs at least two seats and allows up to 150. Limits apply per person, not across the team. Those are Anthropic's published US prices, and they change. Start everyone on Standard, with Opus 5.5 as the everyday model, and move heavy users to Premium along with anyone who needs Fable regularly.

Billing shows your plan, seats, next invoice, payment method, and invoice history, plus the cancel button. New seats are charged right away, prorated; seat reductions take effect at renewal. Removing a member frees the seat but doesn't lower the bill until an Owner reduces the seat count.

Step 4.7: Decide on usage credits

Where: UsageWho: OwnersMy call: Your call

The Usage page has three things:

  • Turn on usage credits: lets people keep working after they hit their seat's limit, billed at usage-based rates. Off until an Owner turns it on. If you turn it on, set an organization limit and per-person limits first.
  • Usage credit requests: lets members ask for credits when they hit their limits, so you decide case by case. Leave it on.
  • Services: spend limits for automated services such as Claude Code Review. Set a limit if anyone uses them.

Two reasons to be deliberate: Standard seats can only use Fable through credits, and Claude Tag won't run in Slack until credits are loaded.

Step 4.8: Assign roles

  • Primary Owner: one per organization. The only person who can export the firm's data and transfer primary ownership. Can be a firm-controlled service account.
  • Owner: billing, capabilities, connectors, organization instructions, single sign-on, analytics, and nearly every setting in this guide.
  • Admin: members, invitations, and seat assignments. Can't change capabilities or see analytics.
  • User: uses Claude, creates projects, no admin access.

A firm-controlled service account (something like claude-admin@firmname.com) makes a good Primary Owner because it doesn't leave with a partner. Give at least one other trusted person Owner access, make one operations person the Admin, and everyone else a User. Team has no custom roles, so every setting applies to the whole firm. That's why several recommendations below say "pilot first."

Step 4.9: Run a pilot before firm-wide rollout

Before you invite everyone, invite one attorney and one staff member as a pilot pair. Have them sign in, install the desktop app and one Office add-in, connect Microsoft 365 or Google, create a test project, and ask Claude a real but non-sensitive question. This catches the obvious problems (for example, Office add-ins that won't install in your Microsoft 365 environment) before you debug them across the firm.

Test that the restrictions hold, not just that things work. Using made-up matter data, confirm that:

  • a colleague who isn't on a project can't open it or its files
  • someone outside the firm can't open an artifact you meant to keep internal
  • a connector write action (sending an email, editing a file) is blocked or asks for approval
  • a connector search stays within the sources you pointed it at
  • removing a test member actually ends their access

Write down the date, who tested, what you expected, and what happened. That record is what you show a client who asks how the firm controls AI.


Part 5: Capabilities

Capabilities is the busiest page in the console. It has six sections: Data sources, Visuals, Tool approvals, Code execution, Remote sessions, and Memory. Several settings that used to live on the Cowork and Claude Code pages now live here.

Step 5.1: Data sources

Where: Capabilities > Data sourcesWho: Owners

  • Web search: On. This is what lets Claude find current statutes, recent rulings, and updated rules, with citations you can check. Research, the longer mode that runs many searches and writes a report, depends on it.
  • Interactive content (default on): On. Lets Claude show maps, images, and similar visuals from third-party services such as Google Maps and Bing.
  • Ask [your organization] (default on): Your call. Lets people search across the firm's connected data sources and knowledge bases in one place, each person seeing only what their own accounts can reach. It does little until you add connectors (Part 8); revisit it after your connector pilot.
  • Built-in browser (default on): Your call. Lets Claude open websites, read pages, and fill in forms in Cowork and Claude Code. It no longer lives on the Cowork page. The Browser site permissions button under it controls which sites Claude may act on, and it's the same list Claude in Chrome uses (Step 7.2). If you leave the browser on, limit the sites first.

Step 5.2: Visuals

Where: Capabilities > Visuals

  • Enable artifact connectors: Off until you have a use. It lets the documents, dashboards, and small tools Claude builds pull data from connected apps. Useful for internal dashboards, unnecessary on day one.
  • Inline visualizations (default on): On. Charts and diagrams right in the conversation.

Step 5.3: Tool approvals

Where: Capabilities > Tool approvalsWho: Owners

This section decides how much Claude may do without asking. It's the most important new section for a law firm.

