Security Teams Can Now Monitor Claude Chats, Files and AI Agent Activity
Claude's Compliance API lets security teams monitor chats, files, and AI agent activity in SIEM and DLP tools.
The Claude Compliance API lets Claude Enterprise customers pull conversation content, uploaded files, projects, and Claude Code or Cowork transcripts, including prompts, tool calls, skills, and artifacts. It can also cover Microsoft 365 add-in activity and an activity feed of logins, admin actions, API-key creation, and configuration changes. Prompts and model responses are not available for Claude Platform deployments. CrowdStrike, SentinelOne, Splunk, Elastic, Microsoft Purview, and other platforms can ingest the telemetry for DLP, SIEM, and auditing.
- Compliance API exposes Enterprise chats, files, projects, and agent transcripts.
- Claude Platform activity feed excludes prompts and model responses.
- Only the Primary Owner can enable the API and create keys.
- CrowdStrike, Splunk, Purview, and others can ingest Claude telemetry.
- Detections cover pasted credentials, code uploads, and unapproved MCP servers.
Full article589 words · extracted from cybersecuritynews.com · click to collapse
The Claude Compliance API gives security teams visibility into employee and AI-agent activity, integrating Claude data with existing monitoring, DLP, identity, eDiscovery, SIEM, and security workflows.
The change addresses a growing enterprise security challenge: generative AI tools are increasingly used for research, software development, document processing, and automated workflows, but they can also become a channel for sensitive-data exposure, risky prompt activity, unapproved connectors, and agent misuse.
For Claude Enterprise customers, the API can provide access to conversation content, including chats, uploaded files, and projects. It can also collect session content from Claude Code and Cowork, including prompts, responses, tool-call content, skills, and artifacts captured as transcript text.
In supported scenarios, it can also monitor Claude activity from Microsoft 365 add-ins, including Word, Excel, PowerPoint, and Outlook.
This visibility lets defenders investigate whether sensitive information such as credentials, personally identifiable information, source code, financial data, or regulated content was shared with Claude.
Security platforms can classify the data, apply policy rules, generate alerts, and send relevant events to a SIEM or case-management workflow.
The Compliance API also records activity-feed events. These include user logins, administrative actions, and configuration changes for Claude Enterprise.
Security Teams Can Monitor Claude Activity
For Claude Platform customers, the activity feed can cover administrative and system events, such as workspace changes, member updates, API key creation, account-setting changes, file downloads, file creation, and skill changes.
Conversation prompts and model responses are not available through the API for Claude Platform deployments. The monitoring expansion is particularly relevant for agentic AI.
Organizations are adopting Claude Code, Cowork, model context protocol servers, connectors, plugins, and AI skills that can access internal tools and data.
Such integrations create new identity, authorization, and software supply-chain risks. Security teams need to know which agents are active, what resources they can access, which MCP servers they invoke, and whether their activity remains within approved policy boundaries.
Several vendors have announced API integrations. Security platforms including CrowdStrike, SentinelOne, Splunk, Elastic, Datadog, Microsoft Purview, Palo Alto Networks, Check Point, Cloudflare, Netskope, Zscaler, Proofpoint, Varonis, Wiz, and others can ingest or analyze Claude-related telemetry for detection, governance, auditing, and data-protection use cases.
For example, an enterprise could detect a developer uploading a source-code archive to Claude, identify a user pasting cloud credentials into a chat, or investigate an AI agent that connects to an unapproved MCP server.
The organization could then correlate the event with endpoint, identity, cloud, and network telemetry to determine whether the behavior was accidental, malicious, or a policy violation.
Claude Enterprise access is controlled at the organization level, with only the Primary Owner able to enable the Compliance API and create access keys.
Owners can create keys limited to their own organization, while administrators cannot enable the API. Once connected, Claude events can flow into the organization’s established security dashboards and incident-response processes.
According to Claude, enterprises should maintain governance controls by defining AI-use policies, limiting agent permissions, applying least privilege, protecting API keys, reviewing connector access, and setting data-retention rules.
As AI tools become embedded in daily business processes, monitoring Claude usage is becoming an important part of enterprise detection and response.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.