- In short
- Feature-level data controls are the claude.ai mechanisms you match to a data-handling need: the code execution sandbox (uploaded files are processed in a sandboxed environment), Memory persistence (carries information across sessions, undesirable for sensitive one-off work), Incognito mode (keeps a session out of chat history and Memory but still follows the organization's data-retention policy), and org-level Memory administration (absent on Team plans; on Enterprise, Owners and Primary Owners hold org-wide Memory settings).
Knowing the controls before you reach for one
Once you have classified data with the sensitivity tiers, you need to act on that classification, and acting means reaching for the right claude.ai control. The CCAO-F exam expects you to know what each control actually does - not a vague sense that they exist, but the specific behavior of the sandbox, Memory persistence, Incognito mode, and organization-level Memory administration. The controls are only useful if you pick the correct one at the correct moment, and picking correctly requires knowing precisely what each one governs.
The recurring theme is that these controls govern different things - where files are processed, whether information persists across sessions, whether a session enters history and Memory, and who administers Memory at the organization level. They are not interchangeable, and the exam's traps come from assuming one control does something it does not.
- Feature-level data controls
- The claude.ai mechanisms for handling data by sensitivity: the CODE EXECUTION SANDBOX (uploaded files are processed in a sandboxed environment); MEMORY PERSISTENCE (carries information across sessions); INCOGNITO MODE (keeps a session out of chat history and Memory, while still following the organization's data-retention policy); and ORG-LEVEL MEMORY ADMINISTRATION (absent on Team plans; on Enterprise, Owners and Primary Owners control org-wide Memory settings).
The code execution sandbox
When Claude runs code, it does so in a sandboxed environment, and uploaded files involved in that analysis are processed inside that sandbox. The practical significance is that code execution is an isolated processing space rather than a general-purpose data store, and the habit that goes with it is to review what you upload before running an analysis on it.
For the exam, the point to carry is factual: code execution means a sandboxed environment where uploaded files are processed. Knowing that placement helps you reason about where data goes when you use the feature, and it distinguishes the sandbox - a processing control - from Memory and Incognito, which are about persistence.
Memory persistence and Incognito mode
Memory persistence is the feature that carries information across sessions. That is exactly what you want for continuity on ongoing work and exactly what you do not want for sensitive one-off tasks, where having the material persist beyond the single session is an unnecessary and undesirable exposure. So Memory is a benefit or a liability depending entirely on the sensitivity and the nature of the work.
Incognito mode is the counterpart control. It keeps a session out of your chat history and Memory, which makes it the right tool for a confidential input you do not want surfacing later in history or persisting in Memory. But its scope is precise and limited: Incognito governs history and Memory, and it still follows the organization's underlying data-retention policy. It is not a delete switch and not an exemption from retention. A concrete consequence to remember is that Incognito chats can still surface in an organization's data exports, because the retention layer keeps them even though they never entered your visible history or Memory. Memory exclusion and data retention are separate controls, and Incognito touches only the first. This precise boundary is the single most tested fact in this knowledge point, and it drives the misconception that matching controls to sensitivity tackles head-on.
Organization-level Memory administration
The fourth control is not something an individual toggles in a chat; it is administration at the organization level, and here plan tier matters. On Team plans there is no organization-wide Memory control - the org-level administration simply is not available. On Enterprise, Owners and Primary Owners hold the org-wide Memory settings, including the ability to disable memory for the organization.
The exam-relevant takeaway is that admin capabilities are not uniform across plans. You cannot assume that because one organization's admins can flip an org-wide Memory setting, every organization's can. Knowing which plan you are on, and who controls the setting on that plan, is part of handling data responsibly - and it is a fact worth confirming against the current Claude Help Center rather than assuming.
What the exam trips candidates on
The first trap is assuming Incognito mode deletes data outright rather than just excluding it from chat history and Memory. Incognito is a persistence-scope control, not a delete function, and it explicitly still follows the organization's data-retention policy. An answer that treats Incognito as erasing data has misread its scope.
The second trap is assuming every plan tier gives admins the same organization-level Memory controls. It does not: Team plans lack org-wide Memory administration entirely, while Enterprise vests it in Owners and Primary Owners. The credited answer respects that the control's availability depends on the plan.
Worked example
A practitioner on a Team plan needs to analyze a confidential (yellow) internal document once, wants nothing to persist afterward, and asks the admin to 'just turn off Memory for the whole org so it's handled.' Walk through which controls apply and correct the misconceptions.
Start with the request to the admin. On a Team plan there is no organization-wide Memory control to turn off - that administration exists on Enterprise, where Owners and Primary Owners hold it. So the "turn off Memory for the whole org" step is not available on this plan; assuming every tier has the same admin controls is the second trap.
Now the actual need: a one-off analysis of a yellow document with nothing persisting. The fitting control is Incognito mode, which keeps this session out of chat history and Memory - exactly the non-persistence the practitioner wants for sensitive one-off work. Memory persistence is precisely what you do not want here, so working in Incognito rather than a standard Memory-on session is the right match.
But set expectations correctly: Incognito excludes the session from history and Memory; it does not delete anything outright, and the organization's underlying data-retention policy still applies. If the practitioner assumed Incognito erases the data, that is the first trap. For a yellow document that has passed its review, this scope is appropriate. (Had it been red/regulated data, Incognito would not be the answer at all - the prior question of whether the entry point is approved for that data would come first, which is the subject of the next knowledge point.)
If code execution is used to compute something from the file, the upload is processed in the sandbox - a processing detail, separate from the persistence question Incognito addresses.
Common misreadings to avoid
Misconception
Incognito mode deletes the data from the session.
What's actually true
Misconception
Every claude.ai plan gives admins the same organization-level Memory controls.
What's actually true
How this shows up on the exam
Domain 6 questions on this knowledge point ask you to pick the control that fits a data-handling need, or to identify what a control does and does not do. The dependable approach is to keep each control's scope straight: the sandbox processes uploads, Memory persists across sessions, Incognito excludes from history and Memory without deleting or overriding retention, and org-wide Memory administration exists only on Enterprise. Reject options that make Incognito a delete button or assume uniform admin controls.
Knowing the controls is the setup for the harder judgment in matching controls to sensitivity, where the key move is realizing Incognito governs persistence, not permission to use regulated data in the first place. The same proportionality thinking extends beyond data controls to least privilege across features and connectors.
A user wants to discuss a confidential input in a session that will not appear in chat history or Memory. They believe turning on Incognito means the data is fully deleted and outside all organizational retention. What correction is needed?
People also ask
What data controls does claude.ai offer?
Does Incognito mode delete data?
Do all plans have org-level Memory controls?
Watch and learn
Official Anthropic Academy lessons first, then hand-picked walkthroughs. Videos load only when you press play.
No videos curated for this concept yet
We are still curating the best official and community videos for this topic.
Official prep for this domain
Anthropic's own free prep module for this part of the syllabus, on the official prep course. Free with an Anthropic Academy sign-in.
References & primary sources
Master this concept with Archie
Practice it inside an adaptive study session. Archie, your Socratic AI tutor, tracks your mastery with Bayesian Knowledge Tracing and schedules the perfect next review.