  • Allow "Automatically approve" mode (default on): Off for the first 30 days. In Cowork, lets people have Claude approve its own actions, including using tools, editing files, and browsing, pausing only for what looks unsafe. It doesn't apply to regular chats. Turn it back on once people have watched Claude work, with the approval rule in Step 7.1.
  • Allow "Skip all approvals" mode (beta): Off. Lets Claude act with no approvals and no safety pause, in Cowork and Cowork in the cloud. The console itself warns it can put organizational data at risk. There's no reason for a law firm to allow it.
  • Allow "Always allow" for connector tools: Off. Lets people pre-approve connector tools that make changes (sending, editing, deleting) so Claude never asks again. The console warns that it raises the risk that content in a connected app steers Claude into unintended actions. It applies to Cowork, Cowork in the cloud, and Claude Code cloud sessions.

Step 5.4: Code execution

Where: Capabilities > Code executionDefault: onMy call: On; domain allowlist: package managers only

Cloud code execution and file creation is what lets Claude hand you a formatted Word document, a spreadsheet with working formulas, a PowerPoint deck, or a PDF, and do real math on damages tables and fee calculations. Skills need it too. Leave it on.

Allow network egress gives Claude's sandbox internet access to install software packages for analysis and file work. Under it, the Domain allowlist decides what the sandbox can reach. Choose the package-managers option rather than All domains. With All domains, a document carrying hidden instructions has a path to send data anywhere on the internet. The console notes that these controls don't cover web search, web fetch, or connectors, which have their own settings.

Step 5.5: Remote sessions

Where: Capabilities > Remote sessionsWho: Owners

  • Remote Control (default on): Your call. Lets people control Cowork on their own computers from claude.ai or the Claude mobile app, and those sessions can reach files, tools, and apps on that computer. Handy for a partner who starts a task at the office and checks it from a phone; a real exposure if a phone is lost. If you leave it on, require trusted devices.
  • Require trusted devices (default off): On. Makes people verify each new device before it can connect to Claude on their computer remotely. It covers both Cowork and Claude Code remote control.
  • Routines (preview, default on): On. Lets people create scheduled and triggered tasks that run in the cloud. Turning it off also turns off scheduled tasks for Cowork in the cloud. Keep it, and make the rule from Step 7.1 about what may be scheduled.

Step 5.6: Memory

Where: Capabilities > MemoryDefault: onMy call: On with client work in projects; sensitive topics Off

Enable memory for your team lets each person's Claude remember context from their own past chats. It's on by default in the console (Anthropic's help articles still describe it as off). Memory stays private to each person, and each person can see, edit, or delete what Claude remembers under Settings > Memory.

Every project keeps its own separate memory, so a matter kept in its own project stays walled off from the others. Memory from chats outside projects can carry from one conversation to the next. That gives you the rule: client work happens in projects, one project per matter.

Sensitive topics in memory lets people choose to have Claude remember things like health conditions or religious beliefs; each person still has to turn it on for themselves. Turn the organization switch off.

Three things to know: deleting a chat doesn't delete the memories formed from it, memory is included in the Primary Owner's data export, and turning memory off for the firm later permanently deletes everyone's memory.


Part 6: Data and privacy settings

Data and privacy now has four tabs: Sharing, Data controls, Privacy controls, and Monitoring. Each switch shows a small label reading "Default" or "Set by admin," which tells you whether someone has changed it.

Step 6.1: Sharing

Where: Data and privacy > SharingWho: Owners

  • Share chats: On. Lets people share a chat with others in the firm. A shared chat is a read-only snapshot.
  • Share chats that use connectors: On. Recipients see Claude's response but not the underlying data from the connector.
  • Share chats externally: Off. Lets people invite someone outside the firm to a chat by email, as a view-only copy. For a law firm, a chat about a matter shouldn't leave by that route.
  • Share cloud sessions (default on): Your call. Lets people share Claude Code cloud sessions inside the firm. Only matters if someone uses Claude Code.
  • Share projects (default on): On. Lets people share projects with specific colleagues. Turning it off also turns off Public projects.
  • Public projects: Off unless you want firm-wide reference projects. "Public" here means everyone at the firm, not the internet; public projects appear in an Organization tab. With it off, one wrong click can't put a matter's documents in front of the whole firm. If you want a firm-wide style guide project, leave it on and make "no client material in firm-wide projects" a written rule.

