Claude in Chrome Compliance API: What Browser-Agent Transcripts Capture

Anthropic's Enterprise compliance export records prompts, responses and text tool activity for Claude in Chrome, with important exclusions and retention limits.

Sonar the Answer Whale archives browser agent prompts and tool calls while filtering excluded evidence

Anthropic has added a compliance export path for Claude in Chrome sessions. For Enterprise administrators, that means browser-assisted work can produce an auditable transcript of prompts, responses and tool activity. It does not mean the API records every action on a device or exposes the model’s hidden reasoning.

What the transcript captures, and what it leaves out

Included

  • User prompts
  • Claude responses
  • Tool calls
  • Text tool results
  • Session and message metadata

Not included

  • Thinking or hidden reasoning
  • System prompts
  • Binary and non-text content
  • Citation metadata
  • General device activity outside the Claude session

This boundary comes from Anthropic’s compliance sessions documentation. It is the most important fact in the release because it defines what an investigator can and cannot reconstruct.

Why publishers and SEO teams should care

Browser agents can touch editorial systems, analytics dashboards, search results and source pages in one session. A normal chat export is not enough when the relevant event is a tool call: opening a page, filling a form, copying a value or changing a record. The compliance API makes those text-based events available to an authorized enterprise archive.

That can improve incident review and workflow governance. It does not replace WordPress revisions, Search Console exports, server logs or application-specific audit trails. A strong record links the agent session to the system where the final change occurred. The same separation of agent output from governed evidence is central to our AI-assisted SEO reporting framework.

The local-session API shape

Anthropic documents the product surface as claude_in_chrome and exposes three local-session paths:

GET /v1/compliance/apps/sessions/local
GET /v1/compliance/apps/sessions/local/{session_id}
GET /v1/compliance/apps/sessions/local/{session_id}/messages

The required scope is read:compliance_user_data. That permission deserves the same review as any other sensitive export. Limit the service account, log access to the archive and avoid giving a broad analyst role direct transcript access by default.

Retention changes the risk calculation

Anthropic states that compliance data is retained for six years by default unless the organization uses a finite custom conversation retention period. The export is unavailable for Zero Data Retention and HIPAA configurations. Those limits should be checked before a legal or security team promises that a browser session will be recoverable later.

A longer archive is not automatically better. Prompts and text tool results may contain unpublished headlines, customer information, analytics values or internal URLs. Decide who can search, export and delete the records, then test those controls with a harmless sample session.

A realistic incident walkthrough

Imagine an editor reports that an article’s canonical URL changed after a browser-assisted task. Start with the Claude session identifier and retrieve the message stream. The transcript may show the user’s instruction, the page opened and a text result returned by the tool. Then compare that time with the CMS revision and web-server log.

If the transcript shows no save action, do not infer that Claude made the change. If it shows a tool call but the CMS has no matching revision, investigate the integration boundary. The transcript narrows the timeline; it does not decide causality on its own.

Six questions to answer before enabling export

  1. Which teams are allowed to use Claude in Chrome?
  2. Which sessions are in scope for retention and investigation?
  3. Who owns the compliance API credential?
  4. Where are transcripts stored and encrypted?
  5. How are requests tied to CMS, analytics or ticket records?
  6. What happens when the expected evidence is intentionally unavailable?

Download the browser-agent evidence map

Bottom line

The release makes Claude in Chrome more governable for Enterprise customers, but only when teams understand the capture boundary. Treat the transcript as one evidence layer. Pair it with system-of-record logs, least-privilege access and a retention policy that matches the sensitivity of the work.

Primary source

Anthropic, Compliance API sessions documentation, reviewed September 18, 2026.

Keep learning

Continue this topic

Community discussion

Discuss: Claude in Chrome Compliance API: What Browser-Agent Transcripts Capture

Have a question, a useful example, or a different perspective? Join the discussion, share evidence, and help other readers reach a better answer.

0 replies Moderated
No replies yet.

Be the first to ask a focused question, share a practical example, or add useful evidence.

Ask a question or join the discussion

Share evidence, a useful example, or a clear question. Be specific, stay on topic, and challenge ideas without attacking people. First-time replies may be held for moderation.