Venice Updates
Venice integrates with the Claude Compliance API to bring every Claude identity under just-in-time access

Venice now integrates with Anthropic's Claude Compliance API, so you can see every Claude Enterprise identity, put just-in-time (JIT) access in front of each one through the Venice MCP Gateway, and retire the standing privilege they've been running on.
Claude users connect to real systems through MCP: production databases, cloud consoles, ticketing systems, source repositories. That access runs on whatever permissions the person behind the session already holds. Not just the permissions the task needs, but all of them. The privilege was standing long before Claude showed up, and it's still standing. The difference is that now there's a much faster actor using it, one that can move from the system you pointed it at to everything else that identity can reach.
Venice removes that privilege. Discovery alone would just give you a list of the problems, with the privilege still sitting there. So Venice goes further: just-in-time becomes the only path Claude has into those systems, the standing access it replaces gets flagged for retirement, and users who never needed that access lose it entirely.
Discovery comes from the Claude Compliance API
Venice pulls every Claude Enterprise user, admin, group, and role across Claude chat, Cowork, and Claude Code, and connects each one to the identity it already governs across your identity providers, cloud platforms, and data stores. Claude stops being a blind spot and simply becomes another system inside your existing governance model.
Prioritization comes from blast radius scoring
Discovery gives you every Claude user, but it doesn’t tell you which ones can do damage. Not every Claude user carries the same risk. What separates them is what the identity behind each one can already reach.
Your platform engineer's Claude is not a chat account. Behind it is an identity with standing production database access, an admin role in AWS, and write access to your code. And the agent isn't confined to the system you pointed it at. Every one of those standing grants is reachable from the same session, so an agent that starts in a ticketing system can walk into the database or the cloud console and effectively elevate itself. Because Venice already understands that identity and has flagged it as privileged, the Claude user inherits that risk the moment the two are joined.
From there, Venice scores the real reachable damage if that user's Claude were compromised. An isolated user record becomes a contextualized risk, and the enrollment worklist stops being alphabetical. Security teams get an ordered answer to the question that decides where a rollout starts: which Claude users do we bring under just-in-time control first.
Prompt injection, a poisoned tool description, an over-eager agent: the entry vectors keep changing. But what decides whether any of them becomes a breach is how far the standing access on the other side reaches.

Enforcement comes from the Venice MCP Gateway
Starting at the top of that prioritized list, Venice applies a just-in-time access policy defining exactly what Claude, acting on that user's behalf, is allowed to do. Privilege is created at the moment of the request and scoped to the task. When the task ends, the privilege is destroyed. Nothing is left standing behind it.
Once a user is enrolled, just-in-time is the only path that Claude user has to those systems. And enrollment cuts both ways: where discovery shows access a user doesn't actually need, Venice removes it outright rather than converting it.

Catch any identity still on standing privilege
Venice continuously reports which Claude users haven't yet been brought under a JIT policy. Each entry is a named user with unscoped access that never expires. Security teams work the list down to zero and track one number: how many Claude users still hold standing privilege.

Availability
Venice's integration with Anthropic's Claude Compliance API is available now for Claude Enterprise organizations.
If Claude is already in your environment, the first question is not how many people are using it. It's how many of them are using it with production access that never expires. If you haven't already counted, the number is higher than you think.
Book a demo to see Venice and Claude together.
