Skip to main content
Claude Enterprise uses two provider APIs with different coverage. The Anthropic Admin API supplies organization inventory. The Claude Compliance API supplies Enterprise activity evidence and, when explicitly authorized, provider remediation operations.

Credentials

Forge stores API keys as managed secrets and reports the two capability lanes independently.

Provider reads

The base Admin collector queries:
When a Compliance key is configured, Forge also polls:
Activity receipts retain the provider event type, timestamp, actor and workspace references, affected object, and content-visibility state.

Setup

  1. Create an Anthropic Admin API key with organization, user, workspace, invite, and API-key read access.
  2. Create a separate Claude Enterprise Compliance API key if activity coverage is required.
  3. Save the keys and optional parent organization ID under Settings → Integrations → Claude Enterprise.
  4. Test the connection and verify Admin and Compliance lanes separately.
  5. Run a sync and compare returned users, workspaces, and a known activity event with the Anthropic console.

Remediation

Read-only setup does not delete provider objects. Remote deletion of chats, files, projects, documents, generated files, or artifacts requires the corresponding Compliance delete scope and an explicit Forge action. Do not add those scopes for inventory-only deployments. Claude UI conversations are not inline-governed by this connector. Supported Claude browser and desktop traffic can be governed separately through agentless Network routing or Device Agent’s transparent proxy. Forge reroutes selected traffic through the LLM Gateway and direct MCP connections through the MCP Gateway.

Verification

Offboarding requires revoking both keys and removing any separately configured network, endpoint, LLM Gateway, or MCP Gateway route.