Case Study
How Wix scaled Al-native work to 5,000 employees with Willow
Read More
News

Willow Integrates with Claude's Compliance API: One Control Plane for Every Agent.

Author:
Shalev Shalit
00 min
July 21, 2026

Willow now integrates with Claude's Compliance API. The integration brings Claude usage on the Claude Platform, and conversation content on Claude Enterprise, into the same control plane that already governs the rest of your agents: endpoint agents, SaaS agents, homegrown automations, and the MCP servers, skills, and tools they run on.

Claude is already in production across enterprise teams, drafting legal documents, building financial models, moving real work through real systems. What most security teams cannot see is the specific data moving through those conversations. That blind spot is exactly what this integration closes.

One policy layer, every agent

Willow is the Agentic Access Platform, the control plane for AI agents in the enterprise. It gives every agent a real identity inherited from your existing provider (Okta, Entra ID, JumpCloud), scopes what each agent can do inside every tool, and records every action in an audit trail tied to a named person.

Until now, activity on the Claude Platform sat outside that picture. The Compliance API integration pulls it in. Claude usage is governed by the same policies, surfaced in the same console, and investigated through the same workflow as every other agent in your environment. One policy layer, applied everywhere agents actually operate.

The integration connects at the organizational level on the Claude Platform. It does not require rearchitecting how employees work, routing traffic through a proxy, or installing software on end-user machines. It runs in the background to give you a complete audit trail, without changing the experience for the people already using Claude.

What is the Compliance API?

Claude's Compliance API gives authorized integrations programmatic access to activity logs on the Claude Platform. It exposes chat sessions, messages, users, roles, and organizational structure through a set of endpoints that integrations poll on a defined schedule.

Willow connects to the Compliance API at the organizational level and polls for new activity, pulling sessions and messages and mapping them to individual user identities through your identity provider. Security teams can see who is active, which sessions are running, and what content is moving through those conversations, with no friction added to how people already use Claude.

The integration applies to Anthropic-hosted deployments. Conversation content access through the Compliance API is available on Claude Enterprise plans only.

What Willow does with the data

Every Claude session that comes through the integration runs through Willow's guardrails, the same runtime checks that govern the rest of your agent estate. That means:

  • Sensitive data detection. PII, credentials, secrets, and regulated records are flagged as they move through sessions.
  • Prompt injection detection. Direct and indirect attempts are surfaced, so a poisoned document or message does not quietly redirect an agent.
  • Full audit trail. Every session is captured in the Logbook, whether or not a detection fires, so you have a defensible evidence trail of what happened over weeks, months, or quarters.

This is more than observability. Claude activity is evaluated against the same centrally defined policy Willow applies across every other control point, and every record is tied back to a real employee through your identity provider. When a session contains a violation, Willow surfaces it with full context: the prompt, the response, the user identity, the timestamp, and a risk classification. Security teams can investigate the session, filter the environment for similar patterns, and export the evidence for compliance reporting. If an investigation needs to reconstruct what a specific person shared, that history is already mapped to their identity.

Part of full-ecosystem coverage

Willow already governs agents across the enterprise: agent identity from your IdP, app-aware permissions that define what an agent can do inside each tool, an inline gateway for agent-to-tool traffic, and shadow-AI discovery at the endpoint through Willow for Chrome. This integration removes one of the last blind spots. Claude Platform usage is no longer invisible in an otherwise governed environment.

Discovery, governance, and runtime detection now extend across the Claude product surface for Anthropic-hosted deployments, inside the same platform that runs in production at multiple enterprise around the world including Wix, where Willow governs roughly 600 tools across about 5,000 weekly active users and more than 1M governed tool calls a week.

Why this matters now

Anthropic is shipping new capabilities faster than most security programs can absorb. Each one is genuinely useful, and each one raises the same questions your existing tools were not built to answer. Who initiated the task? What did the agent access? Did any interaction cross a policy line?

Those questions are answerable, but only if the instrumentation and the audit trail are in place before a capability is widely adopted, not after the first incident review. Bringing Claude Platform activity into your control plane now is how you stay ahead of that curve instead of reconstructing it later.

Get started

The integration is available today for Claude Enterprise. Connect Claude to the same control plane that governs the rest of your agents, and give your security team the visibility and audit trail to say yes to Claude at scale.

Table of contents

    Background Agents in the Enterprise

    Most teams can spin up an agent. Few can deploy one their security team signs off on. Here's the framework that does both.

    FAQS

    No items found.

    Everything you need to get your Basecamp running.

    Blog

    What's happening on the AI agent frontier.

    Documentation

    Get up and running fast.

    Rollout playbook

    How to deploy across your org without chaos.

    Your agents are already in the wild.

    Give them a Basecamp. Go from AI chaos to AI work, in minutes.