Your starting screen brings daily briefs, team updates, and to-dos together. Use the staff sidebar to open conversations; the β’β’β’ button on each row shows the agentβs email and assigned phone number, plus Jobs, Schedule, Triggers, Files, and Manage. The email and phone number are clickable. Settings on My Desk opens your personal inbox connection.
Today at a glance β the day in one column: your daily brief, your to-dos (filter by Today / This week / Next 2 weeks / All; undated items live under All), and underneath, who is working right now and what's scheduled to run today.
From your team β notes and finished documents agents left for you, each labeled with who sent it; click the sender to jump into that agent's chat.
Needs your decision β the notification bell beside Settings shows a count of pending decisions. Open it to review email approvals, unknown-sender holds, budget pauses, and proposed actions.
Recent work, at the bottom of the staff sidebar, opens a dialog that updates live. Filter by In progress, Completed, or All, then click a job to inspect its original request, latest response or result, files, pending decisions, and activity. The desk shows up to 12 jobs from the latest 50 per visible staff member. For more, open that employeeβs Jobs from the staff sidebar.
Agents can post to your desk on request ("put the weekly summary on my desk") or on their own initiative when something is ready. Ask for it in chat and they'll do it.
What your AI employees are
Each staff card in the sidebar represents a persistent AI staff member with a job description, a long-term memory, its own files, and (once connected) its own work email and Google Drive. They do their work in a secure cloud workspace with tools for writing documents, running analysis, and browsing the web.
Treat them like colleagues: give clear assignments, share the files they need, correct them when they get something wrong β they remember, and they get better at working with you over time.
Chatting and assigning work π¬
Click an agentβs row in the sidebar to open their window, and type a task or question. This is also where you follow work in progress β you'll see the agent's activity ("Using bash", "Using web_search"), a live cost counter in the badge, finished documents, and anything waiting on your approval. Click the dimmed area outside, or press Escape, to close it.
How conversations work
Each assignment is a work episode. Messages you send while the badge says Working⦠join the current episode (use this for corrections and follow-ups).
After β Task complete, your next message starts a fresh episode β but the agent opens it with the recent conversation in view, so answering a question it just asked works naturally. For older history it catches up from its work log (a running summary it keeps in memory). This keeps costs low.
The carried context covers roughly the last twenty turns. If a task depends on exact details from something older β a figure, a filename β restate them or re-attach the file, like briefing a colleague who missed that meeting.
Keep instructions in the message; put long content in attachments. Attached files are cheaper for the agent to work with than pasted text.
Files: attachments, cabinet, deliverables π
Attach files with the π button (8 MB per file). Give files meaningful names β agents choose what to open based on the name.
Attachments are one-off by default. Most are a screenshot behind a single question, so they are used for that message and not kept. To keep one for future tasks, untick Just for this message next to the file before sending.
Kept files live in that agent's filing cabinet and are available in every future task β no re-attaching. Open it with π Files on the agent's card; Remove deletes a file for good, and the agent can no longer open it.
Name files meaningfully. Agents choose what to open from the filename alone β they cannot see inside first. Board_Minutes_2026-08-12.rtf is worth more than a tidy cabinet; md1.rtf tells an agent nothing.
If a document matters for what it says rather than that it exists, ask the agent to read it and note what matters in its memory β then remove the file. Memory is summarised and searchable; a cabinet file is a name it has to guess about.
When an agent produces a document, it appears in the chat as a green deliverable card with a Download button.
Agents with a connected Google account can also read Drive files shared with them and save documents to their Drive, returning a link.
Email π§
An agent with a connected work account can search and read its own inbox, and incoming email wakes it automatically β it reads the message, does the work, and drafts a reply.
The approval system
By default, every outgoing email is a draft that appears in the chat as an amber card β nothing sends until someone clicks Approve & send.
Approved contacts (Manage panel): mail to/from these addresses or domains flows without approval β the agent replies to them autonomously.
Email from an unknown sender becomes a "needs your decision" card; the agent doesn't even start working (or spending) until you allow it.
An amber β³ waiting badge on an agent's card means something needs a human decision β click it.
Schedules π
Recurring duties an agent performs on its own β no prompting needed. Open π Schedule on the agent's card (whoever manages the agent can add them).
