Secure checkout via Square — all major cards accepted
You can copy this method and do it yourself. Walk the bench. Score the person you want to promote. Plan the hard talk. Install 1-3-1 so the next problem comes back as a recommendation. Buy Now is the packaged bundle: four Notion tools plus the matching Claude skills, so you are not assembling the readiness read from blank pages.
This is the flagship of the Restoration Leadership Toolkit. Everything an owner needs to see whether their team can actually lead, and who to develop next. For growth-stage restoration owners who sense they are the ceiling on their own business.
What’s in the kit
Leadership readiness kit — checklists before titles.
Leadership Readiness Checklist
Middle Manager Evaluation Scorecard
Accountability Conversation Planner
1-3-1 Delegation Worksheet
The matching skills from the Leadership AI plugin: leadership-readiness-checklist, middle-manager-scorecard, accountability-planner, delegation-1-3-1.
Run them in this order. The checklist is the scan. The scorecard is the person. The planner is the talk. 1-3-1 is the habit that keeps the next problem from landing back on you.
1. Leadership Readiness Checklist
Can your team actually lead, or does everything still run through you? Work six sections. Check only what is truly true today. A box you wish were true is a box left unchecked. Rate each section red / yellow / green. Duplicate the page each quarter so you can watch the bench get stronger.
1. Current leadership bench. Who leads field production, estimating, project files, sales, office / AR, marketing, finance, hiring. If a function has no owner besides you, that is a finding. Check: every core function has a named owner who is not you; each owner knows they own it; someone besides you can speak for the company to a customer or adjuster; you have at least one true second-in-command, not just a senior doer. Red = it is all me. Yellow = one or two real leaders. Green = a functioning leadership team.
2. Decision-making. The test of a leader is whether they can make the call when you are not reachable. Clear dollar threshold. Someone can authorize a job, a crew move, or an equipment purchase if you are out a day. When a lead brings a problem, they bring options and a recommendation. You have not reversed a reasonable decision in front of their team in the last 30 days. Red = everything routes to you. Yellow = small stuff yes, real calls no. Green = they own their lane.
3. Accountability habits. A leader who will not hold the line is a doer with a title. Do leads address underperformance, or do they route it to you? Written standards. Feedback that is not just a task list. Consequences when standards are missed. You are not the only person who delivers hard feedback. Red = you are the only enforcer. Yellow = leads avoid the hard ones. Green = leads own their team’s standards.
4. Communication rhythm. Leadership runs on cadence, not heroics. Weekly or biweekly leadership / ops meeting that actually happens. Daily or start-of-job huddle. Recurring 1:1s. A known way job status is communicated (not you texting everyone). Meetings produce decisions and owners. Bad news reaches you early. Red = ad hoc / by text. Yellow = some of it, inconsistently. Green = reliable cadence.
5. Single points of failure. You. The one estimator. The one person who holds carrier relationships. The one person who knows payroll. The one dispatcher. Passwords in one head. No SOP for the things “only so-and-so knows.” For each checked box, name the person, what breaks, and whether a backup exists. Red = several critical SPOFs. Yellow = one or two. Green = cross-covered.
6. Next leader candidates. Name real people. Rate ready now / 1-2 areas to grow / raw potential. Write the one thing each most needs. Have you actually told your top candidate you see leadership in them?
Tally last. Mostly green: deepen the bench and formalize succession. Mostly yellow: push decision authority and accountability down a level. Mostly red: you are still the company. The priority is not more hiring. It is building one true second-in-command and removing the biggest single point of failure (usually you). Write three lines: biggest SPOF right now; the one leader to develop next; the first move in the next 30 days.
2. Middle Manager Evaluation Scorecard
Middle manager scorecard — teach, then trust.
Great doers do not automatically become great leaders. Score the person you named in section 6 before you promote them. One person, one row. Nine traits, 1-5 each. Total is /45.
Ownership. Takes responsibility for outcomes, no blame-shifting.
Communication. Clear, timely, two-way.
Judgment. Makes sound decisions without being told every step.
Emotional maturity. Stays steady under pressure.
Coachability. Seeks and applies feedback, not defensive.
Follow-through. Closes the loop, does what they said by when they said.
Trains others. Can teach a task and bring others up to standard.
Handles conflict. Addresses tension directly and fairly, does not avoid.
Values alignment. Models company values when no one is watching.
