All access is read-only. Openlayer reads session transcripts and never
writes to, modifies, or deletes anything in your Claude organization. Never
grant
delete:compliance_user_data.How it works
Once connected, Openlayer pulls transcripts from Anthropic’s Compliance API and turns them into traces.- Seeds known surfaces. Cowork (Desktop), Claude Code, Cowork (Web / Mobile), and claude.ai (Web / Mobile) appear under Surfaces. Every surface starts disabled, so nothing is ingested until you opt in. A surface Anthropic adds later shows up the same way, disabled, until you enable it.
- Maps each surface to one project. Enabling a surface creates an Openlayer project or writes into a project and pipeline you already have. One surface writes to one project.
- Pulls on a schedule. Periodic sync brings in new transcripts. You can also run a sync immediately, or backfill history for a surface you have enabled.
- Writes one row per assistant turn. The conversation or session stays intact, so a multi-turn chat reads as a single thread.
Prerequisites
- A Claude Enterprise organization with Compliance API access. The Setup guide link on the connect form opens that page.
- A Compliance Access Key for that organization, scoped to
read:compliance_user_dataonly. - An Openlayer workspace where you are an admin. Connecting, enabling surfaces, and disconnecting are admin-only actions.
Scope the Compliance Access Key
Request only the read scope the connector uses:
An Admin API key is not a substitute. Admin keys are rejected with 403, because they cannot
read session transcripts.
Setup guide
Step 1: Open the integration
In Openlayer, go to Settings → Integrations, find Claude Compliance, and click Enable.Step 2: Connect
Enter the Compliance Access Key. Click Test connection to validate the key without saving it. Then click Connect. Openlayer checks the key against the Compliance API before storing it, and encrypts it at rest. The stored key is never returned by later requests. If the key is rejected, nothing is saved. On success, Openlayer confirms Claude Compliance connected and notes that product surfaces will appear shortly.Step 3: Choose a sync schedule
Open the General tab. Periodic sync pulls new claude.ai chats and Cowork / Claude Code sessions from the Compliance API. Set Sync frequency to Every 15 minutes, Every 30 minutes, or Every hour. Turn periodic sync off to pause ingestion without disconnecting, or click Sync now to run a tick immediately. The overview on the same tab reports Status, how many surfaces are enabled out of the total, Last sync, and Error when the last tick failed.Surfaces
Connecting registers the known surfaces under Configure surfaces. None of them ingest until you turn one on, so you can bring claude.ai, Cowork, and Claude Code online separately.
Turn on a surface’s Enabled switch and choose where its rows go:
- Create new project (the default) — Openlayer creates a project for that surface
- Map to existing project — pick an existing project and pipeline instead
On an enabled row, the menu (the three dots) has View project and Backfill.
Backfill
Backfill re-reads history the surface can still retrieve. The Backfill Surface dialog offers:- All available history
- Custom start date — re-fetch from a date you pick
What lands in Openlayer
Each assistant turn becomes one inference row. The conversation or session is preserved, and the actor’s email — or their user ID, when Anthropic does not provide an email — becomes the user ID.Thinking blocks, system prompts, and file binaries are not returned by
Anthropic, so they are not available to ingest. Synthetic and system markers
are not treated as user prompts.
- Attachments are names, not files. Openlayer never downloads file or artifact bytes. A
filename is folded into the prompt as
[attached: filename]. - Soft-deleted claude.ai chats are still ingested. Openlayer keeps the transcript and records
deleted_aton the session. - Message order follows the transcript Openlayer received. Timestamps on messages can arrive inverted. Openlayer does not re-sort them.
- Sessions that 404 on retrieve are skipped. That includes Zero Data Retention sessions and sessions that have aged out. The rest of the sync continues.
Evaluating the ingested data
Once traces are flowing, you can evaluate Claude Enterprise usage the same way you evaluate application traffic:- Create tests to score response quality, safety, or tone
- Detect PII or toxicity in prompts and replies
- Use governance frameworks to evidence AI-usage controls with real traffic