Skip to content

Docs · Claude · Standard

Claude workspace standards for a regulated firm: models, projects, skills and spend

For it, compliance and operations leads standing up claude enterprise at a regulated firm.

Short answer

A baseline configuration for a Claude Enterprise workspace at a regulated firm: a sticky default model with higher-intensity models by role, project sharing on but public projects off, skills publishing set to Requires review with security scanning, tiered spend limits with the documented alerts, and a retention period set for both chats and projects.

Scope

This standard covers a Claude Enterprise workspace at a financial services or other regulated firm. It sets the minimum configuration for models, projects, skills, spend and retention before the workspace is opened to staff. Settings are described as they appear in Organization settings; anything we could not verify in Anthropic's documentation is left out.

The Enterprise plan is the baseline because it carries SCIM, audit logs, custom data retention controls, the Compliance API and customer-managed encryption keys. On Enterprise, usage is billed at API rates from a shared organizational pool with no per-seat token allowance, so the spend section below is not optional.

Models standard

  • Set an org default model and make it sticky. Admins can enable or disable models org-wide, set default models and effort levels, and turn on a sticky default so new conversations start on it. The consumption guide ranks token intensity as Haiku low, Sonnet moderate, Opus high and Fable very high.
  • Default to a moderate-intensity model for general staff. Grant higher-intensity models to named roles (research, engineering, leadership support) through custom roles rather than org-wide.
  • Cap effort by role. Effort is the second cost lever; set a default and a maximum per role.
  • Review the model list quarterly. New models arrive enabled or disabled depending on your settings; the review confirms the default still fits the use cases and budget.

Projects standard

  • Keep Share projects on, turn Public projects off. Both are on by default under Data and privacy. With Public projects off, existing public projects become private, staff can still share with named users and groups, and nothing becomes visible to everyone by accident.
  • Use role-level sharing control on Enterprise to limit which roles can share projects at all. Changes can take up to 15 minutes to apply.
  • Name projects by business purpose and data class. A project holding client data should say so in its name and instructions so the retention rule below applies without debate.
  • Put firm context in project instructions, not in chat. Style rules, disclosure language and approved sources belong in project knowledge where they're versioned and shareable.

Skills standard

  • Prerequisites. Skills require cloud code execution and file creation to be on. Confirm that decision with security before enabling skills at all.
  • Set Publishing to Requires review. Per the skills provisioning article, Enterprise organizations default to Off, and organizations that haven't set a preference switch to Requires review on October 2, 2026. Requires review means an owner approves each submitted skill and each later version, and reviewers can't approve their own.
  • Turn on security scanning. Scan results are pass, risk or malicious; a blocked skill can't be overridden by its uploader. Scanning isn't available for customer-managed key, zero data retention or HIPAA configurations, so plan manual review there.
  • Provision firm skills from the owner account so they reach everyone and users can toggle but not delete them. Scope specialist skills to groups through plugins.
  • Decide on user-created skills explicitly. The User-created skills toggle is the main switch; custom roles also need the Create skills capability. Our default for regulated firms is on for a pilot group, off for everyone else until the review process has run for a quarter.
  • Know the HIPAA trade-off. In a HIPAA configuration, skills and user-created skills turn off and group sharing is unavailable.

Spend standard

ControlOur defaultWhy
Organization limitSet, but well above expected spendHitting it stops everyone at once
Group or seat-tier limitsPer-user monthly amount for every groupThe documented starting point; 4-6 groups is the suggested range
Individual capsTiered: light, standard, powerIndividual limits always override group limits
Multi-group precedenceLower limit winsConservative default for a new workspace
AlertsLeave org alerts at 75% and 90%; route to finance and the adminBuilt-in thresholds
ReportingMonthly spend CSV by user and model, kept with the budget fileExport covers up to 90 days per request

Limits reset at 00:00 UTC on the first of the month. If no limit exists anywhere, spend is uncapped. Usage-based plans stop a user's access when a limit is reached until the period resets or an admin raises it, so pair caps with a fast approval path for genuine needs.

Retention standard

  • Set a retention period. By default data is retained indefinitely. Only an Owner or Primary Owner can set a period, the minimum is 30 days, and deletion is permanent.
  • Set a project period as well as a chat period. Project retention overrides chat retention for chats inside a project, and projects default to indefinite, so a chat-only setting leaves project chats in place.
  • Match the period to your records policy, and remember these settings cover chats and projects only, not every Claude surface.
  • Use the audit log. Retention changes, deletions and skill sharing events are logged; sample them in your quarterly review.

Sign-off

Before launch, the admin, compliance and finance owners each confirm their section above in writing. Revisit the whole standard when Anthropic changes defaults (the skills publishing change on October 2, 2026 is one such date) or when the firm adds a new surface such as Claude Code or Cowork.

Official documentation

Frequently asked questions

Can we stop staff from running up a large Claude bill?

Yes. On usage-based Enterprise plans, owners set spend limits at the organization, group or seat-tier, and individual level, and individual limits always override group limits. When a user hits a limit their access pauses until the month resets or an admin raises it. Anthropic's guidance is to rely on group and individual caps rather than the org ceiling, because hitting the org limit stops everyone. Alerts fire at 75% and 90% of the org limit.

Should we let employees build their own Claude skills?

Only with review. Set Publishing to Requires review so an owner approves each skill and each new version, turn on security scanning where your configuration allows it, and provision firm-approved skills from the owner account. Keep user-created skills on for a pilot group first. Note that HIPAA configurations turn skills off entirely, and scanning isn't available for customer-managed key, zero data retention or HIPAA setups, so those need manual review.

Salesforce, HubSpot, Anthropic and OpenAI change their products often. Check the official documentation before you rely on a specific setting, limit or price.

Last reviewed October 10, 2026 by the Vantage Point team. Browse all docs