> For the complete documentation index, see [llms.txt](https://handbook.harmonic.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://handbook.harmonic.security/handbook/6.-observability-audit-and-evidence/6.7-continuous-review-cadence.md).

# 6.7 Continuous review cadence

The monthly, weekly, and quarterly rhythm that keeps AI security controls from drifting as tools and capabilities evolve.

*Last reviewed: August 18, 2026*

{% hint style="info" %}
AI controls drift because vendors ship quickly and users find new paths. A review cadence keeps policy close to reality.
{% endhint %}

## Continuous review cadence: what security teams need to know

AI security is not a one-time rollout task. New models, connectors, agent modes, browser features, data controls, and audit endpoints can change the risk of an approved workflow — and vendors also retire surfaces, which can invalidate policies and pilots built on them.

Cadence gives teams a rhythm: weekly alerts, monthly analytics, quarterly access and red-team reviews, and immediate review after incidents or major releases.

## Common continuous review cadence security failures

* Controls are reviewed only during annual audit.
* Vendor releases add features that bypass old policy assumptions.
* Exceptions never expire.
* Usage shifts to a new surface without owner review.
* Red-team findings are not retested.

## Continuous review cadence security controls checklist

* Review SIEM alerts weekly for high-risk surfaces.
* Review usage, spend, and adoption monthly.
* Review high-risk roles, connectors, MCP servers, plugins, and exceptions quarterly.
* Retest red-team findings after fixes.
* Trigger review after incidents, vendor releases, deprecation announcements, new data classes, and new write actions.

## Anthropic

### Overview

Anthropic continuous review should revisit custom roles, connector permissions, Claude Code managed settings, MCP allowlists, plugin, skill and hook inventories, Managed Agent definitions, scheduled deployments, Cowork execution modes, Office add-ins, data retention, and monitoring coverage. Unattended automation deserves its own review line. Cowork scheduled tasks run remotely by default, but tasks that need local folders or desktop applications run locally and require the desktop to remain available. Team and Enterprise admins control scheduled tasks through the Cowork admin toggle.

Re-review when a new Claude surface, connector, or automation path enters production. Cowork now spans web, desktop, and mobile, with remote sessions that follow the user across devices and local capabilities that still depend on desktop. Review telemetry whenever that boundary changes. Cowork and Claude's Office agents currently sit outside the Compliance API and data exports, so any logging change should trigger an evidence-map review.

Add Claude Tag to the cadence: review connected Slack workspaces, member restrictions, allowed channels and DMs, service accounts, Access-bundle inheritance, domains, repositories, saved memory, spend limits, routines, and optional network-event exports. Re-run the review when a channel changes audience or classification, because the same shared credentials become available to every member in scope.

### Anthropic documentation

* [Manage custom roles on Enterprise plans](https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans)
* [Claude Code settings](https://code.claude.com/docs/en/settings)
* [Claude Managed Agents overview](https://platform.claude.com/docs/en/managed-agents/overview)
* [Scheduled deployments](https://platform.claude.com/docs/en/managed-agents/scheduled-deployments)
* [Schedule recurring tasks in Claude Cowork](https://support.claude.com/en/articles/13854387-schedule-recurring-tasks-in-claude-cowork)
* [Use Claude Cowork on web, desktop, and mobile](https://support.claude.com/en/articles/15520349-use-claude-cowork-on-web-desktop-and-mobile)
* [Monitor Claude Cowork activity with OpenTelemetry](https://support.claude.com/en/articles/14477985-monitor-claude-cowork-activity-with-opentelemetry)
* [Work across Microsoft 365 apps with Claude](https://support.claude.com/en/articles/13892150-work-across-microsoft-365-apps)
* [Restrict where Claude Tag operates](https://claude.com/docs/claude-tag/admins/restrict-access)
* [Review what Claude Tag has done](https://claude.com/docs/claude-tag/admins/audit)
* [Set up Claude Tag routines](https://claude.com/docs/claude-tag/users/proactivity)

### Applicable Harmonic guides for Anthropic

* [Securing Claude Cowork: A Security Practitioner's Guide](https://www.harmonic.security/resources/securing-claude-cowork-a-security-practitioners-guide)

## OpenAI

### Overview

OpenAI's July 2026 release changed the control map at once. ChatGPT Desktop (Work / Codex) combines Chat, Work, and Codex, and existing Codex desktop installations update into it. The App Directory became the Plugin Directory, and plugins can package skills, apps, and app templates. ChatGPT Atlas is scheduled to retire on August 9, 2026. Each change warrants a policy, deployment, support, and evidence review.

Recurring review should cover ChatGPT RBAC and action controls, Work web and mobile permissions, local Codex clients and managed desktop configuration, plugins and connected apps, Sites publishing, Computer Use, governance exports, and scheduled tasks. OpenAI documents web and mobile Work as a cloud surface and desktop Work as a local-capable surface. Review both control planes, and re-review when users move among Chat, Work, Codex, the API Platform, and external applications.

