Prepared by The AI Pipe for T3, as an illustrative example. Not a T3 document.

Claude Enterprise: Configuration Evidence Workpaper

Illustrative controls, verification steps and evidence requirements for an assurance engagement.

Workpaper
CE-1, example
Prepared by
The AI Pipe
Prepared for
T3, for review
Register
27 controls, 6 options
Export
Register as CSV

Synthetic example · No client environment assessed · Documentation checked 24 September 2026

The register

A core of controls at the confidentiality boundaries, not a catalogue. Open a row for the role, the exact path, the dated documentation, the test and who decides.

Download the register (CSV)

Retention

What is kept, for how long, and which setting governs each kind of content.

Scope
claude.ai Enterprise: standalone chats, projects, and chats inside projects
Target value
A finite period for chats and a finite period for projects, approved togetherIllustrative policy choice, requires client approval
Verification
Applied configurationRecord both periods, then classify conversations by location: standalone or inside a project
Observed state
Example; no client configuration observed
Evidence ref.
RET-01.1, RET-01.2, RET-01.3; not collected

Example configuration

Chats: 90 days. Projects: no period set, so projects are kept indefinitely.

Role required
Primary Owner or Owner
Exact path
Organization settings > Data and Privacy
Test preconditions
Enterprise plan. Any shortening approved in writing before it is saved: data outside the new period is scheduled for permanent deletion as soon as the change is saved.
Expected
Both periods finite and equal to the approved values. Every conversation falls under one of them.
Obtained
Example configuration below. No client configuration observed.
Decision owner
Client: records management and data protection owners
Exceptions to note
Custom periods do not apply to Claude Design, Claude Tag, Claude Managed Agents or other features built on Claude Code on the web. Moving a chat into a project places it under the project's period.
Evidence to file
  • RET-01.1Effective settings export showing data_retention_periods (Compliance API)
  • RET-01.2Count of conversations held inside projects, with the period that governs each project
  • RET-01.3Written client approval of both periods
Evidence level this verification reaches
Applied configurationTarget value: illustrative policy choice, requires client approval.

Documentation, quoted

Exception E-1, raised on RET-01

The 90-day chat period does not establish how long conversations are kept. Conversations placed inside a project follow the project's period, which here has no limit.

day 0day 90
Standalone chat
deleted
Chat in a project
kept: no project period set
The example configuration. A chat moved into a project leaves the chat period and takes the project’s.

Verification required

Read both periods from the effective settings, then classify conversations by location. For each conversation inside a project, the project's period applies.

Observed state

Example; no client configuration observed

Scope
Artifacts still private to their author, and artifacts that have been shared
Target value
A finite period for each of the two artifact classesIllustrative policy choice, requires client approval
Verification
Applied configurationRecord both artifact periods in the console, alongside RET-01
Observed state
Not observed
Evidence ref.
RET-02.1; not collected
Scope
Models enabled for the organization
Target value
Covered Models enabled only with an approved position on their 30-day minimum retentionIllustrative policy choice, requires client approval
Verification
Verified behaviourCompare enabled models with the approved list; confirm a request to a disabled model is refused
Observed state
Not observed
Evidence ref.
RET-03.1, RET-03.2; not collected

Access and removal of access

Who can sign in, and how access ends when someone leaves.

Scope
Member sign-in to claude.ai. Console sign-in has its own switch, Require SSO for Console
Target value
SSO set up and Require SSO for Claude onIllustrative policy choice, requires client approval
Verification
Verified behaviourEffective settings show enforcement, not only setup; a test account's sign-in without SSO is refused
Observed state
Not observed
Evidence ref.
ACC-01.1, ACC-01.2, ACC-01.3; not collected
Scope
Members provisioned from the identity provider
Target value
SCIM directory sync with group mappingsIllustrative policy choice, requires client approval
Verification
Verified behaviourRemove a test user in the identity provider; confirm the Claude membership ends
Observed state
Not observed
Evidence ref.
ACC-02.1, ACC-02.2; not collected
Scope
All member sessions
Target value
Enabled at an approved duration: 1, 7, 14 or 28 daysIllustrative policy choice, requires client approval
Verification
Applied configurationEffective settings: account_session_duration_seconds, where null means no limit
Observed state
Not observed
Evidence ref.
ACC-03.1; not collected
Scope
Built-in and custom roles, assigned directly or through groups
Target value
Each member's effective permissions match the approved role design; few OwnersIllustrative policy choice, requires client approval
Verification
Applied configurationView effective role for a member who holds several roles; a permission removed in one role may still come from another
Observed state
Not observed
Evidence ref.
ACC-04.1; not collected

Organization perimeter

Separate mechanisms with separate scopes. None of them, alone, establishes that personal accounts are blocked everywhere.

