Eliassen Group
**Overview** Anthropic's Claude is the most capable agentic AI platform on the market, and it creates a control surface most IT and security leaders haven't seen before. Cowork wants admin rights on user devices. Chrome extensions browse with user session cookies. Scheduled tasks run unattended overnight. MCP servers reach into file shares, SharePoint, and mail. The vendor won't tell you what to configure because their incentive is to maximize capability, not minimize your blast radius. This session walks through real enterprise Claude deployments across multiple organizations and unpacks the five decisions that matter most: * **Cowork admin scoping.** Where to draw the line on local device rights, MDM approaches, and the mobile-to-desktop dispatch controls most orgs miss. * **Prompt injection mitigation.** What Anthropic's self-reported \~1% injection success rate on Claude in Chrome actually means, and how to layer defenses without breaking the tool. * **MCP and connector allowlisting.** Read-only enforcement, org-managed vs. self-service registries, and the gotchas across SharePoint, Egnyte, and large mailboxes. * **Scheduled task governance.** The overnight injection loop risk and how to build an approved-pattern model that keeps agents useful without letting them go feral. * **RBAC across the agentic stack.** How to think about roles when skills, plugins, MCP, connectors, Chrome sites, and scheduled tasks all need permission models. For each decision, attendees see what teams with different risk tolerances actually chose, why, and which of those choices are already getting revisited. **What the audience walks away with** * A clear-eyed view of the enterprise Claude control surface and where the real risk sits * A one-page governance decision guide covering all five decisions plus the secondary controls (skills, plugins, network egress, account switching, connector specifics) * Enough context to have a productive conversation with legal, security, and the b
Free
Tuesday, August 18 · 5:30 PM