Step 6.2: Data controls

Where: Data and privacy > Data controls

  • Export data: the button that exports the organization's data. Only the Primary Owner can run it; the link arrives by email and expires after 24 hours. It's also the only way to retrieve AI work on Team for a litigation hold or an internal review, since audit logs are an Enterprise feature. Run one test export this quarter. A control you've never exercised isn't a control.
  • Allow members to export their own data (default off): Off. Lets each person download a copy of their own conversations. For a firm, that's client material leaving on a personal download. The Primary Owner can still export organizational data either way.

Step 6.3: Privacy controls

Where: Data and privacy > Privacy controls

  • Rate chats: Off. The thumbs-up and thumbs-down buttons send feedback to Anthropic, and Anthropic stores the whole conversation with that feedback for up to five years and may use it to train its models. An associate frustrated with a draft about a real client matter can send that matter to Anthropic with one click. Turn it off, and have people tell the firm's AI champion instead.
  • Location metadata (default on): Your call. Lets Claude use a city or region from each person's connection to tailor results, like local court rules. Harmless for most firms; turn it off if location is sensitive for your practice.

Step 6.4: Monitoring

Where: Data and privacy > MonitoringMy call: Off unless you run a SIEM

Monitoring streams activity from Cowork (and, in a separate section, the Office add-ins) to a security monitoring system using OpenTelemetry. You fill in an endpoint, protocol, headers, and attributes. The stream can include prompt text, file paths, and email addresses, so leave it empty unless you already run a system built to hold that. Both settings used to live on their product pages.


Part 7: Products: Cowork, Chrome, artifacts, and more

Step 7.1: Cowork

Where: CoworkWho: Owners

Cowork is Claude working through a multi-step task instead of answering a single question: researching, reading files, running code, and handing back finished documents. The console now calls it generally available. In May I recommended leaving it off; today the useful question is how much Claude may do without asking.

  • Enable for your organization (default on): On. Your network egress settings (Step 5.4) apply to every session.
  • Cowork in the cloud (beta, default on): On. Runs tasks on Anthropic's cloud so they keep going across desktop, web, and mobile after you close the laptop. It also moves the chat and Cowork switch next to the message box and joins projects and artifacts across the two. Files a cloud task opens are processed on Anthropic's servers under the same commercial terms. Scheduled tasks in the cloud follow the Routines setting (Step 5.5).
  • Enable Dispatch: Off. Lets people keep Cowork running on their own computer and send it instructions from any signed-in device; the console says it can then reach files, apps, and websites on that computer without direct supervision. That's more autonomy than a law firm needs.

The rest of the Cowork page now points elsewhere: the built-in browser and the three approval switches live in Capabilities, artifacts have their own page, remote control lives in Remote sessions, and monitoring lives in Data and privacy.

The approval rule I give firms: every Cowork task runs in a mode chosen in the message box. Manual, the default, asks before each action. Use Manual for anything that touches client files or connected accounts. Use automatic approval only for work you'd let a first-year run without checking in. Don't schedule tasks that touch sensitive files or send messages on anyone's behalf, which is Anthropic's own guidance too.

On the desktop, Cowork works far faster on a local working copy of files than on a network drive or a synced OneDrive, SharePoint, Dropbox, or document management folder, because it reaches across the network for every file. But a local copy is another copy of client information, so speed alone shouldn't decide it. If you allow working copies, write the procedure down: firm-managed and encrypted computers only, an approved working folder (your IT vendor can restrict Cowork to it with the allowedWorkspaceFolders policy), the smallest set of files that answers the question, the result filed back where the matter lives, and the working copy deleted only after anything your records policy or a litigation hold requires has been preserved.

Step 7.2: Claude in Chrome

Where: Claude in ChromeWho: OwnersDefault: onMy call: Your call; allowed sites only

Claude in Chrome is a browser extension that lets Claude read and act on the page you're viewing. Anthropic's own safety guidance advises strongly against using it for legal documents or contracts, for work accounts holding sensitive data, or on sites with other people's personal information. Anything visible in a tab becomes part of the conversation, and web pages can carry hidden instructions.

  • Enable for your team (default on): your call. If nobody has a use for it, turn it off.
  • Password managers: Off. Lets people connect a password manager so Claude can sign in to sites while it works. Each request is approved in the password manager, and Claude never sees the passwords, but a law firm doesn't need Claude signing in anywhere yet.
  • Site permissions: these apply to both Claude in Chrome and the built-in browser in the desktop app. Default for all sites can be set to allow all sites (with a Blocked sites list) or to limit Claude to sites you list. Choose the limited option and add only public research sites: court dockets, agency sites, your legal research service.

Step 7.3: Artifacts

An artifact is anything Claude makes that you'd put in front of someone: a document, a deck, a design, a dashboard, a small tool. Claude Docs are living documents colleagues edit together, Claude Slides are decks you can present or export to PowerPoint, and design systems hold your firm's colors, fonts, and components so decks and designs come out on brand. Your document management system stays the file of record: draft in Docs if it helps, then export to Word and file it where the matter lives.

Step 7.4: Set the Artifacts page

Where: ArtifactsWho: Owners

SettingDefaultMy call
ArtifactsOnOn
Organization-wide sharingOnOn
External sharing (anyone with the link)OffOff
Email invitations outside your organizationOnOff
Artifact presenceOnOn
Templates: Slides, Design, Design systems, DocsOnOn

Email invitations outside your organization lets a member invite specific people outside the firm to an artifact by email, and it starts switched on. Turn it off unless you've decided you want that path. Turning it off also blocks anyone already invited. Organization-wide sharing is fine to keep; turning it off would break links people have already shared inside the firm.

Tell your people one trap: sharing an artifact that was made in a chat can also share the files attached to that chat. Check before sharing.

Step 7.5: Claude Design

Where: Claude DesignDefault: onMy call: On; Allow public links Off

This page controls standalone Claude Design at claude.ai/design, which makes visuals, layouts, and mockups. Leave it on. Under it, Allow public links lets Claude create public links to designs and project files and use them to send work to partner tools. Turn it off. A public link is a way out of the firm that nobody reviews.

Step 7.6: Office Agents

Where: Office AgentsDefault: onMy call: Your call; pilot first

Let Claude work across apps lets Claude share context between the Office add-ins, so it can pull from a spreadsheet while it builds a slide. That's useful, and it's also a way for one matter's document to inform work on another's if both are open. Pilot it before relying on it firm-wide: have your testers work with documents from one matter at a time and check what context moves between apps. Installing the add-ins themselves is covered in Step 9.3.

Step 7.7: Claude Tag in Slack

Where: Claude Tag (beta)Who: Owners, plus a Slack adminMy call: Your call; no client matters yet

Claude Tag puts Claude into your Slack channels, where anyone can @mention it and it works in the open. The setup page walks you through three steps: pair your Slack workspace, buy usage credits, and launch. When I checked, Anthropic was offering the first $2,500 of usage free, subject to terms. After setup, the page adds Access bundles (the tools and accounts Claude can use), Activity, and Federated agent access. It's Slack only; there's no Microsoft Teams version.

Anthropic's documentation for the beta raises points to settle before a client matter goes near a channel: everything Claude posts is visible to the whole channel, memory is kept per channel, and Tag transcripts aren't covered by the firm's data export. If you set it up, restrict it to people in your Claude organization and to the channels Claude has been added to.

Step 7.8: Claude Code and Cloud environments

Where: Claude Code; Cloud environmentsWho: OwnersMy call: on only if someone builds tools

Every Team seat includes Claude Code, Anthropic's coding agent. For most lawyers it's irrelevant; for whoever builds the firm's internal tools, it's the best thing Anthropic makes. The page now has real switches:

  • Desktop and Cloud sessions (both default on): turn them off if nobody builds. Turning off cloud sessions also turns off Remote Control.
  • Remote Control: Off unless someone needs to continue a local session from a phone; those sessions have full access to the computer's files. Require trusted devices now lives in Capabilities (Step 5.5).
  • Managed settings: lets an Owner set permissions and allowed folders for everyone's Claude Code. A job for your builder.
  • Fast mode (preview, default off): faster output billed from usage credits. Leave it off.
  • Channels (preview): Off. Lets outside systems send messages into Claude Code sessions.
  • Dynamic workflows (default on), Quick setup (preview, default off), Code review, analytics, and self-hosted infrastructure (GitHub Enterprise, GitLab): leave for your builder.

