Bluebear for Claude Enterprise

Roll out Claude with visibility and runtime control. Detect sensitive data in Claude Enterprise conversations, track configuration drift, and govern Claude Code actions on developer machines. Review the findings together in Bluebear, next to the ones from Cursor and your other agents.

Available now for Claude Enterprise organizations. Request access · How to enable it

Bring Claude activity into your security workflow

Teams draft contracts, analyze customer files, and ship code with Claude. The conversation layer had no security tooling of its own until the Compliance API, the organization settings drift after they are set, and Claude Code runs on developer machines with the developer’s access to repositories, secrets, and cloud.

Bluebear connects in two places. Through the Compliance API it reads your organization’s conversations, files, session transcripts, and security settings, and turns what it finds into incidents. Through the endpoint handler on the developer machine it sees what Claude Code actually runs and applies your policies before it does, with an approval in Slack or the terminal when a human should decide. A transcript is retrospective evidence. The handler is enforcement.

What a finding looks like

From Bluebear’s technical risk brief, Ten ways AI agents cross runtime boundaries.

A developer asks the agent to debug a PostgreSQL migration. The agent retrieves the database credentials from AWS Vault, places the password directly in a Bash command, and then places it in model-visible context, so a secret that never needed to leave the vault reaches shell history, child processes, and the model provider’s retained context.

The session transcript shows the password in the model’s context. The endpoint handler sees it enter the command line, restricts the secret to the process and task that need it, preserves the evidence, and routes the action to human review. Traditional controls record an approved process reading a credential and normal outbound traffic, and miss that the agent exposed a private secret beyond the user’s mandate.

What you get

  • Visibility. Organization-wide Claude usage by user, workspace, and session, in the same console as your other agents.
  • Data protection. Secrets, PII, source code, and the data types your policies name, detected in chats, files, projects, and session transcripts.
  • Posture. Organization security settings checked against a secure baseline, with an incident for every drift and automatic resolution when it is fixed.
  • Runtime control. Policy enforcement, approvals, and sandboxing for Claude Code on the developer machine, where the Compliance API does not reach.

Set up the integration

You need a Claude Enterprise organization with the Compliance API enabled, an owner role in claude.ai, and an administrator role in Bluebear.

  1. In claude.ai, create a Compliance Access Key with read-only scopes.
  2. In the Bluebear console, open Settings → Integrations → Claude, paste the key, and click Test Connection.

Findings start within the hour. The integration is read-only, and Bluebear keeps findings, not transcripts. The endpoint handler is deployed separately from the Bluebear console.

When you have guardrails on a bridge, you can run.

The Compliance API gives you governed access to what happens in Claude Enterprise. Bluebear turns it into incidents you can act on and adds runtime control on the developer machine. Request access and we will set your organization up.

Ready to start securing your AI agents?

Safe to imagine