Enterprise controls and managed settings
Deployment checklist for server/endpoint-managed settings, managed MCP, auto mode, analytics, compliance and GitHub Enterprise Server.
Enterprise deployment needs a control plane for access, providers, MCP, trusted infrastructure, usage and non-overridable compliance boundaries.
For proxies, CA, mTLS and network allowlists, see enterprise administration. This page covers organizational policy and ongoing governance.
With ANTHROPIC_BASE_URL=https://passion8.cc, claude.ai server settings may not govern the gateway path. Enforce critical policy through endpoint management, MDM, system files, gateway policy or Passion8 controls.
#Control-plane map
| Control | Official capability | Passion8/third-party deployment |
|---|---|---|
| Provider/credentials | Server settings, apps gateway, cloud variables | Endpoint settings, user templates and gateway keys |
| Permissions | Permissions, managed-only settings, auto mode | Local/managed settings and gateway auditing |
| MCP admission | managed-mcp.json, allowedMcpServers, deniedMcpServers | System files, MDM and marketplace allowlists |
| Plugins | Managed marketplaces and enabledPlugins | Internal marketplace, managed/project settings |
| Usage | Analytics and OTel | Passion8 usage, gateway logs and collector |
| Compliance | ZDR, commercial terms, BAA, Trust Center | Actual provider and gateway logging policy |
#Server-managed versus endpoint-managed
| Approach | Best fit | Considerations |
|---|---|---|
| Server-managed | Team/Enterprise without MDM or managed devices | Requires access to api.anthropic.com |
| Endpoint-managed | MDM, Intune, Jamf, GPO, Linux fleets | OS/device-delivered policy is harder for users to bypass |
| Local templates | Small teams and quick Passion8 setup | Easy to copy but not a strong enforcement boundary |
| Gateway policy | Unified providers, audit, budgets and routing | Preserve headers, bodies and cache fields |
Managed settings have highest precedence. Server and endpoint settings do not deep-merge; the first nonempty managed source normally wins. Check /status for the active source.
#Operate server-managed settings
Configure them in claude.ai administration; clients fetch at startup and poll during sessions.
| Item | Details |
|---|---|
| Roles | Primary Owner or Owner only |
| Client version | Meet current official minimum requirements |
| Initial fetch failure | Runs without policy if no cache, unless refresh is mandatory |
| Cached startup | Apply cache first, refresh in background |
| Polling | Active sessions periodically fetch updates |
| Sensitive settings | Hooks, managed environment and instructions may require confirmation |
Require successful refresh before sessions:
{
"forceRemoteSettingsRefresh": true
}Verify access to the settings service before enforcing this, or clients can become stuck at startup.
#Security settings template
Disable permission bypass and require managed rules:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(./.env.*)",
"Read(./secrets/**)",
"Bash(curl * | sh)",
"Bash(curl * | bash)"
],
"disableBypassPermissionsMode": "disable"
},
"allowManagedPermissionRulesOnly": true
}Define organizational boundaries for auto mode:
{
"autoMode": {
"environment": [
"$defaults",
"Organization: acme-corp. Primary use: software development and internal automation",
"Source control: github.example.com/acme-corp and all repos under it",
"Trusted internal domains: *.corp.example.com, api.internal.example.com",
"Trusted cloud buckets: s3://acme-build-artifacts, gs://acme-ml-datasets",
"Sensitive remote targets: prod Kubernetes namespaces and production databases"
]
}
}Preserve "$defaults". Omitting it replaces built-in rules and may remove protections against force pushes, curl-pipe-shell and production deployment.
#Auto-mode policy
See auto-mode policy for the full configuration and denial review process. These are the essential organizational boundaries.
Auto mode uses a classifier after permission checks; it is not merely an allowlist.
| Field | Meaning | Risk |
|---|---|---|
| environment | Organization, code, domains, buckets and sensitive scope | Broad descriptions expand trust |
| allow | Exceptions to soft blocks | Permit routine staging work |
| soft_deny | Blocks overridable by explicit intent | Destructive actions needing confirmation |
| hard_deny | Unconditional blocks | Source export or production changes |
| classifyAllShell | Classify every shell command | More consistent checks with possible friction |
Use permissions.deny for actions that must always be forbidden, not only a classifier.
