Claude Code

Enterprise controls and managed settings

Deployment checklist for server/endpoint-managed settings, managed MCP, auto mode, analytics, compliance and GitHub Enterprise Server.

Enterprise deployment needs a control plane for access, providers, MCP, trusted infrastructure, usage and non-overridable compliance boundaries.

For proxies, CA, mTLS and network allowlists, see enterprise administration. This page covers organizational policy and ongoing governance.

With ANTHROPIC_BASE_URL=https://passion8.cc, claude.ai server settings may not govern the gateway path. Enforce critical policy through endpoint management, MDM, system files, gateway policy or Passion8 controls.

#Control-plane map

ControlOfficial capabilityPassion8/third-party deployment
Provider/credentialsServer settings, apps gateway, cloud variablesEndpoint settings, user templates and gateway keys
PermissionsPermissions, managed-only settings, auto modeLocal/managed settings and gateway auditing
MCP admissionmanaged-mcp.json, allowedMcpServers, deniedMcpServersSystem files, MDM and marketplace allowlists
PluginsManaged marketplaces and enabledPluginsInternal marketplace, managed/project settings
UsageAnalytics and OTelPassion8 usage, gateway logs and collector
ComplianceZDR, commercial terms, BAA, Trust CenterActual provider and gateway logging policy

#Server-managed versus endpoint-managed

ApproachBest fitConsiderations
Server-managedTeam/Enterprise without MDM or managed devicesRequires access to api.anthropic.com
Endpoint-managedMDM, Intune, Jamf, GPO, Linux fleetsOS/device-delivered policy is harder for users to bypass
Local templatesSmall teams and quick Passion8 setupEasy to copy but not a strong enforcement boundary
Gateway policyUnified providers, audit, budgets and routingPreserve headers, bodies and cache fields

Managed settings have highest precedence. Server and endpoint settings do not deep-merge; the first nonempty managed source normally wins. Check /status for the active source.

#Operate server-managed settings

Configure them in claude.ai administration; clients fetch at startup and poll during sessions.

ItemDetails
RolesPrimary Owner or Owner only
Client versionMeet current official minimum requirements
Initial fetch failureRuns without policy if no cache, unless refresh is mandatory
Cached startupApply cache first, refresh in background
PollingActive sessions periodically fetch updates
Sensitive settingsHooks, managed environment and instructions may require confirmation

Require successful refresh before sessions:

{
  "forceRemoteSettingsRefresh": true
}

Verify access to the settings service before enforcing this, or clients can become stuck at startup.

#Security settings template

Disable permission bypass and require managed rules:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)",
      "Bash(curl * | sh)",
      "Bash(curl * | bash)"
    ],
    "disableBypassPermissionsMode": "disable"
  },
  "allowManagedPermissionRulesOnly": true
}

Define organizational boundaries for auto mode:

{
  "autoMode": {
    "environment": [
      "$defaults",
      "Organization: acme-corp. Primary use: software development and internal automation",
      "Source control: github.example.com/acme-corp and all repos under it",
      "Trusted internal domains: *.corp.example.com, api.internal.example.com",
      "Trusted cloud buckets: s3://acme-build-artifacts, gs://acme-ml-datasets",
      "Sensitive remote targets: prod Kubernetes namespaces and production databases"
    ]
  }
}

Preserve "$defaults". Omitting it replaces built-in rules and may remove protections against force pushes, curl-pipe-shell and production deployment.

#Auto-mode policy

See auto-mode policy for the full configuration and denial review process. These are the essential organizational boundaries.

Auto mode uses a classifier after permission checks; it is not merely an allowlist.

FieldMeaningRisk
environmentOrganization, code, domains, buckets and sensitive scopeBroad descriptions expand trust
allowExceptions to soft blocksPermit routine staging work
soft_denyBlocks overridable by explicit intentDestructive actions needing confirmation
hard_denyUnconditional blocksSource export or production changes
classifyAllShellClassify every shell commandMore consistent checks with possible friction

Use permissions.deny for actions that must always be forbidden, not only a classifier.

#Managed MCP

Users can add MCP servers by default. Define an enterprise policy explicitly.

ModeEffectBest fit
Disable MCPLoad no serversRegulated environments or initial lockdown
Fixed deploymentEveryone receives the same serversInternal GitHub, Sentry and database tools
Approved catalogUsers choose approved serversLarge but controlled inventories
Plugin servers onlyAllow only plugin-supplied MCPManaged marketplaces
DenylistBlock known dangerous serversMature teams with low friction

managed-mcp.json cannot be delivered through server-managed settings. Typical paths:

PlatformPath
macOS/Library/Application Support/ClaudeCode/managed-mcp.json
Linux and WSL/etc/claude-code/managed-mcp.json
WindowsC:\Program Files\ClaudeCode\managed-mcp.json

Minimal MCP disabling configuration:

{
  "mcpServers": {}
}

Fixed deployment example:

{
  "mcpServers": {
    "github": {
      "type": "http",
      "url": "https://api.githubcopilot.com/mcp/"
    },
    "company-internal": {
      "type": "stdio",
      "command": "/usr/local/bin/company-mcp-server",
      "args": ["--config", "/etc/company/mcp-config.json"]
    }
  }
}

Keep plaintext keys out of system managed-mcp.json. Prefer OAuth, per-user headers, variable expansion or headersHelper.

#Organizational plugin and marketplace rules

Plugins can contain skills, agents, hooks, MCP, LSP and executables. Govern both installation sources and contents.

ControlRecommendation
Official pluginsAllow claude-plugins-official while recording scope
Community pluginsReview before allowing
Internal pluginsVersion through an internal marketplace
Security pluginsEnable through project/managed enabledPlugins
Version driftMarketplace versions or dependency constraints
RecommendationsRelevance rules for matching directories

See marketplaces and distribution.

#Analytics and OTel

Official analytics measures adoption, contributions and trends. Supplement it with gateway requests, models, costs and cache fields for Passion8.

MetricPurpose
Active usersActual team adoption
PR/code contributionsDelivery impact
Plan/usage breakdownIdentify cache misses, long context, MCP and subagent costs
OTel tracesTools, hooks, MCP, errors and latency
Gateway usageReconcile cost, routing and failures

Retain user, team, project, provider, model, status, cache creation/read tokens, cost and trace ID dimensions.

#GitHub Enterprise Server

For self-hosted GitHub Enterprise Server, also check:

AreaCheck
Web/Code ReviewCan it connect to your GHES domain?
MarketplacesOfficial GitHub or internal source?
OAuth/AppApp permissions cover the target organization/repository?
NetworkCloud sessions can reach GHES?
AuditReviews, sessions and commit attribution can write back?

Private GHES may need an apps gateway, VPN, private network egress or local CLI/IDE-only use.

#Compliance boundaries

TopicConsideration
OAuth/API keySubscription OAuth is for users; products/services need API keys or cloud credentials
ZDRDepends on actual organization and request path; verify gateway logs separately
BAACoverage depends on agreement and ZDR status
Local transcriptsCan remain on disk even with provider ZDR
WebFetch/MCPExternal tools can create additional data egress

#Deployment acceptance

CheckPassing condition
Providerclaude -p ping reaches expected endpoint and Passion8 records usage
Settings/status and /permissions show expected managed policy
Auto modeRoutine internal actions pass; production/export/destructive actions block
MCPclaude mcp list contains approved servers only
PluginsApproved marketplaces only
MonitoringCorrelate OTel and gateway logs by user/project
CachingCreation/read visible and TTL policy explainable

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.