Anthropic Compliance organization admin invite sent

This rule is part of a beta feature. To learn more, contact Support.
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detects when a user sends an Anthropic organization invite with an administrative role (admin, owner, primary_owner, or membership_admin).

Strategy

This rule monitors Anthropic Compliance activities for org_user_invite_sent with @invited_role set to an administrative role. Anthropic’s Console does not emit a discrete “role change” activity for new members, so invite-sent is the earliest signal of intended privilege escalation.

Triage and response

  • Verify whether the invite sent by {{@usr.email}} to {{@invited_email}} is authorized.
  • Examine the inviting user’s recent activity for signs of compromise (suspicious IP login, MFA-bypass attempts).
  • Check whether the invited email address belongs to a legitimate organization member or a newly added external domain.
  • Determine if the inviting user has appropriate authority to grant administrative access.