Anthropic Admin Role Assigned to User
Description
The organization admin role controls organization settings, integrations, membership, and security configuration in
Anthropic Claude for Enterprise. Membership role changes are reported as claude_user_role_updated with
anthropic.audit.current_role. An attacker can promote a compromised or newly invited account to org admin to turn
initial access into durable control-plane access. From admin, they can disable SSO, mint admin API keys for automation,
start data exports, and weaken audit logging. Workspace-scoped role_assignment_granted grants (for example bare
admin on a workspace) are out of scope for this rule.
Query · esql
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "iam") and
event.action == "claude_user_role_updated" and
anthropic.audit.current_role in ("admin", "owner", "membership_admin")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*
Investigation fields
Pivot points the source recommends for triage.
@timestampevent.actionevent.idorganization.iduser.target.iduser.target.emailrelated.useranthropic.audit.current_roleanthropic.audit.previous_roleanthropic.audit.actor.typeuser.emailuser.idsource.ipuser_agent.original
Known false positives
- IT administrators promote users to organization admin during onboarding, staffing changes, or incident response. Verify that the target user should hold org admin privileges, and that a change request exists when policy requires one.
Analyst notes
Investigating Anthropic Admin Role Assigned to User
Org admin can change SSO, API keys, exports, and integrations. This rule matches claude_user_role_updated where
anthropic.audit.current_role is the literal admin (organization membership role — not workspace
role_assignment_granted, not project chat_project:* roles, not rbac_role_assigned).
Unauthorized = no IAM ticket naming the target as org admin, target recently invited from an unexpected domain, or the promotion is followed by key creation / SSO weakening / exports by the same actor or target.
Possible investigation steps
- Identify target (
user.target.id,user.target.email,related.user) and assigner (anthropic.audit.actor.type; foruser_actorcheck email/IP/UA). - Compare
anthropic.audit.previous_role→anthropic.audit.current_roleand check whether the target was invited or otherwise role-changed shortly before becoming admin. - After the promotion, review ~48h of target activity and org IAM (primary owner transfer, admin keys, SSO, exports).
- Close as FP when ticket + job function match. Escalate when the change is untracked or precedes control-plane abuse.
False positive analysis
- Onboarding and IR staffing promotions to org admin are valid — require change request when policy demands one.
Response and remediation
- On unauthorized promotion: revoke org admin (downgrade membership role), rotate credentials for assigner and target, audit admin API keys and integration changes for the organization.