Cloud environments is where cloud sessions for Claude Code, Claude Tag, and Claude Security run. Anthropic-hosted environments are the recommended choice; Allow self-hosted environments is off by default, and a law firm should leave it that way. The GitHub page connects a GitHub account for Tag, Code, and Security; skip it unless someone builds.

Step 7.9: Claude Science and Claude Academy

Claude Science (beta, default off) is a workbench for scientists and researchers, with its own connectors, skills, compute, and memory settings. Leave it off. Claude Academy (beta) lets members ask Claude questions inside Anthropic's training courses. Leave it on; it's a cheap way for people to learn.


Part 8: Plugins, skills, and connectors

Step 8.1: Plugins and skills

Where: Plugins & skillsWho: Owners

A skill is a set of instructions, sometimes with files, that Claude follows for a repeatable task. A plugin bundles skills, connectors, and helpers. The page has four tabs: Inventory, Marketplaces, Requests, and Policy. Inventory lists every skill and plugin in the organization, including ones people created for themselves, with the creator, version, audience (for example, Only creator), and how many people used it in the last 30 days. You can see names and who can use them, not the contents.

  • Policy: five settings, and the first four can stay at their defaults.
    • Cloud code execution and file creation (default on): the same switch as in Capabilities; skills need it.
    • Skills (default on): turns skills and plugins on or off for everyone, including the firm's own skills and what Claude Code syncs from the organization. The console warns that skills can contain executable code, so people should be careful with skills from unknown sources.
    • User-created skills (default on): lets people upload or create their own skills. Leave it on; turn it off only if you want to lock the firm to approved skills.
    • Skill sharing (default on): lets people share skills and plugins with each other.
    • Publishing (default Open): publishing makes a skill or plugin available to everyone at the firm, and Open means anyone can publish without review. Change it to require review. Security scanning of uploaded skills is an Enterprise feature, so on Team an Owner's review is the only check.
  • Marketplaces: Anthropic offers plugin collections, including a Legal one. Add the ones you'll use and make plugins available to install rather than required.
  • Add: upload or create firm skills. Good first ones: your citation and formatting conventions, your engagement-letter checklist, and the verification protocol in Part 11.

Step 8.2: Connectors

Where: ConnectorsWho: OwnersMy call: On for what you use

Connectors let Claude search and act in your other systems. The Connectors page lists each connector with its type (Web, with a Custom tag for ones you added yourself), how people authorize it (Individual means each person signs in with their own account), and a category. Use Add to bring in a connector from the directory or a custom one. Claude sees only what each person can already see.

Add Microsoft 365 or Google Workspace, whichever the firm runs, plus the practice tools you already license. Leave the rest until someone asks. Custom connectors aren't verified by Anthropic and can carry hidden instructions; add them only after IT has vetted the server. For each connector, Owners can set every tool to always allow, needs approval, or blocked for the whole firm. Use that to block the actions you ruled out in Part 3, since during Research Claude can call connector tools without asking each time.

The same page has the Desktop extension allowlist (default off): On. Desktop extensions are local connectors that run on a lawyer's computer with that person's permissions. Until you turn this on, anyone can install any desktop extension. Turn it on and use Add desktop extensions to approve the few you want.

Step 8.3: Microsoft 365

  1. An Owner adds Microsoft 365 on the Connectors page
  2. A Microsoft Entra Global Administrator grants tenant-wide consent once
  3. For a pilot, require assignment on the Claude enterprise apps in Entra and assign only the pilot users

What it can read is broad: Outlook mail and calendars (including shared mailboxes), OneDrive and SharePoint across the whole tenant with each person's permissions, and Teams chats, channel messages, and meeting transcripts. If your SharePoint permissions are sloppy, Claude will surface files people could always reach but never found. Fix oversharing first.

It can also write: send and forward email, create inbox rules and out-of-office replies, change calendars, upload and delete files in OneDrive and SharePoint, and post in Teams. Write tools need your Entra admin to approve the added permissions and an Owner to enable them. Keep it read-only during the pilot, then enable only the write tools you approved in Part 3. Every call the connector makes shows up in your Microsoft 365 audit log.

A note for IT: the connector's requests come from Anthropic's servers, not from the lawyer's computer, so don't assume your usual VPN, location, and device rules apply the same way. Anthropic's security guide says location and network restrictions in Conditional Access aren't supported, and device checks rely on the device recorded when the connection was made. Test it before rollout. And tell lawyers that email searches don't cover the separate Online Archive mailbox, so a Claude search isn't a complete mailbox search.

Step 8.4: Google Workspace

The Gmail, Google Calendar, and Google Drive connectors now write as well as read: send and reply to email, create events, and share, move, or trash files. By default Claude asks before each of those, and Owners decide whether people may skip that. Your Google Workspace admin may need to trust the Claude app before anyone can connect. Anthropic doesn't train on connector data.


Part 9: Install the apps your team will actually use

Most attorneys end up using Claude in three places: a browser, the desktop app, and inside Microsoft Office. Walk your team through this once and they won't have to think about it again.

Step 9.1: The desktop app

  1. Go to claude.com/download
  2. Choose Mac or Windows (Linux is in beta)
  3. Install like any other app
  4. Sign in with your firm email and select the firm's organization

The desktop app is required for Cowork on local files, the built-in browser, and desktop extensions. If an IT vendor manages your computers, they can deploy it and set policies such as limiting the app to the firm's account and limiting which folders Cowork may use.

Step 9.2: The mobile app

  1. Install Claude by Anthropic from the App Store or Google Play
  2. Sign in with your firm email
  3. Confirm you're in the firm's organization, not a personal account

Voice mode keeps a text transcript in the chat history, and dictation can capture more than people intend. Treat the phone like any device that records, especially around clients and opposing counsel. If you left Remote Control on (Step 5.5), the phone can also steer work on a lawyer's computer, which is why I recommend requiring trusted devices.

Step 9.3: The Microsoft Office add-ins

Claude for Word, Excel, and PowerPoint are generally available on Team, and Claude for Outlook is in beta. Word works in tracked-changes mode, handles comments, summarizes a counterparty's redlines, fills templates, and understands legal numbering, defined terms, and cross-references. The Outlook add-in drafts replies and meeting requests but can't send; every draft waits for you to click Send.

  1. Open Word, Excel, or PowerPoint
  2. Go to Home > Add-ins and search for Claude
  3. Install the official Anthropic add-in and sign in with your firm account

If that doesn't work, your Microsoft 365 admin deploys it from the Microsoft 365 admin center (Settings > Integrated apps > Add-ins). Outlook also needs a one-time Microsoft Graph consent from a Global Administrator and works only with Exchange Online.

Three things to tell users:

  • Add-in conversations are stored in the browser on that computer, not on Anthropic's servers, and they don't sync between machines. Don't expect them in the firm's data export, and give each person their own computer login.
  • Anthropic's own guidance is to use the Word add-in with trusted documents. A counterparty's draft or an emailed file can contain hidden instructions.
  • Nothing from an add-in goes to a client, a court, or opposing counsel without the review in Part 11.

Step 9.4: Optional, the Chrome extension

If you decided to allow Claude in Chrome (Step 7.2), people install it from the Chrome Web Store, or IT deploys it through Google Workspace or device management. It works only in Chrome.


Part 10: Build your starter projects

Projects are the single most useful feature for a law firm on Team. Each project is a self-contained workspace with its own files, instructions, chats, and memory. Think of them as matter folders or practice area folders.

Step 10.1: Create your first project

  1. Click Projects in the left sidebar, then + New project
  2. Give it a clear name and description
  3. Choose who can see it: only people you invite, or everyone at the firm (if Public projects is on)
  4. Add your files: documents, templates, prior work product
  5. Add instructions specific to that project's purpose

Step 10.2: Sharing inside a project

  • Can view: the person can use the project's files and instructions and chat in the project.
  • Can edit: the person can also change instructions and files and add or remove members.

For client matters, Can view is the right default for everyone but the lead attorney. For templates and reference projects, Can edit is fine for the partners who own them.

Important: chats inside a shared project are still private to the person who created them, unless that person deliberately shares one, and a shared chat is a snapshot the recipient can read but not continue. Two associates can work the same matter project without seeing each other's questions. That's the opposite of ChatGPT, where every member of a shared project reads every chat.

Step 10.3: Why client work belongs in projects

  • Each project has its own memory, separate from other projects and from loose chats (Step 5.6).
  • Connectors work in private projects.
  • Incognito chats aren't available inside projects, so one-off questions that don't belong to a matter can still stay out of history.

But a project isn't a complete ethical wall. Project memory controls what Claude carries between conversations. It doesn't narrow what a connector can reach: from inside any project, the Microsoft 365 or Google connector can still pull any other matter the lawyer can open in Outlook, SharePoint, or Drive, and a read-only search can bring that material into an answer someone then shares. Instructions to keep matters separate aren't access controls. Point each task at the sources it needs, and check which matter the answer drew on before sharing it.

Step 10.4: Plan for departures

When you remove someone, colleagues immediately lose access to their private projects and their chats, and links to chats they shared stop working. Projects they shared stay where they were. So have lawyers share each matter project with at least one colleague, with Can edit for whoever takes over, rather than keeping matter work in private projects. If someone leaves anyway, the Primary Owner's data export still includes their data.

Step 10.5: Suggested starter projects for a small firm

  1. Firm Style and Templates: firm-wide if you left Public projects on, otherwise shared with the partners who maintain it. Engagement letter templates, citation conventions, brief formatting standards, and the firm style guide. No client material.
  2. Practice Area Reference (one per area): governing statutes, key cases you cite often, common motions, jurisdiction-specific rules. Instructions: "Answer questions about [practice area] using the materials in this project as the authoritative source. If the answer isn't here, say so."
  3. Client Intake Helper: private. Your intake form, conflict-check procedure, and sample conflict waivers.
  4. One project per active matter: private, shared only with the attorneys and staff working it. Deposition transcripts, pleadings, and discovery responses go here. Archive or delete it when the matter closes, in line with your retention rule.

Part 11: Verification protocol before anyone uses Claude on live matters

This is the bridge between installing Claude and using it safely. Configuration sets the rails. Verification keeps the firm out of trouble.

The minimum rule

Claude output is never final legal work product. Before any AI-assisted material is filed with a court, sent to a client, served on opposing counsel, or shared with a third party, an attorney must independently verify it. The duty of competence (ABA Model Rule 1.1) and the duty of candor (Rule 3.3) belong to the lawyer, not to the tool. Adopt this verbatim or in your own words, get it signed by the partners, and circulate it to every user.

The minimum checklist

Every AI-assisted deliverable goes through this before it leaves the firm:

  1. Citations: confirm every case, statute, regulation, and rule against the primary authority. AI tools have invented citations, and courts have sanctioned attorneys who relied on them.
  2. Quotations: verify any quoted language against the original source.
  3. Research reports: open the sources behind web search and Research answers and confirm they say what Claude says they say.
  4. Procedural rules and deadlines: confirm them in the relevant jurisdiction's current rules. Federal, state, and local rules differ, and they change.
  5. Calculations: independently recompute damages, dates, deadlines, interest, fee totals, and any other math.
  6. Factual assertions: confirm every factual claim against the source documents.
  7. Actions taken: review anything Claude sent, saved, or changed through a connector or in Cowork before anyone relies on it.
  8. Privilege and confidentiality: confirm nothing client-confidential or privileged appears where it shouldn't.
  9. Court rules on AI: before filing, check the court's local rules and the judge's standing orders for AI disclosure or certification requirements.

Labeling and audit trail

Until an attorney has reviewed AI-assisted work product, label it as a draft. A simple convention: every Claude-generated document starts with a header like "DRAFT, AI-assisted, attorney review required," and that header comes off only when an attorney signs off. Decide whether your firm keeps an internal record of AI-assisted work for audit, training, or risk purposes. Both answers are defensible; the wrong answer is "we never thought about it."


