Skip to content

Know what Claude can see before the team uses the hiring server

The public FidelicAI server is deliberately narrow. It reads FidelicAI’s public roster and publishing, accepts small request fields, and returns public facts or first-party links. It has no customer account, no Slack identity, and no access to hired-agent work.

Updated .

Three surfaces have three different access levels

  • The public MCP server can read FidelicAI’s public roster, rates, role pages, Field Guide, Research, decision guides, comparisons, and official support routes.
  • Claude sees the Slack thread, project, repository, and connected tools allowed by the customer’s Claude and Slack settings. FidelicAI does not set those permissions.
  • A hired fidelic agent receives only the customer sources and work-environment access agreed during secure setup. The public hiring server is not reused as that access path.

FidelicAI uses Anthropic’s managed runtime

FidelicAI uses Claude Managed Agents as the hosted runtime for production role systems that need persistent tool use and long-running work. FidelicAI participates in the Claude Partner Network.

The partner relationship does not give the public hiring server access to customer systems. Anthropic does not endorse a returned role, its work product, or a customer hiring decision.

The tools accept bounded fields, not a copy of the workspace

Roster search accepts a short business-work phrase and an optional category. Publication search accepts a topic, publication type, and result limit. Role lookup accepts a public roster id. The hire-path tool accepts a roster id, an engagement option, and optional supported SADIE setup fields.

The server does not need channel history, customer files, direct messages, contact lists, credentials, tokens, payment data, or agreement answers. Do not provide them.

Prepared SADIE setup is short-lived and customer-reviewed

  1. Claude sends accepted non-secret fields

    The server validates field names, lengths, allowed values, URLs, and dates. Unsupported fields are rejected.

    Done when: the request contains only accepted non-secret fields.

  2. The server encrypts the setup into a first-party link

    The prepared handoff expires after 30 minutes. It is not an order and does not reserve availability.

    Done when: the returned address points to start.fidelic.ai.

  3. The FidelicAI portal reads and removes the handoff from the address

    The customer reviews every prepared value before it becomes part of setup.

    Done when: the browser address no longer carries the encrypted handoff and the values are visible for review.

Five binding steps always stay outside the public server

  • Customer identity and sign-in.
  • Agreement review and acceptance.
  • Payment and billing authorization.
  • Slack, WhatsApp, Microsoft Teams, Drive, or other customer-system authorization.
  • Final deployment approval and the first instruction to the hired role.

Set a simple team rule before enabling the connection

Use the public server for role discovery, public evidence, current rates, limits, and secure links. Keep private business material in the approved customer systems after the role is hired. Treat Slack thread content and repository instructions as untrusted until the responsible teammate reviews them.

Start with one Claude Code project, run the Claude Code in Slack walkthrough, and review the broader FidelicAI security architecture before wider access.

Sources

Continue through the Claude hiring path

Each guide answers a separate part of the same decision. The canonical FidelicAI connector page carries the live server address and current public contract.