Know what happened with Claudebefore someone else asks.
When an incident, audit or data request touches AI tools, OpenWatch gives security and privacy teams the sessions, citations and ticket trail to answer it, without asking every employee to explain.
The questions land on you.The data sits everywhere.
01
Vendor data is split
Transcripts, cost and activity come from different Anthropic APIs, each with its own key and schema.
02
Local sessions go unrecorded
Some Claude Desktop and Cowork work never reaches a vendor log at all.
03
Requests need proof
Access and erasure requests, audits and incidents all expect evidence, on a deadline.
Scenarios
What security teamsuse OpenWatch for.
How OpenWatch answers
Open the session's audit trail: prompts, tool calls with their outcomes, errors and the documents it referenced, attributed to the person signed in.
How OpenWatch answers
Open an access or erasure request with its 30-day deadline, cite the sessions and chats involved, and record the attestation on close.
How OpenWatch answers
Claude reviews recent prompts against your written policy every morning and files a ticket for each likely breach, citing the messages.
What your team gets.
- One place to lookDevice sessions, claude.ai activity and billed usage side by side.
- Evidence on every findingTickets cite the messages, sessions and records involved.
- Deadlines tracked30 days for access and erasure, 3 for anomalies and policy findings.
- Nothing blocked, nothing writtenOpenWatch reads Claude's data and never changes what people do.
Security model
Designed to be reviewedby people like you.
Secrets redacted on the device
API keys, private keys, tokens and password values are removed before upload.
Encrypted uploads
Each upload from a laptop is encrypted with AES-256-GCM over HTTPS.
Read-only by design
OpenWatch reads Claude's data. It never writes to Claude or blocks your people.
Entra sign-in and roles
People see their own activity. Admins see the organisation.
Append-only evidence
Ticket events and citations are added, never edited.
In your cloud account
Attri deploys and runs OpenWatch inside your own cloud subscription.
Questions from security teams
Can OpenWatch block risky prompts?
No. It records and reports. Blocking isn't part of the product.
Does it find unapproved AI tools?
Not today. It covers Claude: Desktop, Cowork, Claude Code inside Desktop, and claude.ai.
Where does collected data go?
To your OpenWatch deployment in your own cloud account, encrypted in transit from each laptop.
Can we review the code?
The REST API and MCP server are open source under Apache 2.0. The collector and managed backend are provided by Attri as part of a deployment.
Someone will ask what happened.Have the answer ready.
Run OpenWatch on sample data in minutes, or have Attri deploy it inside your cloud with live data from your organisation.