Write the duty like any task ("Every morning: review unread email, handle what you can, summarize what needs me"), pick a cadence β every weekday, daily, weekly, or monthly β and a time (Eastern).
Runs appear in the chat feed marked π Scheduled task, with the same cost tracking, email approvals, and auto-task budget protection as email-triggered work.
If the agent's Google account is connected, the schedule also appears on its Google Calendar as a recurring event β share the agent's calendar with your team to make its duties visible.
Pause, resume, or delete schedules anytime from the same dialog.
Agents can also read their own calendar and create events with Google Meet links (invitations only to approved contacts) β so "schedule a check-in with me Thursday" works as a chat request.
Meetings π (Google Meet and Zoom)
For recurring Zoom meetings, open a Meetings cardβs Settings β Google Calendar and select the recurring event by name. Your connected Google accountβs primary calendar supplies upcoming dates for the next 12 months. Events need a Zoom join link. A personal Zoom room can serve several series: recordings are matched using their actual time and Calendar event ID. Cloud recording and Zoom transcription must be enabled. Ambiguous or unmatched recordings appear in Previous meetings β Choose meeting; select a card and click Assign. Existing dedicated Zoom connections remain available under the optional section. When a legacy βrecording readyβ agent duty watches the same room, saving the Calendar connection pauses that duty so the transcript is processed only once; the duty remains available and can be turned back on later.
On My Desk, the Meetings card sits below Today at a glance. Manage recurring meetings, record a one-off meeting, and inspect saved meetings directly in the card. Use All meetings to return to the list and Refresh to update it.
Invite the agent like a person β add its work email to any calendar event. Invites from approved contacts are accepted automatically; the agent appears on the attendee list.
Turn on transcription in the Meet call (host clicks Transcribe β requires Workspace Business Standard or higher for the host). After the meeting, the agent automatically processes the transcript: minutes, decisions, action items β doing its own items and drafting follow-up emails through the normal approval flow.
If the transcript isn't shared with the agent (common across domains), the feed tells you β share the transcript Doc with the agent's email and it proceeds. You can also share any transcript manually and ask the agent to process it in chat.
Agents don't appear inside the live call β they work from the transcript afterwards.
Your own inbox π₯
You can let one assistant agent work in your personal mailbox. On My Desk β Settings β My inbox, pick the agent and click Connect my inbox, then approve with your own Google account. The consent screen asks for Gmail only β no Drive, no Calendar.
It can read and search your mail, summarize what needs you, apply labels, archive clutter, and save drafts in your Gmail.
It can never send mail as you. Drafts sit in your Drafts folder β you review and hit send.
It can never delete anything. Archiving and labelling are reversible; deletion isn't available to it at all.
Your calendar too: it can see what's coming up β ask for a heads-up on your day, or have it prepare you before a meeting. It can block your own time directly, but any meeting with other people is only proposed: you get a card showing who, when, and what, and invitations go out only when you click Schedule & send invites.
Change how it behaves any time by editing its standing instructions in Manage β how aggressively to archive, what to flag, how your drafts should sound.
Disconnect on the same card revokes access immediately; you can also revoke it from your Google account security settings.
Your inbox holds confidential personnel, student, and legal matters, and what the assistant reads passes through the AI model. Use a dedicated assistant for this rather than sharing the job with agents that do other work.
Costs π΅
Agents cost per task, not per month. Routine work (email replies, quick reviews) is typically $0.02β$0.40; deep research or long documents can reach a few dollars.
Each card shows lifetime spend; every finished task shows its exact cost, tool calls, and duration; the Jobs dialog shows the latest 50 jobs and updates live. Select a job to inspect its result and files.
Stopping a task: while an agent is working, a βΉ Stop button sits in the chat header. It halts the task immediately and keeps everything already produced β deliverables, drafts, notes. Use it when a task is running longer or costing more than it's worth.
Each agent has a capability setting β match it to the value of the role's work:
Economy (~β the cost of Maximum) β routine, high-volume work: triage, summaries, scheduled digests, simple replies. Reads shorter documents than the other tiers, so don't use it for long reports.
Balanced β the default, and right for most roles.
