A blocked security task may indicate your account lacks the right Access. Access requires a clear scope of authorized work.
What changed on October 6
Anthropic’s October 6 announcement expands the Cyber Verification Program into three tiers. Defense Access covers defensive security work. Red Team Access adds authorized adversarial testing. Specialized Access is limited to verified organizations working on higher-consequence systems.
Anthropic describes individual researchers with a vulnerability-reporting track record among possible Defense applicants. Red Team Access is currently for organizations. Eligibility does not guarantee approval.
Match the application to authorized work.
Start with the systems you own or have explicit permission to test. Record the task and the responsible organization. Describe the expected output without including credentials or unnecessary sensitive details.
- Identify the legal owner of the systems.
- Document authorization for the proposed testing.
- Select the tier that matches the task.
- List the security controls your team can demonstrate.
- Review retention terms with the data owner.
- Confirm the supported provider and workspace configuration.
These are preparation steps, not a substitute for Anthropic’s application requirements. Do not use the program as a route around a system owner’s restrictions.
Check data retention separately.
Anthropic says the program requires data retention, with specified exceptions and a planned Enterprise Frontier Safeguards option. Review the terms that apply to your organization today. A future option does not establish that it is available for your current project.
Before uploading security material, classify it. Source code, incident records, and customer data can have different handling rules. Resolve a retention conflict before moving the task into a new service.
Approval and task success are different.
Anthropic’s announcement describes review periods and additional controls for the higher tiers. Its evaluations are company-reported results. They do not certify that a model will finish your task correctly or that a proposed fix is safe to deploy.
Keep a human reviewer responsible for the result. Validate findings and test patches within the approved environment. A more permissive tier does not remove that responsibility.
Prepare the workspace after approval.
Our human re-authentication guide covers safeguards around consequential actions. The Sonnet guide addresses a separate model and pricing decision.
Which access requirement would your team need to resolve before submitting an application?