Audit Claude Platform activity with the Compliance API
Summary
The Compliance API is now available on the Claude Platform, offering administrators programmatic access to audit logs across their organization. This API enables security and compliance teams to track user activity, monitor configuration changes, and integrate Claude usage data into existing compliance infrastructures. It is particularly valuable for organizations in regulated industries, such as financial services, healthcare, and legal, which require detailed records of access and modifications. The API logs security-relevant events, including admin and system activities like adding members or creating API keys, and resource activities such as creating or deleting files. It does not log inference activities or direct user interactions with the model. Logging commences upon API enablement, with no historical data available prior to that point.
Key takeaway
For compliance officers or security architects in regulated industries, the Claude Platform Compliance API offers a critical tool for maintaining audit trails. Your teams can now programmatically access detailed logs of administrative and resource activities, streamlining compliance efforts and reducing reliance on manual processes. Ensure you enable this API promptly, as logging only begins from the enablement date, to capture all future security-relevant events.
Key insights
The Claude Platform Compliance API provides programmatic audit logs for organizational activity, excluding model inference.
Principles
- Regulated industries require programmatic audit trails.
- Manual compliance reviews do not scale effectively.
Method
Enable the Compliance API via your account team, create an admin API key, and query the activity feed endpoint to retrieve logs filtered by time, user, or API key.
In practice
- Integrate Claude usage data into existing compliance tools.
- Track admin actions like API key creation.
- Monitor user-driven resource modifications.
Topics
- Compliance API
- Claude Platform
- Audit Logging
- Programmatic Access
- Regulated Industries
Best for: CTO, VP of Engineering/Data, Director of AI/ML, AI Security Engineer, Security Engineer, Legal Professional
Related on AIssential
Editorial summary, takeaway, and curation by AIssential. Original article published by Claude Blog.