Maximum (β 2Γ Balanced) β deep research, high-stakes writing, complex analysis.
Thoroughness (Quick / Standard / Deep) controls how carefully an agent works within its tier. Economy agents run at a fixed depth, so the setting is greyed out there.
You can change capability and thoroughness anytime β promote an agent for a high-stakes week, dial it back after.
Smart routing (on by default, per-agent switch in Manage): before an agent starts, a quick, very cheap check decides how much horsepower the work needs. Short replies, simple questions, and junk email run on the Economy tier; anything substantive still runs on the agent's own tier. Junk email that needs no reply at all is noted in the feed and never becomes a task. When a task was routed down, its completion line says Economy, so it's never hidden from you.
The check always errs toward the full tier β attachments, ambiguity, or anything touching money, policy, personnel, students, or families goes to the agent's own tier automatically. If a quick exchange turns into real work, the agent moves up to its own tier on the spot.
Auto-task budget (default $1): any task the agent starts on its own β incoming email, a schedule, a meeting follow-up β pauses at this amount and asks permission to continue. Tasks you start in chat are exempt, since you're watching them.
Listening mode (π Listen in an agent's chat, manage-level only): have an agent sit in on a meeting held in the room rather than on Meet.
The agent attends as a participant, not as the minute-taker. By default it listens for what concerns its own work β jobs assigned to it, documents it should update, decisions and deadlines worth remembering β does what it can, and leaves you one short note on your desk. It will not write minutes and will not email anyone unless you ask.
If you do want minutes, say so in "Anything you want from this meeting?" β for example "write minutes and share them with everyone who was here". Anything the agent sends by email from a meeting always waits for your approval, even to approved contacts, because a transcript contains names the microphone only thought it heard.
It does not tell speakers apart. Live transcription is one stream of words with no speaker labels, so name who was in the room and the agent will attribute what it can and say when it is unsure. Needs Chrome or Edge, a tab left open, and a microphone near whoever is talking β accuracy drops sharply across a large room. Edit the transcript before sending to fix names and mis-heard words; it makes a real difference. Nothing is stored until you send it, and Discard leaves no trace.
Tell the room. Transcribing a meeting is something the people in it should know about.
Monthly spending cap (Manage β Work & cost; 0 means no cap): a ceiling per calendar month. At the cap the agent's automatic work stops β schedules, incoming email, meeting follow-ups β but you can still chat with it, so a cap never leaves you unable to reach your own agent. A note lands on your desk at 80% and again at the cap, and the agent's card shows how close it is. Raise the cap to resume; it resets on the 1st.
Agents working together π€
Your agents can ask each other for things, the way colleagues do. You don't set this up β it is on for every agent β and you don't have to ask for it: an agent reaches out on its own when the answer or the access belongs to someone else. You can also just say so: "check with Nora first", or "ask Ava to book it, she has the calendar".
A quick question β one agent asks another something it knows, and gets the answer back in the same piece of work. You see π¬ Asked Nora: β¦ in the feed, and the question and answer also appear in Nora's own feed.
Handing over a job β when it needs someone to actually do something, it becomes a real job on that colleague's board. They do it under their own approvals and report back separately, so it shows up as their work, not a footnote in someone else's.
This matters most where access differs. If Ava is the one connected to a calendar or a mailbox, Nora doesn't need a copy of that access β she asks Ava, and Ava does it with her own. Nothing is shared or duplicated.
Approvals don't change. Whatever an agent normally has to ask you before doing, it still asks β being asked by a colleague rather than a person makes no difference. One agent cannot get something past your rules by routing it through another.
Costs land where the work happened. If Jodi asks Nora a question, Nora's budget pays for Nora's answer.
It can't run away. A request can pass through at most three colleagues, an agent already involved won't be asked again, and there is a limit per job β so two agents cannot bounce something back and forth at your expense.
Agents can only reach colleagues in your organization, and only ones who aren't archived. If an agent names someone who isn't on the team β a real person, say β it is told so and asks you instead.
A colleague answering a question replies from what they know, not by going and looking β they don't use their tools for it. If the job really needs someone to search their mailbox or run a report, the agent hands it over as a job instead, and you'll see it appear on their board.
