Claude Projects Share More Than Chats—Check Knowledge and Permissions

To use Claude Projects securely, define a narrow purpose, review every file that will become reusable knowledge, keep the project private and give most collaborators view rather than edit access. Before uploading sensitive material, identify which account’s retention rules apply and whether the task belongs in persistent project context at all.
Project sharing and chat sharing are separate controls. Invited members can receive access to shared knowledge and instructions while each person’s project chats remain private by default; editors, however, can change the context that influences future work across the project.
Set the boundary before adding knowledge
Create one project for one access boundary: a contract review, a product launch or another defined body of work. A general workspace containing customer records, credentials and unrelated strategy makes it harder to decide who needs access and what must later be removed.
Anthropic’s project-management guidance says material uploaded to project knowledge is used across all chats in that project, while ordinary context is not shared between chats unless it is added to the knowledge base. Project instructions also apply to every chat, and supported Team and Enterprise accounts have project-specific memory that is separate from non-project chats.
Those are different routes by which information can affect later work. Knowledge is deliberately reusable reference material; instructions control Claude’s behavior; memory can preserve useful context from earlier chats. Review each one independently instead of treating a new conversation as a clean boundary.
Minimize what becomes reusable
Review each document as if every authorized project member could use its contents in a prompt. Remove credentials, unnecessary personal data, comments, hidden spreadsheet tabs and obsolete versions. If only a few fields are required, upload a redacted extract rather than the complete source.
A practical test is: “Does every person who needs this project also need this file for the approved work?” If not, attach the minimum material to a specific chat or create a smaller project with tighter membership. Project instructions may contain workflow rules and disclosure limits, but they should not hold passwords, access tokens or private keys.
Separate projects are appropriate when teams have materially different information needs. A finance file required by two analysts should not become reusable knowledge in a wider marketing project merely because both groups support the same launch.
Give access without giving control
On Team and Enterprise plans, a public project is available to everyone in the organization; it is not public on the open web. For sensitive work, select private visibility and invite named members. An obscure project name is not an access control.
Anthropic’s sharing guidance distinguishes “Can view” from “Can edit.” Viewers can see project contents, knowledge and instructions and can chat in the project; editors can modify knowledge and instructions and update member settings. Sharing the project and its knowledge base does not share a member’s chats unless that member deliberately shares them.
Default to view access. Reserve edit access for maintainers authorized both to change what Claude receives and to manage who can reach the project. After inviting collaborators, inspect the sharing menu, confirm each role and remove temporary access when the work ends.
Archiving does not revoke access. Current guidance says an archived project preserves members, permission levels and project knowledge, restoring them when the project is unarchived. Remove members explicitly before archiving if their access should end.
Test with non-sensitive material
Before adding real records, use synthetic or thoroughly anonymized material with the same structure. Confirm that a viewer can perform the intended task without editing project knowledge, that only designated maintainers can change instructions or membership, and that an uninvited colleague cannot open a private project.
Start two chats and distinguish their inputs. Project knowledge and instructions should influence both; ordinary conversation context should not cross between them merely because the chats occupy the same project. If project memory is enabled, review or reset it when earlier conversations should no longer influence future work.
Chat sharing needs its own test. A shared snapshot includes the messages and artifacts created before it is shared, while later messages remain private unless the snapshot is updated. Review the snapshot itself rather than assuming that project membership determines what it contains.
Choose retention rules before the upload
Retention depends on the product and account. Consumer rules for Free, Pro and Max should not be applied to Team or Enterprise data, and an Enterprise organization may impose custom retention controls. Confirm the active account and the organization’s policy before placing regulated or contractually restricted information in a project.
For consumer products, Anthropic’s retention terms say a deleted conversation leaves chat history immediately and is removed from back-end systems within 30 days. Data eligible for model improvement may remain in de-identified training pipelines for up to five years; flagged inputs and outputs may be retained for up to two years, with related safety classification scores retained for up to seven years. Incognito chats are excluded from model improvement even when that setting is enabled.
Incognito is therefore a model-improvement and conversation-handling choice, not a promise of immediate deletion. It also does not undo a file already placed in reusable project knowledge. Treat project membership, edit rights, chat sharing, memory, model-improvement settings and retention as separate decisions, and record the project owner, approved purpose and access-review date before sensitive uploads begin.
Also read:
- How to Create, Edit and Share Claude Artifacts Without Exposing Sensitive Files
- Study Finds Self-Driving Waymos Are More Expensive Than Taxis, Take Twice as Long to Get to Destination
- Mythos Just Rewrote the Rules of Cybersecurity: One AI Found 271 Firefox Vulnerabilities in a Month — More Than Human Teams Had in 18 Months
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.