← Back to News

One Integration, and Claude Stops Being a Blind Spot

2026-07-21 · Spencer Thompson

AI adoption creates a visibility problem before it creates a security problem.

The more useful these tools become, the more consequential the work moving through them becomes. People use Claude to write code, dig through internal documents, and work through business decisions that previously moved between several people and systems.

This is exactly what organizations want, but the problem is that most security teams have very little ability to understand that activity once it moves inside an AI interaction.

Origin now integrates with Claude's Compliance API, bringing activity from Claude Enterprise and Claude Platform into Origin, the endpoint AI observability platform teams already use to make the rest of their AI workforce observable.

AI activity does not look like application activity

The security stack was built around applications, identities, endpoints, networks, and data stores. Those systems can tell you that someone authenticated, a process started, or a file moved, but they were not designed to explain what happened between a person and an AI system.

An employee might paste source code into a prompt, upload an internal document, ask Claude to reason about sensitive research, or connect it to another system. Most of this is legitimate work, but security teams still need to be able to understand:

  • Who is using Claude, and for what?
  • What company information is moving through those workflows?
  • Are credentials or other sensitive materials being exposed?
  • Which activity falls outside policy?
  • How does Claude usage relate to the other AI tools running across the organization?

What Claude's Compliance API provides

Claude's Compliance API gives organizations programmatic access to compliance data from Anthropic-hosted Claude deployments.

For Claude Enterprise, that can include conversation content. For Claude Platform, the API provides activity logs rather than conversation content.

The data exists. The real work is connecting it to the people, devices, applications, and AI workflows around it, then finding the handful of interactions worth reviewing.

That's what Origin was built to do.

Claude activity, in context

Once connected, Claude activity becomes part of the broader picture inside Origin. Teams can review it alongside coding agents, browser agents, local models, MCP servers, and the other AI tools being used across their environment.

The Compliance API tells you what happened inside Claude. Origin ties it to who ran it, on which device, alongside which other agents, into one causal chain you can follow end to end.

Find what matters

A growing AI program can produce an enormous volume of telemetry.

Origin's detection layer, Signals, helps security teams move from collecting activity to identifying what matters. Signals can flag patterns such as credential material appearing in AI activity and anchor the finding to the underlying trace for investigation.

Rather than reading every interaction, security teams can start with the traces most likely to matter.

Signal detail view showing a "Credential material in prompt or tool output" finding, firing-rate chart, and a redacted example trace with AWS, GitHub, and Slack credentials

Ask better questions of the data

Origin pairs dashboards with Ask Origin, a natural-language interface for exploring your organization's data.

Teams can answer common questions about adoption, security, and spend, then narrow the investigation based on what is actually happening in their environment. They can see where Claude is being used, what information is moving through it, how usage compares with other AI tools, and where unusual patterns may require a closer look.

Origin answers the questions teams already have and surfaces the ones they did not know to ask.

Origin's conversational interface answering "where is Claude being used," with the underlying canvas dashboard of usage summary stats, daily prompt volume, and a leaderboard of endpoints by prompt volume

From isolated logs to operational intelligence

The Compliance API creates an important source of visibility into Claude. Origin connects that activity to the people, systems, and AI workflows around it.

Teams can investigate usage, monitor risk, and build governance evidence using the same operating model they apply across the rest of their AI footprint.

This becomes part of how the organization runs its whole AI program, not another isolated source of logs.

Point Origin at a single machine and see what your AI is actually doing.