If your staff have connected Claude to your company systems and you need to know exactly what data it can reach, the answer is straightforward: Claude connectors inherit the permissions of whoever connected them. A connector acts with the same access rights as the person who authorised it, so Claude can see whatever that individual could already access in your Microsoft 365, Google Drive, CRM or other connected services.
The risk is not that Claude breaks through your security. The risk is that your permissions were already too broad, and now AI makes that visible.
We spend our working days looking at who can actually see what inside business systems, which is exactly what matters when someone decides to connect Claude to your data.
We work inside Microsoft 365, Google Workspace and CRM permission structures every day: the same structures that Claude connectors inherit when your staff authorise them.
We understand UK GDPR requirements and translate them into practical steps, not legal abstractions.
Our governance frameworks fit businesses with 5 to 50 people. No 80-page policies, no dedicated compliance teams required.
We tell you what actually happens when staff connect AI tools to business systems, because that matters more than what might theoretically happen.
Claude connectors are integrations that allow the AI to access and work with your business applications directly from the chat interface. Claude connectors access external apps and services, enabling Claude to retrieve data and take actions within those systems. They are the connective tissue between Claude and the platforms your business already uses.
There are three types worth understanding. Remote connectors connect Claude to cloud-based services such as Microsoft 365 or Google Drive. Desktop extensions allow access to local files and processes on a local device. Interactive connectors render live interfaces within Claude conversations. All of them rely on the Model Context Protocol, or MCP, which is the standard that enables connector functionality. MCP allows AI integrations to be reusable across different systems without custom builds.
The crucial point for every UK business leader: each connector operates with the exact permissions of the person who connected it. Claude inherits user permissions from connected services. It cannot access data that the connecting user could not already reach themselves. Connectors work through established authorisation protocols and do not create new access routes. User authentication is performed through secure OAuth authorisation flows, and data transfers through connectors are encrypted for security.
But this inheritance cuts both ways. If your staff member can see confidential client files, financial records and every email in a shared mailbox, then so can Claude through their connection. Setup typically takes a few seconds using OAuth, which means a member of staff can grant Claude access to your systems in the time it takes to approve an authentication prompt, often without anyone else knowing.
Connectors are not merely read-only. They can enable actions in external systems based on permissions, meaning Claude could potentially send emails, update records or modify files depending on how the connector is configured and what write tools are enabled.
Claude Cowork, a local device extension, complements remote connectors by enabling Claude to access files and processes directly on your local device, expanding the range of data and actions Claude can perform.
The two columns are identical, and that is the point. A connector creates no new access route. It hands Claude the permissions the connecting person already holds, which is why over permissioned staff accounts become an AI problem the moment someone approves a prompt.
Illustrative example. On Microsoft 365 a Global Administrator must consent before anyone can connect. On Google Workspace, Salesforce, HubSpot and most accounting platforms, no administrator is involved.
Technical teams can write custom connectors for internal database queries and documentation access using the Model Context Protocol (MCP). Custom connectors connect Claude to your MCP server from Anthropic’s cloud, not from your local device. Your server must be reachable over the public internet. If it is behind a corporate firewall or on a private network, you may need to allowlist Anthropic’s IP ranges or configure firewall settings accordingly.
Custom connectors are available on all Claude plans. Free users can add one custom connector. For Team and Enterprise plans, an Owner adds the custom connector via Organization settings before members can connect their accounts.
The connectors directory changes frequently. Instead of relying on a definitive list, browse connectors directly within Claude’s interface to see what is currently offered. Each connector listing details its use cases, read/write capabilities, and availability.
Standard connectors provide tools Claude can call to receive data and respond in conversation. Interactive connectors render live interfaces like dashboards, task boards, and design tools within Claude chats.
Desktop extensions allow Claude Desktop to access local files and processes on your local device. They are packaged and installed in Claude Desktop and are useful for workflows that require local machine access, such as file management and automation. Desktop extensions differ from remote connectors, which connect to cloud-based services.
