# Monitoring records stay in the customer’s account

[Journal](/journal/)

September 3, 2026 · [evidence](/journal/#evidence)



Anthropic says its misuse controls place activity records in customer-controlled cloud storage for customer review.

![Monitoring record cards travel from a cloud intake rail into a customer-side archive with a key, access gate, and audit ledger.](/_astro/monitoring-records-in-the-customers-account.B4fXJ1m0_Z1VtB9r.avif)

A provider’s misuse monitor should leave its evidence with the buyer. The oversight record should join the records a buyer already holds. Provider monitoring does not require provider custody.

Anthropic reports that [automated misuse detection scans a rolling window of traffic](https://www.anthropic.com/news/enterprise-frontier-safeguards). Detection produces a review lead rather than a provider-held case file.

## The monitoring record belongs beside the workload record

Anthropic says [activity data sits in cloud storage the customer controls, under the customer’s encryption keys, access policies, and audit logging](https://www.anthropic.com/news/enterprise-frontier-safeguards). Those controls place the monitoring record inside the buyer’s existing authority boundary.

Zero data retention means the provider keeps no request data after processing. A useful monitoring control must respect that boundary while preserving enough evidence for the buyer’s own review. Customer-controlled storage resolves that tension by separating detection from provider custody.

## Customer custody sets the review boundary

Anthropic says [customer staff review the flags, while Anthropic staff get no access](https://www.anthropic.com/news/enterprise-frontier-safeguards). This division assigns review and custody to the same organization.

A customer can record who reviewed a flag, what evidence informed the decision, and how the case ended. Those details make an accountable oversight record.

Muniment’s analysis is that this record belongs with the workload’s other operating evidence. Provider monitoring does not require provider ownership of the resulting case history.

## Optional controls still require an ownership decision

Anthropic says [each control is optional and carries no Anthropic charge](https://www.anthropic.com/news/enterprise-frontier-safeguards). Anthropic also says [the phased rollout starts in fall 2026](https://www.anthropic.com/news/enterprise-frontier-safeguards). Availability does not decide whether a buyer should activate a control or how long its records should remain.

Anthropic notes that [cloud providers still bill standard storage and access fees](https://www.anthropic.com/news/enterprise-frontier-safeguards). The customer therefore owns both the evidence and its retention cost. That cost should appear beside the policy decision rather than disappear into a provider feature.

Anthropic is neither a Muniment customer nor an endorser. The useful precedent is architectural. A model provider can operate detection without taking custody of the review record. Oversight becomes one more body of evidence the buyer can retain, inspect, and carry forward.

## Sources

1.  [Anthropic: Enterprise Frontier Safeguards](https://www.anthropic.com/news/enterprise-frontier-safeguards) www.anthropic.com
