How to govern Security in Anthropic
A step-by-step guide to governing Security in Anthropic with Rencore: detect, review by owner and severity, and remediate with an audit trail.
Governing Security in Anthropic means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Anthropic with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Security.
Steps
-
Inventory Anthropic
Connect Anthropic and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Security in Anthropic to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Anthropic reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Anthropic controls for Security
Grounded in the Rencore catalog. See the full Anthropic catalog on the Anthropic connector page.
-
API key is active
Active API keys are live credentials, raising the likelihood that a weakness leads to an incident
Severity: Medium -
User has admin role
Admins have organization-wide reach, raising the likelihood that an access issue has serious impact
Severity: High -
External (guest) user
External guest accounts are a common attack vector, raising the likelihood of risky access
Severity: High -
File is downloadable
Downloadable files can be exfiltrated, raising the likelihood that sensitive content leaves the org
Severity: Medium -
Claude Code user is disabled in Entra ID
Detects Claude users which have been disabled in Entra ID and should be removed
Severity: Medium -
Claude Organization with too many admins
Detects organizations where too many users are admins
Severity: Medium -
Claude Organization with not enough admins
Detects organizations with only 1 or less admin
Severity: Medium -
Claude User is not member of Entra ID
Detects users in Claude organizations which are not part of Entra ID
Severity: Medium -
Claude File contains PII
Detects uploaded files which contain Personally Identifiable Information for training
Severity: High -
Claude File contains sensitive information
Detects uploaded files which contain company, medical or financial data
Severity: High -
API Keys not rotated in 90 days
Detects active API keys that were created more than 90 days ago and may need rotation
Severity: High -
External users in Claude organization
Detects users flagged as external in the corporate directory who have Claude access
Severity: Medium -
Admin role invites sent
Detects pending invites granting the admin role, which should be strictly limited
Severity: High -
Claude Admin Users
Shows all users with admin role
-
Claude Developers
Shows users with developer role
-
Claude Code Users
Shows users with Claude Code role
-
Claude Standard Users
Shows users with standard user role
-
External Users
Shows users flagged as external in Entra ID
-
Internal Users
Shows internal corporate users
-
Files with PII
Shows files flagged as containing Personally Identifiable Information