Security Protocols for SMBs Adopting Claude
What security leaders at small and medium-sized businesses actually need to know before they hand anyone a Claude license.

Key points
- The Claude Team plan includes SSO; the Compliance API is only available on the Enterprise plan.
- Shadow AI means an unlicensed user may already be running free Claude or a rival tool.
- API key types differ: admin keys start with sk-ant-admin, standard keys with sk-ant-api.
- Enabling Skills can allow malicious code to execute if no review workflow exists.
- Web search inside Cowork acts as a proxy for web traffic, bypassing conventional filters.
What plan are you actually buying?
Start there. Claude Code, Cowork, and Claude Chat are distinct products with distinct risk profiles, and most users will ask for "Claude" without knowing which one they need. Think of it the way Finance thinks about corporate credit cards: not everyone needs one, and spending limits exist for a reason. Stand up an approval process before you provision anything, and keep blast radius in mind from day one.
Shadow AI complicates this. An unlicensed employee may already be using Claude's free tier or a different AI product. Roughly half of employees are using shadow AI tools, with some surveys putting that figure closer to 80 percent. The user without a corporate license isn't automatically the safer one.
Should you enable every feature at once?
No. Risk-rank Claude's features before you touch the settings. Enabling egress carries a visible warning banner inside Claude's admin console; enabling web search or a browser extension does not, and the risk of indirect prompt injection (where a malicious website manipulates the AI's instructions through content it reads) is real. A three-tranche roadmap works well: enable now, enable with additional controls, hold until risk is better understood.
API key management deserves its own tranche. Admin keys (sk-ant-admin) carry more authority than standard API keys (sk-ant-api), and Anthropic's admin settings offer little guidance on issuing or reviewing them. Keep the pool of people who can create keys small, especially early on. We noted the broader credential-management problem Claude's integrations can create when we covered Anthropic's expansion into 28 enterprise security platforms on 28 May 2026.
Who owns the data risk?
You do. Anthropic continuously improves its guardrails, but security responsibility doesn't transfer with the license fee. Enabling Skills, which are mini-workflows Claude can execute, can lead to malicious code running if no review step exists. One approach: use Claude Code to build a "skills auditor" that automatically submits each new skill for review against your internal documentation and Anthropic's best-practice guidance.
Data governance is the harder problem. What goes into Claude and what comes out both need controls, and web search inside Cowork sidesteps traditional content filters entirely. AI outputs can also be confidently wrong, which matters when a user treats a hallucinated answer as fact before anyone checks it. Existing tools can cover some of this gap, but your vendors need to hear the specific problems you're running into.
The honest read on all of this: the security work here is harder than the procurement work, and the procurement work is already confusing. Plan accordingly.