### OpenAI documentation

* [RBAC](https://help.openai.com/en/articles/11750701-rbac)
* [Apps in ChatGPT](https://help.openai.com/en/articles/11487775-apps-in-chatgpt)
* [Codex managed configuration](https://developers.openai.com/codex/enterprise/managed-configuration)
* [Scheduled tasks](https://learn.chatgpt.com/docs/automations)
* [ChatGPT Work and Codex](https://help.openai.com/en/articles/20001275)
* [Work Admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq)
* [Plugins in ChatGPT and Codex](https://help.openai.com/en/articles/20001256)
* [ChatGPT release notes](https://help.openai.com/en/articles/6825453-chatgpt-release-notes)

### Applicable Harmonic guides for OpenAI

* [Securing ChatGPT Enterprise Guide](https://www.harmonic.security/resources/securing-chatgpt-enterprise-guide)
* [Securing Codex Best Practice](https://www.harmonic.security/resources/securing-codex-best-practice)

## Frequently asked questions about continuous review cadence

### How often should AI controls be reviewed?

Use weekly alert review, monthly usage review, quarterly access and extension review, and event-driven review after incidents or major vendor changes. The event-driven trigger matters most in practice, because vendor deprecations and renames arrive on the vendor's calendar, not yours.

### What should be reviewed monthly?

Review usage, spend, new surfaces, adoption shifts, and policy exceptions. Monthly review is where surface drift shows up first — usage moving from chat to coding agents, API keys, or scheduled automations — while the shift is still small enough to govern.

### What should be reviewed quarterly?

Review roles, connectors, MCP servers, plugins, skills, red-team results, and high-risk workflows. Include unattended automation inventories such as scheduled agent deployments, Cowork scheduled tasks, and ChatGPT scheduled tasks. Check whether each runs remotely or needs a local desktop, and whether its owner and permissions are still valid.

### What triggers an out-of-cycle review?

Incidents, vendor releases, deprecation announcements, new data classes, new write actions, new connectors, and audit gaps. The July 2026 ChatGPT desktop consolidation changed installation, local access, plugin packaging, and product naming together. Atlas retirement on August 9, 2026 adds a dated migration trigger. Anthropic's expansion of Cowork across web, desktop, and mobile similarly changes where work runs and where evidence lives.

### Who owns the cadence?

Security should own the rhythm: the calendar, the trigger list, and the escalation path when a review finds drift. Platform, identity, compliance, and business owners own their control evidence, because they are the ones who can actually re-verify a role grant or a connector scope.

## Applicable regulations and frameworks

| Governance page                                     | Relationship to this article                                                                                                 |
| --------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| G.1 Map your controls to NIST AI RMF and CSF 2.0    | This article supplies implementation evidence for the NIST AI RMF and matching NIST CSF 2.0 outcomes.                        |
| G.2 EU AI Act obligations for deployers             | Conditional: for an in-scope high-risk system, this supports ongoing monitoring and reassessment after material change.      |
| G.3 DORA and AI resilience in financial services    | Conditional: for a DORA-regulated workflow, this supports monitoring, investigation, audit evidence, and incident reporting. |
| G.5 SANS Critical AI Security Guidelines mapping    | This article implements relevant SANS Monitoring and GRC guidance.                                                           |
| G.6 Write an AI Acceptable Use Policy that holds up | This article supplies a technical or process control used to enforce the acceptable-use policy.                              |
| G.7 Ownership and RACI for AI security              | This control depends on the ownership and evidence responsibilities defined in the RACI.                                     |
| G.8 ISO/IEC 42001 AI management system              | This article supports ISO/IEC 42001 AIMS preparation through periodic review, corrective action, and continual improvement.  |
| G.9 HIPAA controls for AI systems handling PHI      | Conditional: for a workflow handling ePHI, this supports HIPAA audit controls, activity review, and investigation evidence.  |

*G.2, G.3, G.4, and G.9 are conditional mappings. They apply only when the deployment is within the legal or regulatory scope described on the linked governance page.*

## Related handbook guidance

* [6. Observability, Audit & Evidence](/handbook/6.-observability-audit-and-evidence.md)
* [6.4 Analytics and usage APIs](/handbook/6.-observability-audit-and-evidence/6.4-analytics-and-usage-apis.md)
* [7.2 Pilot design and success metrics](/handbook/7.-rollout-and-operations/7.2-pilot-design-and-success-metrics.md)
* [G.7 Ownership and RACI for AI security](/reference/governance-and-frameworks/g.7-ownership-and-raci-for-ai-security.md)
* [7.1 Roll out by risk: the phased plan](/handbook/7.-rollout-and-operations/7.1-roll-out-by-risk-the-phased-plan.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://handbook.harmonic.security/handbook/6.-observability-audit-and-evidence/6.7-continuous-review-cadence.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
