Essay/Claude·Apr 18, 2026

Claude Managed Agents Explained: Anthropic's New Way to Run AI at Scale

Claude Managed Agents is Anthropic's hosted service for running long-horizon AI agents — abstracting away session management, sandbox execution, and crash recovery so enterprises can deploy without building the infrastructure themselves.

Luke Thompson
Luke ThompsonApr 18, 2026 · 6 min read
In this article
Claude Managed Agents Explained: Anthropic's New Way to Run AI at Scale
Building AI agents is one thing. Running them reliably in production is another. Anthropic launched Claude Managed Agents on April 8, 2026 — a hosted service that takes on the infrastructure burden of deploying long-running agents: session management, sandbox execution, tool routing, credential handling, and crash recovery. The goal is to let enterprises actually ship agent workflows without spending months on plumbing.

The Problem It Solves

Most AI agent demos are deceptively simple. The hard part isn't getting Claude to complete a task — it's keeping it running reliably when the task takes hours, spans multiple tool calls, hits unexpected errors, or needs to resume after a crash. The engineering teams that have shipped agents in production will tell you: the majority of the work is the harness, not the model. (See also: Claude Code Routines) (See also: Claude API pricing) (See also: Model Context Protocol) Project Glasswing: How Anthropic Is Using Claud... KPMG Just Gave 276,000 Employees Access to Clau...

Claude Managed Agents abstracts that harness. Instead of building your own session management, execution sandboxes, retry logic, and credential vaulting, you hand that off to Anthropic's infrastructure. Your code defines what you want the agent to do. Managed Agents handles making it durable.

Field note

"Harnesses encode assumptions about what Claude can't do on its own — and those assumptions go stale as models improve." — Anthropic Engineering Blog. Managed Agents is built around interfaces designed to outlast any particular implementation.

The Core Architecture: Brain, Hands, Session

Anthropic built Managed Agents around a key architectural decision: decouple the three components of an agent into independent interfaces.

  • The Brain — Claude and its harness. The reasoning engine that decides what to do next. Decoupled from everything else so it can be updated or swapped without touching the rest.
  • The Hands — Sandboxes and tools that actually execute actions. Code runs here, file edits happen here, API calls originate here. Completely isolated from the brain's credentials.
  • The Session — The durable, append-only log of everything that has happened. Lives outside both the brain and the hands, so nothing is lost when either crashes.

This mirrors how operating systems virtualized hardware decades ago. The read() command works the same whether it's hitting a 1970s disk pack or a modern SSD. Managed Agents applies the same thinking: stable interfaces on top, swappable implementations underneath.

Why the Decoupling Matters in Practice

Before decoupling, Anthropic ran all three components in a single container. If the container crashed, the session was lost. If it was unresponsive, engineers had to shell into it — which was also where user data lived, creating a security problem. And if a customer wanted to connect Claude to their own VPC, they had to peer their network with Anthropic's, because the harness assumed everything it needed was sitting next to it.

After decoupling: if a sandbox dies, the harness catches it as a tool-call error and provisions a new one. If the harness crashes, a new one boots, calls getSession(id) to retrieve the event log, and resumes from the last event. No data loss. No manual intervention. Containers become cattle, not pets.

Credential Security: The Vault Pattern

One of the trickier problems in agentic systems is credential security. If Claude generates and runs code in a sandbox, and that sandbox also has access to API keys, a prompt injection attack only needs to convince Claude to read its own environment. Managed Agents solves this structurally.

Credentials never reach the sandbox where Claude's generated code runs. For Git, repos are cloned using the access token during sandbox initialization and wired into the local git remote — Claude can push and pull without ever handling the token directly. For custom tools and OAuth integrations, tokens are stored in a secure vault. Claude calls tools via a dedicated proxy that fetches credentials from the vault at call time. The harness never sees credentials at all.

Context Beyond the Context Window

Long-horizon tasks — the ones Managed Agents is designed for — frequently exceed Claude's context window. The standard approaches (summarization, compaction, trimming) all involve irreversible decisions about what to keep. Managed Agents handles this differently.

