A realistic early morning in a small UK company office: an IT administrator, seen from behind, reviews Microsoft 365 access settings on a laptop while a colleague waits beside them with a notebook. Sh

Checks before giving Claude access to company systems

9 min read

Approve Claude for a defined task, named users and limited data before connecting company systems. Test document permissions, executable tools, write actions and access removal before expanding the rollout.

Written by Kate Bennett Group CEO, Compare the Cloud

A UK company should approve Claude access for a defined task, named users and a limited set of data before connecting business systems. Start with reading, then approve changes separately after testing permissions and recovery. The distinction matters because Anthropic’s Microsoft 365 connector supports write actions when enabled, while Claude Code permissions depend on its operating mode and configuration. Neither product should receive unrestricted access simply to make a pilot easier.

Define the access your business actually needs

Write an approval statement before installing anything. For example, a hypothetical engineering consultancy might permit its support team to search approved equipment manuals, while excluding customer contracts, personnel records and source-code repositories.

That statement gives the administrator a testable boundary. “Help staff work faster” does not identify which documents Claude needs, what it may change or who accepts responsibility for mistakes.

Separate the proposed access into three routes.

RouteWhat the supplied documentation establishesRecommended approval boundary
Microsoft 365 connectorUses the member’s existing access to SharePoint, OneDrive, Outlook and Teams; write actions depend on administrator enablement. DocumentationNamed users, reviewed document permissions and an explicit decision on each write capability
Claude CodeReads files and can edit or execute commands according to its permission configuration. Security documentationA selected repository, restricted credentials and a recorded permission mode
Custom business-system connectionModel Context Protocol, or MCP, servers can expose tools, databases and APIs to Claude Code. MCP documentationAn approved server operator, limited backend permissions and an agreed tool list

For a small business without a dedicated administrator, make configuration, testing and access removal explicit deliverables in the IT provider’s work order. Retain an internal owner who can decide whether a requested expansion serves the original business task.

Checks before Claude access
Approve a defined task and test each access boundary before expanding the pilot.

Resolve data handling before connecting sensitive records

The supplied evidence supports an access-control guide, but it does not establish complete contractual terms for retention, model training, international transfers or UK data residency across every Claude deployment. Obtain the applicable terms before approving confidential or personal information.

Ask procurement or the person responsible for data protection to record:

  • Which Claude product, account type and inference provider will process the information.
  • What happens to prompts, retrieved documents, outputs, logs and backups.
  • Whether information may be used for model training under the selected terms and settings.
  • Where processing occurs, who else processes the data and how deletion works.
  • Whether customer confidentiality agreements permit the proposed use.

Anthropic says its Microsoft 365 connector retrieves content on demand and does not cache file content. That is a statement about the connector’s operation, not sufficient evidence for a conclusion about every downstream copy, conversation record or processing location.

Treat missing answers as a reason to narrow the pilot to synthetic or non-confidential material. Do not treat successful sign-in as approval to process customer records.

Assign responsibility at every access boundary

For Microsoft 365, the documented route involves a user signing in, an Anthropic-hosted connector and access to Microsoft services through delegated permissions. Anthropic manages the connector’s credentials in its backend infrastructure. Microsoft 365 connector security guide

Use the following responsibility map as a proposed operating arrangement.

BoundaryAccountable personEvidence to retain before launch
Business purpose and document selectionDepartment or data ownerApproved task and excluded information
Claude account and organisation settingsClaude administratorApproved account route and enabled connectors
Microsoft identity and consentMicrosoft 365 administratorAssigned users, granted permissions and access-test results
Repository and execution environmentEngineering leadSelected repository, permission rules and available credentials
Custom connector and backend systemApplication owner or contracted providerServer operator, tool inventory and backend access scope
Review and incident responseNamed operational ownerReview procedure, escalation contact and tested shutdown steps

One person may fill several roles in a smaller company. The important requirement is that each decision has an owner and each connection has someone who can disable it.

