Skip to content

Anthropic access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Anthropic, Black Cat runs 31 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Anthropic connector needs.

Checks (31)

severity: medium Excessive Org Admins fix difficulty: easy #

Reduce the number of Anthropic org admins by demoting unnecessary users to lower roles

  1. Navigate to Anthropic Console > Settings > Members
  2. Review users with the admin role
  3. Demote unnecessary admins to developer or user roles
  4. Document the access review for compliance records

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Unscoped Admin fix difficulty: medium #

Replace org-wide Anthropic admin access with workspace-scoped admin roles

  1. Navigate to Anthropic Console > Settings > Members
  2. Review whether org-wide admin access is necessary
  3. Consider using workspace-scoped admin roles instead
  4. Demote to a lower role if org-wide admin is not required

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Managed User Review fix difficulty: easy #

Review managed Anthropic user account permissions and workspace assignments for appropriateness

  1. Navigate to Anthropic Console > Settings > Members
  2. Review the managed user account and its purpose
  3. Verify workspace assignments are appropriate
  4. Ensure access level matches current requirements

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Admin Redundancy Missing fix difficulty: easy #

Add a second admin to the Anthropic organization to prevent single point of failure

  1. Navigate to Console > Settings > Members
  2. Identify the single admin
  3. Invite a trusted team member
  4. Assign admin role to the new member
  5. Verify new admin can manage organization settings

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Dormant Member fix difficulty: medium #

Demote or remove dormant Anthropic organization members who have not been active

  1. Navigate to Console > Settings > Members
  2. Find the dormant member
  3. Verify with their manager whether access is still needed
  4. Demote to lower role or remove from organization
  5. Document the decision

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Stale API Key fix difficulty: medium #

Rotate or delete unused Anthropic API keys that have not been recently active

  1. Navigate to Anthropic Console > Settings > API Keys
  2. Identify the stale key by name or partial hint
  3. Create a new replacement API key
  4. Update applications using the old key
  5. Disable or delete the old key

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Unscoped API Key fix difficulty: medium #

Replace org-wide Anthropic API keys with workspace-scoped keys to limit blast radius

  1. Navigate to Anthropic Console > Settings > API Keys
  2. Identify the unscoped API key
  3. Create new workspace-scoped replacement keys
  4. Update applications to use workspace-scoped keys
  5. Delete the org-wide key

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Inactive API Key Not Removed fix difficulty: easy #

Delete inactive Anthropic API keys that are no longer in use

  1. Navigate to Anthropic Console > Settings > API Keys
  2. Confirm the inactive key is no longer needed
  3. Delete the inactive API key

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium API Key Created By Non-User fix difficulty: medium #

Verify and disable Anthropic API keys created by unauthorized non-user entities

  1. Navigate to Anthropic Console > Settings > API Keys
  2. Identify the key and its non-user creator
  3. Verify the creating entity is authorized
  4. If unauthorized, disable or delete the key

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Stale Invite fix difficulty: easy #

Delete stale Anthropic invitations pending for more than 7 days

  1. Navigate to Anthropic Console > Settings > Members
  2. Find the pending invite that has been stale for over 7 days
  3. Delete the stale invite
  4. Re-invite the user if access is still needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Expired Invite Not Cleaned fix difficulty: easy #

Clean up expired Anthropic member invitations from the pending list

  1. Navigate to Anthropic Console > Settings > Members
  2. Find the expired invite
  3. Delete the expired invite to clean up
  4. Re-invite the user if access is still needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Admin Invite Pending Review fix difficulty: easy #

Review and revoke unaccepted Anthropic admin invitations that are past their expected acceptance window

  1. Navigate to Console > Settings > Members > Invites
  2. Find the pending admin invitation
  3. Confirm the invitation is still needed
  4. Revoke if the recipient has not accepted within expected timeframe

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Excessive Workspace Admins fix difficulty: easy #

Reduce Anthropic workspace admin count by demoting unnecessary admins to developer or user roles

  1. Navigate to the workspace in the Anthropic Console
  2. Review users with the workspace_admin role
  3. Demote unnecessary admins to workspace_developer or workspace_user
  4. Document the access review for compliance records

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Workspace Single Admin fix difficulty: easy #

Add a second admin to each Anthropic workspace to ensure redundancy

  1. Navigate to Console > Workspaces
  2. Select the affected workspace
  3. Go to Members tab
  4. Assign admin role to at least one additional trusted member

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high API Key Expired Or Expiring fix difficulty: medium #

Rotate expired or soon-to-expire Anthropic API keys before they cause service disruptions

  1. Navigate to Anthropic Console > Settings > API Keys
  2. Identify the expired or expiring key
  3. Create a new replacement API key
  4. Update applications using the old key
  5. Delete the expired key

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium API Key No Expiration fix difficulty: medium #

Set an expiration date on Anthropic API keys to enforce regular rotation

  1. Navigate to Anthropic Console > Settings > API Keys
  2. Identify the key without an expiration
  3. Create a new key with an appropriate expiration date
  4. Update applications to use the new key
  5. Delete the old non-expiring key

