Solutions | claude coverage

You can't install an agent on a surface that has no endpoint.

Claude is no longer three tools on a developer's laptop. It's a Slack bot, an Excel sidebar, a design canvas, a phone that never touches a managed device, and a hosted agent session running on infrastructure you don't own. Operant governs all of it from one policy set.

CodeCLICoworkChromeSlackDesignMicrosoft 365Cowork CloudWebDesktopMobile

Operant expansive
Claude coverage

Operant expansive Claude coverage

  • Code
  • CLI
  • Cowork
  • Chrome
  • Slack
  • Design
  • Microsoft 365
  • Cowork Cloud
  • Web
  • Desktop
  • Mobile

Endpoint coverage was built on an assumption that stopped holding.

Claude runs on the user's machine, so govern the machine. That held for Claude Code, the CLI, and desktop Cowork. It doesn't hold for where Claude went next — and in each case the data still leaves the organization and the agent still acts on external systems. Only the observability disappears.

Claude Tag runs in Slack

The prompt is a channel message, often carrying context from people other than the user who invoked it

Claude chat runs on mobile

A phone that may be personal, unmanaged, and entirely outside MDM scope

Claude Design runs in a browser canvas

The sensitive material is pasted data, not a file on disk

Cloud Cowork runs on hosted infrastructure

There is no endpoint. The agent executes elsewhere; the local device sees only a result

Claude for Microsoft 365 runs in an Office sidebar

The sensitive material isn't pasted in at all — it's the workbook, contract, or inbox already open

Three enforcement paths, one policy set.

Operant applies the strongest enforcement each surface's architecture permits. Every path writes to the same policies and the same audit trail.

Claude surface Prompt DLP Agent-loop tracing Command guard Skills and plugins MCP gateway Endpoint audit
Developer surfaces
Claude Code
Developer Machine
REDACT
Claude CLI
Interactive Terminal
REDACT
Agentic knowledge work
Claude Cowork
Business Desktop
REDACT
Claude Cloud Cowork
Hosted Sessions
BLOCK
Claude Tag
Slack Multiplayer
BLOCK
Conversational and creative
Claude chat
Web and Mobile
BLOCK
Claude Design
Canvas and Design
BLOCK
Embedded productivity
Claude for Microsoft 365
Excel, Word, PowerPoint, Outlook
BLOCK
Microsoft 365 connector
Graph Read and Write Tools
BLOCK
Browser and platform
Claude in browser
Chrome Extension
REDACT
Claude inference hooks
API and Model Layer
BLOCK
Full enforcement Partial coverage Not applicable to surface

Redact — Operant is in the data path and strips sensitive values in flight.
Block — enforcement runs through Claude inference hooks, which return an allow or deny verdict; policy violations are stopped rather than rewritten. Both are full enforcement. Surfaces routed through Amazon Bedrock, Google Cloud Vertex AI, or Microsoft Foundry credentials fall outside inference hook coverage and are governed through the Operant gateway.

Anthropic shipped the missing primitive on August 5.

When an organization enables inference hooks, Claude sends the prompt and its surrounding context to a designated security server before the model begins generating, and waits for an allow or deny before proceeding. The same check runs on tool call responses, including tools reached through MCP connectors, skills, and plugins.

The verdict is binary
The protocol carries allow or deny. It does not carry a modified payload back to the model — so enforcement at this layer is blocking, not redaction. A denied request never reaches the model, and the user sees which policy stopped it.
Enforcement is prompt-side today
Prompts and tool call responses are inspected on the inbound path. Enforcement for model responses is planned. Until it ships, output-side governance on hook-only surfaces is detection and audit.
Scope is Claude Enterprise
Hooks don't cover Claude on Amazon Bedrock or Google Cloud, voice mode, or Platform organizations. Operant's runtime coverage for Bedrock, Vertex AI, and Foundry runs through the gateway instead — a different path, stated plainly.

Redact where we're in the path. Block where we're not.

You define a data classification rule once at the org level. Operant applies the strongest enforcement each surface permits.

In-path: rewrite the payload in flight

On Claude Code, the CLI, Cowork desktop, and the browser extension, the endpoint agent sits between the user and the model. PII, PHI, PCI, credentials, and API keys are stripped from the prompt before it leaves the device, and the workflow continues uninterrupted.

Hook layer: verdict authority, not proxy

On Claude Tag, Claude chat, Claude Design, and Cloud Cowork, violations are blocked with the specific rule surfaced to the user, so they can revise and resubmit. The sensitive value never reaches the model. The tradeoff is a harder stop instead of a silent cleanup.

SLACK THREAD · #support-esc

@eng@claude summarize this threadPROMPT
acctACME-4471, jane@acme.ioPII
logsk-live-9f3a…c2CREDENTIAL
notepending legal matterSENSITIVE

NO FILE UPLOADED · NOTHING FOR AN ENDPOINT AGENT TO SEE

Hook layer

Matching policy

Deny

Allow

policy plane idle

MODEL

Claude

awaiting input

01Claude tagged in Slack
02Operant sees the transcript first
03Credential match → deny
04Engineer revises the thread
05Summary on the second try

Claude inside the tools people already have open.

In an Office sidebar, a Slack channel, or a browser tab, Claude isn't a destination the user navigates to. It's a panel next to the work — and embedding changes the threat model in four specific ways.

The prompt is the file

Traditional DLP waits for an event: a paste, an upload, an attachment. A payroll workbook that was already open is in the sidebar's context by default, so a prompt as unremarkable as "update the burden rate" carries every salary in it to the model.

Context crosses application boundaries

Context carries from Outlook to Word to Excel to PowerPoint inside one conversation — the product's central feature. Material non-public figures can surface in a deck without any file leaving any app in a way per-application DLP would recognize.

Write tools turn disclosure into action

The connector can send email, manage drafts and calendar events, and create and update files in OneDrive and SharePoint. Read access risks exposure. Write access risks consequences.

Delegated permissions inherit the user's blast radius

The connector acts on behalf of each user and reaches only what that user could already reach — which is the correct design, and which also means an over-permissioned employee becomes an over-permissioned agent.

Blocking is a harder stop than redaction.
Roll out accordingly.

The shadow window is what keeps the first enforcement day from being a support incident.

1
Start with discovery

Let Operant inventory every Claude surface, MCP connection, skill, plugin, and agent in active use, including which credentials each embedded integration routes through

2
Enable Operant as your inference hook endpoint

A signed WebSocket endpoint and a shared secret, set once at the Claude organization level

3
Run in shadow mode for a week

Verdicts evaluated against live traffic without blocking anything, so you see what would have been denied

4
Tune policy against real traffic, then roll out by percentage

With role-based exclusions before going to full enforcement

5
Install the Cloud Cowork plugin

It binds to the same policy set

Claude now spans eleven surfaces. Start from an accurate picture of yours.

Deploy, let Operant inventory what's actually in use, and work from that inventory before writing a single policy. It tends to be considerably larger than teams expect.