Skip to content

Anthropic logging & audit security checks

Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.

On Anthropic, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Anthropic connector needs.

Checks (4)

severity: low Claude Role Permissions Not Observable fix difficulty: medium #

Investigate why custom-role permission data is not observable via the Compliance API, which blocks broad-access review

  1. Navigate to claude.ai > Organization settings > Compliance API access
  2. Verify the compliance key has the read:compliance_org_data scope required for role visibility
  3. If the scope is present, contact Anthropic support — the roles endpoint may be degraded
  4. Manually review custom role permissions in the console until visibility is restored

Vendor docs ↗

severity: high Claude Sign-In Failure Spike fix difficulty: medium #

Investigate a spike in Claude sign-in failures that may indicate a credential attack

  1. Navigate to claude.ai > Organization settings > Activity
  2. Review the recent failed sign-in attempts by user and IP address
  3. Identify whether failures are attributable to a single actor or credential-stuffing pattern
  4. Force a password/session reset for affected accounts and notify security

Vendor docs ↗

severity: medium Claude Inference Hook Denials Spike fix difficulty: medium #

Investigate a spike in inference-hook denials indicating users are hitting AI-security policy blocks

  1. Navigate to claude.ai > Organization settings > Activity
  2. Review the denied inference requests and the policy rules that blocked them
  3. Determine whether the denials reflect a policy misconfiguration or a genuine attempted violation
  4. Adjust the inference hook policy or provide user guidance as appropriate

Vendor docs ↗

severity: medium Claude Admin Settings Churn fix difficulty: medium #

Review a spike in admin settings changes to rule out unauthorized configuration drift

  1. Navigate to claude.ai > Organization settings > Activity
  2. Review the admin settings change events and the members responsible
  3. Confirm each change was authorized and documented
  4. Investigate and revert any unauthorized changes

Vendor docs ↗

More Anthropic checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial