LoFP LoFP / legitimate project collaboration routinely adds owners and editors when teams spin up or staff claude projects. verify the project (`anthropic.audit.resource_id`), role, and available actor fields against expected membership changes.

Techniques

Sample rules

Anthropic Sensitive Claude Project Role Assigned to User

Description

Detects when a Claude project owner or editor role is granted through a role_assignment_granted event. Project owners and editors can access project chats, artifacts, and knowledge bases that may hold sensitive data. An attacker with organization access can grant these roles to persist access to high-value project content without holding organization admin privileges.

Detection logic

data_stream.dataset: "anthropic.audit" and
    event.category: "iam" and
    event.action: "role_assignment_granted" and
    user.target.roles: ("chat_project:owner" or "chat_project:editor")