Security1 distinct publisher3 min readPublished
The new local session transcript endpoints close a gap that stood before August 2026, though a transcript only records what an agent did on a developer's machine, not whether that access was ever granted to it.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Start with where the code actually runs. The model sits in Anthropic's cloud and keeps no state between turns; the harness on the developer's laptop is the component that executes bash, authenticates to third parties and opens MCP connections [6]. A transcript retrieved from the cloud side therefore describes decisions, while the credential use those decisions caused happened on a host the API never touched. The source article states the limit directly: activity logs alone cannot tell you whether an agent's access is legitimate [2].
Endpoint tooling does not close that gap either. Local telemetry surfaces processes, files and configurations no cloud service can see, but it produces evidence rather than a governance model, and it cannot bind an agent's activity to an owner, an intent, a credential or a permission [9]. Combine the cloud transcript with the endpoint sensor and the record of activity is fairly complete, but nothing in either one establishes who authorized it.
The survey figures repay a little arithmetic. In a Token-commissioned Cloud Security Alliance survey of 418 IT and security professionals, 68 percent rated their visibility into AI agents as high [7], and 82 percent had discovered an agent in the previous year that security, IT or governance did not know existed [8]. Those two groups cannot be separate populations. 68 plus 82 is 150, so at least 50 percent of respondents fall in both, roughly 209 of the 418, people who called their visibility high and were surprised anyway [10]. Token Security commissioned that survey, and Token Security also supplied the 68.6 percent local-agent share from its own discovery data [5][7], so both numbers come from a company selling into the gap they describe. This is one article, published by The Hacker News [15].
Enforcement, for now, is the managed-settings record: a JSON file on Mac and Linux, registry records on Windows, taking precedence over global, project and user settings so a baseline applies to every Claude Code session in the organisation [11]. Enterprise-plan customers apply policy through a GUI; everyone else writes the record across endpoints with MDM [12]. The published rule set includes allow and deny lists for specific MCP servers, regexes over bash commands, and disabling skills [13]. Those are host controls that constrain what a harness may attempt, but they say nothing about which tokens, SSH keys and cloud profiles are already sitting on the box, and there is no central console that reconciles local configuration, identity and runtime in one place [14].
This is not an exploited flaw, and there is no CVE, no named actor, no campaign attached to it. What exists is an agent that reads files, runs shell commands and calls MCP tools using whatever credentials the developer already holds [3], now with a documented trail where before August 2026 the native controls saw very little [4]. That trail makes the entitlement review possible, but someone still has to carry it out.
Ranked by verification strength, evidence, and original report placement.
Anthropic's new Compliance API includes local session transcript endpoints that give security teams their clearest view yet into Claude Code activity.
Before August 2026, Anthropic's native controls had limited visibility into what Claude Code agents were actually doing, forcing teams to use third-party extensions to achieve minimal governance.
Local agents account for 68.6% of the AI agents Token Security discovers in customer environments, and they often inherit the employee's credentials, network position and permissions.
The account is published by thehackernews.com under the headline "Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance".
Activity logs alone cannot tell you whether an agent's access is legitimate.
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer's machine.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
build
255 tools, 71,929 tokens: the standing charge hidden in your MCP config1 distinct publisher
leadership
Anthropic's own telemetry: 93% of permission prompts approved. Budget for blast radius, not reviewers1 distinct publisher
build
When the changelog reaches for your README's word: MCP memory and the price of filling a gap1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One byline, delivered twice
Everything load here traces to a single author writing for a security vendor and published by The Hacker News, then republished to us through a tracked link. The product mechanics are the sturdiest part — managed-settings precedence, the JSON-versus-registry split, the three transcript block types — precisely because Anthropic's documentation could confirm them, yet nothing in this reporting cites it and the August 11 date rests on the author's word alone. The numbers are the weakest part: 68.6% comes out of Token Security's own scanning, and the survey behind 68% and 82% was paid for by the same firm.
Shipped; nobody counted the users
There is a real shipping event with a date on it, and a vendor's claim about how many agents it trips over in the field. What is entirely absent is anyone actually pulling these transcripts: no named enterprise, no volume, no Anthropic figure, not even the author's own customers described as consumers of the new endpoints. The 82% who found an agent nobody sanctioned tells you the underlying problem is widespread; it says nothing about whether the fix is in use.
Marketing that argues with itself
'Clearest view yet' is the author's own phrase, and the survey is arranged so the exit is a layer his employer sells. What keeps the overstatement modest is that the piece undercuts its own headline: a transcript records what an agent did, never whether the access was granted; managed settings are called a boulder in a river; EDR is called evidence, not governance. Self-aware promotion is still promotion, but the caveats are load-carrying rather than decorative, and the gap sits closer to aligned than to inflated.
The survey's buyer holds the pen
Token Security commissioned the Cloud Security Alliance survey that establishes the problem, supplies the discovery statistic from its own scanning, and arrives at a conclusion — you need an endpoint layer that ties each agent to its owner, credentials, intent and permissions — that is a description of what it sells. The Hacker News runs it under its masthead with the author's affiliation legible in the sourcing but no opposing voice, and Anthropic, whose product is being graded, never speaks.
Plausible, unverified, uncontested
The architecture story hangs together and matches how a stateless model plus a local harness would have to work, which is why the mechanics deserve provisional trust. But two entries here are one text, no second newsroom has touched it, the platform vendor is characterised rather than quoted, and the most quantitative claims are the ones only the author's employer can see. Enough to act on for policy hygiene; not enough to cite as a market fact.