Check document permissions before Microsoft 365 consent

Begin with ordinary staff accounts, not the administrator account used to grant consent. Because the connector uses existing Microsoft 365 access, an over-permissioned employee account creates an over-broad starting point for Claude. Delegated access model

Review shared libraries and groups before the pilot. Use harmless test documents to check that a pilot user can retrieve an approved document and cannot retrieve a deliberately restricted one. Include both search and direct retrieval where the enabled tools support them.

Restrict who can connect as well as what they can read. Anthropic documents group-based Conditional Access and an “Assignment required” setting on both Claude applications as ways to limit connector access. Microsoft 365 connector security guide

Test Conditional Access through an actual connector request. Anthropic reports that later requests originate from its servers and can carry the device record from the original connection, rather than the device currently in use. A successful test in a normal Microsoft 365 browser session therefore does not establish how the connector behaves. Conditional Access behaviour

Keep write tools disabled during the initial document-search pilot. Enabling them requires the additional consent and configuration described in Anthropic’s administrator setup guide. Approve that expansion only after testing the intended action and its recovery procedure.

Restrict source-code access and executable tools

Start Claude Code in the selected repository with only the credentials needed for the task. Exclude production credentials, unrelated client repositories and confidential exports from the pilot environment.

Do not mistake the working directory for a complete read boundary. Anthropic says Manual mode prompts before its Read, Grep and Glob tools access paths outside that boundary, but read-only Bash commands have broader access unless sandbox restrictions are configured. Its documented sandbox read restrictions apply only when sandboxing is enabled. Claude Code security controls

Choose the permission mode deliberately. Manual mode asks before file modifications and most shell commands; auto mode uses a classifier to review actions instead of the user. Accept Edits mode automatically approves specified file operations within the working directory. Permission modes and protections

Inspect effective rules with `/permissions` before testing. Anthropic documents persistent approvals for some commands and domains, so yesterday’s “don’t ask again” choice can affect today’s session. Permission management

Require a developer to review the resulting diff and relevant test results before merging or deploying. If a pilot is intended only to explain code, do not provide deployment credentials or approve write tools to overcome a blocked request.

Inspect business-system connectors individually

Approve each MCP server as a separate integration. Record its operator, hosting location, authentication method, exposed tools and the backend account it uses.

A connector’s availability does not make its entire tool catalogue suitable for the pilot. Anthropic’s Messages API MCP connector supports enabling or disabling individual tools, including allowlists and denylists. That is an API-specific control; check the equivalent controls on the Claude surface being deployed. Messages API MCP connector

For a customer-management system, a sensible initial scope might allow searching selected records while excluding deletion, bulk export and outbound messages. Enforce those limits through the connector and backend permissions wherever possible, then test them with synthetic records.

Include a harmless prompt-injection test. Place an instruction in a test document asking the assistant to disclose a synthetic secret or perform an unauthorised action. The expected result is refusal or an enforced block, with no real data movement. Anthropic’s MCP guidance explicitly identifies external content as a prompt-injection risk; treat this test as one check, not proof against every attack.

Budget for administration as well as subscriptions

Individual subscription prices provide a spending reference, but they do not establish the cost of an organisation-managed rollout.

The supplied 28 September 2026 Anthropic pricing extract lists Pro at US$20 per month when billed monthly and Max from US$100 per month. These are individual-plan prices, exclude applicable tax and remain subject to usage limits. They are not GBP quotations or equivalent usage allowances; the extract does not establish UK VAT treatment.

Request the applicable business-plan quotation and budget separately for:

  • Document-permission cleanup and identity configuration.
  • Connector setup, testing and maintenance.
  • Staff training and output review.
  • Monitoring, incident investigation and access reviews.
  • Additional usage and the work required to remove integrations.

Do not present the subscription subtotal as total cost of ownership. For this decision, administrator time and the ability to enforce policy belong in the purchasing assessment.

Rollout and recovery checklist

Complete these checks before expanding beyond the pilot.

