> ## Documentation Index
> Fetch the complete documentation index at: https://openlayer.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Claude Compliance

> Ingest claude.ai chats and Cowork / Claude Code session transcripts into Openlayer from Anthropic's Compliance API

Openlayer connects to Anthropic's [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-sessions)
to pull Claude Enterprise transcripts into your workspace as inference data — with no SDK on
employee machines.

This is the right integration when the AI you need to evaluate is Claude's own product rather than
an application you built. People chat on claude.ai and work in Cowork and Claude Code; each
assistant turn lands in Openlayer, where you can run tests and review real usage.

To instrument your own Anthropic API calls, use the [Anthropic](/docs/integrations/anthropic)
integration. To trace agents you build with the Claude Agent SDK, use
[Claude Agent SDK](/docs/integrations/claude-agent-sdk). Claude Compliance does not replace either one.

<Info>
  All access is **read-only**. Openlayer reads session transcripts and never
  writes to, modifies, or deletes anything in your Claude organization. Never
  grant `delete:compliance_user_data`.
</Info>

## How it works

Once connected, Openlayer pulls transcripts from Anthropic's Compliance API and turns them into traces.

1. **Seeds known surfaces.** Cowork (Desktop), Claude Code, Cowork (Web / Mobile), and claude.ai
   (Web / Mobile) appear under **Surfaces**. Every surface starts **disabled**, so nothing is
   ingested until you opt in. A surface Anthropic adds later shows up the same way, disabled,
   until you enable it.
2. **Maps each surface to one project.** Enabling a surface creates an Openlayer project or writes
   into a project and pipeline you already have. One surface writes to one project.
3. **Pulls on a schedule.** Periodic sync brings in new transcripts. You can also run a sync
   immediately, or backfill history for a surface you have enabled.
4. **Writes one row per assistant turn.** The conversation or session stays intact, so a
   multi-turn chat reads as a single thread.

***

## Prerequisites

* A **Claude Enterprise** organization with
  [Compliance API access](https://platform.claude.com/docs/en/manage-claude/compliance-api-access).
  The **Setup guide** link on the connect form opens that page.
* A **Compliance Access Key** for that organization, scoped to `read:compliance_user_data` only.
* An Openlayer workspace where you are an **admin**. Connecting, enabling surfaces, and
  disconnecting are admin-only actions.

### Scope the Compliance Access Key

Request only the read scope the connector uses:

| Scope | What it reads |
| - | - |
| `read:compliance_user_data` | claude.ai chats and Cowork / Claude Code session transcripts |

<Warning>
  Never grant `delete:compliance_user_data`. Openlayer never requests delete,
  and a key that can delete compliance data can destroy your audit trail.
</Warning>

An Admin API key is not a substitute. Admin keys are rejected with **403**, because they cannot
read session transcripts.

***

## Setup guide

### Step 1: Open the integration

In Openlayer, go to **Settings → Integrations**, find **Claude Compliance**, and click **Enable**.

### Step 2: Connect

Enter the **Compliance Access Key**.

Click **Test connection** to validate the key without saving it. Then click **Connect**.

Openlayer checks the key against the Compliance API before storing it, and encrypts it at rest. The
stored key is never returned by later requests. If the key is rejected, nothing is saved.

On success, Openlayer confirms **Claude Compliance connected** and notes that product surfaces will
appear shortly.

### Step 3: Choose a sync schedule

Open the **General** tab. **Periodic sync** pulls new claude.ai chats and Cowork / Claude Code
sessions from the Compliance API. Set **Sync frequency** to **Every 15 minutes**, **Every 30
minutes**, or **Every hour**. Turn periodic sync off to pause ingestion without disconnecting, or
click **Sync now** to run a tick immediately.

The overview on the same tab reports **Status**, how many surfaces are enabled out of the total,
**Last sync**, and **Error** when the last tick failed.

***

## Surfaces

Connecting registers the known surfaces under **Configure surfaces**. None of them ingest until you
turn one on, so you can bring claude.ai, Cowork, and Claude Code online separately.

| Surface | What it ingests |
| - | - |
| Cowork (Desktop) | Cowork sessions from the desktop app |
| Claude Code | Claude Code sessions |
| Cowork (Web / Mobile) | Cowork sessions from the web and mobile |
| claude.ai (Web / Mobile) | claude.ai chats from the web and mobile |

Turn on a surface's **Enabled** switch and choose where its rows go:

* **Create new project** (the default) — Openlayer creates a project for that surface
* **Map to existing project** — pick an existing project and pipeline instead

The table is the operational view of the connector:

| Column | Meaning |
| - | - |
| **Surface** | Which Claude product this row pulls |
| **Project** | The Openlayer project this surface writes to, chosen when you enable it |
| **Status** | `idle`, `error`, or `disabled` |
| **Last sync** | When the surface last finished a sync |
| **Synced** | How many sessions have been ingested |
| **Enabled** | Whether this surface is opted in |

On an enabled row, the menu (the three dots) has **View project** and **Backfill**.

