Alignmt AI Integrates with Anthropic's Compliance API
- Jul 10
- 3 min read
Alignmt AI turns your Claude organization's activity into a living, risk-scored inventory of every AI resource so governance teams know which resources act autonomously, what data they can reach, and how far a failure would spread.

The inventory problem no one has solved
Most AI governance programs can answer "who is allowed to use Claude." Far fewer can answer the questions that actually determine risk: which of the hundreds of projects, skills, and MCP servers in your organization can write to external systems? Which ones run without a human in the loop? Which touch regulated data? And who owns the one that does all three?
Until now, answering those questions meant stitching together audit exports by hand and the answer was stale before the spreadsheet was finished.
With a single Compliance API key, Alignmt AI connects to your Claude organization and builds that inventory continuously. Every resource in your org becomes a governed item with an owner, a lifecycle, a capability profile, an automation status, and a blast radius score, updated as activity happens, not as audits allow.
Every resource, from creation to deletion
Alignmt AI covers the full breadth of your Claude organization: projects, skills, commands, plugins, MCP servers, platform skills, service accounts, tunnels, and Claude Code resources such as security webhooks and review repositories.
For each resource, you get:
Identity and ownership — the resource's name and its owner, resolved to a real person in your directory.
Full lifecycle — when it was created, last updated, archived, or deleted. Deleted resources stay in the inventory with their history intact, because the resource that was removed last Tuesday is often exactly the one your auditor asks about.
A complete action timeline — policy changes, uploads, sharing updates, and credential events, attached to the resource they belong to, with timestamp and actor.
Confirmed, capable, or assistive — know the difference
Not every Claude resource carries the same risk. Alignmt AI classifies each item by what the evidence actually supports:
Confirmed automation — the resource demonstrably runs unattended.
Capable but unconfirmed — the resource could act autonomously, but autonomous operation hasn't been established yet. These are the resources most inventories miss entirely.
Assistive — a human drives every action.
Crucially, Alignmt AI never scores unknown autonomy as safe. A resource with write capability and no visible trigger isn't treated as harmless — it's flagged, prioritized, and investigated.
Blast radius, not just a checkbox
Every resource receives a blast radius score from 0 to 100, reflecting both what the resource can do and how it operates . The score comes with a transparent breakdown, so "this project scored 87" is never a black box: you can see exactly which signal drove it.
Provenance on every fact
This is where Alignmt AI differs from a log viewer. Every field in the inventory carries a provenance tag telling you how we know it:
Evidenced — stated directly by your organization's Claude activity records.
Analyzed — established through Alignmt AI's deeper analysis of the resource.
Inferred — derived by correlation, always accompanied by a confidence level.
Attested — confirmed by a human owner through a built-in attestation workflow.
Where analysis is involved, we show our work: findings are grounded in cited evidence, and when the evidence is genuinely insufficient, Alignmt AI says so rather than guessing. When a question can't be resolved automatically, it's routed to a human owner as an attestation task instead of being filled in silently.
Data exposure, classified
For resources handling content, Alignmt AI classifies the categories of data in play — including PII, PHI, PCI, financial data, and others — and connects them to where that content flows like uploads, sharing changes. If you already run a DLP platform, Alignmt AI can work with its classifications rather than making you maintain two.
Built to respect your rate limits — and your key
The integration is designed to be a considerate tenant of the Compliance API: it fetches only new activity, stays well within Anthropic's rate limits, and backs off automatically under load. Deeper analysis is deliberately selective and risk-prioritized, so the highest-risk unknowns are resolved first and low-risk resources are touched as little as possible.
Your Compliance API key is encrypted at rest, never displayed after entry, used exclusively for read access to your organization's compliance records, and can be rotated or revoked at any time.
Get started
If your organization uses Claude, you can connect it to Alignmt AI today and have a scored, attributed inventory of your AI resources by the end of the week — usually by the end of the hour.




Comments