shiichan

Claude's Compliance API Now Covers Cowork and Claude Code!

Hey everyone, it's Shiichan! Today I found news that security and compliance folks are going to appreciate. As Claude shows up in more and more places, it gets harder to keep track of everything, and this update tackles exactly that gap.

Claude Blog claude.com

What was announced?

Anthropic's Claude Blog announced that, in beta for Claude Enterprise customers, the Compliance API's coverage now extends to Claude Cowork and Claude Code. As the post puts it:

Security and compliance teams rely on the Compliance API to see how Claude is used across their organization — for audits and eDiscovery — without deploying separate logging infrastructure for each surface.

So the Compliance API's whole job is letting teams see how Claude is used across the org for audits and eDiscovery, without building separate logging pipelines for every surface.

The story so far

Until now, the Compliance API didn't cover usage in Claude Cowork or Claude Code. But in practice, Claude is showing up in a lot more than just chat these days, from collaboration work in Cowork to code edits in Claude Code. That meant compliance teams could end up with an inconsistent picture of what's tracked and what's still a blind spot.

What changes

With this expansion, the following surfaces are now covered together:

  • Claude Cowork (desktop app, web, and mobile)
  • Claude Code (CLI and desktop app)

Session content and metadata are now captured as a single, unified server-hosted transcript per session. That means auditors no longer have to check separate systems for each surface — one record now covers the picture.

Dive Deep

Each session record breaks down into two parts:

  • Session content: prompts, responses, and tool calls (both web and MCP)
  • Session metadata: verified user ID, organization ID, and timestamps

The beta also has clear boundaries on what's not covered yet:

  • Claude Code's web version
  • Sessions run through Amazon Bedrock, Google Cloud Vertex AI, or Microsoft Foundry

Adoption is meant to be low-friction: it works with your existing Compliance Access Key, so no additional integration work is required. You can query the new endpoint directly.

Wrap-up

  • Compliance API coverage now extends to Claude Cowork (desktop, web, mobile) and Claude Code (CLI, desktop), in beta for Enterprise customers
  • Prompts, responses, tool calls, and metadata like user and org IDs are now available as a single unified session record
  • Claude Code's web version and sessions run via Bedrock, Vertex AI, or Foundry aren't covered yet
  • Works with your existing Compliance Access Key, so you can query the new endpoint directly with no extra integration work

This one's for security and compliance teams who want a single, unified view of Claude usage across the org for audits and eDiscovery!