Claude Compliance API: Govern Local Session Retrieval

Govern Claude Enterprise session transcript access with current product coverage, scoped keys, evidence limits, retention, chain of custody, and an export register.

Sonar retrieves one sealed local-session record from an evidence cabinet and hands it to a reviewer who logs the transfer.

Direct answer: Claude Enterprise compliance reviewers can retrieve transcripts from supported Claude sessions through Anthropic’s Compliance API. Local-session coverage currently includes Cowork, Claude Code, Claude Science, and Claude for Microsoft 365. Treat that access like a sensitive records system: scope the key, define the purpose, preserve chain of custody, restrict exports, and document what the transcript omits.

This is not a web-crawler or citation feature. It is after-the-fact retrieval of retained session records. The transcript can help reconstruct what a user asked Claude to do and what Claude returned, but it does not capture every action on the device and does not prove that a published claim is correct.

What changed—and what is current

Anthropic introduced local Cowork and Claude Code transcript retrieval in August 2026. Its August 26 release notes moved those surfaces out of beta and added beta coverage for Claude Science and Claude for Microsoft 365 sessions. The current session documentation is the controlling reference when it conflicts with an older announcement.

The same local endpoint family is used for supported sessions running on a user’s machine. Remote Cowork sessions started on claude.ai web or mobile use a separate remote endpoint family. Claude Code on the web is not returned by either family, according to the current documentation.

Documented session surfaces and endpoint families
Product surface Where it runs Endpoint family Documented status
Cowork in Claude Desktop User’s machine /sessions/local Stable
Claude Code in terminal, Desktop, or IDE extension User’s machine /sessions/local Stable
Claude Science desktop app User’s machine /sessions/local Beta coverage
Claude for Microsoft 365 Microsoft 365 desktop or web apps /sessions/local Beta coverage
Cowork started on claude.ai web or mobile Anthropic-managed cloud /sessions/remote Stable

Use the correct key and scope

Session transcript endpoints require a Compliance Access Key with read:compliance_user_data. Anthropic says a regular Claude API key cannot call them, while an Admin API key reaches the Activity Feed only. A parent-scoped Compliance Access Key can reach content across linked organizations, so its blast radius may be much larger than one workspace.

Create the key in the documented claude.ai organization settings flow, store it in a secrets manager, and assign a named owner. Do not paste it into a transcript, ticket, repository, shell history, or SIEM forwarder configuration. Record the key identifier rather than the secret in the governance register.

Understand the three local-session requests

The local list endpoint returns session metadata. A second request retrieves one session’s metadata. A third returns its messages. All three use the /v1/compliance/apps/sessions/local path family and the read scope. The list has no user filter, so time bounds and a disciplined export process matter.

Separate discovery, metadata retrieval, and transcript retrieval
Request Purpose Record before use
GET /v1/compliance/apps/sessions/local List local-session metadata Time window, page cursor, run ID, operator
GET /v1/compliance/apps/sessions/local/{session_id} Retrieve one session’s metadata Session ID, organization, workspace, user ID, product surface
GET /v1/compliance/apps/sessions/local/{session_id}/messages Retrieve a paginated transcript Purpose, scope, page cursor, content hash, access restrictions

Define the investigation before querying

Write the legal, security, compliance, or editorial purpose before retrieving content. Name the authorized requester, approving role, population, time window, products, organizations, and expected output. “See what employees are doing” is not a bounded review purpose.

Use the narrowest time window that can answer the question. Avoid exporting an entire tenant when session IDs or a short interval will suffice. Log the Compliance API access event and connect the export to a case or review ID. Anthropic documents compliance_api_accessed Activity Feed events for auditing who queried compliance data.

Record session identity without over-trusting email

Use the opaque session ID and user.id as stable join fields. Anthropic notes that an email address can be null after an account leaves an organization and is always null in the messages response. Join to the list or retrieve response when authorized attribution is required.

Record organization_uuid, workspace_id, product_surface, created_at, and updated_at where returned. Pass through unknown product-surface values rather than rejecting them; Anthropic explicitly recommends forward-compatible handling as coverage expands.

Know what the transcript can—and cannot—show

A local transcript reconstructs captured API calls: user prompts, assistant text, tool calls, and text portions of tool results. It can contain URLs, credentials, personal data, source text, and local paths. Anthropic says the content is not masked, which makes access control and downstream redaction essential.

It is not device surveillance. Activity that never reaches the Claude API is absent. Thinking blocks, the system prompt, tool definitions, MCP server configuration, images, PDFs, other binary blocks, and citation metadata are omitted or replaced with markers. Text inputs and results may also be truncated. A missing detail can mean “not captured,” not “did not happen.”