  • [ ] Record the task and owner. The approval names the users, systems, permitted actions and excluded information.
  • [ ] Approve data handling. The responsible person has accepted the applicable terms for the intended data.
  • [ ] Confirm the account route. Pilot users authenticate through the approved organisation or provider.
  • [ ] Capture the starting configuration. Retain granted permissions, connector settings and Claude Code rules so changes can be reversed.
  • [ ] Prepare recovery before allowing writes. Confirm backups or version history and test restoration on disposable material.
  • [ ] Test permitted and forbidden reads. An approved document is accessible and a restricted test document remains inaccessible.
  • [ ] Test changes separately. An authorised change succeeds on a test record; an excluded action is blocked.
  • [ ] Test malicious document instructions. Synthetic content cannot trigger the excluded action in the agreed test.
  • [ ] Train pilot users. Each user demonstrates how to review an action, reject it and report unexpected access.
  • [ ] Rehearse shutdown. Disable the connection or revoke the relevant access, then confirm that a fresh retrieval attempt fails.
  • [ ] Approve expansion from recorded results. The owner reviews failures and unresolved questions before adding users or data.

If a test fails, pause that access route and inspect the effective permissions before adding broader privileges. For Microsoft 365, Anthropic documents organisation-level disabling and capability-specific permission revocation. Connector access restrictions

Warn affected users before revoking a shared integration. Removing access is a containment step; separately inspect and restore any records already changed.

Editorial analysis

The most useful acceptance question is whether an ordinary employee account can complete the approved task while failing to retrieve excluded information or perform excluded actions.

That gives a UK small or mid-sized business a concrete purchasing test. Choose the account, configuration and support arrangement that can demonstrate those boundaries and sustain them when staff leave, permissions change or new tools become available. Expand access when the evidence supports the next task.

Sources

Data & Insights

Individual Claude monthly subscription prices in US dollars

Pro monthly billing and the starting Max monthly price from the supplied 28 September 2026 pricing extract, excluding applicable tax and offering different usage allowances.

Individual Claude monthly subscription prices in US dollarsPro monthly billing and the starting Max monthly price from the supplied 28 September 2026 pricing extract, excluding applicable tax and offering different usage allowances.020406080100Pro billed monthlyPro billed mont…Max starting monthly priceMax starting mo…Pro billed monthly, US dollars per month: 20Max starting monthly price, US dollars per month: 100
View the data
Individual Claude monthly subscription prices in US dollars
CategoryUS dollars per month
Pro billed monthly20
Max starting monthly price100
Source: Anthropic

Frequently Asked Questions

Can Claude read everything in our Microsoft 365 tenant?

Anthropic says the connector uses delegated access and can read or change only what the signed-in user can already access. That can still be extensive, so test ordinary accounts against approved and restricted documents before rollout. Microsoft 365 access model

Is the Microsoft 365 connector read-only?

No. Administrators can enable write tools for actions including sending email, updating files and sending Teams messages. Confirm the actual configuration rather than assuming a document-search connection cannot make changes. Microsoft 365 capabilities

Does Claude Code ask before reading source files?

In Manual mode, reads within its working directory and additional directories do not require approval. Other tools and permission modes have different behaviour, so inspect the effective rules and test the intended boundary. Claude Code permissions

Can we use individual Claude subscriptions for company access?

The Microsoft 365 connector is available on individual plans, subject to tenant consent. However, Anthropic’s individual-plan pricing table lists no central administration, role-based access or audit logs, so availability alone does not establish suitability for your control requirements. Connector prerequisites and plan administration features

Does the connector keep all processing inside Microsoft 365?

The security guide describes an Anthropic-hosted integration that retrieves content on demand without caching file content. That description does not establish that all processing remains inside Microsoft 365 or in the UK; obtain the applicable processing terms before approving sensitive records. Connector architecture

What should we do if Claude accesses something unexpected?

Pause the affected integration and preserve the details needed to investigate the account, permissions and requested action. Anthropic documents disabling the Microsoft 365 connector and revoking specific permissions; verify the shutdown with a fresh access attempt and review any changes already made. Revocation controls