Credentials
Forge stores API keys as managed secrets and reports the two capability lanes
independently.
Provider reads
The base Admin collector queries:Setup
- Create an Anthropic Admin API key with organization, user, workspace, invite, and API-key read access.
- Create a separate Claude Enterprise Compliance API key if activity coverage is required.
- Save the keys and optional parent organization ID under Settings → Integrations → Claude Enterprise.
- Test the connection and verify Admin and Compliance lanes separately.
- Run a sync and compare returned users, workspaces, and a known activity event with the Anthropic console.
Remediation
Read-only setup does not delete provider objects. Remote deletion of chats, files, projects, documents, generated files, or artifacts requires the corresponding Compliance delete scope and an explicit Forge action. Do not add those scopes for inventory-only deployments. Claude UI conversations are not inline-governed by this connector. Supported Claude browser and desktop traffic can be governed separately through agentless Network routing or Device Agent’s transparent proxy. Forge reroutes selected traffic through the LLM Gateway and direct MCP connections through the MCP Gateway.Verification
Offboarding requires revoking both keys and removing any separately configured
network, endpoint, LLM Gateway, or MCP Gateway route.