02-347-7730  |  Saeree ERP - Complete ERP System for Thai Businesses Contact Us

Claude September 2026 Update: Skill Sharing, Teams Messages, Opus 5 Watermark

  • Home
  • Articles
  • Claude September 2026 Update: Skill Sharing, Teams Messages, Opus 5 Watermark
Claude September 2026 Update: Skill Sharing, Teams Messages, Opus 5 Watermark
  • 05
  • September

"Claude September 2026 Update" — the short answer is Claude now lets members share skills and plugins with specific people or groups, can send and reply to Microsoft Teams messages, and begins embedding a text watermark in Claude Opus 5 from 9 September 2026. The first two are off until an administrator switches them on; the third arrives on its own and cannot be disabled. This article covers how each one works, where the settings live, what the risks are, and what organizations running Claude should do first.

In one line: The September 2026 Claude update brings three changes — sharing skills and plugins with specific people or groups (on Team plans the relevant switches are on by default; group sharing exists only on Enterprise), Claude sending, posting and replying in Microsoft Teams (off until an Entra admin approves the new permissions), and text watermarking extending to Claude Opus 5 on 9 September 2026 under the EU AI Act transparency requirements.

Three updates in one email — and why you have to open the console rather than trust the published defaults

The Claude Team update email sent to organization administrators on 5 September 2026 bundles three changes. The distinction administrators need to draw is that only one of them definitely requires action: Microsoft Teams, which is off and needs permission approval on the Microsoft side first. Skill sharing may already be enabled in your organization, and the third change — text watermarking — happens automatically and cannot be turned off.

The point to stress: do not trust the defaults quoted in announcements or documentation — open your own organization's console and look, because the two currently disagree. Details in the section below. And because Anthropic can change switch names, defaults and per-plan feature boundaries at any time, everything stated in this article is a snapshot as of 5 September 2026.

Overlooking that distinction tends to surface as two questions: users reporting they cannot find the Share button, and an executive asking why Claude still cannot post to Teams when the announcement says it can.

UpdateDefault stateWho actsWhere
Share skills / plugins with individualsSkill sharing switch, on by default on Team plansEnd usersCustomize → three-dot menu → Share
Share skills / plugins organization-wideShare with organization switch — check the console; the live value and the documented one disagreeOrganization OwnerOrganization settings → Skills → Policy
Share skills / plugins with groupsEnterprise plans only · off by defaultOrganization OwnerOrganization settings → Skills → Policy
Claude sends / posts / replies in TeamsOffMicrosoft Entra Global Admin + OwnerEntra admin center, then Organization settings → Connectors
Text watermark on Opus 5Rolls out 9 Sept 2026No action neededNo off switch exists

Before you read on — which plans get what:

  • Skill and plugin sharingTeam and Enterprise only, because it hangs off Organization settings, which individual plans do not have. Individual and organization-wide sharing exist on both plans; group sharing is Enterprise only, because Claude supports user groups only on that plan — on a Team plan there is no Share with groups switch on the Policy page at all.
  • Microsoft 365 connector — connectable on every plan (Free, Pro, Max, Team, Enterprise), but the organization-level configuration described in this article exists only on Team and Enterprise. Individual plans still need a Microsoft Entra Global Administrator to grant tenant-wide consent.
  • Text watermarking — applies to every plan and every surface, including API access.

1. Sharing skills and plugins with specific people or groups

A skill is a package of instructions and reference files that teaches Claude to perform a specialized task the same way every time — a month-end close procedure, your company's quotation format, a goods-receipt checklist. A plugin bundles skills, commands and connections together.

Until now, someone who built a genuinely useful skill had two options, neither of which matched how organizations actually work: publish it to the entire organization, or send the file to a colleague. The first clutters the org directory with things most people never use. The second is worse — once the file leaves your hands it is out of your control, and fixing the original never reaches whoever is holding the copy.

What is new: the owner of a skill can now share it with named individuals or with an entire group, while the skill itself stays under the owner's account. Nothing is copied out.

How a shared skill behaves

When someone shares a skill or plugin with you, it appears under "Shared with you" in Customize, labelled with the owner's name. Four behaviors matter to administrators:

  • It arrives switched off. A shared item does nothing until the recipient turns it on. Nothing is pushed into anyone's workflow silently.
  • It is view-only. Recipients can use it but cannot edit its contents, which prevents the same skill from forking into five divergent versions.
  • It updates from source automatically. When the owner saves a new version, everyone it was shared with gets the updated version the next time they use it — no chasing people down.
  • Access can be revoked at any time, and it is removed automatically if the recipient leaves the organization.
Sharing scopeWho sees itDefaultExtra condition
IndividualOnly the named peopleGoverned by the Skill sharing switch, on by default on Team plansWorks immediately, no admin step
Whole organizationEveryone, via the org directoryGoverned by Share with organizationcheck your consoleDocumentation says off by default; the live console we checked on 5 September 2026 showed it on
GroupEvery member of that groupEnterprise only · off by defaultOwner enables Share with groups and "Share resources with this group" on the group itself

What the Owner has to do

Go to Organization settings → Skills → Policy. On a Team plan the page carries five switches, top to bottom:

Claude Organization settings → Skills → Policy on a Team plan showing five switches — Cloud code execution and file creation, Skills, User-created skills, Skill sharing and Share with organization — all marked Default and all turned on
Organization settings → Skills → Policy on a Team plan, checked 5 September 2026 — all five switches are marked "Default" and all of them are on, including Share with organization, which the help documentation says is off by default. Note the absence of a Share with groups row: that is an Enterprise-plan feature.
SwitchWhat it controlsState observed in a live console (5 Sept 2026)
Cloud code execution and file creationLets Claude execute code on a server and create and edit docs, spreadsheets, presentations, PDFs and data reports — required for skills to work at allOn (Default)
SkillsThe master switch for skills across the organization, including admin-managed org skills. Turn it off and skills stop everywhereOn (Default)
User-created skillsLets members upload or create their own skills · turn off to lock the org to approved skills onlyOn (Default)
Skill sharingLets members share skills and plugins with each other — this is the switch behind the new featureOn (Default)
Share with organizationLets members share skills with the entire organization through the directoryOn (Default)

Enterprise plans get two more that Team plans do not have: Share with groups (off by default) and Skill and plugin security scanning. Anyone who read the announcement and went hunting for a switch called "Group skill sharing" on a Team plan will not find one — Claude supports user groups on Enterprise only.

If the permission model in the console is still unfamiliar, read Setting policy in the Claude Team Admin Console and user management with roles, SCIM and SSO alongside this.

The published defaults and the live console disagree — go and look: Anthropic's help documentation states that Share with organization and Share with groups are off by default. A live Team-plan console we opened on 5 September 2026 showed all five switches marked "Default" and all of them on, including Share with organization. The difference may come down to plan, to organization-specific configuration (HIPAA-ready and other regulated setups have skills and sharing off by default), or to documentation lagging a change in defaults. Do not conclude anything from an article or an announcement — this one included. Open your own Policy page first, particularly for Share with organization: if it is on, your members can already publish skills to the whole organization today.

What end users have to do

To share: open Customize, find the skill or plugin you built, click the three-dot menu next to it and choose Share, then enter the names or email addresses of the people you want it shared with — or, on an Enterprise plan where the administrator has enabled Share with groups, pick a group.

To receive: the item waits under "Shared with you" in Customize and does nothing until you turn it on. This is the single most common support question in the first week — the person who shared it insists they shared it, the recipient says it does not work, and the actual answer is that a switch is still off.

If the Share button is missing, there are two likely reasons: your administrator has not enabled sharing at the organization level, or the account is on a plan that does not support it. Ask your administrator to check rather than rebuilding the skill.

The security angle, before you enable it

A skill is not a document — it is a set of instructions Claude will follow. Opening up free-form sharing therefore opens a path for unreviewed instructions to travel across the organization. The useful counterweight is that skill sharing events are recorded in the audit log and the Compliance API as role_assignment events, showing who shared what with whom. Pull that feed into your monitoring on day one rather than reconstructing it later.

Warning: skills containing instructions like "read every file in this folder and summarize it outward" or "call a connector to pull customer records" should be reviewed before they reach group or organization scope. Person-to-person sharing inside one team is low risk; opening cross-department sharing with no review step raises your risk profile quietly, which is the worst way for risk to rise.

2. Claude can now send and read Microsoft Teams messages

Of the three, this is the one we expect to affect daily work most, because it closes a gap that has been open since the Microsoft 365 connector launched.

The connector could already read from Teams — searching chat messages, reviewing meeting information from the calendar, summarizing channel discussions — but it could not write anything at all. The connector documentation stated plainly that Claude could not send Teams messages; write capability existed only for Outlook (mail, drafts, calendar) and SharePoint (creating and updating files).

What is new: Claude can send a chat message, post or reply in a channel, and start a new chat on a user's behalf. It can also read teams, channels, channel messages and chats, and search people in your directory. Existing Outlook and SharePoint actions are unchanged.

