Claude Code and Cowork local sessions now land in the Compliance API

Enterprise admins can now pull on-device prompts, responses and tool calls for audits — closing the gap that left Cowork and CLI sessions off the record.

Nowline AUG 12 4:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • What changed: local sessions stop being off-the-record

    A new `GET /v1/compliance/apps/sessions/local` endpoint returns transcripts of Cowork and Claude Code sessions that run on users' own machines — desktop, web, mobile, CLI and the desktop app. Until now those on-device sessions left no central record.

  • What lands in the transcript

    Records come back consolidated — prompts, responses and tool activity in a single session object, the same shape as claude.ai chats and API traffic. Your agent's file reads, edits and shell commands are in scope, not just the chat text.

  • Who can read it, and what it means for you

    It's Enterprise-only and needs a dedicated Compliance Access Key, not an ordinary Admin key — so a teammate can't browse your sessions, but your org's security and legal teams can, for audits and eDiscovery. If you run Claude Code on a work account, treat local sessions as logged.

  • Why now: the gap the guides flagged in May is closed

    As recently as May, compliance guides warned that Cowork activity "isn't currently captured in audit logs, the Compliance API, or data exports," forcing regulated orgs to build their own on-device proxy. That workaround is now optional.