Table of Contents

Abstract 04
White Papers

How a $300B Investment Firm Secured Enterprise Claude Access With Aembit

TL;DR: A $300B investment firm deployed Claude across its workforce while preserving control over agent access to sensitive financial and Microsoft 365 resources. This case study details how Aembit introduced blended human-agent identity, secretless authentication, runtime policy enforcement and attributable audit logging across MCP-connected services.

Aembit Team

Product & Research

Published Aug 2026

Updated Sep 2026

50:1

Non-human to human identities

18

Agent threat classes mapped

0

Long-lived secrets required

IAM for Agentic AI: Aembit’s Approach to Closing the AI Identity Gap - whitepaper cover
No form · instant

Download the Case Study

Free PDF · no email required

Table of Contents

A $300B investment firm was preparing to put personalized Claude assistants in the hands of its workforce, with access to Microsoft 365, financial research platforms and other sensitive enterprise resources.

The security team needed to know which agent was acting, whose behalf it was acting on, what it could access and exactly what it did.

This case study examines how the firm used Aembit to secure Claude and its MCP-connected services with blended human-agent identity, secretless authentication, runtime access policy, and attributable audit logging.

What the firm achieved:

Download the case study to learn how the firm:

FAQs

You Have Questions? We Have Answers.

Why did the investment firm need additional security controls for Claude?

The firm planned to give Claude assistants access to financial data, email, calendars, SharePoint and other sensitive resources. Its security team required a way to distinguish agent activity from human activity, eliminate long-lived credentials and manage agent access centrally.

Aembit created a blended identity that incorporates both the employee’s Okta identity and the identity of the Claude agent acting on that employee’s behalf. This allowed the firm to apply consistent access policy while preserving attribution for agent actions.

Aembit placed policy enforcement between Claude and connected MCP servers. Access requests were evaluated in real time, with Aembit issuing appropriate downstream credentials or blocking the request before the tool was invoked or data was accessed.

Aembit replaced persistent API keys and other stored credentials with short-lived credentials generated when access was required. Token exchange then provided narrowly scoped credentials for the specific downstream service Claude needed to reach.

Aembit recorded attributable details for each request, including the employee, Claude agent, tool invocation and policy decision. Those logs were forwarded to CrowdStrike SIEM, giving the security team centralized visibility into agent activity.

Continue Exploring

Our learning center features all the latest resources to deepen your understanding of securing workload access, including how-to guides, videos, webinars, and more.

Aembit and CrowdStrike AIDR data sheet for AI agent identity, access control, and content inspection share image

Aembit + CrowdStrike AIDR for AI Agent Security

Aembit and CrowdStrike AIDR combine AI agent identity and MCP access controls with real-time content inspection and enforcement.
Auditing and Governance for Workload and AI Agent Identity

Auditing and Governance in Modern Identity

Aembit turns workload and AI agent access activity into detailed audit trails, policy insights, and operational visibility.
A $300B Investment Firm
Secures Claude Access with Aembit

How a $300B Investment Firm Secured Enterprise Claude Access With Aembit

See how a $300B investment firm secured Claude for 500+ users with governed MCP access, secretless credentials, and full auditability.