Blog

AI Governance for Claude: How to Secure Code, Cowork, and Agents

Lumia Security Team
Lumia Security LabsLumia Security Team

August 5, 2026 | 5 min read

How to govern Claude across chat, code, Cowork, agents, data, and tool use.

Claude has expanded from a chatbot into a suite of tools that can access files, write code, connect to business systems, and act on behalf of employees.

In our webinar, Securely Scaling Claude with Lumia Security, we examined what AI governance for Claude now requires from security teams. Securing Claude means governing the data employees share, the accounts and tools they use, and the actions agents perform.

How to Secure Claude

Start by defining what acceptable Claude use looks like for your organization.

A Claude security policy should identify approved products and accounts, the information employees may share, the tools and Model Context Protocol servers Claude may access, and the actions agents may perform. It should also establish when employees may use premium models and when approval or justification is required.

The written policy then needs to be operationalized. Employees should receive clear guidance. But security cannot depend on awareness alone; organizations need technical controls that identify usage, inspect data and files, enforce rules in real time, and create records for investigation and audit.

The rest of the program depends on three capabilities: coverage everywhere Claude is used, context-aware enforcement, and governance over model usage and cost.

Why Claude Requires a Broader Governance Model

Claude originally presented a familiar data-security problem. Employees could expose sensitive information through prompts and file uploads.

Claude Code expanded that risk into development environments containing source code, local files, credentials, and API keys. Claude Cowork expanded it further by allowing employees to automate work across HR, finance, legal, sales, and operations.

Through connectors and Model Context Protocol servers, Claude may also interact with enterprise tools and execute actions on behalf of employees.

Existing permissions may determine whether an agent can access a file or system, but they can’t determine whether a particular use case or action is appropriate.

An HR employee, for example, may be authorized to access a salary spreadsheet. That does not automatically grant permission to disclose the file to an AI provider, use it for every purpose, or allow an agent to take downstream actions based on its contents.

Even within an approved enterprise account, submitting the complete file may violate internal requirements for data minimization, approved processing purposes, or third-party disclosure. Aggregated or anonymized data may have been sufficient.

Three Requirements for Scaling Claude Securely

1. Coverage Everywhere Claude Operates

Claude governance cannot stop at the browser.

Organizations need visibility across Claude Desktop, Code, Cowork, file uploads, connected tools, and agentic workflows. Controls should also account for internally developed applications or scripts that communicate with remote models outside the standard Claude interfaces.

Security teams should be able to determine:

  • Which Claude product was used
  • Which employee initiated the interaction
  • Whether the employee used a corporate or personal account
  • What files and data were involved
  • Which tools, connectors, or MCP servers were accessed
  • What actions an agent attempted to perform

This visibility allows security teams to assess actual Claude usage before deciding where enforcement is necessary.

2. Real-Time, Context-Aware Enforcement

Visibility helps security teams understand exposure. Enforcement prevents a known policy violation from becoming an incident.

Some interactions should be blocked. An employee should not be able to upload a payroll file when organizational policy prohibits sharing that information with an external AI service.

Lumia blocks a Claude Cowork request when an uploaded file violates the organization’s AI governance policy.
Lumia blocks a Claude Cowork request when an uploaded file violates the organization’s AI governance policy. 

Other situations call for a less disruptive response. Credentials, payment card numbers, personal identifiers, or other protected values can be redacted before the request reaches Claude. The employee can continue working without exposing the sensitive information.

Sensitive values are redacted before they reach Claude, while the request continues.  

Organizations may also warn the user, explain the policy, request a business justification, or redirect the employee to an approved account or workflow.

These decisions require more than keyword matching. A governance system needs deep understanding of the content, context, and intent of AI interactions, even when it lacks a predictable numerical pattern or explicit label.

The appropriate control should depend on the employee, account, application, data, intended purpose, and requested action. This allows the organization to enforce its policy without broadly blocking useful Claude workflows.

3. Model and Cost Governance

A complete Claude policy should also address model selection.

Premium models may be justified for complex reasoning, specialized analysis, difficult development work, or long-running agentic tasks. They are less appropriate for basic formatting or routine lookups.

Without governance, employees may default to the most expensive available model regardless of the task.

Model routing is not primarily a security control, but it belongs in the same policy and telemetry layer. It allows security, IT, and finance teams to establish when advanced models are appropriate, document exceptions, and identify unmanaged consumption.

Organizations can warn employees when a request does not appear to justify a premium model and recommend a smaller option. When the advanced model is necessary, the employee can provide a business justification and continue.

A policy prompts the employee to justify using an expensive frontier model for a low-complexity request.

Operationalize the Policy at Runtime

A written policy establishes expectations. Runtime controls turn those expectations into enforceable decisions.

Controls govern prompts, responses, files, attachments, and sensitive information, while agent-specific controls evaluate what AIs attempt to do through connected tools and enterprise systems.

Lumia applies organizational policies to AI traffic in real time: inspecting files and prompts, identifying account and workspace context, blocking restricted data transfers, redacting sensitive values, and coaching users toward more appropriate model choices.

These controls complement identity, access management, vendor protections, data classification, and employee education. Together, they create a practical way to enable Claude while keeping its use aligned with organizational policy.

See Claude Governance in Practice

Watch Securely Scaling Claude with Lumia Security to see how organizations can identify Claude usage, block a sensitive payroll workflow, redact regulated data, distinguish corporate and personal accounts, and manage unnecessary model spending across Claude’s browser, desktop, coding, and agentic experiences.

Frequently Asked Questions

AI Governance for Claude: How to Secure Code, Cowork, and Agents

Lumia Security Team
Lumia Security LabsLumia Security Team

August 5, 2026 | 5 min read

Claude AI governance is the combination of policies, visibility, and technical controls used to manage how employees and agents use Claude. It covers the information sent through prompts and files, the accounts and applications being used, the tools Claude can access, and the actions agents are permitted to execute.

Claude Enterprise can provide stronger administrative and organizational controls than unmanaged consumer usage, but it does not make every prompt or file appropriate to submit. Organizations still need policies that account for the data involved, the employee’s purpose, the Claude product being used, the destination account, and any tools or agents involved.

Yes. Not every policy violation requires a full block. Sensitive values such as Social Security numbers, credit card numbers, or credentials can be redacted before the request reaches Claude, allowing the rest of the interaction to continue. Organizations can also warn users, request justification, or guide them toward an approved model or workflow.

Yes. organizations can configure whether raw prompt content is retained, retain content only for selected violations, limit administrators to metadata, and apply role-based access to sensitive interaction details. Administrative access and policy changes can also be recorded in audit logs.

Blocking AI apps is not an option anymore. Adopt AI. Safely. Reach out today to learn more.

We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept", you consent to our use of cookies.