Scope
The company's email domains
Target value
Every company domain verified; Restrict organization creation onIllustrative policy choice, requires client approval
Verification
Applied configurationConsole shows each domain as verified and the toggle on
Observed state
Not observed
Evidence ref.
PER-01.1; not collected
Scope
Free, Pro and Max accounts registered with a verified domain
Target value
An explicit decision; if enabled, only after SSO is required and provisioning is in placeIllustrative policy choice, requires client approval
Verification
Applied configurationPreview and export of the accounts concerned, reviewed before the switch is turned on
Observed state
Not observed
Evidence ref.
PER-02.1; not collected
Scope
Supported connectors, when connected with an email address on a verified domain
Target value
OnIllustrative policy choice, requires client approval
Verification
Verified behaviourFrom a personal Claude account, attempt a supported connector with a work identity; expect refusal
Observed state
Not observed
Evidence ref.
PER-03.1; not collected
Scope
Requests to Claude that pass through the corporate proxy with TLS inspection
Target value
The proxy injects the organization's ID only, overwriting any existing headerIllustrative policy choice, requires client approval
Verification
Verified behaviourFrom the restricted network, sign in to another organization; expect a 403 tenant_restriction_violation
Observed state
Not observed
Evidence ref.
PER-04.1; not collected

Sharing: projects, chats and artifacts

Each sharing path has its own switch, its own default and its own treatment of existing shares.

Scope
Projects. Public here means visible to everyone in the organization, not on the internet
Target value
Share projects limited to approved roles; Public projects offIllustrative policy choice, requires client approval
Verification
Verified behaviourAfter turning sharing off, test with a user who already had access: existing shares remain
Observed state
Not observed
Evidence ref.
SHR-01.1, SHR-01.2; not collected
Scope
Chats. On Team and Enterprise, shared chats are visible only to signed-in members of the organization
Target value
Off, or on with a periodic review of shared chatsIllustrative policy choice, requires client approval
Verification
Applied configurationEffective settings: claude_ai_chat_sharing_enabled; sharing activity in the audit log
Observed state
Not observed
Evidence ref.
SHR-02.1, SHR-02.2; not collected
Scope
Artifacts published by members. Three separate routes out: public links, invitations outside the organization, individual exceptions
Target value
External sharing off; Email invitations outside your organization off; individual exceptions listed and approvedIllustrative policy choice, requires client approval
Verification
Verified behaviourList individual exceptions; confirm a public link to a non-excepted artifact fails
Observed state
Not observed
Evidence ref.
SHR-03.1, SHR-03.2, SHR-03.3; not collected

Memory, feedback and training

No training on customer content is a contractual term. It is not a retention setting.

Scope
Chat memory. The new memory experience and the legacy experience treat deleted conversations differently
Target value
Off unless approved. If on, the regime in use identified and recordedIllustrative policy choice, requires client approval
Verification
Verified behaviourIdentify the regime; delete a test conversation and check whether memory derived from it remains
Observed state
Not observed
Evidence ref.
MEM-01.1, MEM-01.2, MEM-01.3; not collected
Scope
Member ratings of responses
Target value
OffIllustrative policy choice, requires client approval
Verification
Applied configurationConsole toggle; effective settings field claude_ai_feedback_collection_enabled, matched to the toggle by name
Observed state
Not observed
Evidence ref.
MEM-02.1; not collected
Scope
Commercial products
Target value
No opt-in route in use: ratings, Claude Code /feedback, the Development Partner ProgramIllustrative policy choice, requires client approval
Verification
DocumentationContract terms read; MEM-02 off; /feedback disabled where Claude Code is in scope
Observed state
Not observed
Evidence ref.
MEM-03.1; not collected

Connectors and effective rights

Adding a connector, authenticating to it and the member's rights in the source system are three separate controls.