Claude connectors link Claude to your business applications, enabling it to retrieve data and take actions based on your permissions in those services. Examples include Microsoft 365, Google Drive, Salesforce, HubSpot, and accounting systems like Xero or QuickBooks.
Each connected service uses the same permission inheritance principle: Claude can only access data the connecting user can already see. This applies to emails, files, calendar events, CRM records, and more.
Scroll the table sideways to see every column.
| Connector | What Claude can read | What it can write | Who has to approve it | The limit that catches people out |
|---|---|---|---|---|
| Microsoft 365 Outlook, Teams, SharePoint, OneDrive | Emails and shared mailboxes where the user has delegate access, calendar entries, Teams chats and channel messages, and files across every SharePoint site and OneDrive the user can open. | Send email, create calendar items, edit files. Off by default. | A Global Administrator must grant tenant wide consent in Microsoft Entra. Write tools need separate admin consent. | SharePoint search cannot be restricted to named sites, so it spans everything the connecting user can reach. |
| Google Workspace Drive, Gmail, Calendar | Docs, Sheets and Slides plus any shared drive the user can access, Gmail message content and metadata, calendar events and shared calendars. | Draft emails, create, update and delete calendar events. Sending email needs write tools enabled. | The connecting user, through an OAuth prompt. No admin gate. | Format conversion, embedded images and some attachments are not fully supported. Write actions usually ask for confirmation. |
| Salesforce | Customer records, pipeline and commercial data, filtered by object level permissions, field level security and sharing rules. | Only the actions the user's own Salesforce permissions already allow. | The connecting user, inside their existing Salesforce role. | A sales manager's connection exposes everything their role can see, which is often the entire customer database. |
| HubSpot | Contacts, Deals, Tickets and Companies the user can already see. | Create and update some records. Cannot delete. | The connecting user, inside their existing HubSpot permissions. | Bulk updates are capped at roughly 10 records. Sensitive Data mode can block engagement data entirely. |
| Accounting Xero, QuickBooks | Invoices, payments, bank transactions and client billing visible to the connecting user. | Governed by the same inherited permissions. | The connecting user. No admin gate. | A bookkeeper's connection can cover every transaction in the business. |
| Custom connector your own MCP server | Whatever your MCP server chooses to expose. | Whatever tools your server exposes. | On Team and Enterprise an Owner adds it in Organization settings before anyone can connect. | Anthropic's cloud calls your server, so it must be reachable over the public internet. Firewall or IP allowlisting may be needed. |
| Desktop extension local device access | Files and processes on the local machine, outside your cloud tenant entirely. | File management and local automation, depending on the extension. | The individual user installs it in Claude Desktop. | There is no tenant level control point, which makes this the hardest type to govern centrally. |
Write tools are disabled by default on every connector listed above. Where a connector has no admin gate, an individual member of staff can grant access in the time it takes to approve an OAuth prompt.
The Microsoft 365 connector for Claude is often the first one UK businesses encounter, and potentially the most significant given how much underlying data lives in a typical M365 tenant.
When a staff member connects Claude to Microsoft 365, the connector makes the following accessible, subject to their existing permissions:
Write capabilities, including sending email, creating calendar items and editing files, are disabled by default. They require additional admin consent in Microsoft Entra (formerly Azure AD) and must be explicitly enabled. This is an important safeguard.
One limitation worth noting: the SharePoint search component of the Claude M365 connector does not support site-specific restrictions. The connector’s application permissions include broad search access, though it still only returns results the connecting user is permitted to see. In practice, a partner in a legal firm with access to all client matter folders could give Claude the same broad visibility across every matter, simply by authorising the connector.
For Microsoft 365, an administrator with Global Administrator rights must grant tenant-wide consent in Microsoft Entra before individual users can connect. Without that consent, no one in your organisation can use the Microsoft 365 connector for Claude.
Google Workspace connectors follow the same permission inheritance pattern as Microsoft 365. Claude inherits user permissions from connected services, so only data already visible to the connecting user is exposed.
