THREAT OPS › Threat News › Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate.
AI has moved from the browser tab to the
MITRE ATT&CK techniques
- CredentialsT1589.001