Tool groupWhat it doesDefault
Teams readList teams and channels, read channel messages and chats, search people in the directoryAvailable within the user's own permissions
Teams writeSend a chat message, post in a channel, reply in a thread, start a new chatOff until enabled
OutlookSend mail, manage drafts, labels, filters, automatic replies, calendar eventsUnchanged
SharePoint / OneDriveSearch and analyze documents, create and update files in SharePointUnchanged

Two admin steps — you cannot skip either

Step 1, on the Microsoft side: a Microsoft Entra Global Administrator must approve the connector's new permission set. Existing tenant consent covers reading plus Outlook and SharePoint writes; it does not cover writing in Teams. This is a one-time action per tenant, performed under Enterprise applications in the Entra admin center.

Step 2, on the Claude side: go to Organization settings → Connectors → Microsoft 365 and set the Teams send, post and reply tools to Ask (confirm before acting) or Blocked, according to your policy.

What end users have to do

Once an administrator has completed both steps, users configure nothing. They just ask in plain language — "message the procurement team that this purchase requisition is approved", or "reply in the project channel that the meeting moves to Wednesday afternoon".

What happens next is that Claude shows you the message and its destination and waits for confirmation, every time. Nothing goes out unseen. Say this explicitly when you announce the feature, because a lot of people hold back from trying it out of fear that a mistyped instruction fires off immediately.

If Claude replies that it cannot do it, the permission is not enabled — the instruction was not wrong. Report which step it failed at rather than rephrasing the request over and over.

Security warning: all permissions are delegated — Claude can only do what that user could already do, never more. The real exposure is different: messages go out under an employee's name, and channel content is text that people outside the team can write, which is exactly the shape of a prompt-injection surface. Set these tools to Ask first. Do not jump straight to unattended approval in the first rollout.

Note (checked 5 September 2026): some public connector documentation still carries the old line that Claude cannot send Teams messages, because docs trail announcements. Treat what you actually see in your own Organization settings as the source of truth.

3. Text watermarking extends to Claude Opus 5 on 9 September 2026

From 9 September 2026, responses from Claude Opus 5 carry the same imperceptible text watermark that Claude Fable 5.1 already has. Other current Claude models follow over the weeks after.

What a text watermark actually is

It is not extra characters, not hidden zero-width glyphs, and not appended metadata. The technique changes the source of randomness the model uses when choosing words during generation. The output still looks random to a reader, but with the verification key you can check whether the observed sequence of words is consistent with the choices that model would make. The approach follows Google DeepMind's SynthID-Text research.

The point that matters most to administrators: the watermark is applied at the model layer, not the application layer. It is therefore present everywhere your organization uses Claude — chat, Claude Cowork, Claude Code and the API, including access through the major cloud platforms. Because it lives in the text itself, it travels with copy-and-paste and survives some degree of editing.

Why it exists

The driver is the transparency requirement of the EU AI Act, which applies to every major AI provider serving the EU. Anthropic signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026 and chose to apply the marking worldwide rather than only for European users — so organizations in Thailand are covered by it automatically.

AspectWhat changesWhat does not
Output qualityUnchanged
Speed and usage limitsUnchanged; no extra tokens counted
Characters in the responseNothing is added
Information encoded in the markNo organization or individual user data
CoverageEvery surface: chat, Cowork, Claude Code, API
Turning it offNo admin or user setting exists

Detection is not something everyone can do yet

Be precise about this: there is no public tool for checking text. Detection runs through an API still in private preview, limited to organizations that qualify under European law — regulators, law enforcement, media, fact-checkers, independent researchers, educational institutions and EU civil society groups. Anthropic states it does not see or store the text submitted to it for checking.

In practical terms, an ordinary organization cannot verify the watermark itself today. Organizations planning to use it as an internal review tool, and institutions considering it for student work, cannot do so in this round and should plan without counting on that capability.

Image files: C2PA Content Credentials since 1 September 2026

This is a separate mechanism from text watermarking. Files Claude creates in the apps (.png, .jpg, .svg) have carried cryptographically signed provenance metadata under the open C2PA standard since 1 September 2026. It lets you verify that a file was created or processed with Claude, and whether it has been tampered with since. The caveat is that this kind of metadata is easily stripped — by re-compression, by screenshotting, or by uploading through platforms that clear metadata.

The honest limitation: the watermark survives copy-paste and some editing, but that is not the same as 100% detection. Very short passages, wholesale rewriting and translation into another language all weaken the signal. More importantly, the absence of a watermark does not prove a human wrote something — it may simply come from a provider that does not watermark at all.

What organizations should do about it

For most work, the watermark changes nothing. Two cases deserve a written position in advance: work delivered to clients or government agencies that carry AI-disclosure conditions, and documents that pass through external audit. Decide organization-wide how you will disclose AI assistance rather than leaving it to individual judgement. Read Claude data governance and security and Claude and PDPA for Thai organizations for the surrounding policy work.