Scope
Connectors added for the organization; each member then authenticates
Target value
Only approved connectors addedIllustrative policy choice, requires client approval
Verification
Applied configurationConnector list compared with the approved list; network exposure of each custom server reviewed
Observed state
Not observed
Evidence ref.
CON-01.1; not collected
Scope
Each tool of each connector; roles on Enterprise
Target value
Write tools set to Needs approval or BlockedIllustrative policy choice, requires client approval
Verification
Verified behaviourSign in as a test member holding all their roles; call a blocked tool
Observed state
Not observed
Evidence ref.
CON-02.1, CON-02.2; not collected
Scope
Sensitive connectors authorized through the identity provider
Target value
On for sensitive connectorsIllustrative policy choice, requires client approval
Verification
Verified behaviourDeprovision a test user in the identity provider; confirm connector access ends
Observed state
Not observed
Evidence ref.
CON-03.1; not collected

Network egress

Each capability that reaches the network is governed separately.

Scope
Claude's code execution environment in claude.ai. Not the Claude Code network setting
Target value
Off, or limited to package managers and named domains; never All domainsIllustrative policy choice, requires client approval
Verification
Verified behaviourEffective settings: code_execution_network_egress_enabled; a request to an unlisted domain fails
Observed state
Not observed
Evidence ref.
NET-01.1, NET-01.2; not collected
Scope
All members
Target value
Off unless approvedIllustrative policy choice, requires client approval
Verification
Applied configurationEffective settings: web_search_enabled
Observed state
Not observed
Evidence ref.
NET-02.1; not collected
Scope
Maps, weather and image results served by third parties
Target value
OffIllustrative policy choice, requires client approval
Verification
Applied configurationEffective settings field third_party_interactive_content_enabled, matched by name
Observed state
Not observed
Evidence ref.
NET-03.1; not collected

Audit logs and Compliance API

The evidence instruments themselves, with their own coverage limits.

Scope
Organization activity over the past 180 days; identifiers only
Target value
Exported at least every 180 days and kept by the clientIllustrative policy choice, requires client approval
Verification
Applied configurationExport received; period covered matches the schedule
Observed state
Not observed
Evidence ref.
AUD-01.1; not collected
Scope
Activity and content of the organization. Not retroactive. Cloud sessions in Claude Code are not covered
Target value
Enabled early, with the local session transcript capture it starts approved in advanceIllustrative policy choice, requires client approval
Verification
Applied configurationActivity Feed shows the enabling event; records start from that date
Observed state
Not observed
Evidence ref.
AUD-02.1; not collected
Scope
GET /v1/compliance/organizations/{org_uuid}/settings, scope read:compliance_org_data
Target value
Queried on a schedule and compared with the approved baselineIllustrative policy choice, requires client approval
Verification
Applied configurationDated JSON responses archived; differences with the baseline listed
Observed state
Not observed
Evidence ref.
AUD-03.1; not collected
Scope
Keys that read or delete organization content
Target value
Least privilege: separate read and delete keys, held in a secrets vault, reviewedIllustrative policy choice, requires client approval
Verification
Applied configurationEffective settings: api_keys, with name, scopes, active state and creator
Observed state
Not observed
Evidence ref.
AUD-04.1; not collected

Key to the evidence levels. They are never merged: each row names the level its verification reaches. Nothing on this page goes beyond documentation, except the Claude Code runs at the end.

  1. DocumentationDocumentationAnthropic documents the setting, where it lives and what it covers.It says nothing about any organization's configuration.
  2. Declared configurationDeclared configurationA file, export or screenshot supplied to the assessor contains the value.It does not show that the value is loaded where it matters.
  3. Applied configurationApplied configurationAn observation of the environment shows the value in force, for example the Compliance API effective settings.It does not show that the setting stops what it is meant to stop.
  4. Verified behaviourVerified behaviourA test run on an identified scope produced the expected result.It covers that scope and that date only.

Options to qualify separately

Documented with conditions of eligibility, activation or scope. They are questions for the client and Anthropic, not switches to include in a baseline.

OPT-01 OpenIP allowlistingEnterprise only. Setup route differs between two Help Center pages: through the Anthropic contact or Support, or in the console for roles with the Identity & Access permission.Requests from any other address are blocked, so every legitimate exit (offices, VPN) must be listed. The effective settings flag is true only while at least one range is active.

How to qualify it

Confirm the setup route with Anthropic; record ip_allowlist_enabled and the ranges; test from an address outside the list.

OPT-02 OpenCustomer-managed encryption keysActivated through the Anthropic account team, then configured in Organization settings > Data and privacy.Permanent once enabled. Organization data exports and audit log exports are disabled. Anthropic states that its list of affected features is not exhaustive.

How to qualify it

Decide with the key custodian; record cmek_enabled; agree the audit route before enabling, since the log export button no longer works.

