Blog
>
Securing Agentic Identities in Claude: The Valence Integration with the Compliance API

Securing Agentic Identities in Claude: The Valence Integration with the Compliance API

Valence Security
July 21, 2026
Time icon
5
min read
Share
Securing Agentic Identities in Claude: The Valence Integration with the Compliance API

Valence now ingests activity and configuration data from Claude's Compliance API, giving security teams visibility into how Claude Enterprise and Claude Platform are used, from the people using Claude to the AI agents acting on their behalf, and correlating that activity and the identities behind it with risk across the rest of the environment.

The visibility gap in enterprise AI

Claude is already part of how teams work. Developers build with it, analysts draft with it, and a fast-growing population of AI agents now acts on their behalf. Those agents are the sharpest edge of the problem. Each one is an agentic identity that can take on non-human identities such as API keys and service accounts, reach connected systems through MCP servers and tools, and keep operating long after the person who created it has moved on. Every new user, agent, key, and connector expands what the organization runs on Claude, often outside the workflows security teams already use to govern everything else.

The result is a familiar problem in an unfamiliar place. Security teams are accountable for how Claude is used, but they lack the same visibility they have for the rest of the stack. Activity happens inside a system they cannot fully see, driven by human, non-human, and agentic identities they cannot easily attribute or trace.

What the integration does

Valence integrates with Claude's Compliance API to ingest activity and configuration data from Claude Enterprise and Claude Platform. That data gives security teams a clear view of how Claude is used across the organization:

  • Identities: the human and non-human identities with access to Claude, from employee accounts to service accounts, API keys, and other non-human principals.
  • AI agents: the agents built on and acting through Claude, a fast-growing and often ungoverned population of agentic identities that use non-human identities such as API keys and service accounts to act.
  • MCP servers and connectors: what identities and agents connect Claude to across the business.
  • Tools: the specific tools agents can invoke, and the actions they can take.
  • Configurations: Claude security configuration and settings, including the controls that govern access, sharing, and how the environment is set up.

Rather than treating Claude as an isolated product to monitor, Valence correlates all of it with the permissions, exposures, and risks it already tracks across the rest of the environment, with the identities behind the activity, human and agentic alike, treated as first-class.

One integration, both Claude surfaces

Claude runs across two distinct surfaces, and most tools see only one. Claude Enterprise is where employees use Claude day to day, delivered through the Claude.ai web application, so you may see the two names used interchangeably. Claude Platform is where engineering teams manage workspaces, API keys, and the agents they build and deploy, and it is often where key exposure and unauthorized access begin.

Valence ingests activity and configuration data from both surfaces through the Compliance API, so coverage does not stop at the boundary where employee use ends and developer activity starts.

Context is the point

Activity logs on their own tell you what happened. They do not tell you whether it mattered. Valence correlates Claude activity with identities, permissions, and risks across the rest of the customer's environment, so a signal that looks routine in isolation can be understood in context.

A single Claude agent with access to a couple of connected systems looks unremarkable. The same agent looks very different once Valence shows that its owner left the company last month, its permissions were never revoked, and it can still reach sensitive data through a connected tool. That is the difference between a log entry and a finding.

From activity to prioritized findings

Valence analyzes Claude activity to detect risky behavior, sensitive data exposure, and misconfigurations, then surfaces prioritized findings with remediation guidance. Much of that risk now concentrates in agentic identities and the non-human identities they use: agent sprawl with no clear owner, over-permissioned agents, stale or unrotated keys, and agents that can still reach sensitive systems after the person who built them has left. Valence surfaces these alongside the human-driven risks so nothing falls between the cracks of "who" and "what."

Because those findings sit alongside the identities, permissions, and exposures Valence already tracks across SaaS and AI, teams can investigate an incident with the full picture rather than reconstructing it across tools. Each finding arrives with the context needed to act: which identity is involved, human or agentic, what it can reach, and what to do about it. Teams spend less time correlating raw logs and more time resolving the exposure behind them.

Adopt Claude with the governance you already expect

Security's job is not to slow Claude adoption. It is to make sure that when Claude is in the environment, and it already is, the same governance, oversight, and audit readiness apply that teams rely on across their broader stack.

By extending its coverage to Claude Enterprise and Claude Platform, Valence lets organizations move quickly on AI while holding it to that standard, adopting Claude confidently without giving up the visibility and control they expect everywhere else.

Get started

The Valence integration with Claude's Compliance API is available now, schedule a demo.

What to Read Next