Reference

Policies for Anthropic

See the Anthropic inventory reference for the objects these templates work on.

Policy Description Severity Category Checks
Admin role invites sent ⭐ Detects pending invites granting the admin role, which should be strictly limited Admin role invites grant organization-wide management access including the ability to manage all workspaces, API keys, and members. Anthropic recommends limiting admin access to 2-3 trusted operators maximum. Each admin invite should have documented approval and business justification. Unauthorized admin invites should be revoked immediately to prevent privilege escalation. High Security Claude Invite
API key is active ⭐ Active API keys are live credentials, raising the likelihood that a weakness leads to an incident An active API key is a live credential. If leaked, it grants immediate access; inactive and archived keys cannot be used. Active keys therefore raise the likelihood that any weakness — no rotation, broad scope — results in an actual incident. Medium Security Claude API Key
API Keys not rotated in 90 days ⭐ Detects active API keys that were created more than 90 days ago and may need rotation API keys that haven't been rotated in 90 days represent a growing security risk. Compromised long-lived keys grant extended unauthorized access to Claude resources. Industry standards (NIST IA-5, SOC 2 CC6.1) require regular credential rotation. Create a new key, update dependent services, then archive or delete the old key to maintain a strong security posture. High Security Claude API Key
Claude Code user exceeds the costs limit ⭐ Detects users of Claude Code which are causing to high costs Individual users exceeding cost thresholds may indicate inefficient usage patterns or potential misuse. These outliers require investigation to understand if they need training on cost-effective practices or if their legitimate workload justifies higher spending. Early detection prevents budget overruns and enables proactive cost management conversations. High Costs Claude User
Claude Code user is disabled in Entra ID ⭐ Detects Claude users which have been disabled in Entra ID and should be removed Disabled users maintaining Claude access creates critical security vulnerabilities and violates access control policies. When accounts are disabled in Entra ID, their Claude access should be immediately revoked to prevent unauthorized use. This also prevents wasting licenses on inactive user accounts. Medium Security Claude User
Expired invites not cleaned up ⭐ Detects expired invites that should be deleted to maintain a clean organization Expired invites clutter the organization's invite list and make it harder to audit legitimate pending access requests. Anthropic invites expire after 21 days, but expired entries remain visible until manually deleted. Regular cleanup of expired invites supports SOC 2 provisioning controls (CC6.2/CC6.3) and simplifies access audits. Low Declutter Claude Invite
External users in Claude organization ⭐ Detects users flagged as external in the corporate directory who have Claude access External users (contractors, vendors, partners) in Claude organizations require heightened oversight as they operate outside standard corporate identity governance. Their access may persist after contract termination, and their usage cannot be monitored through standard internal controls. Review external user access quarterly, ensure each has a documented business justification, and remove access immediately when the engagement ends. Medium Security Claude User
Claude File contains PII ⭐ Detects uploaded files which contain Personally Identifiable Information for training Personally Identifiable Information (PII) uploaded to Claude services poses serious privacy and compliance risks under regulations like GDPR and CCPA. PII exposure in training data or file storage can lead to data breaches, legal penalties, and loss of customer trust. Files containing PII should be removed immediately to prevent unauthorized access and ensure regulatory compliance. High Security Claude File
Claude File contains sensitive information ⭐ Detects uploaded files which contain company, medical or financial data Files containing sensitive company, medical, or financial data uploaded to Claude services create significant confidentiality and compliance risks. Exposure of proprietary business information, healthcare records (HIPAA), or financial data (PCI-DSS, SOX) can result in competitive disadvantages, regulatory violations, and severe legal consequences. Immediate removal of such files is essential to protect organizational assets and maintain regulatory compliance. High Security Claude File
File is downloadable ⭐ Downloadable files can be exfiltrated, raising the likelihood that sensitive content leaves the org A downloadable file can be retrieved and exfiltrated through the API. Combined with sensitive content, downloadability raises the likelihood that the data actually leaves the organization. Non-downloadable files do not match. Medium Security Claude File
Large files uploaded to Claude ⭐ Detects files larger than 5 MB uploaded to Claude workspaces Large files (>5 MB) uploaded to Claude workspaces increase token consumption, processing costs, and potential data exposure surface. They may contain unnecessary bulk data, full database exports, or uncompressed assets that could be optimized. Review large files to determine if they are still needed, if a smaller subset would suffice, or if they contain sensitive data that shouldn't be stored in Claude. Low Costs Claude File
Archived workspaces older than 180 days ⭐ Detects workspaces archived more than 6 months ago that could be permanently removed Workspaces archived for more than 6 months are unlikely to be needed again. While archived workspaces don't count toward Anthropic's 100-workspace limit, they clutter the admin view and may retain associated API keys and data. Review these workspaces and permanently delete them if the data is no longer needed, or document the retention reason for compliance purposes. Low Declutter Claude Workspace
