Above mentioned in Gartner's Secure Behavior Management research
Read more
.png)
Today is an exciting day for the Above team. Anthropic announced a series of new integrations with Claude's Compliance API for Claude Enterprise customers - including ours. Security teams can now bring Claude activity, including prompts, responses and tool calls, into the same behavioral investigations Above already runs across the rest of the business.
We'll admit this one is a little personal. Claude is part of how we work at Above every day, to the point that there's a running joke in the office about giving it an Employee of the Month plaque. So when Ariel Domb, a Full Stack Engineer on our team, set out to build this integration, he was building for teams that look a lot like ours: people who rely on AI to move faster, and security leaders who need to understand what that speed means.
AI assistants are part of everyday work now. Claude can summarize a pipeline, draft a customer reply, or turn a messy export into something readable in moments. That's the point.
It also sharpens a problem security teams already know well. The session where someone does great work and the session where data starts to leave the company can look nearly the same. Insider risk has always been hardest to spot inside legitimate business processes, and AI tools add a staggering new layer of legitimate-looking activity to sort through.
When security leaders ask what their people are actually doing with AI, they usually get prompt counts, keyword matches, or a flag every time a sensitive term shows up. That's a lot of alerts and very little understanding, delivered to teams that are already stretched thin. This is the same SIEM alert overload we set out to eliminate. If teams were already struggling to manage alerts brought on by human activity, it almost seems pointless to try in the agentic era due to the orders of magnitude more work being done with AI.
First, what it doesn't do: it doesn't change how Claude works for employees. The integration is read-only. It observes and investigates, and it gives the security team something they rarely get from AI tools today: context.
Above connects to Claude's Compliance API and pulls two kinds of data from Claude Enterprise: conversations (prompts, responses and tool calls) and activity logs. That data flows into the same investigations our AI agents already run across browser, identity, SaaS, endpoint and email activity.
The result is an investigation that can show what someone asked, what came back, and what they did next. A single prompt rarely tells you much. Connected to everything else a person does, it becomes part of a story.
Separating the malicious from the benign is Above's core competency, and it's easiest to show with an example.
Someone in sales asks Claude for the top ten deals in the CRM. That's a reasonable request from anyone in sales, and nothing worth flagging.
Then they export the results to a CSV and send the file to a personal email address with the subject line "Vacation Photos."
No single step is alarming on its own. Each one could be part of doing the job. Together, they tell a clear story. Above's agents connect the steps into one timeline, reason about whether the pattern is normal for this person and this role, and hand the security team an investigation with a recommended next step instead of three disconnected alerts.
The reverse matters just as much. Most Claude activity is exactly what it looks like: people getting their work done. Good context lets an investigation clear that activity quickly. Better context means fewer false alarms and better catches. We've always said insider risk is an investigation problem, not a policy problem, and AI tools make that even more true.
If your organization runs Claude Enterprise, setup is short: a Claude admin generates a read-only Compliance API key and adds it on the integrations page in the Above console. Anthropic's Compliance API integrations guide covers the Claude side, and our team can walk you through the rest. You'll find details on our integrations page, and our Trust Center covers how we handle your data.
The real value shows up in your own environment. Request a demo to see it on your own workflows.
The insider hasn't changed. The tool in their hand has.
.png)
%201%201.png)
May we use analytics cookies to understand visits, clicks and demo requests? Your choice won’t affect the site. No session recordings. Privacy policy