Claude Code

Enterprise rollout

Roll out Claude Code with settings delivery, MCP policy, analytics, auto mode and custom gateway boundaries.

Design providers, identity, networking, permissions, MCP, observability and support together. Otherwise deployments tend to become usable but ungoverned, configured but ineffective, or impossible to attribute for billing and security.

See enterprise controls for governance and adoption communications for announcements, champions, drip campaigns and FAQs.

With a custom base URL or Passion8, server-managed settings generally do not govern gateway behavior. Prioritize endpoint settings, templates, MDM/registry, system managed-mcp.json and gateway policy.

#Rollout decision map

1. Provider / identity
   ├─ Direct Anthropic Team / Enterprise?
   │  ├─ Yes: organizational identity, SSO/SCIM, server settings and analytics
   │  └─ No: Passion8/custom gateway, enterprise IdP, key mapping and endpoint policy
   └─ Key ownership: individual, team service account, project or short-lived token

2. Network
   ├─ Direct access to api.anthropic.com / claude.ai / downloads.claude.ai?
   ├─ Corporate proxy, TLS inspection, CA or mTLS?
   └─ Gateway: define URL, allowlist, retries, limits and logging boundaries

3. Settings delivery
   ├─ Server-managed: official cloud delivery for Anthropic organizations
   └─ Endpoint-managed: MDM, registry, system files and templates for enforced/custom-provider policy

4. Permissions
   ├─ Default allow / ask / deny
   ├─ Auto mode: environment / allow / soft_deny / hard_deny
   └─ Disable bypass; protect sensitive files and dangerous shell; isolate risky projects

5. MCP
   ├─ Disable, fixed deployment, approved catalog, plugin-only or denylist
   ├─ System managed-mcp.json cannot be delivered through server settings
   └─ Govern OAuth, headersHelper, environment and token storage separately

6. Observability
   ├─ Adoption: users, sessions, acceptance and code contributions
   ├─ Cost: spend, tokens, model, project, team and cache hits
   ├─ Tools: Bash, Edit, MCP, hooks and auto decisions
   └─ Errors: auth, network, provider errors, tools and policy denials

7. Training / support
   ├─ Pilot users, champions, templates and default permissions
   ├─ Troubleshoot URL, token, proxy, CA, MCP and settings merge
   └─ Support queues, tickets, escalation and change announcements

#Settings delivery methods

MethodSourceBest fitLimitation
Server-managedOfficial cloud, fetched at startup/runtimeDirect Team/Enterprise, unmanaged devices, lightweight consistencyDepends on official identity/endpoints; does not govern custom gateway behavior
Endpoint-managedMDM, preferences, registry, system files or imagesManaged devices, custom gateways and enforced policiesNeeds device management/install scripts and IT change processes
Local templatesUser/project settings and devcontainersPilots, small teams and project defaultsUsers can edit them; not sole compliance enforcement
Gateway policyAccounts, models, rates, logs and data controlsCustom providers, billing and routingControls gateway requests, not local Bash, MCP or files

The difference is the trust boundary: server settings come from Anthropic for official identities/providers; endpoint settings come from enterprise devices and suit enforced client behavior and custom providers.

For Passion8, place model access, budgets, rates and retention in gateway policy; place file access, shell, MCP installation and auto-mode boundaries in endpoint settings.

#Passion8 and custom gateways

Do not assume official organizational settings automatically apply to a third-party path. Recommended controls:

ControlPractice
Base URLDeliver ANTHROPIC_BASE_URL=https://passion8.cc through managed settings or environment templates
TokenEnterprise vault, MDM secret, short-lived tokens or self-service; never repository commits
Models/budgetsGateway model allowlist, project/team budgets and rates
ProtocolVerify tools, caching, streaming, discovery, beta fields and errors
AuditAttribute requests to users, teams, projects, tokens, models and request IDs
RollbackRetain an authorized fallback profile and explicit switching/verification commands
export ANTHROPIC_BASE_URL="https://passion8.cc"
export ANTHROPIC_AUTH_TOKEN="sk-ENTERPRISE_OR_PASSION8_TOKEN"
claude -p "Check the current provider, model and basic tools"

Gateway acceptance checks:

CheckPassing condition
Request pathNo extra /v1 on the Claude Code root; Messages API works
StreamingLong output remains connected; errors are readable
Prompt cacheRead/write fields forwarded or an explicit alternative documented
Tool useCalls, MCP references and results preserved
Model pickerDiscovery shows gateway-permitted models when enabled
ErrorsDistinguish keys, permissions, limits and upstream failures

#Managed MCP policy

Deliver managed-mcp.json through administrators, MDM, images, installers or configuration management at the fixed system path; server-managed settings cannot distribute it.

PlatformSystem path
macOS/Library/Application Support/ClaudeCode/managed-mcp.json
Linux / WSL/etc/claude-code/managed-mcp.json
WindowsC:\Program Files\ClaudeCode\managed-mcp.json
PolicyUsage
Disable MCPEmpty server map for sensitive repositories or early pilots
Fixed deploymentApproved GitHub, Jira, read-only databases and retrieval
Approved catalogPermit listed servers while blocking arbitrary URLs/stdio
DenylistBlock risky servers, unknown hosts and arbitrary command executors
Separate tokensOAuth, headersHelper, keychain or short-lived credentials
{
  "mcpServers": {
    "github-enterprise": {
      "type": "http",
      "url": "https://github.example.com/mcp"
    },
    "docs-readonly": {
      "type": "stdio",
      "command": "/usr/local/bin/company-docs-mcp",
      "args": ["--readonly"]
    }
  }
}

Ensure trusted definitions, protected credentials, auditable output and interceptable writes. System files may be readable by users; do not place plaintext API keys there.

#Analytics and telemetry

Answer five questions: who uses it, what it costs, whether caching works, whether tools exceed boundaries and where failures cluster.

GroupMetricsSources
AdoptionActive users/teams, sessions, task types, acceptance and pilot conversionAnalytics, OTel, surveys and startup logs
CostSpend, tokens, models, cost centers and task costProvider/Passion8 consoles, gateway and OTel
CacheReads/writes, TTL hits, invalidation and schema changesUsage, logs, OTel and reports
ToolsTool counts, denials, hook failures and auto decisionsLogs/traces, debug and SIEM
ErrorsHTTP status, TLS/proxy, MCP timeout, settings and hard denialsGateway, OTel, helpdesk and client debug
export CLAUDE_CODE_ENABLE_TELEMETRY=1
export OTEL_METRICS_EXPORTER=otlp
export OTEL_LOGS_EXPORTER=otlp
export OTEL_EXPORTER_OTLP_PROTOCOL=grpc
export OTEL_EXPORTER_OTLP_ENDPOINT="https://otel.example.com:4317"
export OTEL_RESOURCE_ATTRIBUTES="department=engineering,tool=claude-code"

Keep raw prompts, responses, tool content and API bodies disabled by default. They can contain code, customer data, secrets, tickets and designs. Enable briefly in isolated diagnostics only.

#Enterprise auto mode

Use auto mode for low-risk, reversible, bounded development. Define environment, allow, soft-deny and hard-deny policy while retaining "$defaults".

{
  "autoMode": {
    "environment": [
      "Company source code lives under github.example.com/acme and approved internal GitLab groups.",
      "Production credentials are never available in developer workstations.",
      "Approved package registries are npm.corp.example.com and pypi.corp.example.com.",
      "Network egress goes through the corporate proxy and approved gateways."
    ],
    "allow": [
      "$defaults",
      "Read(./src/**)",
      "Read(./docs/**)",
      "Edit(./src/**)",
      "Edit(./tests/**)",
      "Bash(npm test)",
      "Bash(npm run lint)",
      "Bash(git diff *)"
    ],
    "soft_deny": [
      "Bash(npm install *)",
      "Bash(pip install *)",
      "WebFetch(*)",
      "mcp__jira__create_*"
    ],
    "hard_deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)",
      "Read(./**/*private_key*)",
      "Bash(curl * | sh)",
      "Bash(rm -rf *)",
      "Bash(git push *)",
      "mcp__prod_database__write_*"
    ]
  }
}

Use soft_deny for actions needing confirmation or a different process, such as dependencies, internet access or tickets. Use hard_deny for forbidden secret reads, deletions, pushes or production writes.

#Security baseline

ControlRequirement
Devcontainer/sandboxIsolate risky repositories in containers, VMs, worktrees or sandboxes; no production secrets
Disable bypassPrevent one-click policy bypass
Sensitive filesDeny environment files, keys, certificates, customer exports, dumps and cloud credentials
Proxy/CA/mTLSStandardize configuration and startup allowlists independently of remote settings
TokensShort-lived/individual/service-account mapping with revocation, rotation, least privilege and attribution
ZDRDoes not automatically cover transcripts, MCP, OTel, debug, gateway or proxy logs
VersionsMinimum version, release windows, rollback and pilot rings
SupportDiagnostic scripts and escalation for endpoints, tokens, networks, MCP and policy

Endpoint-managed example:

{
  "env": {
    "ANTHROPIC_BASE_URL": "https://passion8.cc",
    "CLAUDE_CODE_ENABLE_TELEMETRY": "1",
    "OTEL_METRICS_EXPORTER": "otlp",
    "OTEL_LOGS_EXPORTER": "otlp",
    "OTEL_EXPORTER_OTLP_ENDPOINT": "https://otel.example.com:4317",
    "HTTPS_PROXY": "http://proxy.corp.example.com:8080",
    "NODE_EXTRA_CA_CERTS": "/etc/ssl/certs/corp-root-ca.pem"
  },
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)",
      "Read(./**/*private_key*)",
      "Bash(curl * | sh)",
      "Bash(rm -rf *)"
    ],
    "disableBypassPermissionsMode": "disable"
  },
  "allowManagedPermissionRulesOnly": true,
  "forceRemoteSettingsRefresh": false
}

Do not require remote refresh from api.anthropic.com on offline or gateway-only devices; this can block startup.

#30 / 60 / 90 rollout

PhaseGoalControlsMetrics
Days 0–30Pilot providers, network, permissions and cost20–50 users, gateway profile, proxy/CA/mTLS, no bypass, sensitive-file deny, read-only/no MCP, basic OTelInstallation/first-task success, error distribution, daily cost, cache fields and ticket categories
Days 31–60Expand to core teams and standard templatesMDM/registry settings, project templates, approved MCP, low-risk auto policy, dashboards and attributionWeekly activity, completion, denials, MCP timeouts, cache hits, team costs, errors and training
Days 61–90Scale into routine governanceRing releases, team policies, layered gateway controls, token rotation, retention audit and support playbookCoverage, retention, lower task cost, zero severe incidents, explainable policy and rollback drills

#Release checklist

CheckAcceptance criterion
ProviderIdentity, tokens, models, budgets and rollback established
NetworkProxy, CA, mTLS, allowlist, offline install and startup verified
SettingsClear server/endpoint roles; custom gateways do not rely solely on server settings
PermissionsSensitive-file/command denies, no bypass, no keys in templates
MCPSystem deployment, protected credentials and write policies
Auto modeEnvironment/allow/soft_deny/hard_deny configured with defaults retained
ObservabilityAdoption, costs, caching, tools and errors have dashboards/alerts
PrivacyDocumented retention boundaries across provider, local and gateway systems
TrainingPilot materials, troubleshooting, support, announcements and escalation published

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.