Claude adoption rarely starts with a formal rollout. A developer creates an API key. A team connects an MCP server. Someone publishes an artifact. Before long, security teams are piecing together admin records, activity logs, and offboarding data to answer a basic question: “Who still has access, and what can they do?”
Today, Silverfort expands its Anthropic integration through Anthropic’s Compliance API, giving security teams a unified view of Claude users, credentials, and activity alongside the rest of their identity estate.

Four Identity Security risks from enterprise AI adoption
The more Claude connects to, the more valuable it becomes. Once it can reach code, documents, tickets, and business systems, teams get meaningful work done faster. But each of those connections runs through an identity, whether that’s a person, a service account, or an agent acting on someone’s behalf. The challenge for security teams isn’t the AI itself. It’s keeping track of which identities are involved, what they can access, and whether that access still makes sense.
Agents are a good place to start. When a developer uses an AI agent on their own machine, the agent typically works under the developer’s identity and whatever credentials are already available there. That’s what makes it useful, but it also means the agent’s actions look exactly like the developer’s in every downstream log. If the agent is steered toward something unintended, the activity still appears to be a legitimate user doing legitimate work.
Delegated access adds another layer. When employees connect an AI assistant to tools like a document store or CRM, they grant access through OAuth, often with broader scopes than any single task requires. Those grants tend to persist, and because they aren’t traditional accounts, they rarely come up in access reviews. Across a large organization, that delegated access can become difficult to inventory.
Automation brings non-human identities into the picture. As teams build AI into scripts, pipelines, and internal tools, API keys get shared across workflows and outlast the projects they were created for. When one key supports several processes, it becomes hard to tell which one is responsible for a given action, or who should own it once the original creator has moved on.
Finally, AI makes it easier for data to move across permission boundaries. A user with access to a restricted source can bring that content into a shared workspace, and the original permissions don’t always follow it. No control was bypassed, but information can end up available to people who were never meant to see it.
None of these are reasons to slow down AI adoption. They’re reasons to bring AI identities into the same visibility and governance that already applies to the rest of the organization, and that’s what the Silverfort Compliance API integration is built to do.
How the Silverfort integration with Anthropic’s Compliance API works
The integration brings Anthropic users, roles, organization settings, chats, and activity into the Silverfort Identity Security Platform. Silverfort connects that information with workspaces, API keys, and the identities already mapped across the organization.
This gives security teams a clearer view of Claude usage and the people, permissions, and credentials behind it.
Find the gaps that audit logs leave behind
Silverfort turns Claude data into posture findings teams can act on, including:
- Privileged accounts that have gone dormant
- Former employees who still have Claude access or active API keys
- MCP servers with no tool policy
- Magic-link logins that bypass enforced SSO
- Missing IP restrictions
- Exposed tunnel secrets, public artifacts, and organization data exports
A log tells you that something happened. Identity context tells you whether it should have happened, which identity was used, and what else may be exposed.
For example, an alert fires on unusual Claude activity. The log shows the event and the account behind it, such as a service account key making thousands of calls overnight or a user exporting organization data. What it doesn’t show is whether the service account’s owner is still with the company, whether exports fit that user’s role, or what else the identity can reach. Without that context, analysts are left choosing between escalating an alert that may be benign and closing one that may not be. Identity context lets them ask a better question: “Is this normal for this identity, and if not, how far could it go?”
AI raises the stakes. An agent connected to several MCP servers can use existing permissions across all of them in a single task, which makes knowing the identity behind each action more important, not less. Without that, security teams are reading the log without the story.

A step further: Turning Claude visibility into runtime enforcement with Silverfort
You can’t enforce policy on identities and activity you can’t see. This integration establishes that first layer by mapping Claude users, credentials, agentic components, and activity into the broader identity estate.
But visibility isn’t the finish line.
The next step is bringing Silverfort’s identity context and policy decisions into the execution path, so risky access can be evaluated inline, in real time, before a sensitive action is completed. That means moving from finding an overprivileged agent or unsafe tool connection after the fact to controlling what it can do at the moment of access.
That could look like an engineer asking a Claude-connected agent to investigate a production issue. The agent searches the code repository through an approved MCP tool, then tries to use a write tool against the production database. With that call routed through Silverfort, the platform would check the identity behind the session and the tool’s permitted scope, and block the write before it reaches the database connector. The security team could then trace the attempted action back to the agent and its human owner, and see the access paths that made the agent risky. The decision happens when the tool is called, while there’s still time to stop it.
Get started with the integration to strengthen AI Security

For setup instructions, see the Silverfort Anthropic integration documentation. For a personalized demo of how the integration works with the Silverfort Identity Security Platform, get in touch.
Frequently Asked Questions (FAQs)
What Identity Security risks does Claude introduce?
The risks come less from Claude itself and more from how AI connects to the rest of the organization. Agents often act under a developer’s identity and credentials, so their actions are hard to distinguish from the user’s. OAuth grants to connected tools can carry broad scopes and persist long after they’re needed. API keys get shared across scripts and pipelines and outlive their original owners. And, content can move from restricted sources into shared workspaces where the original permissions don’t apply.
What is Anthropic’s Compliance API?
It’s a REST API that gives enterprise IT and security teams programmatic access to Claude activity data, rather than relying on manual exports and periodic reviews. It covers two types of data: conversation content from Claude Enterprise, including chats, uploaded files, and projects, and activity events such as user logins, administrative actions, and configuration changes. It’s available to Enterprise plan organizations, excluding Public Sector organizations.
How do I find out who in my organization is using Claude?
Connect the Compliance API to the Silverfort Identity Security Platform. Silverfort maps Claude users, roles, workspaces, API keys, and activity to the identities already known across your environment, so you can see who is using Claude, which credentials they’re using, and whether that access still fits their role.

