Claude ↗
The capabilities and sub-capabilities listed for this connector are available with any active Cortex XSIAM, Cortex Cloud Posture Security, Cortex Cloud Runtime Security, or Cortex Data Security license.
Scan sensitive content and monitor data security risks for Anthropic Claude AI.
This connector includes the following capabilities and sub-capabilities (if applicable):
- Data Security: Scan and protect data across the Claude service
- Identity Posture: Maintain visibility and control over Claude identities, including users, groups, roles, and granular permissions.
To configure this connector, follow these steps:
Prerequisite
Sign in to your Anthropic Claude organization as a Primary Owner and generate a Compliance API key.
1. Enable Compliance API access
- Sign in to the Claude.ai console using an account with Primary Owner privileges.
- Click Settings in the left navigation menu, and select Organization Settings.
- In Organization Settings, select the API tab.
- Verify that the Compliance API option is enabled.
2. Generate a Compliance API key and assign scopes
- On the API tab, locate the Keys section and click + Create Key.
- Enter a name for the API key.
- Under Scopes, select the required scopes:
read:compliance_activities— Read compliance activity logs and audit trails.read:compliance_org_data— Read organization-level workspace metadata and asset definitions.read:compliance_user_data— Read user identities, group memberships, and role assignments.delete:compliance_user_data— Allow programmatic purging or remediation of non-compliant sensitive data.
- Click Create.
-
Copy the generated API key and store it securely.
Note: You cannot retrieve the API key after you close the dialog.
How to configure the Claude connector
Task 1. Select services
- In Cortex Cloud, navigate to Settings → Data Sources & Integrations.
- Click + Add new.
- On the Add Data Source page, search for Claude, hover over it, and click Add.
In the Configuration Wizard, configure the following settings.
Capabilities tab
- Enter a unique name for the new connector instance.
-
Under Select Capabilities, select the capabilities that you want to enable.
- Data Security to enable scanning and inventory collection across the selected repositories.
- Identity Posture to maintain visibility and control over SaaS-based identities, including users, groups, roles, and granular permissions.
Note: Identity Posture is automatically enabled when Data Security is selected and cannot be disabled during setup. Identity Posture is required for user and group validation and cross-tenant exposure analysis.
- Click Next.
Connection tab
- On the Connection tab, select your preferred authentication method:
- Recommended: Paste your Anthropic Claude organization API key into the API key field.
- Advanced: Select this option if your enterprise security policy requires separate authentication tokens for Data Security and Identity Posture.
- Click Test to validate the connection.
- If the connection is successful, the wizard displays a green Verified status indicator.
- Click Save to save the connection settings.
- Click Next.
Summary tab
- On the Summary tab, verify that each selected capability displays a Connected status.
- If validation succeeds, the wizard displays a Verification Success message.
- Click Create Instance to create the Claude connector.
Task 2. Post verification
After configuration is complete, verify asset discovery and data security findings.
1. Verify discovered assets
- Go to Inventory > All Assets.
- Filter the asset list by setting Provider to Anthropic.
- Verify that Cortex discovers the following supported asset types:
- Claude Personal Workspace: Individual user conversations, chat history, and associated metadata.
- Claude Project: Shared workspaces, custom prompt instructions, and attached knowledge repositories.
2. Verify policy findings
- Select an asset to open the details panel.
- Click the Overview tab to review general properties and total finding counts.
- Click Findings or navigate to the Compliance tabs to review detected security findings, such as:
- Personally identifiable information (PII)
- API keys or secrets
- Credit card numbers
- Unauthorized data sharing