Glossary · term

Claude Managed Agents

Claude Managed Agents is Anthropic's API product for running long-lived Claude agent sessions with a managed harness, persisted event history and configurable execution environments. A developer defines a versioned agent—model, system prompt, tools, MCP servers and skills—then starts task-specific sessions in an Anthropic-managed or self-hosted sandbox. The product manages the agent loop and built-in tool execution; the developer still owns application logic, access policy and custom tools.

Products2026-04-08Wave 2 · 2024Maturity: 3/5

Origin and context

Anthropic launched Managed Agents in public beta in April 2026, then added memory, scheduling, outcomes and multi-agent features across public-beta and research-preview stages. Its engineering account separates session logs, the evolving Claude harness and sandboxed execution behind interfaces. AWS exposes product resources through IAM, and Cloudflare publishes an independent control plane for running compatible sandbox environments on its infrastructure.

Sources: s1, s2, s4, s5

Why it matters

A custom Messages API loop must retain conversation history, dispatch tool calls, recover from interruptions and operate its own runtime. Managed Agents moves much of that stateful orchestration behind persistent Agent, Environment, Session and Event resources. This makes long-running and asynchronous execution easier to embed while preserving choices such as agent versioning, self-hosted execution environments and custom-tool handling. It also concentrates operational and security decisions in a provider-specific control plane, making its exact boundaries important.

Sources: s2, s3, s4, s5

Example

A team creates a versioned repository-maintenance agent with file and shell tools, attaches a sandbox environment, uploads or mounts the working files and starts a session. The client sends a task as an event and streams status and tool events until the session becomes idle. Built-in tools execute in the sandbox; a proprietary ticketing action remains a custom tool handled by the team's application. A later session can reuse the agent definition without treating the first session as a permanently running process.

Sources: s2, s3

How it differs

Cloud Agents

Cloud agents are the broader pattern of remote agent execution. Claude Managed Agents is one vendor product with specific persisted resources, APIs and beta constraints.

Agent sandboxes

A sandbox is the environment in which tools act. Managed Agents additionally supplies the Claude harness, agent definitions, sessions and event transport; it can also point at a self-hosted sandbox.

Claude Cowork

Claude Cowork is a user-facing Claude work surface. Managed Agents is a developer API and must not be branded or described as Cowork or Claude Code.

Memory and context poisoning

Persistent history and memory enable continuity but can preserve malicious or incorrect context. Managed storage is not evidence that retained information is trustworthy.

Maturity and evidence

Maturity is 3. The service has documented, versioned APIs, public-beta access, migration guidance and independent AWS and Cloudflare infrastructure support. It is not rated higher because the API requires a beta header, feature parity varies by environment, some capabilities remain research preview, the Cloudflare integration calls itself alpha, and the reviewed performance claims come from Anthropic or quoted customers rather than independent controlled evaluation.

Sources: s1, s2, s4, s5

Limits and open questions

Managed infrastructure does not remove deployment responsibility. Teams must set tool permission policies—the built-in agent toolset defaults to automatic execution—scope credentials and egress, validate custom tools, budget sessions and monitor outputs. Stateful transcripts persist until deleted; the reviewed first-party policy says Managed Agents is not eligible for zero data retention or HIPAA readiness. AWS also excludes the third-party offering from its standard compliance programs. Self-hosting a sandbox does not self-host Claude or erase platform-side state. Availability, behavior and preview features can change during beta.

Sources: s2, s4, s5, s6, s7

Related terms

References

Last updated: 2026-09-07

In the Skills Atlas

This term is also covered in the Skills Atlas as anthropic api skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as ai agent design skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as agent state management skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as agent sandboxing skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as multi agent orchestration skill.