The session log is the context object. It lives outside the context window, stored durably. The harness can call getEvents() to fetch specific slices — pick up from the last checkpoint, rewind a few events before a critical action, or re-read context before making a consequential decision. Nothing is discarded; it's all selectively surfaced. This means an agent can pause, crash, resume, and never lose the thread of what it was doing.

What This Means for Enterprises

VentureBeat noted the obvious concern: this is a meaningful vendor lock-in play. Managed Agents is deeply integrated with the Claude platform — the session format, sandbox provisioning, tool proxy, and credential vault are all Anthropic infrastructure. Teams that build on it are building on Anthropic's abstractions, not portable ones.

The counter-argument is that most enterprise teams were already going to build proprietary harnesses anyway — the lock-in was just self-imposed. Managed Agents trades homegrown complexity for Anthropic-hosted complexity, and gets you faster time-to-production in exchange.

For startups and small engineering teams, the calculus is clearer: months of infrastructure work, or use Managed Agents and ship. The answer is usually ship.

How to Get Started

Claude Managed Agents is available via the Claude Platform. Access is through the API — this is not a consumer product. Anthropic's engineering blog has a detailed technical walkthrough, and the documentation covers session interfaces, sandbox provisioning, and the MCP tool proxy setup.

  • Read the Anthropic engineering post: anthropic.com/engineering/managed-agents
  • Claude Platform docs cover the full API surface for sessions, sandboxes, and tool routing
  • Start with a single scheduled agent task — document processing, nightly data sync, or bug triage — before building multi-agent workflows

What This Means For You

If you're a developer building with Claude's API: Managed Agents removes the biggest barrier to shipping agents that do real work over extended time horizons. The session durability and crash recovery alone are worth evaluating for any workflow that runs longer than a few minutes.

If you're evaluating AI infrastructure for enterprise: the security architecture here is notably mature — credential isolation via vault, sandbox separation, no agent access to its own auth tokens. These are the patterns that make agents safe to run in production environments with real data.

If you're watching the competitive landscape: Managed Agents puts Anthropic directly in competition with agent infrastructure startups like LangChain, CrewAI, and AWS Bedrock AgentCore. Anthropic is betting that the best inference provider is also the best place to run the agent layer.

Sources & Further Reading

Related essay
Anthropic Opens Milan Office: Europe's Sixth Hub and a Play for Italian Enterprise
Related essay
Claude Opus 4.8 Is Here: Faster, Cheaper Fast Mode, and Dynamic Workflows That Run Hundreds of Agents
Related essay
Claude Opus 4.7 Is Here: Anthropic's Most Capable Coding Model Yet

THE CLAUDE INSIDER

Get the Claude playbook in your inbox.

One weekly email for Claude and Claude Code users. Real workflows, no hype. Subscribe and we send you The Claude Power-User Cheatsheet.

GUIDES AND COMPARISONS

— ¶ —

Luke Thompson

Luke Thompson

Editor-in-Chief · The Claude Insider

Luke Thompson is the founder of The Operations Guide, LLC and editor of The Claude Insider. Based in Jonesborough, Tennessee, he has spent years building AI-augmented business systems and automation workflows for operators and teams. He began working with large language models in production well before the current wave of consumer AI tools, integrating them into client workflows, content pipelines, and operational infrastructure. At The Claude Insider, he writes about Claude with the specificity of someone who uses it daily as a professional tool — not as a reviewer or commentator, but as a builder. His coverage focuses on what actually works: prompt patterns, API integration strategies, agentic workflows, and the real-world tradeoffs that practitioners face. He is not affiliated with Anthropic, PBC.

Articles are researched and drafted with AI assistance, reviewed and edited by Luke Thompson.

From Reading to Action

Know where AI can pay off in your company.

Take the free two-minute AI Readiness Assessment. See your score, the two gaps holding you back, and the next move worth making.

Get your readiness score

Instant report · No account to start

Related reading

View archive →