An administrator's checklist

  1. Open the Policy page before anything else — Organization settings → Skills → Policy, and look at the state of all five switches (seven on Enterprise), especially Share with organization, because the documented default and the live one disagree. Decide nothing until you have seen the real thing.
  2. Name a skill reviewer — who approves a skill before it reaches group or organization scope, and what they check for.
  3. Wire the audit log into monitoring — sharing events land as role_assignment; feed them to your SIEM or a monthly report.
  4. Talk to your Microsoft 365 team early — Teams write needs an Entra Global Administrator to approve new permissions. Book that slot before users start asking.
  5. Always start at Ask — set Teams send, post and reply to Ask, then review after a month or two of real use.
  6. Prepare a watermark answer for users — someone will ask whether it degrades their work. The short answer is no, and it cannot be switched off.
  7. Revisit your AI-disclosure policy, especially for deliverables that leave the organization.

The view from building ERP systems

All three updates point the same direction we keep seeing in ERP work: capability is rarely the problem — control is.

Skill sharing maps directly onto permission design in an ERP. Shared assets are good; shared assets that anyone can edit and publish are how an organization loses track of which version is correct. The model here — the owner keeps the original, recipients can use but not edit, updates propagate automatically — is exactly the pattern ERP systems use for a chart of accounts or a document template.

Teams write is the clearer parallel. Letting an AI post under an employee's name is structurally the same as letting a system generate a document on someone's behalf. What makes it safe is not blocking everything; it is a confirmation point before the action, which is the same principle behind approval steps in Saeree ERP, where a person always presses the button.

In practice we connect organizations to Claude through MCP on one rule: the ERP is the source of truth and Claude is an assistant that reads and helps compose, never a second copy of the data. Access still follows the existing roles in the system, and every lookup leaves a trace that can be audited afterwards. We ran this on our own internal work before offering it to customers.

Enable now, or wait?

CapabilityEnable now if…Wait if…
Individual skill sharingPeople already build skills for their own use (it is on by default)You operate under rules that forbid sharing content between users
Organization-wide skill sharingA reviewer vets skills before they hit the org directory (check first whether the switch is already on)Nobody owns review — in that case consider actively turning it off rather than merely not turning it on
Group skill sharingYou are on Enterprise, group structure is clear and a reviewer is namedYou are on Team (the feature does not exist there), or users are not grouped yet
Teams write (Ask)Teams is your primary channel and a Global Admin is ready to approveYou have not reviewed prompt-injection exposure in channels outsiders can reach
Teams write (fully automatic)Wait in every case for the first rollout — use Ask
Text watermarkNot a choice — it arrives on its own and cannot be disabled. What you can do is have an AI-disclosure policy ready

Conclusion

None of these is a headline feature, but together they change how an organization controls AI in practice. Targeted skill sharing lets internal know-how spread without losing version control. Teams write moves Claude from an assistant that only reads to one that acts, which brings responsibilities that have to be designed rather than assumed. And text watermarking is the signal that content provenance is becoming an enforced standard rather than an optional nicety.

Two things are worth doing this week and the rest can follow the checklist: open Organization settings and see where the switches actually are, and talk to your Microsoft 365 team about approving the new Entra permissions.

New AI capability is not measured by what the tool can additionally do, but by how well the organization controls what it does — a switch still sitting in the off position is a chance to design it right from the start.

- Saeree ERP team, Grand Linux Solution Co., Ltd.

References

Disclaimer

Everything in this article — switch names, menu locations, on/off defaults, per-plan feature boundaries and the console screenshot — was verified on 5 September 2026 against the Claude Team announcement email, Anthropic's help documentation and a live organization console on a Team plan.

Anthropic can change any of it at any time and without notice — renaming switches, moving menus, flipping defaults, releasing features in staged rollouts, or applying different values per organization depending on plan, region and organization-specific configuration. HIPAA-ready and other regulated setups, for instance, are documented as having different defaults.

Before making a policy decision or enabling or disabling any permission, always treat your own console and Anthropic's official documentation as authoritative — not this article. If you find something here that no longer matches reality, tell us at sale@grandlinux.com and we will correct it.

Want your Claude rollout governed properly from day one?

Grand Linux Solution supplies Claude licences for organizations, invoices as a Thai legal entity, and advises on Admin Console policy, connector configuration and connecting Claude to your internal systems through MCP.

Get advice / request a quote

Tel 02-347-7730 | sale@grandlinux.com

Saeree ERP Author

About the Author

Paitoon Butri

Network & Server Security Specialist, Grand Linux Solution Co., Ltd.