Claude Compliance API
The Claude Compliance integration gives your organization visibility into Claude.ai usage through Anthropic's Compliance API. After you register a Compliance API key, Quilr continuously fetches your organization's activity and runs DLP scanning on user inputs, surfacing findings in the console.
Install the Claude Compliance card from Settings › Integrations › Library, and register the Compliance Access Key under Settings › Compliance › Claude in Console V1.
Before you start
You need a Claude Enterprise organization with the Compliance API turned on, and an Anthropic Compliance Access Key:
- The primary owner turns on the Compliance API in claude.ai under Organization settings › API.
- In the Keys section of the same page, the primary owner (or an organization owner, for that organization only) clicks Create key.
- Select the read scopes QuilrAI uses:
read:compliance_activities,read:compliance_user_dataandread:compliance_org_data. QuilrAI does not needdelete:compliance_user_data. - Copy the key (it starts with
sk-ant-api01-). Anthropic shows it only once.
A key created for the parent organization covers every linked organization. Admin API keys (sk-ant-admin01-) and Claude API keys (sk-ant-api03-) do not work. See Anthropic's Set up the Compliance API.
What it provides
How it works
- Register a Compliance Access Key. Your
sk-ant-api01-…key is validated and stored securely. The plaintext key is never exposed after registration. - Data syncs automatically. Organizations, users, chats, projects, and activities are fetched from the Compliance API about every 5 minutes.
- Inputs are scanned for DLP. User message text, file attachments, and project content are scanned and classified by severity.
- Findings are surfaced and can be filtered by time, severity, user, and more.
Register a key
In Console V1, open Settings › Compliance › Claude, click Add Key and enter the Compliance Access Key.
The key is validated immediately with a live call to the Compliance API. If it cannot authenticate, registration is rejected with "Compliance API key validation failed", and nothing is stored. If the Compliance API cannot be reached, the error is "Could not reach compliance API"; try again later. A key that is already registered shows "This API key is already registered." Once registered, the key is encrypted at rest and the plaintext is never returned or logged.
Sync and verification
After registration, Quilr automatically:
- Syncs data about every 5 minutes: the latest organizations, users, chats, projects, and activity events. Organizations covered by the key are discovered automatically.
- Runs DLP scans on all new user inputs since the last pass.
- Tracks sync state per key. Each key keeps its own sync timestamp.
Failed calls to Anthropic are retried with backoff. To verify the first sync, check that the key shows Active and that Claude activity appears in Findings and interactions within a few sync cycles. As long as the key stays valid with Anthropic, data continues to be fetched and scanned.
If data stops arriving, check in claude.ai that the key still exists and that the Compliance API is still on. While the Compliance API is off, Anthropic records no activity, and that activity cannot be recovered later.
Revoke a key
In Settings › Compliance › Claude (Console V1), find the key and click Revoke. A revoked key is removed from all future sync and DLP passes. Data already fetched and scanned stays in the system unless it is explicitly deleted.
Revoking a key in QuilrAI does not invalidate it with Anthropic. To fully disable access, delete the key in claude.ai under Organization settings › API.