Managed Agents
Also: Claude Managed Agents, cloud agents
Managed Agents are cloud-hosted AI agents that Anthropic runs for you. Instead of building and hosting your own agent infrastructure, you define what the agent should do and Anthropic handles execution — secure sandboxing, long-running sessions, tool access, and scaling. Think of it as Claude-as-a-worker: you assign a task, it runs in the cloud, and you get the result. Currently in public beta at $0.08/session-hour plus token costs.
In practice
You build an agent that drafts weekly status reports. You deploy it through Anthropic's managed infrastructure — it runs on a schedule, Anthropic handles the compute, logging, and uptime, and you just configure what it does. Managed Agents are hosted agents where Anthropic manages the runtime so you don't have to.
Related concepts
Where Managed Agents shows up
4 articlesOn September 3, 2026 Anthropic shipped `ant apply` in version 1.30.0 of the ant CLI. It reads agents, environments, skills, memory stores, and scheduled deployments from files in your repository, prints a plan, and reconciles the Claude API against them once you approve. A committed claude-lock.json maps each file to the resource it created. This is the piece that was missing between clicking an agent together in the Console and having one your team can review, diff, and roll back.
Anthropic just launched Managed Agents. Here is what they do, who they are for, and how to think about whether your team should use them.
Between August 7 and August 19, 2026, Anthropic shipped a hard spend cap per Managed Agents session, an advisor model the primary thread can consult mid-turn, inference geo pinning, GitHub-loaded Skills, memory stores in self-hosted sandboxes, and a rebuilt session viewer. Taken together, this is the month Managed Agents became something you can put a budget behind.
On September 10, 2026 Anthropic added an `auto` permission policy to Claude Managed Agents. The server evaluates each agent or MCP tool call against the session so far and either runs it, denies it outright, or pauses for your approval. Here is what the three policies do, what `auto` will and will not protect you from, and how to read the new `evaluation` field on the event stream.