Claude Code Deployment

State Water Resources Control Board

HIGH RISK Classification

January 24, 2026
Prepared for Executive Leadership

Bottom Line Up Front

Claude Code CAN be deployed safely at SWRCB, but requires careful, phased implementation with appropriate controls.

Required Before Deployment

  • Mandatory CDT consultation before procurement
  • 8-9 month phased rollout (not immediate full deployment)
  • Executive sponsorship at CIO level
  • Investment in logging, monitoring, and training infrastructure
8-9
Months to Full Deploy
6
Phased Stages
10-15
Pilot Developers

What is Claude Code?

An AI-powered coding assistant that helps developers write, review, and debug code.

What It Does

  • Runs on developer workstations
  • Reads and suggests code changes
  • Executes commands (builds, tests)
  • Assists with debugging
  • Generates documentation

Key Capabilities

  • Understands entire codebases
  • Follows project patterns
  • Integrates with development tools
  • Supports enterprise controls
  • Full audit logging available
Important: Because Claude Code can execute commands and access files, it requires security controls appropriate to its access level.

Why HIGH RISK Classification?

CDT GenAI Risk Classification
HIGH RISK
Mandatory CDT Consultation Required
Factor Implication
Water Rights & Permits Decisions directly affect Californians' access to resources
Critical Infrastructure Heightened security requirements for water systems
Infrastructure/DevOps Access AI with system-level access requires strictest controls
Benefits/Services Systems Permit and compliance systems affect public welfare

Source: CDT GenAI Guidelines (July 2024)

Key Compliance Requirements

Requirement Source Status
CDT consultation before procurement Technology Letter 24-01 Required
GenAI Risk Assessment (SIMM 5305-F) CDT SIMM Required
Data must stay in Continental US SAM 4983.1 Verify
High-risk AI inventory reporting AB 302 Required
Privacy Impact Assessment CCPA Regulations Required
Equity Impact Assessment CDT Guidelines Required
Additional California AI Regulations (2025-2026)
  • SB 53 - Transparency in Frontier AI Act (effective Jan 1, 2026) — Primarily affects AI vendors
  • AB 2013 - Training Data Transparency (effective Jan 1, 2026) — Verify vendor compliance
  • CCPA/CPRA ADMT Regulations - Automated Decision-Making (effective Jan 1, 2026)

IT Division's Concern: Resolved

⚠️ The Problem

Network monitoring cannot distinguish human actions from AI-initiated actions.

  • Security teams can't investigate accurately
  • Audit trails become unreliable
  • Compliance reporting compromised
  • Accountability unclear

✓ The Solution

Claude Code supports OpenTelemetry logging that tags all AI actions with:

  • Timestamps
  • User IDs
  • Session data
  • Commands executed
  • Files accessed

Combined with network logs = complete attribution.

Architecture: Claude Code → OpenTelemetry → State SIEM (Splunk/Elastic) → Security Dashboard → Alert Rules

Vendor (Anthropic) Compliance

Certification Status Source
SOC 2 Type II Verified Trust Center
ISO 27001:2022 Verified Privacy Center
Data NOT used for training Verified (commercial) Data Usage Policy
SSO/SAML support Available Security Docs
Zero Data Retention option Available ZDR Info
Must verify before contract: Data center locations (must be Continental US per SAM 4983.1)
Additional Verification Needed with Anthropic Sales
  • ❓ Exact data center locations (must confirm Continental US)
  • ❓ Specific retention periods under government contract
  • ❓ Indemnification terms for AI-generated code
  • ❓ California government-specific contract terms
  • ❓ Government pricing

Implementation Timeline

Phase 0: Discovery

Weeks 1-2

Answer prerequisite questions, schedule CDT consultation

Phase 1: Foundation

Weeks 3-6

CDT consultation, assessments, procurement

Phase 2: Technical Setup

Weeks 7-10

SSO, logging, permissions, monitoring

Phase 3: Pilot

Weeks 11-16

Internal systems only (10-15 developers)

Phase 4: Expansion

Weeks 17-24

Add public websites

Phase 5: Infrastructure

Weeks 25-32

DevOps (read-only)

Phase 6: Benefits Systems

Week 33+

Only after 6+ months proven safety

Total: ~8-9 months to full deployment — This timeline reflects the HIGH RISK classification.

Cost Estimate

Item Estimate Notes
Claude Code Enterprise ~$20/user/month Verify with Anthropic Sales
SIEM (if not existing) Varies May use CDT shared service
Training development Staff time 4 modules required
External security audit $15-50K Annual requirement
$20
Per User/Month
4
Training Modules
$15-50K
Annual Audit
Budget Consideration: Pilot phase (10-15 users) would cost approximately $200-300/month plus staff time for training and setup.

Risk Mitigation Summary

Risk Mitigation
Data exposure Permission restrictions block sensitive file access
Unattributed actions OpenTelemetry logging tags all AI activity
Malicious code Mandatory human code review before deployment
Compliance violation Phased rollout with gates at each stage
Shadow AI Formal program reduces unauthorized tool use
Technical Controls Detail

Permission Restrictions

Claude Code can be configured to block dangerous commands:

  • ❌ Network tools (curl, wget, nmap)
  • ❌ Destructive commands (rm -rf, sudo)
  • ❌ Sensitive files (.env, credentials, keys)
  • ✓ Build/test commands (npm run, pytest)
  • ✓ Version control (git status, git log)
  • ✓ Code editing (source files only)

Source: Claude Code Settings

Immediate Action Items (This Week)

# Action Owner
1 Confirm SIEM availability IT Security
2 Identify executive sponsor Leadership
3 Schedule CDT consultation CIO
4 Review budget Finance
5 Identify pilot developers (10-15) Department leads
Critical: CDT consultation is mandatory for HIGH RISK classification. No procurement can proceed until this is completed.

Executive Decision Required

Approve or decline proceeding to Phase 0 (Discovery) and CDT consultation

If Approved:

  • CIO becomes accountable for GenAI governance
  • CDT consultation must occur before any procurement
  • Quarterly reporting to CDT required
  • Executive sponsor identified and committed

If Declined:

  • Document decision rationale for records
  • Monitor CDT guidance for future opportunities
  • Address shadow AI risk through policy
Recommendation: Approve proceeding to Phase 0 Discovery. This allows SWRCB to gather information and consult with CDT before making any financial commitments.

Full Plan Reference

Complete 10-section plan with all technical details, compliance citations, and implementation checklists:

Plan Contents

  1. Understanding the Risks
  2. California-Specific Requirements
  3. Technical Security Controls
  4. Data Protection Framework
  5. Governance & Policy Framework
  6. Procurement & Vendor Management
  7. Training & Awareness Program
  8. Monitoring & Incident Response
  9. Implementation Roadmap
  10. Verification & Testing Plan
All regulatory claims hyperlinked to official sources. See Appendix D in the full plan for complete reference list.

Sources & References

California Government Sources

Anthropic Official Sources

All sources verified January 24, 2026. Links should be re-verified before presenting to executives.