The Claude Google Drive connector allows Claude to search files and read Google Docs, Sheets and Slides that the connecting user can access. Shared drives accessible to the user become accessible to Claude. Recent documents receive priority in Claude search results, making it straightforward for Claude to work with current projects and check project status.
The Gmail connector provides access to email content, not just metadata. Claude can search and read emails, create drafts, and see message metadata. Sending emails automatically requires explicit write permissions to be enabled.
Google Calendar integration lets Claude view events and shared calendars. With appropriate permissions, Claude can create, update and delete calendar events. This is useful for scheduling analysis but means Claude could also modify your diary if write tools are enabled.
Some advanced operations in Google Drive have limitations. Converting file formats, handling embedded images and reading certain attachments may not be fully supported. Write operations typically prompt for confirmation before execution.
Connectors help users reduce repetitive tasks and context-switching in workflows, which is the core appeal of these integrations. But every convenience also represents a data access point that needs governing.
The Gmail connector is especially valuable for knowledge workers who manage client relationships through email. Claude can search emails, summarize threads, and draft replies. This capability allows users to quickly find every email from a specific client or generate status updates without manual searching or copying content.
Best for: anyone overwhelmed by email volume or managing client communications primarily through Gmail.
Customer relationship management (CRM) systems and business applications often contain your most sensitive commercial data. When Claude connects to these systems, the same permission inheritance applies.
The Salesforce connector gives Claude access to customer records, sales pipeline data and commercial information, filtered by Salesforce’s object-level permissions, field-level security and sharing rules. A sales manager connecting Claude could expose the entire customer database and sales pipeline visible to their role. Any write actions must likewise be covered by the user’s source system permissions.
The HubSpot Claude connector exposes objects such as Contacts, Deals, Tickets and Companies. It can create or update some records depending on permissions, but cannot delete records. A sales representative who cannot view deals outside their team will not see them via Claude either. HubSpot’s Sensitive Data mode can block certain engagement data entirely, adding another layer of control. Bulk updates are limited to approximately 10 records at a time through the connector.
If your business were to connect Claude to Xero or QuickBooks, the same inheritance principle would apply to financial data and client billing information. This is perhaps the sharpest example of why inherited permissions matter: a bookkeeper connecting Claude to your accounting platform could give it visibility over every invoice, payment and bank transaction they can see.
Each CRM connector inherits the specific role-based permissions of the connecting individual. Claude communicates with various tools via a standardised schema of tools and permissions, meaning the connector makes it simple for Claude to query structured data across different platforms using natural language.
Administrator visibility and control over Claude connectors varies significantly by your Claude plans and business systems. This matters because managing permissions is only possible when you can actually see what has been connected.
On team and enterprise plans, organisational Owners or Primary Owners can enable or disable specific connectors organisation-wide. They can restrict write tools, setting whether write actions via a connector are permitted, need approval, or are blocked entirely. Enterprise plans provide the most comprehensive controls, including role-based permissions that allow different roles to have different connector access. Owners must enable connectors for team and enterprise plans before staff can use them.
Basic connectors are available on all Claude plans. Free users can add one custom connector. But consumer Claude plans provide virtually no administrative oversight or control options. There is no central dashboard, no ability to disable specific connectors, and no audit trail of who connected what. Many UK SMEs find governance impossible without upgrading from consumer plans.
Within your Microsoft Entra ID, you can view enterprise applications to see whether applications containing “Anthropic” or “Claude” have been granted consent. Google Workspace administrators have similar visibility through their admin console. In HubSpot, you can check who installed the connector and whether engagement history and write access have been enabled.
Anthropic released enterprise-managed authentication for MCP connectors, allowing administrators to provision connectors centrally via identity providers such as Okta. Users inherit access automatically based on groups and roles rather than having to authenticate individually. This is a significant improvement for organisations wanting to manage connectors at scale.
The honest reality: many administrators discover connector use only after investigating unusual access patterns in their audit logs. Proactive checking is far better than reactive discovery.
Effective governance requires three elements: an approved connector list, clear connection rules, and regular reviews. Organisations should manage permissions and data handling carefully when using connectors, and the following framework is designed for SMEs without dedicated IT departments.
