5
 min read
September 29, 2026
|
Updated: 

Claude Code, Cowork, and Claude for Microsoft 365 now report into Island

Artificial Intelligence/ AI
Compliance
IT modernization
Enterprise security

Anthropic widened the Claude Compliance API to cover the agent work in Claude Cowork and more. Island customers pick it up through the integration dozens of them already run.

In June, Island connected to the Claude Compliance API, Anthropic's application programming interface (API) for audit and eDiscovery, and brought Claude Enterprise chats into the same record as everything else Island governs. Since then, much of the serious AI work inside companies has moved into agents. Developers hand whole tasks to Claude Code. Teams run multi-step jobs in Cowork. Finance builds models with Claude in Excel.

Anthropic has now extended the Compliance API to all of it: Claude Code, Claude Cowork, the Claude for Microsoft 365 add-ins in Excel, Word, PowerPoint, and Outlook, and Claude Science. Island reads every one of those sessions and governs them inside Island's control plane for the agentic enterprise, next to the rest of your AI activity.

Dozens of customers already run it

Dozens of Island customers connected the integration after the June launch. Their security and compliance teams use it to classify what employees send to Claude, answer audit requests, and investigate sessions that look wrong. The new surfaces arrive through the connection those customers already have, with nothing new to deploy.

Agent sessions, recorded in full

A chat is one question and one answer. An agent session is a chain of work, and a single Claude Code task can read a dozen files, call several Model Context Protocol (MCP) servers, load a skill, and write code back to disk before anyone reviews the result.

The Compliance API now returns each Claude Code and Cowork session as one transcript. It holds the prompts, the responses, every tool call to the web and to MCP servers, and the skills and artifacts the agent produced, all tied to a verified user. Island's data protection engine reads the transcript and classifies what it finds - personally identifiable information (PII), protected health information (PHI), payment card industry (PCI) data, source code, secrets, and more.

One chain across the API, the endpoint, and the network

A transcript records what the agent said and asked for. The endpoint and the network see the rest, and Island covers them from its other control points: Island Desktop on the endpoint, Island Network on the connection, and the Island MCP Gateway for the tools agents call. The Compliance API joins them as one more source, and the Enterprise Agentic Control Plane ties them into a single chain under one identity.

Take a developer running Claude Code on a laptop. The agent picks up an unapproved skill. The skill tells it to run a Python script, the script pulls in a malicious package, and the package reads a sensitive file and sends it to an external domain.

Island traces the whole sequence. The Compliance API transcript shows the prompt that started it, the skill, and every tool call in between. The endpoint shows the script, the package, and the file read. The network shows the connection to the outside domain. With the full chain in view, security teams get several chances to stop it. Flag the skill as unapproved and the agent never runs it. Miss that, and Island can still block the file read on the endpoint or the connection on the network.

Image 1: A Claude AI session timeline, with the conversation details, tool usage, and data classification

For prompts that need a verdict before Claude answers, Island also connects to Claude Inference Hooks. The Compliance API supplies the full record, and Inference Hooks supply the inline decision. Both land in the same audit trail.

Past the developer desk

Agent work reaches well beyond engineering. An analyst asks Claude in Excel to reconcile a customer list against a billing export. A sales lead drafts a renewal email in Outlook. A research team runs a trial dataset through Claude Science. Each of those sessions now reaches Island, and the same classification and policies apply to all of them. A clinical researcher cleared for PHI works without interruption. The same records in the hands of someone outside the study raise an insight right away.

What security and compliance teams get

  • One audit report of regulated data reaching Claude, across chats, Claude Code, Cowork, the Microsoft 365 add-ins, and Claude Science, alongside every other AI app in use
  • Insider patterns that only appear across surfaces, such as a user who runs unusual database queries an hour before uploading earnings data to Claude
  • Alerts that route to your security information and event management (SIEM), ticketing, and incident response workflows like every other Island insight, with a notification to the user when a policy fires
  • A risk score on each session, based on the data involved, the user's normal pattern, and what the agent was asked to do

As agents take on more of the work, security and compliance teams need one record of what those agents did. Island keeps it in one place, whichever Claude surface the work came from.

Get started

Customers already running the integration will see the new sessions on the Anthropic integration page, under SaaS API Protection in the Island Management Console.

Image 2: Anthropic integration page under the SaaS API Protection module in the Island Management Console

New to the integration? Talk to your account team to turn it on.

‍

Avishai Winiwarter

Avishai is a Product Group Manager at Island, responsible for the Data protection, Extension platform and AI Security domains. His work focuses on browser infrastructure, modern data protection & secure AI enablement across enterprises worldwide.