#Managed MCP
Users can add MCP servers by default. Define an enterprise policy explicitly.
| Mode | Effect | Best fit |
|---|---|---|
| Disable MCP | Load no servers | Regulated environments or initial lockdown |
| Fixed deployment | Everyone receives the same servers | Internal GitHub, Sentry and database tools |
| Approved catalog | Users choose approved servers | Large but controlled inventories |
| Plugin servers only | Allow only plugin-supplied MCP | Managed marketplaces |
| Denylist | Block known dangerous servers | Mature teams with low friction |
managed-mcp.json cannot be delivered through server-managed settings. Typical paths:
| Platform | Path |
|---|---|
| macOS | /Library/Application Support/ClaudeCode/managed-mcp.json |
| Linux and WSL | /etc/claude-code/managed-mcp.json |
| Windows | C:\Program Files\ClaudeCode\managed-mcp.json |
Minimal MCP disabling configuration:
{
"mcpServers": {}
}Fixed deployment example:
{
"mcpServers": {
"github": {
"type": "http",
"url": "https://api.githubcopilot.com/mcp/"
},
"company-internal": {
"type": "stdio",
"command": "/usr/local/bin/company-mcp-server",
"args": ["--config", "/etc/company/mcp-config.json"]
}
}
}Keep plaintext keys out of system managed-mcp.json. Prefer OAuth, per-user headers, variable expansion or headersHelper.
#Organizational plugin and marketplace rules
Plugins can contain skills, agents, hooks, MCP, LSP and executables. Govern both installation sources and contents.
| Control | Recommendation |
|---|---|
| Official plugins | Allow claude-plugins-official while recording scope |
| Community plugins | Review before allowing |
| Internal plugins | Version through an internal marketplace |
| Security plugins | Enable through project/managed enabledPlugins |
| Version drift | Marketplace versions or dependency constraints |
| Recommendations | Relevance rules for matching directories |
See marketplaces and distribution.
#Analytics and OTel
Official analytics measures adoption, contributions and trends. Supplement it with gateway requests, models, costs and cache fields for Passion8.
| Metric | Purpose |
|---|---|
| Active users | Actual team adoption |
| PR/code contributions | Delivery impact |
| Plan/usage breakdown | Identify cache misses, long context, MCP and subagent costs |
| OTel traces | Tools, hooks, MCP, errors and latency |
| Gateway usage | Reconcile cost, routing and failures |
Retain user, team, project, provider, model, status, cache creation/read tokens, cost and trace ID dimensions.
#GitHub Enterprise Server
For self-hosted GitHub Enterprise Server, also check:
| Area | Check |
|---|---|
| Web/Code Review | Can it connect to your GHES domain? |
| Marketplaces | Official GitHub or internal source? |
| OAuth/App | App permissions cover the target organization/repository? |
| Network | Cloud sessions can reach GHES? |
| Audit | Reviews, sessions and commit attribution can write back? |
Private GHES may need an apps gateway, VPN, private network egress or local CLI/IDE-only use.
#Compliance boundaries
| Topic | Consideration |
|---|---|
| OAuth/API key | Subscription OAuth is for users; products/services need API keys or cloud credentials |
| ZDR | Depends on actual organization and request path; verify gateway logs separately |
| BAA | Coverage depends on agreement and ZDR status |
| Local transcripts | Can remain on disk even with provider ZDR |
| WebFetch/MCP | External tools can create additional data egress |
#Deployment acceptance
| Check | Passing condition |
|---|---|
| Provider | claude -p ping reaches expected endpoint and Passion8 records usage |
| Settings | /status and /permissions show expected managed policy |
| Auto mode | Routine internal actions pass; production/export/destructive actions block |
| MCP | claude mcp list contains approved servers only |
| Plugins | Approved marketplaces only |
| Monitoring | Correlate OTel and gateway logs by user/project |
| Caching | Creation/read visible and TTL policy explainable |
#Official references
Support
Need help?
For setup, billing, or model issues, email us. Check the status page for uptime.
WeChat / QQ support is available at the bottom right.

