Table of contents
Anyone who can prompt Claude is now a builder. Engineers are writing code with it. Analysts are drafting research with it. Operators are creating dashboards with it. Support teams are answering tickets with it. Whole business functions are quietly being rewired around it. Claude is enabling an explosion of builders inside organizations of all sizes.
Claude adoption is happening faster than most security programs can track. New users are being added, admins are configuring org settings, projects are being created and shared, and none of it is flowing through the tools security teams already rely on.
Today, we’re closing that gap. Orca now connects to Claude’s Compliance API, bringing Claude Enterprise organizations into the same platform Orca customers already use to secure the infrastructure, code, and AI assets in cloud-native apps.
Why this needs to live inside your cloud security platform
For the last decade, security teams have done the hard work of mapping identities, permissions, data stores, and workloads across cloud providers. AI platforms recreate every one of those problems in a new place: identities that can escalate, projects that can be over-shared, retention and training settings that can quietly change data exposure, network egress that can create exfiltration paths.
Treating that as a separate problem with a separate tool, a separate inventory, and a separate alert queue is how the last generation of cloud security ended up with 6+ point tools and no context to correlate them. Doing it again for AI is a step backward.
Big idea: Claude is where employees are building. It belongs in the same platform where security teams are managing risk across cloud, code, and AI.
What Orca sees in Claude Enterprise
The integration uses a read-only Compliance API key. It deploys in minutes and never touches chat or file content. What Orca ingests today is the configuration and identity layer:
- Organizations and org settings: SSO enforcement, IP allowlist, session-duration limits, data retention, content redaction, model-training opt-in, org-wide project sharing, code-execution egress
- Users: identity, org role, and how each user relates to the rest of your environment
- Groups: membership and whether they’re provisioned through SSO/SCIM or managed directly in Claude
- Roles and role bindings: custom permissions and who holds them
- Projects: name, owner, visibility (private vs. org-wide)
- Chat metadata: name, owner, model, timestamp, visibility (metadata only, never content)
Every one of these becomes a first-class asset in Orca’s Unified Data Model, alongside your existing cloud accounts.
Coverage and context to drive decisions
Visibility coverage must be operationalized in the age of AI. The following categories give a glimpse into how security teams can use Orca’s insights to govern Claude Enterprise.
Identity and access: Orca surfaces privilege sprawl, shadow identity outside SSO/SCIM, and gaps in session and network scope. Example: if SSO isn’t enforced on the account, members can sign in with standalone credentials outside your identity provider. Turn on SSO enforcement in the org settings so every sign-in flows through the same IdP you use for the rest of your cloud.

Data security: Orca flags how prompts, outputs, and files are shared, stored, and consumed inside Claude, covering project visibility, content redaction, retention, and model-training opt-in. For example, if content redaction is disabled at the org level, prompts and activity are stored with sensitive data intact. Turn it on in org settings, or if there’s a documented reason it needs to stay off, consider other compensating controls.

Secure Claude through your existing workflows
Orca delivers visibility, context that drives decisions, and security that fits the way your teams work:
- Security engineers. A Claude project that connects to sensitive internal workflows shows up on the same graph as the AWS accounts and data stores it interacts with. Ownership, exposure, and blast radius are visible in one place. No tool-switching, no manual correlation.
- Compliance leads. An audit conversation about AI governance stops being an exception. Who has access, what permissions they hold, whether SSO and retention are enforced, and how Claude resources map to the rest of the enterprise. All information in the same platform where existing compliance workflows already run.
- IT and platform teams. As Claude Enterprise rolls out across the business, they can see how many projects exist, who’s creating them, whether configurations drift from policy, and catch shadow groups before they become an access-review problem.
Getting connected
This integration requires a Claude Enterprise plan and a Compliance API key generated by the primary owner. Only two read-only scopes are needed: read:compliance_org_data and read:compliance_user_data. Check out the documentation to set up the Orca integration with Claude’s Compliance API. Request a demo to see it in your environment.
About the Orca Platform
The Orca Platform identifies, prioritizes, and remediates risks and compliance issues across AWS, Azure, Google Cloud, Kubernetes, Oracle Cloud, Alibaba Cloud, and now Claude Enterprise.