Decide which connectors are appropriate for your business and communicate this clearly. Prohibit others. Review your approved list quarterly as the connectors directory evolves.
Define who may connect which systems based on their business role. Not every team member needs Claude connected to your CRM. Not every user should have write tools enabled. Consider requiring approval before anyone can connect Claude to a new system.
Check your Microsoft Entra ID, Google Workspace admin console and CRM admin panels quarterly for unexpected AI tool authorisations. Look for applications you did not approve. Review OAuth consent logs for authentication prompts you did not expect.
Include connector use in your AI policy and make it part of staff onboarding. Staff should understand that when they connect Claude, they are granting it access to everything they can see in that system.
This is the most important step. The real risk is not that Claude creates new access. The risk is that your existing permissions are too broad. Users often have access to files and data beyond their daily work requirements, and a connector makes that surplus access searchable and discoverable. Proper permission structures in your source systems are the only lasting fix.
Consider requiring team and enterprise plans for better administrative control. The cost difference is modest compared to the governance gap on consumer plans.
Claude connector risks follow exactly the same pattern as the Microsoft Copilot over-sharing issues many UK businesses have already experienced. Both problems stem from AI inheriting overly broad human permissions in business systems.
Staff accumulate access over time: anyone access to SharePoint sites, shared mailbox permissions, broad CRM visibility. When those permissions were only exercised manually, the excess access was invisible. Nobody was searching every folder they could technically open. AI changes that equation entirely. Claude, like Copilot, can search and surface everything the user has access to, instantly. Cross referencing data across multiple data sources becomes trivial.
Data classification, proper labelling, and workspace governance in your source systems. Restricting AI tools without fixing the underlying data permissions is treating the symptom, not the cause.
At £29.68 per user per month (not-for-profit rate £26.98), excluding VAT, on a three-year term, it addresses these underlying permission structures through Purview classification and labelling and AvePoint workspace governance. The pack is available to clients on Complete Unlimited IT Support and tackles the root cause: overly broad permissions that any AI tool, whether Claude or Copilot, will inherit and amplify.
Understanding what Claude can access is just the first step. The real solution requires properly structured permissions in your underlying business systems, so that whatever AI tools your staff connect, the data exposure stays within appropriate boundaries.
No. Claude connectors are limited to the permissions of whoever connected them. Claude cannot escalate permissions or access restricted data beyond the user’s normal rights. However, AI makes searching and discovering accessible data much easier than manual browsing, which is why permissions that seemed harmless before can become problematic once Claude connects to a system.
Consumer Claude plans provide virtually no administrative control over connector use. Team plans allow owners to enable or disable specific connectors and manage write tools organisation-wide. Enterprise plans provide the most comprehensive controls including role-based permissions, audit capabilities and centrally managed authentication. Many UK SMEs find meaningful governance impossible without upgrading from consumer plans.
Check your Microsoft Entra ID or Google Workspace admin console for third-party application authorisations. Look for applications containing “Anthropic” or “Claude” in the enterprise application lists. Review OAuth consent logs for unexpected AI tool authorisations. Our AI Security Review includes a comprehensive audit of existing AI connections across your business systems.
Revoke the application permissions immediately through your admin console. Review what data may have been accessible through the unauthorised connection, paying particular attention to client files, financial records and email content. Update your AI policy to prevent future unauthorised connections. Consider upgrading to managed Claude plans with proper administrative controls so you can prevent this rather than react to it.
Yes. Technical teams can write custom connectors for internal database queries and documentation access using the Model Context Protocol. MCP-based connectors can bridge static language models with dynamic engineering environments. Developers can use connectors to inspect logs and query monitoring dashboards in real time. However, custom connectors for internal systems are typically outside the scope of most UK SMEs and carry additional security considerations that should be assessed carefully.
This website uses cookies to improve your experience. Choose what you're happy with.
Required for the site to function and can't be switched off.
Help us improve the website. Turn on if you agree.
Used for ads and personalisation. Turn on if you agree.