OPT-03 OpenInference hooks (beta)Claude Enterprise, in beta. Each request can be sent to the client's own security server before inference.Allow or deny only, no redaction. Requests outside the sampled percentage are not inspected.

How to qualify it

Record the failure handling mode and the sampling percentage; test a request the client's server denies.

  • Inference hooks are in beta and available to Claude Enterprise organizations.Inference hooks, read 24 September 2026
  • Verdicts are allow or deny. Rewriting or redacting a prompt is not supported.Inference hooks, read 24 September 2026
  • Voice mode is not covered.Inference hooks, read 24 September 2026
OPT-04 OpenUS-only inferenceUsage-based Enterprise plans.Sets where inference runs, not where data is stored.

How to qualify it

Establish the client's territorial requirement first; this is the only geographic control documented for claude.ai.

OPT-05 OpenZero data retention for Claude CodeNot part of the standard Enterprise plan and not an admin setting; arranged with Anthropic for eligible accounts.Covers Claude Code only. Chat in the Enterprise web interface and Cowork are not covered.

How to qualify it

Ask Anthropic about eligibility; record the effective settings field once enabled.

OPT-06 OpenAccess TransparencyEligible customers, on request; not self-serve.claude.ai Enterprise seats, Cowork and Claude in Chrome are not covered.

How to qualify it

Ask Anthropic about eligibility and the scope that would apply.

  • Access Transparency is available to eligible customers on request and is not self-serve.Access Transparency, read 24 September 2026
  • claude.ai Enterprise seats, Claude for Work, Cowork, and Claude in Chrome are not covered.Access Transparency, read 24 September 2026

Often assumed, not described in the documentation checked

Searched on 24 September 2026 across the Help Center, the Privacy Center, the Claude Code and Claude Platform documentation, and the Compliance API reference. Absence here means not documented, not unavailable.

  • UK or EU data residency for claude.ai. The only geographic control documented is US-only inference, which does not govern storage.
  • An idle timeout. Only a maximum session length exists (ACC-03).
  • An organization switch that blocks file uploads in chat.
  • A restriction of chat access by device type or managed device.
  • A native legal hold.

When Claude Code is in scope

Claude Code is governed by its own settings files, not by the claude.ai console alone. Two instruments: a static check of a settings file, and runs of Claude Code itself.

Claude Code static policy check

A passing static check does not establish that the policy is deployed or that the environment is secure.

It reads one file against the rules below and says what it observed and what remains to test. Another managed source can add to or override what a single file says.

Synthetic example files

Pasted configuration is not transmitted. The check runs in this page’s memory; nothing is sent or stored.

What the check found

1 exception. 2 items passed the static check and still need runtime verification. 5 items not set.

  • ExceptiondisableBypassPermissionsMode

    Set at the top level to true. The documented type is the string "disable".

    The settings reference defines this lock under permissions only. On our test machine, the same key at the top level left bypass mode available (trace T2).

    Remains to test: Move it to permissions.disableBypassPermissionsMode with the value "disable", then confirm that --dangerously-skip-permissions no longer starts a bypass session.

    Every permissions.* key below nests under this object. Claude Code docs: Settings reference, read 24 September 2026

  • Static check passedpermissions.deny

    1 Read deny rule, with a strict sandbox.

    Read deny rules are merged into the sandbox configuration, which applies at the operating system level to sandboxed commands.

    Remains to test: Repeat the grep -r test on each platform in scope. The sandbox does not run on native Windows.

    Paths and domains from both sandbox settings and permission rules are merged into the final sandbox configuration. Claude Code docs: Sandboxing, read 24 September 2026

  • Static check passedsandbox

    Enabled, fails closed, no unsandboxed retries.

    The documented strict configuration.

    Remains to test: On each platform in scope, confirm the sandbox starts and a read of a denied path fails. Check credential files such as ~/.aws and ~/.ssh: the default read policy still allows them unless configured.

    Make Claude Code exit with an error at startup when sandbox.enabled is true but the sandbox can't start Claude Code docs: Settings reference, read 24 September 2026

Not set in this file, or outside this check

  • permissions.disableAutoModeNot setAuto mode stays available: a classifier approves actions in place of the user. Source
  • allowManagedPermissionRulesOnlyNot setPermission rules from user, project and local settings, and from --settings, also apply. Source
  • allowedMcpServersNot setAnyone running Claude Code can connect any MCP server. Source
  • forceLoginOrgUUIDNot setThis file does not restrict which account or organization Claude Code signs in with. Source
  • allowManagedHooksOnlyNot setHooks from every settings scope and plugin run. Source

Runs of Claude Code on our test machine

Verified on a test machine, not in any client environment

Each operation ran in its own non-interactive Claude Code session, on synthetic files created for the test. The permission policy was passed with --settings; user settings were excluded with --setting-sources project.

