We had an enterprise customer tell us their entire AI footprint was Copilot. That was the whole answer. One tool, one line item, done.
We ran the first scan. Copilot wasn't even close to number one. Claude was. OpenAI came in second. Copilot was third.
Nobody on the security team knew because Claude doesn't show up the way a SaaS app used to show up. There's no single login screen, no single admin console, no one place to look.
That's the part most security teams miss. Claude isn't one surface. It's six.
The six places Claude actually runs
Claude Enterprise and Connected Apps. This is the surface everyone pictures: employees typing into Claude, OAuth'd into Google Drive, GitHub, Slack, and Jira, asking Claude to act on what's inside. The audit log shows that a connection happened. It does not show what got pulled into the prompt or what came back out. A finance analyst can drop a quarter of board materials into a conversation in ten seconds, and the log has no idea it happened.
Claude Projects. Persistent workspaces that hold files and instructions across sessions. A Project built around one deal or one investigation keeps living long after the deal closes, because nobody owns the cleanup. Give a Project workspace-wide visibility, and a file of test customer records becomes reachable with no data classification step ever running.
MCP servers. Every MCP server carries a credential or an OAuth token scoped to whatever the user authorized. The server itself can be vulnerable. There are public CVEs already, across more than one community implementation. The token can be over-scoped. And prompt injection hidden in tool output can hijack the agent into taking actions it was never asked to take, while the destination system sees nothing but a legitimate, authenticated request.
Claude Code. Shell access, network egress, read and write across a developer's filesystem. It can read .env files and AWS credentials sitting in plaintext on a laptop. Nothing stops it from doing that unless someone has explicitly told it to stop.
Managed Agents. Scheduled, autonomous, and running on a cadence with standing access a human user would never have. An agent with hourly write access to Salesforce, Slack, and a data warehouse doesn't fail quietly. It fails hundreds of actions before anyone reads the alert.
Claude Platform Console. Where engineering creates API keys and deploys agents, entirely outside the chat surface. This is where exposure actually starts most often, and it's the surface almost nobody's security tooling is pointed at.
Six surfaces. Six identity models. Six different failure modes. And there is still no CIS Benchmark, no NIST mapping, nothing close to a standard audit checklist built specifically for Claude, the way there is for practically every other piece of infrastructure your team already governs.
![]() |
| Reco's AI Discovery dashboard, showing Claude and Anthropic ranked among sanctioned applications. |
The risk isn't on any one surface. It's in the combination.
An agent with access to Salesforce and Google Drive looks unremarkable by itself. Now add that its owner left the company last month. Add that the permissions were never revoked. Add that there are no guardrails on what the agent can do. No single one of those three facts is alarming. Together, they're a critical risk sitting in your environment right now, and a tool that only watches one surface will never show you the combination.
We call this toxic combination detection. It's also the reason securing Claude in isolation doesn't actually secure Claude. Attackers don't think on surfaces. They think in access chains: an over-permissioned agent, a stale API key, an account nobody offboarded. Each one looks low priority alone.
![]() |
| A Reco alert detecting a user connecting Claude.ai to the organizational Google Drive. |
What we built
The six mitigations for the six surfaces all assume the same underlying capability: continuous, accurate visibility into where Claude is operating, what it's touching, and which identities are involved. Most security teams have pieces of this picture spread across different tools with no way to correlate them.
Reco discovers every Claude surface across an environment using seven independent sensors: endpoints, network, browser, SSO logs, social logins, connected plugins, and shadow email. Every account gets classified as sanctioned, shadow, or agent. From there, the same graph that maps a Claude identity also maps its access across the other 260+ apps we already cover, so a Claude Project, a Salesforce permission, and a GitHub token show up as one picture instead of three separate tickets in three separate tools.
![]() |
| Reco's Agents Posture dashboard, scoring agent governance across connected apps. |
What I'd tell any CISO mapping this today
You don't need to block Claude, and blocking it doesn't work anyway. What you need is the inventory: every surface, every identity, every credential, tied to an owner. Once that inventory exists, the mitigations aren't complicated. They're the same discipline security teams already run for every other identity in the company. Claude just made the timeline shorter.
We wrote out all six surfaces, the specific risk each one introduces, and the six mitigations that close them in The CISO's Guide to Claude Risk in the Enterprise.
About the Author: Gal Nakash is Co-founder and Chief Product Officer of Reco. He previously served as a Lieutenant Colonel in the Israeli Prime Minister's Office, where he worked as a security researcher focused on the human element of cybersecurity. At Reco, he builds the product that discovers, maps, and governs agents and SaaS identity risk for security teams at Fortune 500 enterprises.
Gal Nakash — CPO and Co-founder at Reco https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuQWbnqXQszfF7Ro1ckEfpJAt4R_6RI4pi_EParenaMvBTPNTZ5vs91QXTU7w_7mZukKntRojMFYpgQRTBFYFTFRnP9zaj8KrlfFrkG8Rwo_GjkEFsNt4pbGhmI2aoJHB-ENuTVLOKGQUDy_hxD3Fiy4dSlhRlnZA5jyqfkyKbUpdUx6ZCD8op9n6uo90/s1700-e365/Gal.png