### Backfill

**Backfill** re-reads history the surface can still retrieve. The **Backfill Surface** dialog
offers:

* **All available history**
* **Custom start date** — re-fetch from a date you pick

Then click **Start backfill**.

The default history window is about **90 days**. Transcripts older than that window are not pulled.

Backfills are safe to repeat. Duplicate sessions are filtered on the way in, so re-reading
transcripts you have already ingested does not create duplicate rows.

***

## What lands in Openlayer

Each assistant turn becomes one inference row. The conversation or session is preserved, and the
actor's email — or their user ID, when Anthropic does not provide an email — becomes the user ID.

<Note>
  Thinking blocks, system prompts, and file binaries are not returned by
  Anthropic, so they are not available to ingest. Synthetic and system markers
  are not treated as user prompts.
</Note>

A few other behaviors are not obvious from the trace:

* **Attachments are names, not files.** Openlayer never downloads file or artifact bytes. A
  filename is folded into the prompt as `[attached: filename]`.
* **Soft-deleted claude.ai chats are still ingested.** Openlayer keeps the transcript and records
  `deleted_at` on the session.
* **Message order follows the transcript Openlayer received.** Timestamps on messages can arrive
  inverted. Openlayer does not re-sort them.
* **Sessions that 404 on retrieve are skipped.** That includes Zero Data Retention sessions and
  sessions that have aged out. The rest of the sync continues.

***

## Evaluating the ingested data

Once traces are flowing, you can evaluate Claude Enterprise usage the same way you evaluate
application traffic:

* [Create tests](/docs/tests/overview) to score response quality, safety, or tone
* Detect [PII](/docs/tests/catalog/contains-p-i-i) or [toxicity](/docs/tests/catalog/toxicity) in prompts and
  replies
* Use [governance frameworks](/docs/governance/overview) to evidence AI-usage controls with real traffic

***

## Disconnecting

On the **General** tab, under **Remove Claude Compliance from workspace**, click **Disconnect
Claude Compliance** and confirm.

Disconnecting stops syncing new transcripts. Projects, pipelines, and traces already ingested are
kept. Revoke the Compliance Access Key in Anthropic afterwards so the organization no longer grants
that access.

***

## Troubleshooting

| Symptom | Likely cause | Fix |
| - | - | - |
| Connect fails with **403** | The key is an Admin API key, or it is missing `read:compliance_user_data` | Create a Compliance Access Key with only `read:compliance_user_data`. Admin API keys cannot read session transcripts |
| **Test connection** fails | The key is wrong, revoked, or the Compliance API is unreachable | Reissue the key from the Claude Enterprise organization. A failed test does not save the key |
| Surfaces are missing right after connect | Known surfaces are still being registered | Expected for a moment. The success confirmation says product surfaces will appear shortly |
| A surface stays at zero sessions after you enable it | There is no activity in the history window yet | Use that surface, then wait for the next tick or click **Sync now** |
| **Status** is `error` | The last sync for that surface failed | Read **Error** on the **General** tab, fix the cause, and click **Sync now** |
| Cowork (Desktop) or Claude Code lists nothing, but the key tests successfully | On a HIPAA-ready organization, listing those sessions can return 404 while the key is still valid | Expected when Cowork (Web / Mobile) or claude.ai chats succeed. The key is valid; desktop and Claude Code sessions are not available to list |
| Individual sessions never appear | A Zero Data Retention session, or a session that has aged out, returned 404 when Openlayer retrieved it | Expected. That session is skipped. Other sessions in the same sync are still ingested |
| Attachment contents are missing | Anthropic does not return file bytes on this API | Expected. The prompt includes `[attached: filename]`, not the file |
| Thinking or the system prompt is missing | Anthropic does not return them | Expected. They are not available to ingest |
| Turns are out of chronological order | Message timestamps in the transcript can invert | Expected. Openlayer keeps the order it received and does not re-sort |
| Backfill does not reach past about 90 days | The default history window | Transcripts older than that window are not available through the connector |
| Nothing new arrives | **Periodic sync** is off | Turn it back on, or click **Sync now** |