Claude organization exceeds the 30 days cost limit ⭐ Detects organization with costs larger than 2000 EUR Organizations exceeding budget thresholds require immediate attention to prevent financial surprises and maintain cost control. High spending may indicate runaway AI usage, inefficient practices, or the need for plan adjustments. Monitoring organizational costs enables proactive budget management and strategic decisions about AI investment. High Costs Claude Organization
Claude Organization with not enough admins ⭐ Detects organizations with only 1 or less admin Organizations with only one administrator create a single point of failure for access management and platform governance. If the sole admin becomes unavailable, leaves the organization, or has their account compromised, no one can manage the Claude organization, approve access requests, or respond to security incidents. Assign at least two administrators to ensure business continuity and proper oversight. Medium Security Claude Organization
Claude Organization with too many admins ⭐ Detects organizations where too many users are admins Excessive admin privileges violate the principle of least privilege and significantly increase security risks. Too many administrators complicate audit trails and increase the risk of accidental or malicious configuration changes. Organizations should limit admin roles to only those users who truly need elevated permissions. Medium Security Claude Organization
Skill is actively maintained ⭐ Skills updated within the last 90 days are in active use, raising the likelihood that any weakness is exploited A skill updated within the last 90 days is actively maintained and in use: skills are autonomous capabilities that agents invoke to act with the organization's context. An actively used skill is far more likely to be exercised — and any weakness in its logic exploited — than an abandoned one. This raises the likelihood axis of the risk score, not the impact axis. Medium Operation Claude Skill
Custom skills not updated in 180 days ⭐ Detects custom skills that haven't been updated in 6 months and may be outdated Custom skills that haven't been updated in 6 months may contain outdated instructions, reference deprecated APIs, or use insecure patterns. Stale skills reduce the quality and reliability of AI-assisted workflows. Review each stale skill to determine if it should be updated, replaced, or deleted. Maintain a skill governance process that includes regular reviews and version control. Low Operation Claude Skill
User has admin role ⭐ Admins have organization-wide reach, raising the likelihood that an access issue has serious impact Organization admins can manage every workspace, API key and member. A compromised or misgoverned admin account has organization-wide reach, making it a high-value target and raising the likelihood that any access issue has serious impact. High Security Claude User
External (guest) user ⭐ External guest accounts are a common attack vector, raising the likelihood of risky access External guest accounts operate outside corporate identity governance and are a common attack vector. Their presence raises the likelihood of risky or unmonitored access. Internal users simply do not match. High Security Claude User
Claude User is not member of Entra ID ⭐ Detects users in Claude organizations which are not part of Entra ID Users outside the corporate directory bypass identity governance and cannot be managed through centralized policies. This creates security blind spots and may indicate shadow IT, external contractors without proper access controls, or orphaned accounts. All Claude users should be linked to Entra ID for proper identity lifecycle management. Medium Security Claude User
Workspace with high 7-day cost spike ⭐ Detects workspaces with costs exceeding 500 EUR in the last 7 days A workspace exceeding $500 in just 7 days may indicate a sudden spike in usage, a compromised API key, or runaway automation. Short-term cost anomalies are often easier to address early before they compound into monthly budget overruns. Investigate the workspace's recent API key activity, model usage, and token consumption to identify the root cause and take corrective action. High Costs Claude Workspace
Claude workspace exceeds the 30 days costs limit ⭐ Detects workspaces where the costs are greater than 1000 EUR High-cost workspaces need immediate review to identify optimization opportunities and prevent budget surprises. Excessive spending may indicate inefficient coding practices, unnecessarily large context windows, or heavy usage that requires architectural review. Proactive monitoring enables targeted interventions and cost optimization strategies. High Costs Claude Workspace
Workspace is live (not archived) ⭐ Non-archived workspaces are active and reachable, raising the likelihood that an issue manifests A workspace that has not been archived is live: it holds active API keys, files and usage. Live workspaces are reachable and in use, raising the likelihood that any cost or data issue manifests. Archived workspaces do not match. Medium Operation Claude Workspace
Inactive Claude Code users ⭐ Detects users that are not using Claude Code in the last 90 days Inactive users with licenses represent wasted investment and opportunity cost for the organization. These users may need additional training or support to improve adoption, or their licenses could be reallocated to active team members. Monitoring adoption patterns ensures maximum value from your AI investment. Medium Adoption Claude User
Unused Claude Api Keys ⭐ Detects API Keys which had no usage in the last 90 days and could be removed Long-unused API keys are forgotten security liabilities that continue to grant valid access if compromised. They consume management resources through rotation requirements and complicate security audits. Revoking inactive keys minimizes your attack surface and reduces the scope of security incident response. Medium Declutter Claude API Key
Unused Claude workspaces Detects Claude workspaces without usage in the last 30 days Unused workspaces waste resources and licenses while increasing management overhead. They often indicate abandoned projects that should be archived or deleted. Regular cleanup of inactive workspaces helps maintain a lean and cost-effective AI infrastructure. Medium Declutter Claude Workspace

Last updated: 7/19/2026