LoFP LoFP / shared service or automation accounts may receive editor access during content workflows. confirm the assigner and affected project are expected for the workflow; grantee identity may require correlating org membership or `anthropic.audit.target_id` when the api supplies it.

Techniques

Sample rules

Anthropic Sensitive Claude Project Role Assigned to User

Description

Detects when a Claude project owner or editor role is granted through a role_assignment_granted event. Project owners and editors can access project chats, artifacts, and knowledge bases that may hold sensitive data. An attacker with organization access can grant these roles to persist access to high-value project content without holding organization admin privileges.

Detection logic

data_stream.dataset: "anthropic.audit" and
    event.category: "iam" and
    event.action: "role_assignment_granted" and
    user.target.roles: ("chat_project:owner" or "chat_project:editor")