Twine + Anthropic: Governing Claude Enterprise

Alex, Twine's IAM digital employee, brings Claude Enterprise under the same governance as everything else - inventorying members, roles, groups, and connectors, surfacing the blind spots, and routing every change for human approval before anything is applied.

Twine + Anthropic — IAM governance for Claude Enterprise
What it does

Claude, governed like every other enterprise app

Alex, our IAM digital employee, brings Claude Enterprise under the same governance as every other enterprise application. Through the Compliance and Admin APIs, Alex inventories members, custom roles, groups, and the connectors each role grants, then enriches every account with identity context from across the enterprise through Twine's data fabric.

This makes the blind spots visible: accounts provisioned outside SSO, users whose connector access is out of line with peers in the same role, and applications reachable through Claude connectors that were never onboarded into the customer's IGA platform. Where remediation is warranted, Alex prepares the change and routes it for human approval within Twine before anything is applied — whether that is removing a departed member, adjusting a role, or updating group membership.

The result: Claude Enterprise becomes a governed application rather than an exception, which is what security teams need before they can expand it across the organization.

Members

Every account in the org, joined to the identity system of record.

Custom roles

What each role grants, and which permissions look over-provisioned.

Groups

Membership and the entitlements that follow from it.

Connectors

Which applications Claude can reach, including ones IGA never onboarded.

The problem this solves

Accounts created outside SSO survive termination

Enterprises expect Claude access to be governed by SSO, but accounts get created outside it through pilots, one-off invites, or direct admin provisioning. Those accounts survive termination, leaving active access to corporate data for people who have left — and today Claude sits outside the access review, so nobody is asking the question.

Alex closes this gap because it already governs the surrounding estate: it holds the identity system of record alongside Claude, so it can tell that an account has no SSO path or that a Claude connector reaches an application IGA never onboarded. That same position unifies access requests, letting a user request Claude access through the company's existing ITSM workflow (e.g. ServiceNow), while Alex resolves the request and provisions the connector — rather than routing it through a separate process. Neither is possible from inside Claude alone.

How it works

Claude in your Identity Governance Program

Step 01 · Anthropic

Compliance & Admin APIs

Full directory snapshots of organizations, users, roles, groups and settings, plus the incremental Activity Feed.

Step 02 · Alex

Correlate, review, remediate

Accounts are enriched through Twine's data fabric, findings are raised, and every change waits on human approval in Twine.

Step 03 · Enterprise

IGA and ITSM

Claude appears in access reviews, and access requests run through the existing ITSM workflow (ServiceNow, for example), or through Twine.

Nothing is applied without human approval in Twine
Setup

Connected in four steps

STEP 1
Create a Compliance API key

A primary owner issues the key for the Claude Enterprise organization.

STEP 2
Add the key in Twine

The key goes straight into AWS Secrets Manager under your tenant's KMS key.

STEP 3
First poll and backfill

Alex takes a full directory snapshot and backfills up to 90 days of activity.

STEP 4
Turn on reviews and requests

Claude joins your access reviews, and requests route through your existing ITSM workflow.