Roles π
Admin β one or two per organization. Sees and controls everything: all agents, organization settings, the Anthropic API key, and people and their roles.
Manager β can hire new agents, and fully controls the agents they created (or that were shared with them at Manager level): profile, email, budgets, sharing. For other agents they're like a member.
Member β works with agents shared with them or open to the organization.
Per agent, whoever manages it chooses: Everyone in the organization (choosing whether everyone can view, chat, or manage) or Only specific people, each at one of three levels β Manager (full control), Chat (assign work, handle approvals), or View (follow the work read-only).
For managers & admins βοΈ
Hiring
+ Hire β name, role title, and a real job description (this is literally the agent's brief β specific beats vague).
Add standing instructions: house style, preferences, recurring duties, things to always/never do. You can refine these anytime in Manage.
For an email-enabled agent: have IT create a Workspace account (see the IT Guide), set it as the work email, then Generate connect link in Manage.
The Manage panel
Edit the profile, job description, and instructions β changes apply from the agent's next task.
Portrait β describe how the agent should look ("warm, early 40s, glasses, teal blazer") and click Generate; an illustrated avatar replaces the initials on the team card. Regenerate until it fits, or remove it. You can also fill this in on the Hire form. These are illustrations of fictional staff, never real people.
Set approved email contacts and the auto-task budget.
Adjust capability/thoroughness anytime β promote for a high-stakes week, dial back after.
Who can use an agent (Manage β Access): Everyone in the organization β with a second choice of what everyone gets: chat (the default), view (read-only), or manage (full control, so use it deliberately β it includes settings, connections, and archiving, for future members too) β Only specific people (pick them and give each Manager, Chat, or View), or Only me β nobody but the owner. Organization admins can always see every agent, whichever you pick.
Web accounts β letting an agent use your systems
In Manage β Web accounts, add a site the agent may use: site name, login URL, username, password, and optional notes (e.g. which report to run).
The password goes into that agent's secure vault β never into the dashboard or database, and it is never shown again. The agent itself only receives a placeholder; the real password is substituted by the secure gateway on requests to that site's domain, so it is useless anywhere else.
Agents drive a real headless browser: they log in, navigate, read, search, and download reports β then bring the results back to you.
Read-only by default. Agents may log in, navigate, read, and download β but never create, edit, delete, or submit on their own.
Approving an action: when a task genuinely needs a change, the agent fills the form, screenshots it, and stops. You get a red-edged card in the chat showing exactly what it would submit, with View screenshot so you can see the filled form. Click Approve this action and the agent performs that one action and reports back; Decline and it stands down. An approval covers only the action described β never a standing permission.
Give each agent its own least-privilege account (never a shared admin login), and remove the account here when the agent no longer needs it β the stored password is deleted from the vault.
Limits: accounts protected by two-factor authentication cannot be automated, and sites with strong bot protection may refuse. Check your vendor's terms on automated access.
Connected services β giving an agent a whole toolset π
In Manage β Connections β Connected services, connect a service that speaks MCP β a standard way for a product to hand an AI its full set of tools. Where a web account means the agent drives the website by hand, this gives it the service's proper tools directly: faster, more reliable, and far less likely to misread a page.
Pick one of the suggested services and the name and address fill themselves in; you only paste the access token. Choose Something else⦠for anything not listed, including a server your district runs itself.
The token goes into the agent's vault, the same one holding its site logins. It is attached to requests on the way out and never reaches the agent, so nothing it writes can contain the token.
Connecting and disconnecting take effect immediately β no need to press Save changes. Both are noted in the agent's feed, and you will see Using linear: create_issue style lines while it works.
Why the suggested list is short: a service only works here if it accepts a token you can paste. Several well-known ones (Notion, Slack, Asana, Atlassian, Linear, Canva) require a sign-in flow we do not support yet, so they cannot be connected today however you enter them. For Zoom, see Zoom setup β it connects organization-wide with no token or sign-in at all.
Connect only what that agent's job needs, and prefer a read-only token where the service offers one. An agent holds up to 20 services.
Zoom β scheduling, recordings and transcripts πΉ
One small app connects your organization's Zoom: agents can then schedule Zoom meetings, list cloud recordings, and read transcripts. Reading is strictly personal: an agent only ever sees the recordings of the person who gave it the task β never anyone else's, whoever asks.
