- White Papers
How a $300B Investment Firm Secured Enterprise Claude Access With Aembit
TL;DR: A $300B investment firm deployed Claude across its workforce while preserving control over agent access to sensitive financial and Microsoft 365 resources. This case study details how Aembit introduced blended human-agent identity, secretless authentication, runtime policy enforcement and attributable audit logging across MCP-connected services.
A $300B investment firm was preparing to put personalized Claude assistants in the hands of its workforce, with access to Microsoft 365, financial research platforms and other sensitive enterprise resources.
The security team needed to know which agent was acting, whose behalf it was acting on, what it could access and exactly what it did.
This case study examines how the firm used Aembit to secure Claude and its MCP-connected services with blended human-agent identity, secretless authentication, runtime access policy, and attributable audit logging.
What the firm achieved:
- 500+ users secured
- 2 weeks to deploy
- 100% of agent actions logged and auditable
- 100% of enterprise AI agents secured by Aembit
Download the case study to learn how the firm:
- Established distinct, attributable identity for Claude agents acting on behalf of employees
- Replaced long-lived credentials with short-lived, policy-scoped access
- Enforced centralized policy across MCP-connected services
- Integrated agent activity into its existing CrowdStrike security monitoring
- Built an enterprise architecture designed to support broader agentic AI adoption
FAQ
You Have Questions? We Have Answers.
Why did the investment firm need additional security controls for Claude?
The firm planned to give Claude assistants access to financial data, email, calendars, SharePoint and other sensitive resources. Its security team required a way to distinguish agent activity from human activity, eliminate long-lived credentials and manage agent access centrally.
How did Aembit give Claude agents their own identity?
Aembit created a blended identity that incorporates both the employee’s Okta identity and the identity of the Claude agent acting on that employee’s behalf. This allowed the firm to apply consistent access policy while preserving attribution for agent actions.
How did Aembit secure Claude access to MCP servers?
Aembit placed policy enforcement between Claude and connected MCP servers. Access requests were evaluated in real time, with Aembit issuing appropriate downstream credentials or blocking the request before the tool was invoked or data was accessed.
How did the firm eliminate stored credentials for Claude?
Aembit replaced persistent API keys and other stored credentials with short-lived credentials generated when access was required. Token exchange then provided narrowly scoped credentials for the specific downstream service Claude needed to reach.
How did the firm audit Claude agent activity?
Aembit recorded attributable details for each request, including the employee, Claude agent, tool invocation and policy decision. Those logs were forwarded to CrowdStrike SIEM, giving the security team centralized visibility into agent activity.