# Claude Code Enterprise deployment overview

> Choose providers, authentication, managed settings, permissions, monitoring, Claude Platform on AWS and Passion8 boundaries.

URL: https://docs.passion8.cc/en/docs/claude-code/enterprise-deployment-overview
Language: en
Publisher: Passion8

Deployment involves providers, identity, policy delivery, models, egress, usage, retention and cost attribution. Distinguish Claude Code client capabilities from gateway capabilities.




ANTHROPIC_BASE_URL=https://passion8.cc does not grant subscription, official web, Remote Control, Routines or apps-gateway account capabilities.




## Decision order

| Decision | What you choose | Common options |
| --- | --- | --- |
| API provider | Billing, identity, regions and capabilities | Team/Enterprise, Console, Bedrock, Vertex, Foundry, AWS Platform, Passion8 |
| Policy delivery | Who overrides local settings | Server settings, MDM, system files, registry, policy helper |
| Permissions | Tools, commands, paths, MCP and plugins | Managed permissions, sandbox, managed MCP and marketplace restrictions |
| Observability | Costs, tokens, tools and adoption | OTel, analytics, provider billing and gateway limits |
| Data boundaries | Prompt, transcript, log, telemetry and cache location | Provider/cloud policy, gateway logs and local .claude |

The official admin setup emphasizes these decisions before distributing installers. Larger teams should define providers and managed settings before rollout.

## Provider selection

| Provider | Best fit | Consideration |
| --- | --- | --- |
| Team/Enterprise | Unified Code, web, desktop and administration | More complete cloud/account features |
| Console API | API-first or metered usage | No subscription account capabilities |
| Bedrock | AWS-native compliance/billing | Verify region, model IDs, IAM and parity |
| Claude Platform on AWS | Marketplace billing with direct Anthropic API | SigV4 or workspace keys; separate organization |
| Vertex AI | GCP billing and IAM | Verify region, aliases and caching |
| Foundry | Azure identity and billing | Standardize Entra, endpoint and deployment names |
| Passion8/custom gateway | Central routing, billing, models or existing keys | Official account features and settings do not automatically apply |

If you need both official cloud capabilities and Passion8 routing, document separate paths: local CLI through Passion8, official web/cloud through authorized Anthropic accounts.

## Managed-settings sources

| Source | Priority | Best fit |
| --- | --- | --- |
| Server-managed | Highest | Team/Enterprise or apps-gateway login |
| macOS plist / Windows HKLM | High | Managed enterprise devices |
| System managed-settings.json | Medium | Linux, WSL, containers and non-MDM devices |
| Windows HKCU | Low | Convenient defaults, not strong enforcement |
| policyHelper | Overrides managed sources | Dynamic device/user/group policies |

Put mandatory controls in administrator-writable locations such as MDM, HKLM or /etc/claude-code/managed-settings.json. Repository settings provide defaults, not anti-bypass enforcement.

## Controls to enforce

| Control | Configuration direction |
| --- | --- |
| Permissions | Manage allow/deny and managed-only rules where needed |
| Bypass | Disable dangerously-skip-permissions for production repositories |
| Sandbox | Enable sandbox and limit domains/credentials |
| MCP | Managed server files or allowlists |
| Marketplaces | Restrict sources and sideload flags |
| Hooks | Managed-only hooks and bounded HTTP URLs |
| Models | availableModels, enforceAvailableModels and provider restrictions |
| Versions | minimumVersion or required range |

These controls supplement code review and CI by establishing consistent safer defaults.

## Claude Platform on AWS

Claude Platform on AWS is operated by Anthropic with Marketplace billing and IAM/workspace-key authentication. Unlike Bedrock, requests reach Anthropic API and follow its model/API release cadence.

| Item | Explanation |
| --- | --- |
| Organization | Marketplace creates an AWS-linked Anthropic organization; do not mix old Console workspaces |
| Authentication | SigV4 credential chain or workspace key |
| Billing | AWS Marketplace and cost systems |
| Code configuration | Platform-specific URL, workspace, profile or key |
| Passion8 | Verify upstream signing, usage and error forwarding if layered through a gateway |

## Passion8 rollout

1. Decide which users use Passion8 and which retain official login.
2. Deliver URL and token helpers via MDM/system settings; no keys in repositories.
3. Identify official-account requirements for Web, Routines, Remote Control and Code Review.
4. Attribute costs with gateway spend limits and OpenTelemetry.
5. Use [feature availability](https://docs.passion8.cc/en/docs/claude-code/feature-availability) as the acceptance matrix.

## Caching and cost

| Scenario | Cache effect |
| --- | --- |
| Continuous local sessions | Stable prompts/settings/tools favor five-minute reuse |
| Uniform managed settings | More consistent prefixes, but users/repos remain separate caches |
| Provider/Base URL changes | Usually establish a new cache prefix |
| AWS Platform | One-hour TTL depends on client, upstream and forwarding |
| Passion8 | Preserve cache_control, beta headers and usage for accurate accounting |
| Official cloud | Independent context/cache, not shared with local Passion8 |

See [command cache effects](https://docs.passion8.cc/en/docs/claude-code/command-cache) for details.

## Official references

- [Set up Claude Code for your organization](https://code.claude.com/docs/en/admin-setup.md)
- [Enterprise deployment overview](https://code.claude.com/docs/en/third-party-integrations.md)
- [Claude Code on Claude Platform on AWS](https://code.claude.com/docs/en/claude-platform-on-aws.md)
- [Authentication](https://code.claude.com/docs/en/authentication.md)
- [Network configuration](https://code.claude.com/docs/en/network-config.md)

## Related pages



- [Enterprise administration](https://docs.passion8.cc/en/docs/claude-code/enterprise-admin): Proxies, CA, mTLS, managed settings and MCP.
- [Enterprise controls](https://docs.passion8.cc/en/docs/claude-code/enterprise-controls): Settings, MCP, marketplaces, auto mode, analytics and compliance.
- [Gateway operations](https://docs.passion8.cc/en/docs/claude-code/gateway-operations): Apps gateways, OIDC, Postgres, spend limits and cache forwarding.
- [Data usage and privacy](https://docs.passion8.cc/en/docs/claude-code/data-usage): Training, retention, transcripts, telemetry, WebFetch and gateway logs.

