What you will be able to do
- Map procurement, billing and identity requirements to a Claude deployment route
- Choose between the Messages API and Claude Managed Agents based on state and data-retention requirements
- Turn security requirements into container, network and credential controls
- Name the hosting criteria to check when picking a sandbox provider for an agent
1.Where Claude is procured, billed and authenticated
Infrastructure requirements usually come from outside the engineering team: procurement, finance, identity and compliance. The Claude Code deployment docs compare the routes to Claude on exactly these points. The comparison is written for rolling out Claude Code, but it shows how an organisation's existing cloud contracts, audit tooling and identity provider narrow the choice.
| Route | Best for | Billing | Enterprise features |
|---|---|---|---|
| Claude for Teams/Enterprise | Most organizations (recommended) | Per seat, or Contact Sales | Team management, SSO, usage monitoring |
| Anthropic Console | Individual developers | PAYG | None |
| Amazon Bedrock | AWS-native deployments | PAYG through AWS | IAM policies, CloudTrail |
| Claude Platform on AWS | AWS Marketplace billing with Claude API features | PAYG through AWS Marketplace | IAM policies, CloudTrail |
| Google Cloud’s Agent Platform | GCP-native deployments | PAYG through GCP | IAM roles, Cloud Audit Logs |
| Microsoft Foundry | Azure-native deployments | PAYG through Azure | RBAC policies, Azure Monitor |
Network rules add two more options. A corporate proxy routes traffic through HTTPS_PROXY or HTTP_PROXY when every outbound request has to be monitored. An LLM gateway sits between the client and the provider when the organisation wants central usage tracking, per-team budgets or central authentication. It is configured with variables such as ANTHROPIC_BASE_URL or ANTHROPIC_BEDROCK_BASE_URL.
An enterprise needs a coding agent capable of running autonomously for multiple hours to perform a large-scale refactor across a complex codebase, prioritizing accuracy over cost. Which model best fits this requirement?
Correct answer: C — Claude Opus 4.8
- A. Haiku 4.5 is optimized for speed and cost efficiency, not for the deepest reasoning needed in multi-hour autonomous refactoring across a complex codebase.
- B. Sonnet 5 is a strong generalist for coding and agentic tool use, but Opus 4.8 is the model positioned specifically for complex, long-horizon agentic coding and enterprise work.
- C. Opus 4.8 is described as the model for complex agentic coding and enterprise work, including multi-hour autonomous coding agents and large-scale refactoring, matching the accuracy-first requirement.
- D. Opus 4.1 is a deprecated legacy model with a smaller 32k output limit and higher cost than current models, and is being retired rather than recommended for new work.
Sources1
2.Messages API or Managed Agents: state and data retention
The second infrastructure decision is who runs the agent loop. The Messages API gives you direct access to the model and suits custom agent loops that need fine-grained control. You build the loop, the tool execution and the runtime yourself. Claude Managed Agents is a pre-built harness that runs on managed infrastructure. It handles long-running execution, sandboxes, scheduled runs, and sessions that keep a persistent filesystem and conversation history.
No. Managed Agents is stateful by design and stores conversation history, sandbox state and outputs on the server, so it is not currently eligible for Zero Data Retention or HIPAA BAA coverage. The retention requirement outranks the convenience preference. You can delete sessions and uploaded files through the API, but that is not the same as zero retention.
Data residency is a separate requirement. Managed Agents can run sessions in self-hosted sandboxes on infrastructure you control, which the docs position for compliance and data-residency needs. That governs where the sandbox runs. These sources don't say where model inference itself runs, so don't read self-hosting as a guarantee about inference location.
A product team needs frontier-level intelligence for code generation, data analysis, and agentic tool use across a large user base, and wants the best balance of speed and intelligence rather than the highest-end, most expensive reasoning model. Which model fits this requirement?
Correct answer: C — Claude Sonnet 5
- A. Opus 4.8 is the most capable option for complex agentic coding and enterprise work, but it is priced and positioned above the balanced speed-and-intelligence tier the requirement asks for.
- B. Haiku 4.5 is the fastest and cheapest option, but it is positioned for high-volume, cost-sensitive workloads rather than frontier-level code generation and data analysis at scale.
- C. Sonnet 5 is explicitly described as frontier intelligence at scale with the best combination of speed and intelligence, fitting code generation, data analysis, and agentic tool use.
- D. Mythos 5 shares Fable 5's premium specs and pricing and is limited-availability through Project Glasswing, not a general-purpose balanced option for a large user base.
