Skip to content
Rush Commerce
AI & Automation3 min read

Claude's Activity Feed drops file names — retroactively

Anthropic's Compliance API Activity Feed no longer returns file names or artifact titles, including on records written before the change. Own your audit log.

Anthropic's Compliance API Activity Feed stopped returning file names, project document names, and artifact titles. The change applies to activities recorded before it shipped, too. If your audit trail for AI usage is a periodic pull from that feed, the human-readable half of your history went blank this week.

What actually happened

Per the Claude Platform release notes, dated September 24, the Compliance API Activity Feed no longer returns file names, project document names, or artifact titles. The filename and title fields on file, project document, and artifact activities are now always empty or omitted — Anthropic's wording is explicit that this includes activities recorded before the change.

The IDs are still there. To resolve a name or title from an ID, you make a second call using a Compliance Access Key with the read:compliance_user_data scope.

Read that as a design decision, not a bug. The feed is now identifiers and events; the names sit behind a higher-privilege scope. That is a defensible privacy posture — a file name like Q3-layoff-list-final.xlsx leaks plenty on its own, and a broad feed reader should probably not see it. But it changes the shape of the data you get, and it changed the shape of what you already collected.

Why your AI audit log matters for your business

Here is the part that should get your attention: this was retroactive. Not "new records will omit this field" — records written in July now come back without it as well. If you were treating the Activity Feed as your archive rather than as a source you copy from, you did not have an archive. You had a view into someone else's database, and the schema changed underneath you.

We say a version of this every time a vendor adjusts an export, and it keeps being true: a log you cannot re-read on your own terms is not a log. The fix is unglamorous. Pull the feed on a schedule, write the raw response to storage you control — object storage with versioning is fine, this is not a big-data problem — and do your joins and reporting against your copy. Then a vendor schema change is a thing you notice in a diff instead of a thing you discover during an audit.

Two specifics for anyone rebuilding this now. Resolve names at ingest, not at query time, if your policy allows you to keep them; the ID-to-name lookup exists today but that is a second dependency and a second thing that can change. And treat the read:compliance_user_data scope with real care — it now reads the layer that was deliberately removed from the general feed. That key belongs with your production database credentials, not in a shared automation account that six people can reach.

If you are a ten-person shop wondering whether this applies to you: it applies the first time a client's security questionnaire asks what your AI tools touched and when. That is a much easier week when the answer is a query against your own store.

Key takeaways

  • The Compliance API Activity Feed no longer returns filename or title on file, project document, and artifact activities
  • The change applies retroactively, including to activities recorded before it shipped
  • Names and titles are resolvable by ID using a Compliance Access Key with the read:compliance_user_data scope
  • Copy vendor audit feeds into storage you control — a view into someone else's database is not an archive
  • Guard the read:compliance_user_data scope like a production credential; it reads what the general feed now hides

Is your AI audit trail just an API call you hope still works? We build the ingest-and-retain layer that lands vendor compliance feeds in storage you own, with retention you set. See how we do it.

Sources: Claude Platform API release notes, Compliance API documentation.

  • #compliance
  • #audit-logs
  • #claude-api
  • #ai-governance
  • #data-retention
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.