Anthropic expands CVP: three access tiers for security teams
The updated Cyber Verification Program separates defence, authorised testing and specialised access. Prepare data boundaries, permissions and oversight before rollout.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 7 October 2026
- READING TIME
- 5 min read
- TOPIC
- AI Security
On October 6, Anthropic announced an expanded Cyber Verification Program. It offers verified security professionals advanced cyber capabilities with reduced classifier blocking. Defense Access covers defensive work, Red Team Access authorised testing, and Specialized Access selected organisations testing systems where failures could have particularly serious consequences. The two higher tiers are for organisations.
Breachroad recommends defining the use case, data boundaries and approval process before expanding access. A provider’s decision to grant an access tier does not replace the system owner’s permission to test or your organisation’s own rules.
Who should review the change
This announcement concerns SOC teams, incident responders, application security teams and the people responsible for workplace AI adoption. A manager should be able to connect each employee’s access to an actual task. “Security work” is too broad a description to justify giving every team member the same permissions.
Our proposed starting point is one specific need: assistance with sanitised alert analysis, for example, or review of a section of your own code. Record the expected output, the person reviewing the answer and the conditions for stopping work. Then consider integrations that can read repositories, retrieve files or perform operations in other tools.
A model can assist with an analysis, while the organisation still needs someone accountable for the decision. Your internal procedure should identify who checks the evidence, who approves a change and who responds when an answer includes an unauthorised instruction or exposes information beyond the task’s scope. Those responsibilities should remain clear when more employees gain access.
Provider requirements and data boundaries
The programme documentation specifies one application per organisation and continued application of the usage policy. For Defense Access, it sets December 15, 2026 as the deadline for phishing-resistant MFA and moving away from API keys. It also describes CVP data retention and ZDR exceptions for qualifying organisations with Fable or Mythos access.
Breachroad’s practical conclusion is to confirm the terms for your particular account and access channel before supplying incident data. The information owner should decide what may be shared, whether it needs sanitising and where the output will be kept. A general product description should not be treated as confirmation of your own contractual terms.
A useful starting point is a table of permitted data types: a synthetic example, organisation-owned code, logs with secrets removed and client material requiring separate approval. Give each type an owner and a handling rule. This helps an employee decide what to do before pasting material into a tool, rather than trying to correct a disclosure afterwards.
Assess model access and tool permissions separately
In our assessment, choosing a CVP tier should be accompanied by a review of integrations. Someone authorised to analyse an alert does not necessarily need access to an entire disk or permission to change production configuration. Give tools only the access required for the agreed task and identify actions that require human approval.
If you use connectors or MCP servers, review MCP security boundaries as well. Check the process account, available resources and the ability to disconnect the integration. Evaluate a model’s answer alongside its source material, especially when it informs a decision to block an account or change an application.
An example decision before a pilot
Imagine an organisation that wants to help analysts organise incoming reports. In this illustrative scenario, the team starts with sanitised examples and manual review of answers. The data owner approves the information scope, an administrator gives selected analysts access and the team lead establishes how errors will be reported. They consider production integration after evaluating the pilot.
This is Breachroad’s proposal, rather than a requirement announced by Anthropic. It tests the working process before widening permissions. Our cybersecurity and secure AI training for organisations can help teams practise data assessment, action approval and answer verification using examples relevant to their work.


