TL;DR: SailPoint’s integration with Anthropic’s Claude Compliance API extends identity governance to Claude Enterprise by centralising visibility over users, groups, roles, and AI agents, while highlighting the rise of shadow AI and non-human identity sprawl in enterprise environments. Access review models built for stable human accounts do not fully fit AI platform usage, because the control problem now includes dynamic agent activity and contextual authorisation across the session.
NHIMG editorial — what this means for NHI practitioners
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
Questions worth separating out
Q: How should security teams govern AI platform access in the enterprise?
A: Start by treating the AI platform as a governed identity surface, not a separate innovation layer.
Q: Why does shadow AI create an identity governance problem?
A: Shadow AI creates an identity governance problem because unapproved tools and agents can access enterprise data without being inventoried, owned, or recertified.
Q: What breaks when AI platform access is managed like ordinary user access?
A: What breaks is the assumption that access is stable, human-owned, and easy to review in a later cycle.
Practitioner guidance
- Classify AI platform identities in the NHI register Add Claude Enterprise users, groups, roles, and any agents to the non-human identity inventory so ownership and review can be assigned consistently.
- Map access paths before broad adoption Document which teams can create, approve, and inherit access to AI platforms, including group membership and role-based escalation paths.
- Apply zero standing privilege to AI usage Remove broad persistent access where possible and replace it with task-scoped permissions that expire when the business purpose ends.
What's in the full announcement
SailPoint's full article covers the operational detail this post intentionally leaves for the source:
- How the Claude Compliance API connector maps users, groups, group members, and roles inside SailPoint Identity Security Cloud
- The vendor's description of how Claude AI agents are discovered and governed through a single agent registry
- Operational context for applying adaptive identity and contextual access decisions to AI platform usage
- The specific availability details for customers already running SailPoint Identity Security Cloud
👉 Read SailPoint's analysis of Claude Compliance API governance for AI platforms →
Claude Compliance API integration: what it means for IAM teams?
Explore further
AI platform access has become part of the identity perimeter. This integration shows that enterprise identity security can no longer stop at user authentication or workforce IAM. When Claude Enterprise is brought into the governance model, the security question shifts to who, what, and which agent can use the platform, and under what authority. That is a programme-level change, not a feature update. Practitioners should treat AI platform access as an identity domain with its own policy, review, and attestation requirements.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to the State of Non-Human Identity Security.
- The same research found that only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, which helps explain why AI platform governance is moving from optional to operational.
A question worth separating out:
Q: When should organisations prioritise AI identity governance over new AI deployments?
A: They should prioritise it before broad deployment, because the first wave of AI usage often creates the largest blind spots. If the identity model, approval path, and review cadence are not defined early, the organisation inherits shadow usage and excess access that are harder to unwind later. Governance should precede scale.
👉 Read our full editorial: SailPoint and Claude compliance API: AI platform identity governance