Security teams are about to get a much clearer view of what AI coding agents do inside the enterprise. On September 30, TrendAI — the enterprise business unit of Trend Micro — announced that its Vision One security platform now pulls session transcripts from Claude Code and Cowork through Anthropic's Claude Compliance API, giving defenders a record of the prompts, responses, and tool calls behind agentic work.
The integration extends a partnership TrendAI first announced with Anthropic in June 2026. While the earlier work covered general Claude Enterprise usage, the new coverage reaches the two surfaces where agentic behavior is most concentrated: Claude Code, the AI coding agent developers run from the terminal and desktop, and Cowork, Anthropic's agent for knowledge-work tasks.
What the integration adds
According to the announcement, published via Media OutReach Newswire, the Claude Compliance API returns session records for Claude Code and Cowork that include prompts, model responses, and tool calls, each tied to a verified user. TrendAI feeds those records into Vision One, where security teams can investigate AI activity alongside the rest of their telemetry and correlate it with endpoint, identity, cloud, and network signals.
That correlation matters because agents operate differently from chatbots. An AI coding agent can hold credentials, remember context across sessions, and act on production systems without a human approving every step. Security teams typically know such agents are running somewhere in the organization but cannot see what they were asked to do, what they actually did, or whether the behavior stayed within policy. The new integration is designed to close that gap.
TrendAI's chief platform officer described the goal as giving security teams the transparency to validate agent activity against company policy, using the same workflows they already use for endpoint and network data. With the records in Vision One, teams can also build custom detections tuned to the agent behaviors that matter to their environment — for example, flagging tool calls that fall outside expected boundaries.
The integration lands alongside a separate TrendAI announcement supporting NVIDIA's Agent Safety Platform, in which Vision One pairs hardware-level detection on BlueField DPUs with threat intelligence from the Zero Day Initiative. Together, the two moves signal a strategy of meeting agents at every layer: the infrastructure underneath them and the session transcripts above.
Where the coverage stops
The Claude Compliance API itself has grown steadily. Anthropic expanded it on August 11, 2026, to cover Cowork sessions across desktop, web, and mobile, plus Claude Code sessions from the CLI and desktop app, using an existing Compliance Access Key. More recently, Anthropic added Claude in Chrome transcripts in beta for enterprise organizations, and the API also covers the Microsoft 365 add-ins and Claude Science.
But the coverage has hard boundaries, and security teams relying on it should know them. Sessions routed through Amazon Bedrock, Google Vertex AI, or Microsoft Foundry return nothing through the Compliance API. Organizations with HIPAA readiness enabled get no data, sessions under zero data retention return a 404, and Claude Code sessions run on the web or through the Claude Platform are excluded. Records are retained for six years by default, and the transcript content is not masked — credentials or connection strings an engineer typed into a session remain readable to reviewers for years.
Security researchers have also flagged a structural gap: activity records confirm what an agent did, but they cannot confirm whether the agent's access was legitimately provisioned in the first place. Identity governance — knowing the agent is who it claims to be — remains a separate problem that logging alone does not solve. That critique applies well beyond Anthropic: it is a property of transcript-based oversight in general.
Why it matters for the agent era
The TrendAI move fits a broader pattern across the agent ecosystem. Enterprise security vendors spent 2026 racing to instrument the agent layer, from NVIDIA's agent safety platform to identity and tool-call guardrails. As one earlier analysis argued, agent identity security has become the defining race of the agentic era — and visibility is the precondition for all of it.
For enterprises, the practical takeaway is straightforward: if engineering and knowledge-work teams are already running Claude Code and Cowork agents against business systems, the audit trail now exists to watch them. The Compliance API exposes every user prompt, assistant response, and tool call as structured blocks, which means parsed session transcripts can also feed an inventory of agents — their skills, their MCP servers, and their plugins.
The harder question is what teams do with that visibility. Transcript review is labor-intensive, and the six-year retention window turns every session into a long-lived data store that itself needs protection. Detections built on tool-call patterns will only be as good as the baselines teams establish. But for organizations moving agent fleets from pilot to production, the alternative — agents acting on production systems with no record at all — is quickly becoming indefensible.
Sources: Media OutReach Newswire announcement, GBHackers coverage of the Claude Compliance API, Let's Data Science on the August expansion, Hyrax analysis of the identity gap, and The Hacker News on securing Claude Code.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.