Interpret transcript evidence at the right boundary
Material Typical transcript treatment Governance implication
User prompts and assistant text Returned when captured, subject to retention Treat as sensitive content
Tool calls and text results Returned with size limits Check truncation before relying on completeness
System prompt and thinking Omitted or replaced by a marker Do not claim full prompt reconstruction
Images, PDFs, binary blocks Placeholder or omission Preserve the original evidence elsewhere when permitted
On-device actions never sent to the API Not captured Do not infer absence of local activity
Citation metadata on text blocks Omitted Verify sources independently

Account for coverage exclusions

Local-session capture applies while users are signed in with their Claude Enterprise account and the Compliance API is enabled. Current documentation excludes Claude Code sessions authenticated with a Claude Console API key, sessions run through Amazon Bedrock, Google Cloud, or Microsoft Foundry, and Claude Code on the web.

Anthropic also documents no local-session capture for organizations with HIPAA readiness and for sessions where zero data retention is in effect. A 404 can combine not-found, unreadable, ZDR, or expired-retention cases. Preserve the response and request ID; do not translate every 404 into “the session never existed.”

Anthropic documents six years of local transcript retention by default, or the organization’s finite custom conversation-retention period. Each captured call ages against the retention boundary. Lengthening the setting later does not restore content that has already expired.

If the organization’s legal-hold horizon exceeds the API retention window, decide whether an authorized export archive is necessary. Give that archive its own retention, encryption, access, deletion, and audit rules. A copied transcript should not become an ungoverned duplicate that outlives the policy it was meant to support.

Preserve chain of custody

For every export, record the source endpoint, query parameters, retrieval timestamp, operator, case ID, page cursors, response request IDs, and a content hash. Store raw evidence read-only, then make a separate redacted working copy. Record every transformation applied to the working copy.

Paginate until next_page is null. Do not assume that a short page is the last page. Cursor expiry and changing retention boundaries can affect later walks, so record start and completion times. Deduplicate sessions and messages by their opaque IDs.

Separate compliance evidence from editorial proof

A transcript can show that a source was mentioned or a tool was called. It does not prove the source was authorized, current, accurately interpreted, or reflected in the final publication. Build a separate claim-source ledger and open every material reference.

The evidence-led publishing guide sets that editorial standard. Use the source credibility audit for claim support and the attachment evidence register when long source material crosses a composer or attachment boundary. Compliance records support those checks; they do not replace them.

Build a minimum access and export gate

  1. Confirm the organization is eligible and the requested surface is documented.
  2. Approve a bounded purpose, population, and time window.
  3. Use a named Compliance Access Key with only the required read scope.
  4. Log the operator, key identifier, endpoint, case ID, and request IDs.
  5. Store raw data in an access-controlled evidence location.
  6. Create a redacted working copy for reviewers who do not need raw content.
  7. Verify pagination, truncation markers, omissions, and retention boundaries.
  8. Apply the declared deletion, legal-hold, correction, and review rules.

For controls that act before inference rather than after it, see the site’s Claude inference-location governance guide and keep real-time enforcement, telemetry, analytics, and transcript retrieval as separate systems.

Download the local-session compliance register

The CSV uses one row per authorized retrieval or review unit. It connects the request purpose, product surface, session identity, coverage caveats, export evidence, retention, reviewer, and final disposition. Remove the rows marked EXAMPLE-REMOVE before operational use.

Download the Claude local-session compliance register (CSV)

Limits and re-audit triggers

Anthropic’s product coverage, endpoint behavior, status, scopes, fields, truncation limits, and retention rules can change. Re-audit this workflow after a documentation or release-note change, a new product surface, a retention-policy change, a key rotation, an incident, a failed reconciliation, or a material change to your legal basis.

This guide is an operational editorial framework, not legal advice. Security, privacy, labor, and records obligations vary by jurisdiction and contract. Ask the responsible legal and security owners to approve the policy before broad transcript access is enabled.

Primary sources

Source check: August 29, 2026. Recheck Anthropic’s current documentation before implementing or changing an export workflow.

Keep learning

Continue this topic

Community discussion

Discuss: Claude Compliance API: Govern Local Session Retrieval

Have a question, a useful example, or a different perspective? Join the discussion, share evidence, and help other readers reach a better answer.

0 replies Moderated
No replies yet.

Be the first to ask a focused question, share a practical example, or add useful evidence.

Ask a question or join the discussion

Share evidence, a useful example, or a clear question. Be specific, stay on topic, and challenge ideas without attacking people. First-time replies may be held for moderation.