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Claude Code User Not In Workspace fix difficulty: easy #

Assign Claude Code users to a workspace for proper usage tracking and governance

  1. Navigate to Anthropic Console > Workspaces
  2. Identify or create an appropriate workspace
  3. Add the user to the workspace
  4. Verify Claude Code activity appears under the workspace

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Claude Code User Role Review fix difficulty: easy #

Review members with the claude_code_user role to verify intended access scope

  1. Navigate to Anthropic Console > Settings > Members
  2. Find the member with claude_code_user role
  3. Verify the role assignment is intentional
  4. Adjust to a more appropriate role if needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Claude Code Commits Without Pull Requests fix difficulty: easy #

Ensure Claude Code users creating commits also open pull requests for code review

  1. Contact the user to establish PR-based workflow
  2. Review repository branch protection settings
  3. Enable required pull request reviews on protected branches
  4. Verify the user begins opening PRs for Claude Code changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Unscoped API Usage fix difficulty: medium #

Scope API usage to specific workspaces by replacing org-level API keys with workspace-scoped keys

  1. Navigate to Anthropic Console > Settings > API Keys
  2. Identify org-level API keys generating unscoped usage
  3. Create workspace-scoped replacement keys
  4. Update applications to use the workspace-scoped keys
  5. Delete the org-level keys

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Claude SSO Not Enforced fix difficulty: medium #

Enforce SSO for Claude organization sign-in to prevent password-based account takeover

  1. Navigate to claude.ai > Organization settings > Authentication
  2. Review the current SSO enforcement configuration
  3. Enable enforced SSO for all members
  4. Save the updated authentication setting

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Claude SSO Provisioning Not Required fix difficulty: medium #

Require SSO-based provisioning for the Claude organization instead of allowing manual member additions

  1. Navigate to claude.ai > Organization settings > Authentication
  2. Review the SSO provisioning mode
  3. Set provisioning mode to required
  4. Save the updated authentication setting

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Claude No Active IP Allowlist fix difficulty: medium #

Configure an IP allowlist for the Claude organization to restrict sign-in to trusted networks

  1. Navigate to claude.ai > Organization settings > Authentication
  2. Review the IP allowlist configuration
  3. Add trusted network ranges to the allowlist
  4. Enable the IP allowlist

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Claude Excessive Session Duration fix difficulty: easy #

Reduce the maximum Claude session duration below 30 days to limit exposure from stolen sessions

  1. Navigate to claude.ai > Organization settings > Authentication
  2. Review the session duration configuration
  3. Reduce the session duration to an appropriate value
  4. Save the updated authentication setting

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Compliance Key Has Delete Scope fix difficulty: medium #

Remove the irreversible delete:compliance_user_data scope from the active compliance access key

  1. Navigate to claude.ai > Organization settings > Compliance API access
  2. Identify the compliance key with the delete scope
  3. Create a replacement key without the delete scope
  4. Update integrations to use the replacement key
  5. Delete the over-scoped key

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Deactivated Compliance Key Still Listed fix difficulty: easy #

Delete deactivated Claude compliance access keys to reduce audit surface

  1. Navigate to claude.ai > Organization settings > Compliance API access
  2. Identify the deactivated compliance key
  3. Delete the deactivated key

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Compliance Key Stale fix difficulty: medium #

Rotate Claude compliance access keys that are over a year old

  1. Navigate to claude.ai > Organization settings > Compliance API access
  2. Identify the stale compliance key
  3. Create a new replacement compliance key
  4. Update integrations to use the new key
  5. Delete the old key

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Claude Admin Sprawl fix difficulty: medium #

Review and reduce the number of Claude org admin-equivalent members (admin, owner, and primary_owner roles)

  1. Navigate to claude.ai > Organization settings > Members
  2. Review the list of admin, owner, and primary_owner role holders
  3. Demote members whose admin-equivalent access is not required
  4. Document the access review for compliance records

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Claude Empty Group fix difficulty: easy #

Remove empty Claude RBAC/SCIM groups to reduce access-control clutter

  1. Navigate to claude.ai > Organization settings > Groups
  2. Confirm the group has no members and is not a placeholder for pending provisioning
  3. Delete the empty group

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Claude Custom Role Broad Connector Access fix difficulty: hard #

Review custom Claude roles that grant MCP server or connector tool access to limit agent blast radius

  1. Navigate to claude.ai > Organization settings > Roles
  2. Identify the custom role(s) granting MCP server or connector tool permissions
  3. Verify the scope of access is intentional and necessary
  4. Narrow the role's permissions if broader than required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Compliance Key No Expiry fix difficulty: medium #

Set an expiry date on active Claude compliance access keys to enforce regular rotation

  1. Navigate to claude.ai > Organization settings > Compliance API access
  2. Identify the compliance key without an expiry date
  3. Create a new replacement key with an expiry date set
  4. Update integrations to use the new key
  5. Delete the old non-expiring key

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Anthropic checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial