Enterprise deployment overview
Choose providers, authentication, managed settings, permissions, monitoring, Claude Platform on AWS and Passion8 boundaries.
Deployment involves providers, identity, policy delivery, models, egress, usage, retention and cost attribution. Distinguish Claude Code client capabilities from gateway capabilities.
ANTHROPIC_BASE_URL=https://passion8.cc does not grant subscription, official web, Remote Control, Routines or apps-gateway account capabilities.
#Decision order
| Decision | What you choose | Common options |
|---|---|---|
| API provider | Billing, identity, regions and capabilities | Team/Enterprise, Console, Bedrock, Vertex, Foundry, AWS Platform, Passion8 |
| Policy delivery | Who overrides local settings | Server settings, MDM, system files, registry, policy helper |
| Permissions | Tools, commands, paths, MCP and plugins | Managed permissions, sandbox, managed MCP and marketplace restrictions |
| Observability | Costs, tokens, tools and adoption | OTel, analytics, provider billing and gateway limits |
| Data boundaries | Prompt, transcript, log, telemetry and cache location | Provider/cloud policy, gateway logs and local .claude |
The official admin setup emphasizes these decisions before distributing installers. Larger teams should define providers and managed settings before rollout.
#Provider selection
| Provider | Best fit | Consideration |
|---|---|---|
| Team/Enterprise | Unified Code, web, desktop and administration | More complete cloud/account features |
| Console API | API-first or metered usage | No subscription account capabilities |
| Bedrock | AWS-native compliance/billing | Verify region, model IDs, IAM and parity |
| Claude Platform on AWS | Marketplace billing with direct Anthropic API | SigV4 or workspace keys; separate organization |
| Vertex AI | GCP billing and IAM | Verify region, aliases and caching |
| Foundry | Azure identity and billing | Standardize Entra, endpoint and deployment names |
| Passion8/custom gateway | Central routing, billing, models or existing keys | Official account features and settings do not automatically apply |
If you need both official cloud capabilities and Passion8 routing, document separate paths: local CLI through Passion8, official web/cloud through authorized Anthropic accounts.
#Managed-settings sources
| Source | Priority | Best fit |
|---|---|---|
| Server-managed | Highest | Team/Enterprise or apps-gateway login |
| macOS plist / Windows HKLM | High | Managed enterprise devices |
| System managed-settings.json | Medium | Linux, WSL, containers and non-MDM devices |
| Windows HKCU | Low | Convenient defaults, not strong enforcement |
| policyHelper | Overrides managed sources | Dynamic device/user/group policies |
Put mandatory controls in administrator-writable locations such as MDM, HKLM or /etc/claude-code/managed-settings.json. Repository settings provide defaults, not anti-bypass enforcement.
#Controls to enforce
| Control | Configuration direction |
|---|---|
| Permissions | Manage allow/deny and managed-only rules where needed |
| Bypass | Disable dangerously-skip-permissions for production repositories |
| Sandbox | Enable sandbox and limit domains/credentials |
| MCP | Managed server files or allowlists |
| Marketplaces | Restrict sources and sideload flags |
| Hooks | Managed-only hooks and bounded HTTP URLs |
| Models | availableModels, enforceAvailableModels and provider restrictions |
| Versions | minimumVersion or required range |
These controls supplement code review and CI by establishing consistent safer defaults.
#Claude Platform on AWS
Claude Platform on AWS is operated by Anthropic with Marketplace billing and IAM/workspace-key authentication. Unlike Bedrock, requests reach Anthropic API and follow its model/API release cadence.
| Item | Explanation |
|---|---|
| Organization | Marketplace creates an AWS-linked Anthropic organization; do not mix old Console workspaces |
| Authentication | SigV4 credential chain or workspace key |
| Billing | AWS Marketplace and cost systems |
| Code configuration | Platform-specific URL, workspace, profile or key |
| Passion8 | Verify upstream signing, usage and error forwarding if layered through a gateway |
#Passion8 rollout
- Decide which users use Passion8 and which retain official login.
- Deliver URL and token helpers via MDM/system settings; no keys in repositories.
- Identify official-account requirements for Web, Routines, Remote Control and Code Review.
- Attribute costs with gateway spend limits and OpenTelemetry.
- Use feature availability as the acceptance matrix.
#Caching and cost
| Scenario | Cache effect |
|---|---|
| Continuous local sessions | Stable prompts/settings/tools favor five-minute reuse |
| Uniform managed settings | More consistent prefixes, but users/repos remain separate caches |
| Provider/Base URL changes | Usually establish a new cache prefix |
| AWS Platform | One-hour TTL depends on client, upstream and forwarding |
| Passion8 | Preserve cache_control, beta headers and usage for accurate accounting |
| Official cloud | Independent context/cache, not shared with local Passion8 |
See command cache effects for details.
#Official references
- Set up Claude Code for your organization
- Enterprise deployment overview
- Claude Code on Claude Platform on AWS
- Authentication
- Network configuration
#Related pages
Support
Need help?
For setup, billing, or model issues, email us. Check the status page for uptime.
WeChat / QQ support is available at the bottom right.

