Guide

Anthropic consent

Anthropic is in Preview. It is available when your Subscription includes the Anthropic service. If it is not included, the service shows "Contact sales".

The Anthropic service connects Rencore Governance to a Claude Enterprise organization. It reads metadata only, such as owners, dates, visibility and counts. Rencore Governance never reads, stores or displays chat messages, session transcripts or file content.

Anthropic does not use a Microsoft consent. Instead, you enter API keys that an owner of your Claude organization creates.

Before you start

You will need a Claude organization on the Claude Enterprise plan. Team plan and Claude Console organizations cannot be connected.

Rencore Governance uses up to three Anthropic API keys. Each one opens a different Anthropic API, so each covers a different area of your Inventory. Every key is optional. Create only the keys for the areas you want to cover:

KeyWhat it coversScopes to selectWho can create it
Compliance Access KeyUsers, roles, groups, organization settings, chats, projects, sessions, Code artifacts and the activity feedread:compliance_activities, read:compliance_org_data, read:compliance_user_dataPrimary owner, or an organization owner for their own organization only
Analytics API KeyAdoption, seats, and cost and token usage per userread:analyticsPrimary owner
Scoped Admin API KeySpend limitsread:spend_limitsPrimary owner

To run the “Delete Claude Project” automation, you will also need a Compliance Access Key with the delete:compliance_user_data scope.

A Compliance Access Key with read:compliance_user_data can technically reach chat and session content across your Claude organization. Rencore Governance only calls the endpoints that return metadata, and never reads, stores or displays that content.

Create the keys in Claude

All three keys are created by an owner of your Claude organization, in claude.ai. The Claude Console is not used.

Before any key can be created, the primary owner turns on the Anthropic APIs that the keys use. This is done once for the whole Claude organization.

To turn on the Anthropic APIs, you will need to:

  1. Sign in to claude.ai as the primary owner.
  2. Go to “Organization settings” and then “API”.
  3. Turn on the Compliance API.
  4. Turn on the Analytics API.

The Scoped Admin API Key does not need an API to be turned on.

To create a key, you will need to:

  1. Go to “Organization settings” and then “API”.
  2. In the “Keys” section, click ”+ Create key”.
  3. Enter a name for the key (e.g. Rencore Governance - Compliance).
  4. Select the scopes for the key, as listed in the table above.
  5. Click “Create”.
  6. Copy the key and store it somewhere secure. Each key starts with sk-ant-api01- and is shown only once.

Repeat these steps for each key you need.

Anthropic does not allow the scopes of a key to be changed after it is created. To change them, create a new key and delete the old one. Anthropic recommends a separate key for the delete scope, so a read-only key cannot be used to delete content.

For more detail, see Anthropic’s own guides: Set up the Compliance API, Analytics APIs and Create an Admin API key.

Turn on the service

To turn on the Anthropic service, you will need to:

  1. Click on “Settings” and then “Environment Settings”.
  2. Click on “Manage Services”.
  3. Toggle the selector for “Anthropic (Preview)”.
  4. Click “Save”.

Connect the scan keys

To connect the keys used for scanning, you will need to:

  1. Click on “Settings” and then “Environment Settings”.
  2. On “General Settings”, click the ellipses menu ([…]) and select “Manage consent”.
  3. On the “Scan” tab, click “Give Consent” on “Anthropic”.
  4. Enter the keys you have. Each field is marked (optional):
    • “Compliance Access Key”
    • “Analytics API Key”
    • “Scoped Admin API Key”
  5. Click “Connect”.
  6. When “Connection Successful!” is shown, click “Save and Close”. The first scan starts.

If you left a key empty, the success message lists the areas that stay unavailable (e.g. “Scoped Admin API Key not provided - effective spend limits will be unavailable.”). You can add the key later by repeating these steps.

If “Partial Success” is shown, at least one key you entered failed its check, and no keys were saved. Read the message for each key, click “Review Configuration”, correct the key, and click “Connect” again. The most common causes are:

  • The key was revoked or deleted in Claude.
  • The key was entered in the wrong field, for example an Analytics API Key in the “Compliance Access Key” field.
  • The key is not from a Claude Enterprise organization.
  • The key was not copied completely.

Connect the automation key

The “Delete Claude Project” automation uses its own key, entered separately from the scan keys. Automations for Anthropic stay unavailable until this key is provided.

To connect the automation key, you will need to:

  1. Click on “Settings” and then “Environment Settings”.
  2. On “General Settings”, click the ellipses menu ([…]) and select “Manage consent”.
  3. On the “Automations/Actions” tab, click “Give Consent” on “Anthropic”.
  4. In “Compliance Access Key”, enter a Compliance Access Key that has the delete:compliance_user_data scope.
  5. Click “Connect”, then “Save and Close”.
Warning: Rencore Governance cannot test the delete scope without deleting content, so it is checked the first time the automation runs. A deleted Claude project cannot be recovered.

If a key stops working

If a key that was working is later revoked or changes, the Environment shows a consent warning and a notification email is sent. Areas covered by your other Anthropic keys keep scanning. To fix it, create a new key in Claude and enter it again, as described in Re-consent Permissions.

To link Claude users to their Entra ID accounts, including department and country, Rencore Governance matches them by email against your Microsoft 365 users. Microsoft 365 needs to be scanned in the same Environment for this to work.

Last updated: 9/25/2026