The short version
As AI moves from answering questions to completing multi-step work, a single access switch becomes too crude. Anthropic’s enterprise guidance describes controls that operate at several layers: who can use a capability, what connector actions are available, how spending is allocated, and what administrators can observe.
The wider lesson is to scale capability and control together. Each layer answers a different operational question and can change independently as a workflow proves useful.
Four layers
Access: Decide which roles or groups need each capability. Broad product access does not imply that every team needs every tool.
Action permissions: Separate reading from writing. A team may need to search approved sources without being able to modify records or send external messages.
Budget: Place usage limits where responsibility sits, such as a group or workflow. This helps teams experiment without making cost invisible.
Operational visibility: Record enough information about tool use, file access, connector activity, and approvals to understand adoption and investigate failures.
Start with the useful minimum
The safest starting point is not zero capability; it is the smallest permission set that still allows the workflow to deliver value. A research group might receive broad read access to approved sources but no ability to modify shared repositories. A finance team might prepare reconciliations while changes to financial systems remain limited to authorized roles.
Observe real usage before expanding. If a read-only pilot consistently produces useful results and the approval path is working, a smaller group can receive carefully scoped write actions. Expansion should follow evidence about the workflow, not a blanket assumption that every capability must be enabled together.
Controls should reinforce one another
Access alone does not limit what a connector can do. Connector permissions do not control spending. Budgets do not explain which workflows create value. Operational records do not prevent an unauthorized action. Treat the layers as complementary rather than interchangeable.
A useful rollout sequence is:
- Define the users and business purpose.
- Enable only the required capabilities and data sources.
- Keep consequential actions read-only, staged, or approval-gated.
- Set a budget appropriate to the group.
- Review usage, outcomes, and exceptions.
- Expand only the layer justified by the evidence.
Example
A document-review team may need Claude to classify and summarize material from an approved repository. Begin with read access and a defined output destination. Keep record modification and external publication unavailable. Measure whether review time and quality improve, then consider a narrow write permission for approved users if it removes a genuine bottleneck.
Practical checklist
- Assign capabilities by role and business need.
- Distinguish read access from write actions.
- Set group-level budgets where useful.
- Preserve operational visibility for important actions.
- Begin with the minimum permission set that delivers value.
- Expand controls separately as evidence supports the change.
- Keep accountable approval for consequential outcomes.
Try it
Choose one enterprise AI workflow. Define its users, necessary read sources, permitted actions, budget owner, important operational events, and the evidence required before any permission expands.