Setup β once per organization, about five minutes, no sign-ins:
On marketplace.zoom.us, an admin chooses Develop β Build App β Server-to-Server OAuth app. Fill in the required app information; it stays private and needs no review.
Under Scopes, add meeting:write:meeting:admin and cloud_recording:read:list_user_recordings:admin, then activate the app.
Copy the Account ID, Client ID and Client Secret from its credentials page into Organization settings β Zoom. The save mints a real token, verifies all three values, and tells you exactly which of the two abilities the app's scopes enable.
What agents can then do:
Schedule: "set up a Zoom call Tuesday at 4" creates the meeting on your Zoom account and hands back the join link. Creating a meeting notifies nobody; it can also go straight onto your calendar as an event with the Zoom link attached (with attendees, that is proposed for your approval β and the Zoom meeting itself is only created when you approve).
Recordings & transcripts: "find last Tuesday's board meeting and summarize the transcript" lists your cloud recordings, finds the meeting, and reads its transcript with speaker labels. Zoom only keeps cloud recordings, and a transcript exists only if transcription was on for that meeting.
The privacy line, spelled out: the app's credential is account-level, but the platform only ever reads the recordings of the person who assigned the task β checked on every call. Scheduled and email-triggered tasks have no person behind them, so recording reads are refused there entirely.
Systems an agent can query β connecting an API π
Most school systems have an API rather than an MCP server β a student information system, a lunch or transport database. Add one in Manage β Connections β Systems this agent can query: a name, the base web address, how it authenticates, the key, and notes.
The notes field matters more than it looks. The agent gets no menu of what the system can do, so tell it what you know β which parts you want used, the version, anything unusual. For SchoolTool, writing "OneRoster v1.2" is most of the work, because that is a published standard the agent already understands.
As with site logins, the agent only ever receives a placeholder. The real key is substituted on the way out, and only for that system's own address β so it is useless anywhere else, and cannot leak through anything the agent writes.
Read-only. Agents are instructed to look things up and never to change, add, or delete anything β not even to correct something that looks wrong. Use a read-only key as well where the system offers one; that is the part that actually enforces it.
Before connecting a student system, check with whoever administers it whether it restricts access by IP address. Agents do not have a fixed address to register, so if that restriction is switched on the connection will not work and we would need to build it differently. Worth asking before requesting a key.
These systems hold real records about real children. Agents are told to retrieve only what a task needs and to keep names and identifying details out of anything they produce β but decide deliberately which agents get access, and give the narrowest key you can.
A website an agent maintains β connecting AWS S3 βοΈ
If your school website is a static site kept in an Amazon S3 bucket, one agent can be given the ability to edit and publish it. The agent never holds an AWS key: it gets six website_* tools β list, read, write, upload, delete, clear cache β and our servers carry each one out with a key you store once. The setup is about twenty minutes in the AWS console, done once.
Before you start β find three things in AWS
Which bucket is the live site. Go to S3 β Buckets. If there are several (old domains, redirect buckets, a logs bucket), open the one whose name matches your current domain and check Properties β Static website hosting is enabled, or see step 2. Note its name and its AWS Region column (e.g. us-east-2).
Whether a CloudFront distribution sits in front of it. Go to CloudFront β Distributions and look for one whose Alternate domain names include your site and whose Origin is that bucket. Note its ID (looks like E2Q1B5D6WXBFT1). If none matches, the site is served straight from S3 and you leave that field blank. A quick check from any computer: if the site's response headers say x-cache: β¦ cloudfront, there is a distribution.
Your 12-digit account ID β top-right menu of the console.
Step 1 β Turn on bucket versioning (the undo button)
S3 β your bucket β Properties β Bucket Versioning β Edit β Enable β Save changes. From now on every change keeps the previous copy, so a bad edit is a one-click restore in the console (Objects β Show versions). Without this there is no undo β do not skip it.
Step 2 β Create an IAM user for the agent
IAM β Users β Create user. Name it something recognisable, e.g. schoolclaude-website. Leave Provide user access to the AWS Management Consoleunticked β this identity only ever calls the API. Next.
