Guide
Anthropic consent
The Anthropic service connects Rencore Governance to a Claude Enterprise organization. It reads metadata only, such as owners, dates, visibility and counts. Rencore Governance never reads, stores or displays chat messages, session transcripts or file content.
Anthropic does not use a Microsoft consent. Instead, you enter API keys that an owner of your Claude organization creates.
Before you start
You will need a Claude organization on the Claude Enterprise plan. Team plan and Claude Console organizations cannot be connected.
Rencore Governance uses up to three Anthropic API keys. Each one opens a different Anthropic API, so each covers a different area of your Inventory. Every key is optional. Create only the keys for the areas you want to cover:
| Key | What it covers | Scopes to select | Who can create it |
|---|---|---|---|
| Compliance Access Key | Users, roles, groups, organization settings, chats, projects, sessions, Code artifacts and the activity feed | read:compliance_activities, read:compliance_org_data, read:compliance_user_data | Primary owner, or an organization owner for their own organization only |
| Analytics API Key | Adoption, seats, and cost and token usage per user | read:analytics | Primary owner |
| Scoped Admin API Key | Spend limits | read:spend_limits | Primary owner |
To run the “Delete Claude Project” automation, you will also need a Compliance Access Key with the delete:compliance_user_data scope.
read:compliance_user_data can technically reach chat and session content across your Claude organization. Rencore Governance only calls the endpoints that return metadata, and never reads, stores or displays that content.Create the keys in Claude
All three keys are created by an owner of your Claude organization, in claude.ai. The Claude Console is not used.
Before any key can be created, the primary owner turns on the Anthropic APIs that the keys use. This is done once for the whole Claude organization.
To turn on the Anthropic APIs, you will need to:
- Sign in to claude.ai as the primary owner.
- Go to “Organization settings” and then “API”.
- Turn on the Compliance API.
- Turn on the Analytics API.
The Scoped Admin API Key does not need an API to be turned on.
To create a key, you will need to:
- Go to “Organization settings” and then “API”.
- In the “Keys” section, click ”+ Create key”.
- Enter a name for the key (e.g. Rencore Governance - Compliance).
- Select the scopes for the key, as listed in the table above.
- Click “Create”.
- Copy the key and store it somewhere secure. Each key starts with
sk-ant-api01-and is shown only once.
Repeat these steps for each key you need.
For more detail, see Anthropic’s own guides: Set up the Compliance API, Analytics APIs and Create an Admin API key.
Turn on the service
To turn on the Anthropic service, you will need to:
- Click on “Settings” and then “Environment Settings”.
- Click on “Manage Services”.
- Toggle the selector for “Anthropic (Preview)”.
- Click “Save”.
Connect the scan keys
To connect the keys used for scanning, you will need to:
- Click on “Settings” and then “Environment Settings”.
- On “General Settings”, click the ellipses menu ([…]) and select “Manage consent”.
- On the “Scan” tab, click “Give Consent” on “Anthropic”.
- Enter the keys you have. Each field is marked (optional):
- “Compliance Access Key”
- “Analytics API Key”
- “Scoped Admin API Key”
- Click “Connect”.
- When “Connection Successful!” is shown, click “Save and Close”. The first scan starts.
If you left a key empty, the success message lists the areas that stay unavailable (e.g. “Scoped Admin API Key not provided - effective spend limits will be unavailable.”). You can add the key later by repeating these steps.
If “Partial Success” is shown, at least one key you entered failed its check, and no keys were saved. Read the message for each key, click “Review Configuration”, correct the key, and click “Connect” again. The most common causes are:
- The key was revoked or deleted in Claude.
- The key was entered in the wrong field, for example an Analytics API Key in the “Compliance Access Key” field.
- The key is not from a Claude Enterprise organization.
- The key was not copied completely.
Connect the automation key
The “Delete Claude Project” automation uses its own key, entered separately from the scan keys. Automations for Anthropic stay unavailable until this key is provided.
To connect the automation key, you will need to:
- Click on “Settings” and then “Environment Settings”.
- On “General Settings”, click the ellipses menu ([…]) and select “Manage consent”.
- On the “Automations/Actions” tab, click “Give Consent” on “Anthropic”.
- In “Compliance Access Key”, enter a Compliance Access Key that has the
delete:compliance_user_datascope. - Click “Connect”, then “Save and Close”.
If a key stops working
If a key that was working is later revoked or changes, the Environment shows a consent warning and a notification email is sent. Areas covered by your other Anthropic keys keep scanning. To fix it, create a new key in Claude and enter it again, as described in Re-consent Permissions.