Date
24 September 2026, 12:53 to 13:00 UTC
Claude Code
2.1.281 (Claude Code)
Machine
macOS 27.0 (arm64)
Model
claude-sonnet-5
Not exercised
Delivery through managed settings (file, MDM profile, server-managed settings); other platforms and versions

Traces A and B: a deny rule, with and without the sandbox

Policy A, rules only
{
  "permissions": {
    "allow": [
      "Read(./engagement/**)",
      "Bash(grep -r *)",
      "Bash(cat *)"
    ],
    "deny": [
      "Read(./client-secrets/**)"
    ]
  }
}
Policy B, rules and sandbox
{
  "permissions": {
    "allow": [
      "Read(./engagement/**)",
      "Bash(grep -r *)",
      "Bash(cat *)"
    ],
    "deny": [
      "Read(./client-secrets/**)"
    ]
  },
  "sandbox": {
    "enabled": true,
    "failIfUnavailable": true,
    "allowUnsandboxedCommands": false
  }
}

Synthetic files: ./engagement/scope-note.md (allowed) and ./client-secrets/export-token.txt (denied), each holding one line marked SYNTHETIC.

  1. A112:53 UTC
    Rules onlyRead: ./engagement/scope-note.mdThe allowed read succeeds.
    Tool result, verbatim
    1	SYNTHETIC engagement note: scope review for a fictitious firm. No real data.
    2	
    Allowed operation preserved.
  2. A212:54 UTC
    Rules onlyRead: ./client-secrets/export-token.txtThe Read deny rule refuses the read.
    Tool result, verbatim
    <tool_use_error>File is in a directory that is denied by your permission settings.</tool_use_error>
    Blocked.
  3. A312:54 UTC
    Rules onlyBash: cat client-secrets/export-token.txtRefused, although Bash(cat *) is allowed: deny rules reach file commands Claude Code recognises, such as cat.
    Tool result, verbatim
    Permission to use Bash with command cat client-secrets/export-token.txt has been denied.
    Blocked.
  4. A412:55 UTC
    Rules onlyBash: grep -r SYNTHETIC .Not covered: the rule does not apply to a command that reads files without naming them.
    Tool result, verbatim
    client-secrets/export-token.txt:SYNTHETIC-TEST-VALUE-7Q2M (fictitious value created for a permission test, not a credential)
    engagement/scope-note.md:SYNTHETIC engagement note: scope review for a fictitious firm. No real data.
    Exception: the denied file's content was returned.
  5. B112:55 UTC
    Rules and sandboxRead: ./engagement/scope-note.mdThe allowed read still succeeds.
    Tool result, verbatim
    1	SYNTHETIC engagement note: scope review for a fictitious firm. No real data.
    2	
    Allowed operation preserved.
  6. B212:55 UTC
    Rules and sandboxBash: grep -r SYNTHETIC .The sandbox applies the Read deny rule at operating system level.
    Tool result, verbatim
    Exit code 2
    ugrep: warning: cannot open directory client-secrets: Operation not permitted
    engagement/scope-note.md:SYNTHETIC engagement note: scope review for a fictitious firm. No real data.
    Blocked at OS level; the allowed file is still found.

A4 is the documented limit of permission rules, reproduced: They don’t apply to a command that reads files without naming them, such as grep -r pattern . run from the directory that holds the file (Claude Code docs: Permissions, read 24 September 2026). B2 shows the sandbox closing it on this machine.

Trace T: the bypass lock, written three ways

Each run passed --dangerously-skip-permissions. The column on the right is the permission mode the session actually started in, read from the session’s own start event.

  1. TX13:00 UTC
    {}
    Session mode bypassPermissions
    Baseline: no lock, the flag starts a bypass session.
  2. T013:00 UTC
    {"permissions":{"disableBypassPermissionsMode":"disable"}}
    Session mode default
    Documented form: the lock held.
  3. T113:00 UTC
    {"permissions":{"disableBypassPermissionsMode":true}}
    Session mode bypassPermissions
    Wrong type: the lock did not hold.
  4. T213:00 UTC
    {"disableBypassPermissionsMode":"disable"}
    Session mode bypassPermissions
    Wrong location: the lock did not hold.