The new Compliance API is a step up, but it's reactive. Activity logs tell you what happened, not who should have been allowed to do it. To secure Claude Code properly, you need local visibility paired with identity governance: enforce policies on the machine, not just audit after the fact.