How to govern Claude across chat, code, Cowork, agents, data, and tool use.
Claude has expanded from a chatbot into a suite of tools that can access files, write code, connect to business systems, and act on behalf of employees.
In our webinar, Securely Scaling Claude with Lumia Security, we examined what AI governance for Claude now requires from security teams. Securing Claude means governing the data employees share, the accounts and tools they use, and the actions agents perform.
How to Secure Claude
Start by defining what acceptable Claude use looks like for your organization.
A Claude security policy should identify approved products and accounts, the information employees may share, the tools and Model Context Protocol servers Claude may access, and the actions agents may perform. It should also establish when employees may use premium models and when approval or justification is required.
The written policy then needs to be operationalized. Employees should receive clear guidance. But security cannot depend on awareness alone; organizations need technical controls that identify usage, inspect data and files, enforce rules in real time, and create records for investigation and audit.
The rest of the program depends on three capabilities: coverage everywhere Claude is used, context-aware enforcement, and governance over model usage and cost.
Why Claude Requires a Broader Governance Model
Claude originally presented a familiar data-security problem. Employees could expose sensitive information through prompts and file uploads.
Claude Code expanded that risk into development environments containing source code, local files, credentials, and API keys. Claude Cowork expanded it further by allowing employees to automate work across HR, finance, legal, sales, and operations.
Through connectors and Model Context Protocol servers, Claude may also interact with enterprise tools and execute actions on behalf of employees.
Existing permissions may determine whether an agent can access a file or system, but they can’t determine whether a particular use case or action is appropriate.
An HR employee, for example, may be authorized to access a salary spreadsheet. That does not automatically grant permission to disclose the file to an AI provider, use it for every purpose, or allow an agent to take downstream actions based on its contents.
Even within an approved enterprise account, submitting the complete file may violate internal requirements for data minimization, approved processing purposes, or third-party disclosure. Aggregated or anonymized data may have been sufficient.
Three Requirements for Scaling Claude Securely
1. Coverage Everywhere Claude Operates
Claude governance cannot stop at the browser.
Organizations need visibility across Claude Desktop, Code, Cowork, file uploads, connected tools, and agentic workflows. Controls should also account for internally developed applications or scripts that communicate with remote models outside the standard Claude interfaces.
Security teams should be able to determine:
- Which Claude product was used
- Which employee initiated the interaction
- Whether the employee used a corporate or personal account
- What files and data were involved
- Which tools, connectors, or MCP servers were accessed
- What actions an agent attempted to perform
This visibility allows security teams to assess actual Claude usage before deciding where enforcement is necessary.
2. Real-Time, Context-Aware Enforcement
Visibility helps security teams understand exposure. Enforcement prevents a known policy violation from becoming an incident.
Some interactions should be blocked. An employee should not be able to upload a payroll file when organizational policy prohibits sharing that information with an external AI service.

Other situations call for a less disruptive response. Credentials, payment card numbers, personal identifiers, or other protected values can be redacted before the request reaches Claude. The employee can continue working without exposing the sensitive information.

Organizations may also warn the user, explain the policy, request a business justification, or redirect the employee to an approved account or workflow.
These decisions require more than keyword matching. A governance system needs deep understanding of the content, context, and intent of AI interactions, even when it lacks a predictable numerical pattern or explicit label.
The appropriate control should depend on the employee, account, application, data, intended purpose, and requested action. This allows the organization to enforce its policy without broadly blocking useful Claude workflows.
3. Model and Cost Governance
A complete Claude policy should also address model selection.
Premium models may be justified for complex reasoning, specialized analysis, difficult development work, or long-running agentic tasks. They are less appropriate for basic formatting or routine lookups.
Without governance, employees may default to the most expensive available model regardless of the task.
Model routing is not primarily a security control, but it belongs in the same policy and telemetry layer. It allows security, IT, and finance teams to establish when advanced models are appropriate, document exceptions, and identify unmanaged consumption.
Organizations can warn employees when a request does not appear to justify a premium model and recommend a smaller option. When the advanced model is necessary, the employee can provide a business justification and continue.

Operationalize the Policy at Runtime
A written policy establishes expectations. Runtime controls turn those expectations into enforceable decisions.
Controls govern prompts, responses, files, attachments, and sensitive information, while agent-specific controls evaluate what AIs attempt to do through connected tools and enterprise systems.
Lumia applies organizational policies to AI traffic in real time: inspecting files and prompts, identifying account and workspace context, blocking restricted data transfers, redacting sensitive values, and coaching users toward more appropriate model choices.
These controls complement identity, access management, vendor protections, data classification, and employee education. Together, they create a practical way to enable Claude while keeping its use aligned with organizational policy.
See Claude Governance in Practice
Watch Securely Scaling Claude with Lumia Security to see how organizations can identify Claude usage, block a sensitive payroll workflow, redact regulated data, distinguish corporate and personal accounts, and manage unnecessary model spending across Claude’s browser, desktop, coding, and agentic experiences.

