LoFP LoFP / anthropic

anthropic rule

TitleTags
a user repeatedly clicking an expired or invalid magic link from the same browser session can produce several failures before requesting a new link or signing in successfully.
administrators deactivate or delete sso connections during identity provider migrations, certificate rotation, or maintenance. validate the actor, `anthropic.audit.connection_id`, and whether sso was restored after the change.
administrators disable magic link second factor during authentication policy changes or troubleshooting. verify the actor and whether the setting was re-enabled or replaced with an equivalent control.
approved internal automation, ci jobs, or sdk integrations may present scripting user agents. validate the actor, source ip, and action against change tickets before treating as compromise. prefer excluding stable identities or source networks rather than removing the matching user-agent pattern.
cloud egress, split-tunnel, or dual-homed clients that present different public ips for concurrent anthropic sessions (for example browser and api tooling) can look like impossible travel when both resolve far apart.
compliance, legal, and platform teams download organization data exports after scheduled audits, migrations, or litigation holds. validate the actor and business justification before escalating.
developers, analysts, or knowledge workers bulk-uploading documents during migrations, evaluations, or large project onboarding can exceed the daily threshold from a single workstation or vpn egress.
finance or platform teams delete outdated spend limits when consolidating billing policies or replacing them with new limits. confirm the actor, nearby create or update events, and an approved change before escalating.
identity provider directory sync and scim provisioning can deactivate or delete sso connections during idp migrations, directory attribute changes, or connector maintenance. if `anthropic.audit.actor.type` is `scim_directory_sync_actor`, correlate with workos or okta change windows before escalating.
idp or sso cutover testing against a pilot account can generate a short burst of failed attempts for one email during maintenance windows.
it administrators and hiring workflows routinely invite new members during onboarding, contractor access, or staffing changes. verify the invited email, role, and that a hiring or access request exists when policy requires one.
it administrators promote users to organization admin during onboarding, staffing changes, or incident response. verify that the target user should hold org admin privileges, and that a change request exists when policy requires one.
it and identity teams verify or add corporate domains during tenant onboarding, mergers, or dns migrations. confirm the domain and actor against change management records.
legitimate project collaboration routinely adds owners and editors when teams spin up or staff claude projects. verify the project (`anthropic.audit.resource_id`), role, and available actor fields against expected membership changes.
network or security teams remove ip restrictions during office moves, vpn migrations, or policy redesigns. validate the actor, and confirm replacement restrictions were applied if the control is still required.
organization administrators, identity teams, and compliance reviewers may list users, export members, and view groups during audits, access reviews, or offboarding. confirm the actor and change ticket before escalating.
organizations transfer primary ownership during reorganizations, administrator departures, or vendor transitions. verify both the previous and new owner with internal stakeholders before treating the event as malicious.
penetration tests and red-team exercises that use curl, httpx, or similar clients will match. add temporary exceptions for the engagement window after validation.
planned tenant offboarding, sandbox teardown, or contract termination can produce these events. confirm the actor and timing against change management or offboarding records before escalating.
platform and security teams create compliance-scoped api keys when onboarding the anthropic fleet integration or setting up siem ingestion. verify the actor and confirm the key is in the approved credentials inventory.
platform and security teams delete admin api keys during scheduled rotation or decommissioning. check for a nearby `admin_api_key_created` event or an approved change ticket to explain the deletion.
platform or security administrators disable compliance logging during onboarding, integration testing, or log pipeline migrations. verify the actor, source ip, and whether logging was re-enabled promptly. planned changes can be exempted from this rule.
platform, security, and observability teams create admin api keys during integration setup or scheduled key rotation. verify the actor, `anthropic.audit.scopes`, and whether the creation matches an approved change.
power users, automation engineers, or evaluation scripts that create many short-lived chats during testing can exceed the threshold without malicious intent.
power users, trainers, or documentation owners who intentionally snapshot many chats for sharing, archival, or handoff workflows can exceed the threshold without malicious intent.
security and compliance teams download audit log exports for investigations, regulatory requests, or siem validation. validate the actor and confirm the activity matches an approved ticket.
shared service or automation accounts may receive editor access during content workflows. confirm the assigner and affected project are expected for the workflow; grantee identity may require correlating org membership or `anthropic.audit.target_id` when the api supplies it.
teams enable approved mcp connectors for data platforms, ticketing systems, and internal tools during claude rollouts. validate the server name, actor, and whether the integration matches an approved request.
users browsing many stale or revoked shared chat links during incident response or legal review can produce bursts of access failures. confirm whether the activity matches an approved investigation before escalating.
users or administrators purging old chats during workspace hygiene, retention exercises, or gdpr-related cleanup can exceed the daily threshold legitimately.
users publish artifacts intentionally for demos, documentation, or external collaboration. validate the artifact, actor, and business justification before escalating.