Part 12: Roll out to your team

Step 12.1: A 30-minute orientation for every new user

  1. How to sign in to the firm's account, not a personal one
  2. What the firm can see, and the confidentiality rules from Part 2
  3. Client work in projects, one project per matter
  4. The approval rule: Manual for client files and connected accounts
  5. The verification protocol from Part 11 (this is non-optional)
  6. How to give feedback to the firm (not Anthropic) when Claude is wrong

Step 12.2: Designate an internal champion

Pick one person, ideally not a senior partner, who is the go-to for "how do I do X with Claude" questions. This person doesn't need to be technical. They need to be curious and willing to experiment.

Step 12.3: Schedule a 30-day review

Put a recurring 30-day check on your calendar and review:

  • Seats. Move Premium seats from light users to heavy ones, and reduce seats nobody uses before renewal.
  • Members. Anyone pending who shouldn't be? Anyone who joined outside your process?
  • "Set by admin" labels. Scan Capabilities and Data and privacy for switches that changed since last month, and confirm someone meant to change them.
  • Projects. Are matter projects shared only with the matter team?
  • Skills. Check the Inventory for new skills and plugins, and the Requests tab for anything waiting on review.
  • Connectors and approvals. Which write tools are on, and whether it's time to allow automatic approval.
  • Spend. Usage credits against your limits, especially for Fable and Cowork.
  • Governance reviews. If the firm reviews usage or exports, do it under a written policy, for a defined reason, with partner or ethics oversight. The point is to confirm the rules are followed, not to surveil lawyers.

Step 12.4: Write the offboarding and incident checklists

Neither of these is a single button in Claude. They're firm procedures, and they belong on paper before you need them.

When someone leaves:

  1. Preserve what your records policy or a hold requires, and hand off their projects, skills, and scheduled tasks to a named colleague before you remove access.
  2. Remove them from Members and from your identity provider, and have them (or IT) disconnect their connected apps.
  3. Stop their scheduled tasks and remote sessions, and review the chats and artifacts they shared and any local working copies on their computer.
  4. Reduce the seat count separately; removing a person doesn't lower the bill.

When something goes wrong (a document uploaded to the wrong matter, a mistaken share, an action Claude shouldn't have taken):

  1. Stop the workflow and restrict access: unshare, remove the member, or disconnect the connector.
  2. Tell the firm's designated contact, usually the general counsel or risk partner.
  3. Preserve the evidence. Don't reflexively delete the chat or file; counsel may need it to assess what happened and whether anyone must be notified.

Quick reference: where things live

To do thisGo here (Organization settings)
Team name, logo, seats, instructionsOrganization and access
Verify domains; set DiscoverableOrganization and access > Domains
Single sign-onOrganization and access > Authentication
Invite link, member invites, approvalsOrganization and access > User provisioning
Plan, payment, invoices, cancelBilling
Usage credits and service spend limitsUsage
Web search, browser, approvals, code, remote sessions, memoryCapabilities
Chat and project sharingData and privacy > Sharing
Export the organization's dataData and privacy > Data controls
Rate chats, location metadataData and privacy > Privacy controls
OpenTelemetry monitoringData and privacy > Monitoring
Add members, roles, seat tiers, export listMembers
Cowork, cloud tasks, DispatchCowork
Claude in Chrome and site permissionsClaude in Chrome
Artifact sharing and templatesArtifacts
Standalone Claude Design, public linksClaude Design
Skills and pluginsPlugins & skills
Connectors and desktop extension allowlistConnectors
Your own memorySettings > Memory (your personal settings)
Download the desktop appclaude.com/download
Install the Office add-insIn the Office app: Home > Add-ins, search "Claude"

Where to get help

If your firm needs custom retention periods, audit logs, the Compliance API, SCIM directory syncing, custom roles and groups, control over which models people can use, IP allowlisting, US-only processing, or a HIPAA BAA, Team isn't enough. Talk to Anthropic about Enterprise.


Configuration is one piece of responsible AI use in a law firm. The bigger piece is judgment: deciding what to put into Claude, how much it may do on its own, how to verify what comes out, and how to disclose AI use to clients. The setup above gives you the guardrails. The verification protocol in Part 11 keeps you out of trouble. The rest is on you and your team.

Let's talk

Want help setting this up?

A 30-minute call. I'll help you find which workflows are worth prioritizing, and the right way in.

Prefer to reach me directly? steve@intelligencebyintent.com (805) 876-4847

Please don't include confidential client information in an email.