On Set permissions choose nothing (do not add it to an admin group) β Next β Create user. Then open the user.
Permissions β Add permissions β Create inline policy β JSON. Delete what is there, paste the policy below, and replace YOUR-BUCKET (twice), YOUR-ACCOUNT-ID and YOUR-DISTRIBUTION-ID. If there is no CloudFront distribution, delete the whole third statement (and the comma before it). The editor should say no errors. Next β name it e.g. website-bucket-only β Create policy.
This is the whole of the agent's power in AWS: read, write and delete files in that one bucket, and clear that one cache. It cannot see other buckets, change bucket settings, or touch anything else in the account. Never use a root or administrator key here.
Step 3 β Create the access key
On the user's page: Security credentials β Access keys β Create access key.
Use case: Third-party service β tick I understand the above recommendation β Next.
Description tag: anything like SchoolClaude website agent β letters, numbers, spaces and _ . : / = + - @ only; parentheses are rejected. Create access key.
You are now on Retrieve access keys. Stay on this page β the secret is shown exactly once. Leave it open while you do step 4.
Step 4 β Grant the agent access in SchoolClaude
Open the agent β Manage β Connections β Website this agent maintains β + Grant website access.
Fill in: bucket name, region, the public site URL, the CloudFront distribution ID (or blank), the Access key ID (starts AKIA), and the Secret access key β use the copy icon next to it in AWS rather than retyping; it is exactly 40 characters and one wrong character is invisible. Notes are optional but useful: how the site is built, which pages the agent owns.
Grant access. This checks the key against the bucket on the spot. You will see either Website access granted or AWS's own reason for refusing (InvalidAccessKeyId β the key ID was mistyped or the key is inactive; SignatureDoesNotMatch β the secret is wrong; AccessDenied β the policy names a different bucket than the one you entered). Fix and try again; nothing is stored until it works.
Now click Done in AWS. If you ever lose a secret, do not hunt for it β deactivate that key under Security credentials and create a new one; Replace key or settings in SchoolClaude takes the new pair.
Step 5 β Test before you trust it
Give the agent a new task: "List the top-level files on the website and read index.html. Change nothing." It should report the file list and the page. Then try a real but tiny edit on a low-traffic page and check it live. Every publish appears in the agent's activity feed as Published <path>.
Day to day
The agent is briefed to list and read before writing, to write whole files rather than fragments, to touch only what the task names, to delete only when explicitly asked, and to clear the CloudFront cache once at the end of a job so visitors see the change within a minute or two.
Give it context in Notes and in its job description: how the site is built, which pages it may touch, house style. That is part of the safety.
Replace key or settings swaps the key pair or changes the bucket/distribution β rotate the key whenever someone who saw it leaves. β deletes the stored key; the bucket itself is untouched.
Made a mistake live? S3 β bucket β Objects β Show versions, pick the file, and delete the newest version β the previous one is served again. Then clear the CloudFront cache for that path.
Why the key is not simply handed to the agent: AWS signs every request with the secret, and our credential vault (which keeps other keys out of agents' sandboxes by swapping placeholders for real values) cannot reproduce a signature. Running the tools on our servers is the documented alternative β and it means nothing AWS-related ever enters the agent's environment at all.
Archiving ("firing") an agent
Archive (Manage β Employment): all work stops immediately β schedules pause, incoming email and meetings no longer wake them, and no new tasks can be assigned. Chat history, deliverables, job records, and the agent's memory are all kept.
Archived agents move to a collapsed Archived agents section at the bottom of the team view, where their history stays readable.
Reinstate at any time β they return to the roster; paused schedules stay paused until you resume them.
Delete permanently (archived agents only) erases memory, files, history, and schedules, and revokes the agent's Google access. You must type the agent's name to confirm. This cannot be undone.
The agent's Google Workspace account is separate β suspend or delete it in the Google Admin console when offboarding for good.
Organization settings (admins)
Organization (top bar, admins only): add or remove people and set their role (Member / Manager / Admin).
Your organization's Anthropic API key powers your agents and receives their usage billing. Get one at platform.claude.com and paste it there once.
A member can belong to only one organization, and everything β agents, chats, files, approvals β is visible only inside your organization.