Sources2
3.Isolation, network and credential requirements
When the solution runs an agent that executes code, security requirements become concrete controls. The Agent SDK deployment guide lists them by resource: mount only the directories the agent needs, restrict the network to specific endpoints through a proxy, inject credentials through the proxy, and drop Linux capabilities. Isolation technologies differ in strength and cost. A sandbox runtime has very low overhead. gVisor and VMs give excellent isolation when set up correctly, but cost more in performance and complexity.
docker run \
--cap-drop ALL \
--security-opt no-new-privileges \
--security-opt seccomp=/path/to/seccomp-profile.json \
--read-only \
--tmpfs /tmp:rw,noexec,nosuid,size=100m \
--tmpfs /home/agent:rw,noexec,nosuid,size=500m \
--network none \
--memory 2g \
--cpus 2 \
--pids-limit 100 \
--user 1000:1000 \
-v /path/to/code:/workspace:ro \
-v /var/run/proxy.sock:/var/run/proxy.sock:ro \
agent-imageWith --network none, the agent can reach the outside world only through the mounted proxy socket. That shapes the credential design: a proxy outside the container adds the credentials, so the agent never sees them and they are stored in one place. The same proxy can enforce an endpoint allowlist and log every request for audit.
Sources3
4.Hosting: where state lives and what to ask a sandbox provider
A self-hosted Agent SDK deployment also has to decide where state lives. By default, session transcripts go under ~/.claude/projects/, CLAUDE.md memory files sit at the user and project tiers, and artifacts land in the session's working directory. If the requirement is for users to resume conversations across requests, the SDK can resume a session ID from a SessionStore. That can be an object store, a key-value store or a database.
| Criterion | Requirement it answers |
|---|---|
| Who runs the sandbox | Build and operate it yourself, or buy it as a service |
| Cold-start latency | Ephemeral patterns need sub-second starts; long-running ones tolerate more |
| Persistent storage | The hybrid pattern needs durable storage somewhere |
| Pricing model | Per-second suits bursty ephemeral work; hourly suits long sessions |
| Networking | Custom egress, outbound proxies, private VPC peering for regulated environments |
Sources4
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Because Managed Agents lets you delete sessions, it satisfies a Zero Data Retention requirement.Why is that wrong?
Managed Agents stores session history, sandbox state and outputs on the server by design. It is not currently eligible for ZDR or HIPAA BAA coverage. Deleting data after the fact is not zero retention.
Covered in Messages API or Managed Agents: state and data retention
2.A sandbox proxy with a domain allowlist inspects encrypted traffic, so nothing can reach hosts outside the list.Why is that wrong?
The sandbox runtime proxy checks the client-supplied hostname and does not decrypt traffic. Techniques like domain fronting can get around it. If your threat model needs stronger guarantees, you need a TLS-terminating proxy.
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Use this if your organization requires all outbound traffic to pass through a proxy server for security monitoring, compliance, or network policy enforcement.”
↩︎ Where Claude is procured, billed and authenticated“Use this if you need centralized usage tracking across teams, custom rate limiting or budgets, or centralized authentication management.”
↩︎ Where Claude is procured, billed and authenticated - 2.
“Instead of building your own agent loop, tool execution, and runtime, you get a fully managed environment”
↩︎ Messages API or Managed Agents: state and data retention“Managed Agents is not currently eligible for Zero Data Retention or HIPAA Business Associate Agreement (BAA) coverage.”
↩︎ Messages API or Managed Agents: state and data retention“Self-hosted execution: Sandboxes on infrastructure you control for compliance or data-residency requirements”
↩︎ Messages API or Managed Agents: state and data retention“Managed Agents is not currently eligible for Zero Data Retention or HIPAA Business Associate Agreement (BAA) coverage.”
↩︎ Exam trap 1 - 3.
“Mounts code read-only so the agent can analyze but not modify it.”
↩︎ Isolation, network and credential requirements“The agent never sees the actual credentials”
↩︎ Isolation, network and credential requirements“Credentials are stored in one secure location rather than distributed to each agent”
↩︎ Isolation, network and credential requirements“No TLS inspection: The proxy allowlists domains based on the client-supplied hostname and does not terminate or inspect encrypted traffic.”
↩︎ Exam trap 2 - 4.https://code.claude.com/docs/en/agent-sdk/hostingOfficial docs
“Persistent storage: whether the provider offers durable volumes or only ephemeral disk.”
↩︎ Hosting: where state lives and what to ask a sandbox provider“Per-second pricing suits bursty ephemeral workloads. Hourly suits long-running sessions.”
↩︎ Hosting: where state lives and what to ask a sandbox provider“Networking: support for custom egress rules, outbound proxies, and private VPC peering for regulated environments.”
↩︎ Hosting: where state lives and what to ask a sandbox provider