AI agent · Claude Desktop

Claude Desktop, with every gated call waiting for you.

Claude Desktop reaches your services only through PrivacyFence, which reviews reads before release and holds changes for your approval. It works with both deployments: PrivacyFence on your own computer (local mode) and PrivacyFence run by your organization (organization mode). Claude Desktop runs on macOS and Windows; on Linux, use Claude Code.

How it connects

An extension on your computer, a connector to your organization.

Local mode: the extension

PrivacyFence ships its own Claude Desktop extension, PrivacyFence.mcpb. It waits for PrivacyFence to answer, asks it for your token over its local control channel, and relays Claude Desktop's requests to PrivacyFence's /mcp endpoint. Nothing is edited in Claude Desktop's configuration, and no token is stored in a file you can read.

Organization mode: a custom connector

Claude Desktop connects to your organization's PrivacyFence at its /mcp URL, registers itself, and you sign in with your organization account. There is no extension and no token to copy. Access tokens last one hour and are refreshed silently; after 30 days you sign in again.

Set it up

A few steps, and no configuration file.

Local mode

  1. Install PrivacyFence from the download page.
  2. Open the extension that came with it: double-click PrivacyFence.mcpb on the macOS DMG, or accept it on the Windows installer's last page.
  3. Accept when Claude Desktop offers to install it. There is nothing to configure and no token to copy.
  4. Connect your services in PrivacyFence's Settings.

Organization mode

  1. Your administrator gives you the deployment's URL, for example https://pf.example.com.
  2. In Claude Desktop's connector settings, add a custom connector with the URL https://pf.example.com/mcp. Leave the OAuth client ID and secret empty.
  3. Click Connect and sign in with your organization account.
  4. Connect your services at https://pf.example.com/connect.

Install the extension or the custom connector, not both: with both, Claude Desktop lists every tool twice, and the extension only talks to a PrivacyFence on the same computer.

Set it up Local or organization mode?

Confirmations

Claude Desktop may ask first. PrivacyFence's card decides.

PrivacyFence tells Claude Desktop truthfully what each tool does: reads are read-only, writes are writes, and the two tools that delete something are marked destructive. Claude Desktop uses that to decide when to ask you before it calls a tool, so it may ask before a write, in front of PrivacyFence's own card.

When it asks, you can allow the tool for the rest of the chat or always. Allowing it only stops Claude Desktop asking: a gated call still waits for PrivacyFence's approval card, whatever Claude Desktop was told or allowed. There is no mode that advertises writes as read-only.

What we observed with the extension: with default tool permissions, Claude Desktop asked before creating a calendar event; choosing to always allow the tool stopped it asking, and PrivacyFence's approval card was still shown. The custom connector has not been checked yet.

Files

Local paths through the extension, one-time links otherwise.

Local mode. Tools that read or save a file work with paths on your computer. The extension reads or writes the file as you and passes it to or from PrivacyFence. On macOS, the first time a tool uses a folder outside Claude's own, macOS may ask whether Claude may access it; allow it once per folder.

Organization mode. A local path means nothing to the server, so files travel through one-time links: Claude uploads to a single-use address, and a download comes back in the tool result or as a one-time link. Files has the sizes and lifetimes.

How it's identified

A name is a claim until an administrator pins it.

Local mode. Every AI client on your computer uses the same credential, so PrivacyFence cannot tell them apart, and the approval card names the requester Undetected. The audit log still records the name Claude Desktop sent.

Organization mode. The card shows the name Claude Desktop registers with as a claim (Says it is, then the name), marked Not verified, because any program can send the same name. Its custom connector most likely registers as Claude, as claude.ai does; that has not been verified. An administrator can pin the registration on Settings → AI systems, and the cards for it are then verified.

Which AI system is asking

Client settings worth knowing

Set up once, for you or for everyone.

  • Claude Desktop's tool permissions. Always allowing a PrivacyFence tool leaves PrivacyFence's card as the only confirmation for it.
  • Team and Enterprise plans. An owner can add the custom connector for the whole organization; each person then connects it with their own sign-in.
  • If the tools do not appear. PrivacyFence is stopped: choose Start PrivacyFence… from the companion's menu, and the extension picks it up by itself.

Next

Other clients, and what they can reach.

Compare the AI clients PrivacyFence is tested with, or see what each connector lets them read and change.