智能报告显示您的组织如何使用 Claude。默认情况下,只有主所有者、所有者、管理员和具有分析查看权限的自定义角色可以创建和查看智能报告。通过委派访问权限,您可以让团队负责人或部门主管运行智能报告,而无需将其设为管理员。他们只能报告您选择的群组、部门或成本中心,并且只能看到他们运行的报告或其他人与他们共享的报告。
智能报告在 Claude Enterprise 计划中以测试版形式提供,不适用于使用客户管理的加密密钥 (CMEK)、HIPAA 配置或 访问透明度的组织。对于使用零数据保留的 Claude Enterprise 组织,Claude Code 的智能报告也不可用。
重要提示:智能报告可帮助您了解采用情况并规划对 Claude 的投资。它们不是为评估个人绩效或做出就业决定而设计的,也不应用于此目的。
谁可以管理智能报告的访问权限
要管理对智能报告的访问权限,您必须是所有者或主所有者,或者拥有 分析权限和 身份和访问权限的自定义角色。如果您没有这些角色之一,您将看不到 管理访问权限按钮。
开始前
您的组织必须使用 Claude Enterprise 计划,并在 组织设置 > 功能 > 分析中启用
The people you add must be on the Custom roles access level, which is set per member in Organization settings > Members.
Step 1: Open Manage access
Go to Analytics > Smart reports (beta) and click "Manage access." The Who can run reports screen opens.
The line at the top tells you which roles can run reports. Admins and owners can always run reports.
Step 2: Add a person
Under Add people, type a name or email and pick the person.
Some users appear greyed out with the label Not on Custom roles. Change their access level in Organization settings > Members, then close and reopen Manage access and add them.
Step 3: Choose what they can report on
The person appears under People with access, with the columns Person and Can run reports on. Nothing is saved for them until you choose a scope.
If your organization has more than one kind of scope, select Group, Department, or Cost center in the first dropdown menu.
Groups come from Organization settings > Groups.
Departments and cost centers are offered only if your identity provider provisions members through SCIM with those attributes.
Select the group, department, or cost center values in the second dropdown menu.
Each change is saved as soon as you make it and will say "Saved."
If you click "Close" while someone still has no scope, or their last change couldn't be saved, the screen asks "Close without saving?" and explains that their access isn't saved.
Keep in mind:
You can select up to 50 groups, departments, or cost centers of each kind per person.
A delegate can only run a report on what you assign here. They never get a whole-organization option.
Note: People you give access to aren’t notified. They can view smart reports by clicking on their name in the lower left corner in Claude, then going to Analytics > Smart reports (beta).
What happens automatically
The first time you save a delegate, smart reports creates two things in your organization:
A group named Smart Reports delegates
A custom role named Smart Reports delegates, assigned to that group, with the Smart Reports delegated admin permission
Every person you add is placed in this group, which is how they get permission to run reports. We recommend that you don’t edit these roles manually.
The following badges can appear on a person's row:
Not on Custom roles: the person's access level changed after you added them. Change it back in Organization settings > Members.
Needs the permission: this person doesn’t have access to any roles that grant permission to run smart reports (for example, they were removed from the smart reports delegates group). Click Add to the Smart Reports delegates role on their row to add them back. If the automatic role itself lost the permission, restore it in Organization settings > Roles first.
What a delegate sees and can do
In Analytics, delegates see only Smart Reports. Their list is titled Your reports and contains only the reports they ran.
When they click "New report," the People in scope menu offers only the groups, departments, or cost centers you assigned. All of them are selected to start, and the delegate can narrow the selection.
Delegates can share their reports with other members of your organization and download them, the same way admins can.
The attributed view, which shows user emails and session IDs, only appears when your organization's Allow attribution to individual users setting is on.
Reports run by delegates count toward your organization's monthly smart reports limit and share the same limit on reports running at once.
Delegates cannot:
Run a report on the whole organization, or on anything outside their assigned scope
See reports other people ran, unless someone shares the report with them
Rename, archive, or delete reports
Open Manage access or change who can run reports
Change or remove access
To change what someone can report on, open Manage access and change their selections. The new selection replaces their previous scope. Reports they already ran stay available to them.
To remove someone, click the "✕" (Remove) button on their row. Their access is removed right away, and you'll see a confirmation that they can no longer run reports. If the smart reports delegates group is used only by the automatic role, they are also taken out of it. Otherwise, remove them from the group in Organization settings > Groups. Once they no longer hold the permission, they can't open smart reports, including the reports they ran. Reports they already downloaded aren't affected.
When a user is removed from your organization, they can no longer run reports. Their saved scope is usually removed at the same time. If your identity provider removes users through SCIM, remove them in Manage access first so their old scope isn't kept if they're added back later.
When a group is deleted, or a department or cost center value no longer exists, it disappears from the person's row and from their selections. If a delegate tries to run a report with a selection that no longer exists, the report is refused and they can pick again. You can also open their row and choose new values.
FAQ
Can I grant the permission through my own roles instead of the automatic one?
Yes. In Organization settings > Roles, the Smart Reports delegated admin permission appears under Product controls. Adding it to a role isn't enough on its own: each person still needs a scope. Open Manage access on the smart reports page, add each person, and choose what they can report on.
Why is someone greyed out when I try to add them?
They aren't on the Custom roles access level, which custom roles (including the automatic one) require. Change it in Organization settings > Members, or in your identity provider if it sets access levels.
Can a delegate see individual users' names or emails?
Only if your organization's Allow attribution to individual users setting is on. It is off by default.
