Anthropic logging & audit security checks
Audit logs, event retention and incident-response hooks — the evidence you need when something goes wrong, and the controls auditors ask for first.
On Anthropic, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Anthropic connector needs.
Checks (4)
severity: low Claude Role Permissions Not Observable fix difficulty: medium #
Investigate why custom-role permission data is not observable via the Compliance API, which blocks broad-access review
- Navigate to claude.ai > Organization settings > Compliance API access
- Verify the compliance key has the read:compliance_org_data scope required for role visibility
- If the scope is present, contact Anthropic support — the roles endpoint may be degraded
- Manually review custom role permissions in the console until visibility is restored
severity: high Claude Sign-In Failure Spike fix difficulty: medium #
Investigate a spike in Claude sign-in failures that may indicate a credential attack
- Navigate to claude.ai > Organization settings > Activity
- Review the recent failed sign-in attempts by user and IP address
- Identify whether failures are attributable to a single actor or credential-stuffing pattern
- Force a password/session reset for affected accounts and notify security
severity: medium Claude Inference Hook Denials Spike fix difficulty: medium #
Investigate a spike in inference-hook denials indicating users are hitting AI-security policy blocks
- Navigate to claude.ai > Organization settings > Activity
- Review the denied inference requests and the policy rules that blocked them
- Determine whether the denials reflect a policy misconfiguration or a genuine attempted violation
- Adjust the inference hook policy or provide user guidance as appropriate
severity: medium Claude Admin Settings Churn fix difficulty: medium #
Review a spike in admin settings changes to rule out unauthorized configuration drift
- Navigate to claude.ai > Organization settings > Activity
- Review the admin settings change events and the members responsible
- Confirm each change was authorized and documented
- Investigate and revert any unauthorized changes