Anchor every score in a recent, specific example. Untested is itself a finding. Do not guess a high score on a trait you have never seen. Bands: Promote about 37-45. Develop first about 27-36. Not yet 26 or below. Override: a 1 or 2 on Ownership, Emotional maturity, or Values alignment caps the recommendation at Develop first, regardless of total. Those are the floors for putting someone over people.
Name the lowest 2-3 traits. One concrete development action each. A re-eval date, typically 60-90 days. The owner decides. The score is an input, not a verdict.
3. Accountability Conversation Planner
Use this when someone keeps missing the mark and you have been avoiding the talk. Ten minutes of prep. Six prompts, then a five-beat script.
What is the actual issue? The pattern, not a single bad day. Business impact.
What specific behavior needs to change? Observable. “Calls in after the crew is already on site,” not “doesn’t care.”
What have I already allowed or tolerated? Where you let it slide or finished their file yourself.
What expectation needs to be clarified? State the standard the way you would want it repeated back.
What consequence or support is needed? Both sides.
What does success look like in 30 days? Concrete. “Zero late starts for four weeks.”
Script beats: open and set the tone; name the issue and the behavior; own your part; state the expectation and the support; confirm the 30-day target and listen. Private, not on the job site, not by text. This is a planning doc, not a personnel record.
4. 1-3-1 Delegation Worksheet
1-3-1 worksheet — force a recommendation.
The old way: “The dehu on Maple St died. What do you want me to do?” You just took back the problem, the thinking, and the decision.
The 1-3-1 way: one issue (the fork in the road, one or two sentences); three real options with pros, cons, and rough cost (“do nothing” can be one when it is honest); one recommendation and why in one line; a default if they do not hear back by a deadline. Explain it once. Pin it where decisions get made. When someone brings a raw problem, ask: “What are your three options, and which do you recommend?” Then wait. Run at least five real conversations. Approve the recommendation whenever it is reasonable. Phase done when at least one person brings 1-3-1s without being reminded.
If the Readiness Checklist “options and a recommendation” box is empty, install 1-3-1 before you hire another lead.
If you want the packaged kit
You can run the four tools from the outline above. Buy Now is the bundle delivered by email after checkout: the four Notion pages (duplicate each so the master stays clean), plus the matching skills if you want the interviews walked. Same Square button at the top of this page.
Coaching and operational tools only. Not legal or HR advice. The planner is a planning doc, not a personnel record. The scorecard is decision support, not a hiring, firing, or promotion determination.
Secure checkout via Square — all major cards accepted
You can copy this method and do it yourself. Teach the team to bring one issue, three options, and one recommendation instead of a raw problem. Buy Now is the packaged Notion worksheet you duplicate for every decision they hand up, so you are not rebuilding the form from a blank doc.
Tool 1 of the Restoration Leadership Toolkit. The line is: stop bringing me problems. Start bringing me decisions. The 1-3-1 method trains your people to think like owners. You keep one job: approve, tweak, or redirect.
The old way vs the 1-3-1 way
Old way vs 1-3-1 way.
The old way (escalation): “Hey boss, the dehu on the Maple St job died. What do you want me to do?” You just took back the problem, the thinking, and the decision. That is three jobs.
The 1-3-1 way (delegation): “The dehu on Maple St died. Here are three options I looked at, here is the cost of each, and here is what I would do. Just need your yes.” You own one job: the decision.
The rule
The 1-3-1 rule.
1. One issue. State the decision that is actually needed, in one or two sentences. Not the whole story. The fork in the road.
3. Three real options. Three things you could actually do. Each with pros, cons, and a rough cost or effort. “Do nothing” can be one of the three when it is honest.
1. One recommendation. The option they would pick if it were their call, and why in one line.
A default. What they will do on their own if they do not hear back by a deadline, so the job does not stall waiting on you.
Stuck at two options? Push for a third. Even “do nothing and revisit Friday” or “escalate to the carrier.” A real third option is where the good thinking usually hides.
How to install it
How to install 1-3-1 on the team.
Explain the rule to the team once, out loud. Pin the format where decisions get made: truck, office, group chat.
When someone brings a raw problem, ask: “What are your three options, and which do you recommend?” Then wait.
Run at least five real 1-3-1 conversations before you decide it “isn’t working.” Approve the recommendation whenever it is reasonable.
Resist solving it yourself, even when you are faster. Let them carry it. That is the hard part.
Note who takes to it quickly. That is a signal for your future-manager pick.
The first few times, the 1-3-1s will be lopsided. Three fake options, or a recommendation with no reasoning. Coach it. Do not grade it. The goal is a team that brings you thinking, not just questions. Phase done when at least one person is bringing 1-3-1s without being reminded.
The worksheet (copy this)
Duplicate a page or print a half-sheet for every decision that gets handed up. Fill it in this order.
Who and when
Prepared by
Date
Job / account (if any)
How urgent: Today / This week / No rush
1. The issue / decision needed
One or two sentences. What decision are we actually making? Why does it need a decision now? Then one more line: what happens if we do nothing / decide nothing?
3. The three options
For each option write four lines:
What it is
Pros (two bullets)
Cons (two bullets)
Rough cost / effort
1. My recommendation
I recommend Option __. Why (one or two lines). What I need from you: a yes / a budget approval / a different call / a quick conversation.
What I will do if I do not hear back
If I do not hear back by: (date / time)
I will go ahead and: (the default)
Owner is OK with me proceeding this way unless they say otherwise
Owner decision / sign-off
Approved as recommended / Approved with changes / Chose a different option / Let’s talk
If changed, what
Any conditions or budget cap
Owner name and date
Owner gut-check before you sign
Could this person have made this call without me? If yes, tell them so, and next time push it all the way down to them. That is how the bottleneck clears.
This worksheet is Weeks 3-4 of the 90-Day Doer-to-Leader Transition Plan. After it sticks, write decision rights (who decides what, up to what dollar amount) so people stop defaulting to you out of habit. Hand off one decision completely and do not take it back.
A prompt you can give your own Claude if you want it walked: convert this escalated question into one issue, three options with pros/cons/cost, one recommendation, and a default if I do not answer by a deadline.
If you want the packaged worksheet
You can run 1-3-1 on a legal pad. Buy Now is the Notion page delivered by email after checkout. Duplicate it (··· → Duplicate) for every decision so the master stays clean. The fields, the option tables, the default, and the sign-off are already laid out. Same Square button at the top of this page.
Pairs with the 90-Day Doer-to-Leader Transition Plan (Weeks 3-4) and the Owner Dependency Audit when you are ready to map who should decide. Matching Claude skill: delegation-1-3-1. Coaching aid, not legal or HR advice.
Claude Managed Agents is the product. Slack, Notion, Jira, and Asana are just the interface. Anthropic is building the invisible execution layer that powers the next generation of enterprise software.
There is a pattern emerging in enterprise AI that most people are reading wrong. They see Anthropic launch Claude Tag in Slack and think “chatbot upgrade.” They see Claude show up inside Notion and think “productivity feature.” They see AI agents appear in Jira and Asana and think “automation plugin.”
They are missing the architecture underneath all of it.
Anthropic is not building a better chatbot. It is building the invisible agent runtime that sits beneath every collaboration tool your team already uses. The company’s Claude Managed Agents (CMA) platform — launched in public beta on April 8, 2026 — is the infrastructure layer that makes this possible. And the speed at which partners are embedding it tells you everything about where enterprise software is heading.
What Claude Managed Agents Actually Is
What Claude Managed Agents actually is — the runtime layer.
Claude Managed Agents is a set of composable APIs for building and deploying production AI agents on Anthropic’s cloud infrastructure. The service handles sandboxed code execution, session persistence, credential management, scoped permissions, and end-to-end tracing — all the operational complexity that previously kept agents stuck in proof-of-concept limbo.
The architecture rests on three primitives: the Agent (configuration and behavior), the Environment (sandboxed execution), and the Session (the event log that tracks everything the agent does). What makes this interesting architecturally is how Anthropic decoupled the “brain” from the “hands.” Claude’s reasoning runs on Anthropic’s own infrastructure while the code execution sandbox spins up independently — and in parallel. The brain starts reasoning immediately while the sandbox provisions, delivering roughly 60% faster time-to-first-token at the p50 level and over 90% faster at p95, according to Anthropic’s engineering team.
Pricing follows a transparent model: standard Claude API token rates plus $0.08 per session-hour of active runtime during the current beta period. Runtime is measured to the millisecond and only accrues while the agent is actively executing — idle time waiting for input or tool confirmations does not count.
For teams that need to keep execution inside their own perimeter, CMA supports self-hosted sandboxes through partners including Cloudflare, Daytona, Modal, and Vercel, or custom VPC deployments. MCP tunnels allow agents to connect to private Model Context Protocol servers inside your network without exposing them to the public internet. A Vaults system keeps credentials out of the sandbox entirely using envelope encryption. And a feature called Dreaming runs scheduled reviews of past sessions to curate agent memory — essentially letting agents learn from their own operational history.
The Embedded Layer: Where CMA Actually Lives
Embedded layer: where CMA actually lives in the stack.
The real story is not the infrastructure. It is where that infrastructure shows up. In the ten weeks since CMA launched, Anthropic has embedded its agent runtime inside the collaboration tools that enterprises already depend on. This is not a roadmap — these integrations are live or in active beta.
Slack: Claude Tag as Persistent Team Member
Claude Tag, launched June 23, 2026, replaces Anthropic’s original Claude in Slack integration with something fundamentally different. This is not a chatbot you summon with a slash command. It is a persistent AI team member that lives in your channels, builds memory across conversations, and can take initiative through what Anthropic calls “ambient mode” — proactively surfacing information, following up on forgotten threads, and keeping teams updated across the organization.
Claude Tag is multiplayer by design: one Claude identity per channel, accessible to everyone, with the ability to hand off half-finished tasks between team members. It runs on Claude Opus 4.8, Anthropic’s most capable model released May 28, 2026. And internally, Anthropic reports that Claude Tag is already approving and incorporating 65% of the code changes their product team submits. The existing Claude in Slack app will be retired on August 3, 2026. Claude Tag is available on Enterprise and Team plans.
Notion: Claude as External Agent
On May 13, 2026, Notion launched its Developer Platform version 3.5, which introduced the External Agents API. This API lets AI agents — including Claude — operate inside your Notion workspace as first-class participants. They can read pages, write to databases, create tasks, trigger automations, and be @-mentioned directly in documents. Claude operating through this API can chain actions together: read a project brief, check the task database for related work, draft a new document, and create a linked task entry — all in a single session, running on CMA infrastructure with full sandboxing.
Asana: AI Teammates
Asana built AI Teammates on CMA — agents that pick up assigned tasks inside projects, draft deliverables, and hand back outputs for human review. Specialist agents handle specific workflows: the Campaign Brief Writer turns scattered notes into structured briefs, the Workflow Optimizer identifies process gaps and builds automations, and the Compliance Specialist checks work against regulatory standards. Asana’s CTO said CMA let them ship these features “dramatically faster” than any prior approach to agent development.
Atlassian: Claude Agent for Jira
Atlassian released Claude Agent for Jira, built on CMA infrastructure, which lets teams assign work items directly to Claude from the Jira UI. The agent clones the repository, analyzes the codebase, implements changes on an independent branch, pushes the code, and opens a draft pull request — streaming real-time status updates back to the Jira work item throughout the process.
Sentry: From Bug Detection to Merge-Ready PR
Sentry’s existing AI debugging agent, Seer, already used Claude for root cause analysis. With CMA, Sentry extended the workflow from diagnosis to automated fixing — the agent takes Seer’s root cause output, generates a fix, opens a branch with the changes, and creates a pull request for developer review. Sentry processes over one million root cause analyses per year and provides near-immediate reviews on over 600,000 pull requests per month. The CMA integration was built by a single engineer in weeks, eliminating months of custom agent runtime development.
Rakuten: Specialist Agents Across the Enterprise
Rakuten deployed specialist agents across product, sales, marketing, and finance using CMA, with each agent deployed in approximately one week. Agents plug into Slack and Teams, letting employees assign tasks and receive deliverables including spreadsheets, slides, and applications. In the pilot, Rakuten reported a 97% drop in critical first-pass errors, with cost down more than 30% and latency reduced by 34%, without any loss in output quality.
KPMG: Global Professional Services Alliance
On May 19, 2026, KPMG and Anthropic announced a global alliance and launched “Digital Gateway Powered by Claude.” The partnership embeds Claude, Cowork, and CMA directly into KPMG’s client delivery platform, with an initial focus on tax and private equity clients. Building an AI agent for tax regulation workflows previously took weeks and required switching between multiple tools. With CMA integrated into Digital Gateway, KPMG says the same capability takes minutes. The alliance extends to KPMG’s 276,000-person global workforce.
The Strategic Pattern: Agent Runtime as a Service
Step back from the individual integrations and the strategic pattern becomes clear. Anthropic is not trying to own the interface. It is deliberately positioning CMA as the execution layer underneath interfaces that other companies own. Slack owns the messaging UI. Notion owns the workspace UI. Jira owns the project tracking UI. Anthropic owns the agent brain that powers all of them.
This is a fundamentally different strategy from its two largest competitors.
OpenAI chose vertical integration. When OpenAI launched Workspace Agents on April 22, 2026, it positioned ChatGPT itself as the central hub — a no-code successor to custom GPTs that connects to Slack, Salesforce, Google Drive, and Notion through plugins. Agents are created inside ChatGPT, accessed from ChatGPT, and managed through ChatGPT. OpenAI wants to own the surface area.
Google chose platform depth. At Google Cloud Next on April 22, 2026, Google unveiled the Gemini Enterprise Agent Platform — a reimagined evolution of Vertex AI — alongside Workspace Intelligence, a semantic unifying layer that connects data across Docs, Slides, Gmail, and the broader Google Cloud ecosystem. Google’s agent platform supports 200+ models including Claude, and the Agent2Agent (A2A) protocol enables distributed peer-to-peer agent communication. Google is leveraging its data moat and distribution at the platform level.
Anthropic chose tool-centric orchestration. Rather than owning the UI (OpenAI) or the platform (Google), Anthropic is embedding its agent runtime into every tool through composable APIs and the Model Context Protocol. The platform you use becomes irrelevant — whether it is Slack, Notion, Jira, Asana, or Sentry — because the agent brain running underneath is Claude on CMA.
This is the agent-as-a-service model. And it may be the most defensible position of the three, because it does not require users to change their behavior or migrate to a new platform. The agent shows up where they already work.
What the Numbers Say About Enterprise Agent Adoption
The macro context supports Anthropic’s timing. Gartner predicts that 40% of enterprise applications will include embedded task-specific agents by the end of 2026, up from less than 5% in 2025. McKinsey’s April 2026 analysis found that agentic AI can enable automation of 60 to 80 percent of routine infrastructure work over time, translating to a 20 to 40 percent run-rate cost reduction in initial deployments.
The gap between experimentation and production remains the defining challenge. Industry research compiled from major firms shows that nearly four in five enterprises have experimented with or deployed agents in some form, but fewer than one in nine are running them in production at a scale that generates measurable business value. For the agents that do reach production, the average return on investment is 171% — though 19% of deployments never reach payback at all.
That production gap is exactly what CMA is designed to close. The infrastructure burden — sandboxing, session persistence, credential isolation, error recovery, observability — is the bottleneck. Engineering teams routinely dedicated significant senior engineering resources for months before a single agent reached production. CMA eliminates that layer entirely, which is why partners like Asana, Sentry, and Rakuten report shipping production agents in days or weeks rather than quarters.
What This Means for Businesses Already Using These Tools
If your organization uses Slack, Notion, Jira, or Asana — and statistically, you use at least two of them — you are about to encounter Claude whether you planned to adopt it or not. This is not a technology decision your IT team is making. It is a feature that your existing vendors are shipping.
The practical implications are significant. Claude Tag in Slack means your team channels will have an AI participant that remembers past conversations, can be handed tasks asynchronously, and may proactively surface information. Claude in Notion means your project documentation, databases, and task boards can be read, analyzed, and acted upon by an agent that chains actions together. Claude Agent for Jira means development tickets can be assigned to an AI that clones your repo, writes code, and opens pull requests.
For agencies and service providers managing client work across multiple tools, the embedded agent layer changes the economics fundamentally. Work that previously required a human to context-switch between Slack, Notion, and a project management tool — reading a brief here, updating a task there, drafting a document somewhere else — can be handled by an agent that operates across all of them simultaneously. The coordination tax that consumes a substantial share of knowledge work time is the exact problem embedded agents are built to solve.
The companies that benefit most will be the ones that have clean operational systems — structured task boards, documented processes, well-organized project databases — because agents can only act on information they can read. Messy Notion workspaces and disorganized Jira boards will limit what agents can accomplish. Operational hygiene just became a competitive advantage.
What This Means for Solo Operators Already Running Agent Infrastructure
There is a specific audience that should be paying very close attention to CMA: the solo operators and small agency owners who have already built their own agent stacks from scratch. If you are running scheduled Claude tasks on a GCP Compute Engine VM, connecting to WordPress via REST API proxies, piping work orders through Notion, monitoring Gmail for client replies, and publishing content through MCP-connected pipelines — you have already built a version of what CMA is productizing.
The economics question is worth doing the math on. A lightweight GCP VM running 24/7 to host recurring agent tasks — news desk monitors, outreach reply checks, newsletter extraction, scheduled content audits — costs a fixed monthly rate whether the agents are actively working or sitting idle. CMA at $0.08 per session-hour of active runtime only charges when agents are executing. For tasks that run for a few minutes every few hours, the per-session billing model could be substantially cheaper than keeping a VM warm around the clock. A task that runs for ten minutes six times a day would cost roughly $0.08 per day on CMA, versus the cost of a VM instance that never sleeps.
But the migration path is not ready yet, and solo operators should understand exactly where the gaps are before making any infrastructure decisions.
The biggest gap is MCP tunnels. CMA’s ability to connect agents to private MCP servers inside your network is still in research preview — not production-ready. If your agent stack depends on a private WordPress REST API proxy, a Notion workspace connected via MCP, or any internal tool that is not exposed to the public internet, CMA cannot reach it today. The Vaults system for credential management is promising, but it does not solve the network connectivity problem for self-hosted infrastructure.
The second gap is orchestration control. Solo operators who have built their own agent infrastructure typically have precise control over scheduling, retry logic, error handling, and the exact sequence of tool calls. CMA’s Dreaming feature — which reviews past sessions to curate agent memory — is an interesting approach to agent learning, but it is not the same as having direct control over a cron job that fires at 6:00 AM, checks three data sources in a specific order, and writes results to a specific Notion database with a specific schema.
The thesis for solo operators is straightforward: CMA is almost certainly the future migration path for self-hosted agent infrastructure. The economics favor it for intermittent workloads, the managed security and sandboxing eliminate operational risk you are currently carrying yourself, and the session persistence model solves problems that custom agent runtimes handle poorly. But the plumbing — particularly MCP tunnels to private infrastructure — is not production-ready. Track it closely. Do not migrate yet. When MCP tunnels graduate from research preview to general availability, revisit the math and the connectivity story. That is the trigger point.
The Risk Nobody Is Talking About
The risk nobody talks about — agents that act with memory.
There is a tension in this model that deserves attention. When Claude operates as an invisible layer inside tools you already trust, the boundary between the tool’s native capabilities and the AI agent’s actions blurs. A Jira ticket that was “completed” might have been implemented by Claude, reviewed by a human for thirty seconds, and merged. A Notion project plan that looks thorough might have been generated by an agent that filled in the sections with plausible-sounding content.
The embedded model works precisely because it reduces friction — but reduced friction also means reduced scrutiny. Organizations adopting embedded agents need to build review processes that match the speed at which agents can produce output. The 171% average ROI from agent deployments accounts for the value created, but it does not account for the subtle quality risks of production work generated by systems that are confident, fluent, and occasionally wrong.
Anthropic has built guardrails into CMA — sandboxed execution, credential isolation, session logging — but the governance layer for reviewing agent output at enterprise scale is still largely unsolved. This is a space where internal operational discipline matters more than the technology itself.
Where This Goes Next
Claude Tag launched on Slack first. Anthropic has indicated plans for wider rollout beyond Slack. If the pattern holds, expect Claude Tag’s persistent team member model to appear in Microsoft Teams, Discord, and any other collaboration surface where teams coordinate work.
The CMA primitives are designed to be composable, which means the partner integration list will grow rapidly. Any SaaS company with an API and a workflow that involves reading context, making decisions, and taking actions is a candidate for CMA integration. Customer support platforms, CRM systems, design tools, analytics dashboards, HR systems — the addressable surface is essentially every tool that knowledge workers touch.
Gartner’s long-term projection estimates that agentic AI could drive approximately 30% of enterprise application software revenue by 2035, surpassing $450 billion. If Anthropic’s embedded strategy succeeds, a meaningful slice of that revenue flows through CMA as the underlying runtime — regardless of whose logo is on the interface.
The chatbot era is ending. The embedded agent era is starting. And Anthropic is betting that the company that owns the invisible execution layer wins the market, even if no end user ever sees its name.
Claude Managed Agents is a set of composable APIs launched by Anthropic on April 8, 2026 in public beta. CMA lets developers build and deploy production AI agents on Anthropic’s cloud infrastructure, handling sandboxed code execution, session persistence, credential management, and end-to-end tracing. The architecture separates the “brain” (Claude reasoning) from the “hands” (code execution sandbox), enabling parallel processing and faster agent responses.
How much do Claude Managed Agents cost?
During the current public beta, CMA pricing is standard Claude API token rates plus $0.08 per session-hour of active runtime. Runtime is measured to the millisecond and only accrues while the agent is actively executing — idle time does not count. GA pricing has not been finalized and may differ from the beta rate.
What is Claude Tag in Slack?
Claude Tag is Anthropic’s persistent AI team member for Slack, launched June 23, 2026. Unlike a traditional chatbot, Claude Tag lives in channels, builds memory across conversations, takes initiative through ambient mode, and works asynchronously. It is multiplayer — one Claude identity per channel that all team members interact with. Claude Tag runs on Claude Opus 4.8 and is available on Enterprise and Team plans. It replaces the original Claude in Slack app, which retires August 3, 2026.
Which tools have Claude Managed Agents embedded?
As of June 2026, CMA is embedded in Slack (via Claude Tag), Notion (via the External Agents API), Asana (AI Teammates), Atlassian Jira (Claude Agent for Jira), and Sentry (extending the Seer debugging agent). Enterprise deployments include Rakuten (specialist agents across product, sales, marketing, and finance) and KPMG (Digital Gateway Powered by Claude for tax and private equity clients).
How does Anthropic’s agent strategy differ from OpenAI and Google?
Anthropic uses a tool-centric orchestration approach, embedding its agent runtime inside existing tools via composable APIs and the Model Context Protocol (MCP). OpenAI chose vertical integration with Workspace Agents, positioning ChatGPT as the central hub. Google chose platform depth with the Gemini Enterprise Agent Platform and Workspace Intelligence semantic layer. Anthropic’s approach does not require users to change platforms — the agent shows up where they already work.
What percentage of enterprise apps will have embedded AI agents by end of 2026?
Gartner predicts that 40% of enterprise applications will include embedded task-specific agents by the end of 2026, up from less than 5% in 2025. However, fewer than one in nine enterprises currently run agents in production at scale, suggesting significant growth ahead.
Can Claude Managed Agents run inside a private network?
Yes. CMA supports self-hosted sandboxes through partners including Cloudflare, Daytona, Modal, and Vercel, or custom VPC deployments. MCP tunnels allow agents to connect to private Model Context Protocol servers inside your network without public exposure. A Vaults system keeps credentials out of the sandbox using envelope encryption.
Claude is far more than a chatbot. Anthropic calls Claude Code and Cowork “general agents — broad-domain systems that handle research, operations, analysis, and code with equal fluency.” In practice, that means the same AI that writes software can also run your marketing, draft grant proposals, analyze a spreadsheet, and automate the busywork that fills your week. This guide maps what people actually use Claude for, organized by the job you’re trying to get done — with a deeper walkthrough behind each one.
Content & marketing
Content, ops, build, knowledge — pick the lane first.
The most popular non-technical use. Claude researches, drafts, edits, and optimizes — from a single blog post to an entire editorial pipeline.
Where Claude started. Claude Code is an agentic coding tool that reads your codebase, writes and refactors, runs tests, and ships — from the terminal, an IDE, or a desktop app.
Which Claude is right for you depends on the job, not the brand.
Chatbot, coding agent, knowledge-work agent, Slack teammate — these are different doors into the same models. Match the surface to your job first, then size the plan.
Content creation, software development, business operations, data analysis, and knowledge work. Anthropic positions Claude Code and Cowork as general-purpose agents, not just a chat assistant.
Do you need to know how to code to use Claude?
No. Claude’s chat, Cowork, and Slack surfaces require no coding, and even Claude Code can be driven by non-developers for writing, research, and file work.
What’s the difference between Claude, Claude Code, and Cowork?
Same underlying models, different surfaces: Claude (chat) for conversation, Claude Code for agentic coding, and Cowork for agentic knowledge work. See the full comparison.
Is there a version of Claude for my industry?
Yes — see the industry walkthroughs above (marketing, real estate, agencies, restoration, local news, B2B SaaS, and nonprofits) for sector-specific workflows.
New to Claude? Start with pricing & plans, then pick the surface that fits the job you have in mind.
Claude for Nonprofits is Anthropic’s program that gives qualifying nonprofits up to 75% off Claude’s Team and Enterprise plans — with Team seats starting around $8 per user per month — plus nonprofit-specific data connectors, free AI training, and access to a $150M fellowship. If your organization holds 501(c)(3) status (or an international equivalent), you almost certainly qualify. Here’s what’s included, who’s eligible, and how mission-driven teams are putting it to work.
Direct Answer (August 2026): Anthropic offers discounted Claude Team subscriptions and grants for verified 501(c)(3) nonprofit organizations, charities, and educational foundations, facilitating grant writing, donor communications, and operational reporting.
What is Claude for Nonprofits?
What Claude for Nonprofits actually is.
Launched by Anthropic in 2026, Claude for Nonprofits packages the same Claude models used by enterprise teams into an offering built for the realities of mission-driven work: tight budgets, lean staff, and a constant need to do more with less. It bundles three things nonprofits rarely get together — steep pricing discounts, sector-specific integrations, and free training — into one program. It runs on the same foundation as Anthropic’s commercial plans, so nonprofits get the latest Claude models (Opus, Sonnet, and Haiku), not a stripped-down version.
Who qualifies?
Who qualifies — check eligibility before budgeting.
Eligibility is broad, and Anthropic validates organizations through its partner Goodstack. The program covers:
501(c)(3) nonprofits in the U.S., and organizations with equivalent charitable designations internationally
K–12 schools, public and private
Mission-based healthcare organizations with 501(c)(3) status — including independent Critical Access Hospitals (CAHs), Rural Emergency Hospitals (REHs), HRSA-designated Federally Qualified Health Centers (FQHCs) and FQHC Look-Alikes, and CMS-certified Rural Health Clinics (RHCs)
If you can document charitable status, eligibility is usually straightforward.
How much does it cost?
Qualifying organizations receive up to 75% off Claude’s Team and Enterprise plans:
Team plan — discounted pricing starts around $8 per user, per month, which makes it realistic to roll Claude out to an entire staff rather than a single power user.
Enterprise plan — custom pricing for larger organizations; you contact Anthropic’s sales team.
The highest-leverage uses cluster around the work that eats the most staff time:
Grant writing — drafting proposals aligned to a specific funder’s priorities, then tailoring them per application.
Donor stewardship — personalizing outreach and acknowledgements at a scale a small development team could never manage by hand.
Program evaluation & impact analysis — turning messy program data into the impact narratives boards and funders want.
Board & compliance documentation — generating board materials, reports, and compliance documents from source data.
The common thread: Claude removes the blank-page tax on the writing- and analysis-heavy work that keeps nonprofit staff at their desks instead of in the field.
Connectors built for the nonprofit stack
Anthropic built integrations with the platforms nonprofits already run on, so Claude can work against real organizational data:
Benevity — access to 2.4M+ validated organizations for volunteering and donation research
Blackbaud — CRM and fundraising tools for donor management, campaign tracking, and donation optimization
Candid — data on nonprofits and funders to discover organizations, grants, and philanthropic opportunities
Free training and the Claude Corps fellowship
Two things set this apart from a plain discount:
AI Fluency for Nonprofits — a free course Anthropic developed with GivingTuesday, covering grant writing, program evaluation, donor engagement, and organizational efficiency. It’s aimed at staff, not engineers.
Claude Corps — a $150M fellowship initiative pairing nonprofits with AI expertise and resources to implement Claude across their operations. Anthropic also works with partners including The Bridgespan Group, Idealist Consulting, Vera Solutions, and Slalom to support adoption.
How to get started
Confirm your charitable status (501(c)(3) or international equivalent).
Apply through Anthropic’s nonprofit page — eligibility is validated via Goodstack.
Choose Team (self-serve, discounted seats) or contact sales for Enterprise.
Enroll staff in the free AI Fluency for Nonprofits course to get value quickly.
Not free, but heavily discounted — up to 75% off Team and Enterprise plans, with Team seats starting around $8 per user per month for qualifying organizations.
Who qualifies for Claude for Nonprofits?
501(c)(3) nonprofits (and international equivalents), K–12 public and private schools, and mission-based healthcare organizations with 501(c)(3) status. Eligibility is validated by Goodstack.
Which Claude models do nonprofits get?
The discounted plans include Claude’s current lineup — Opus, Sonnet, and Haiku — the same models on the commercial plans, not a limited version.
What can a nonprofit do with Claude?
Common uses include grant writing, donor stewardship, program evaluation, and board and compliance documentation, plus integrations with Benevity, Blackbaud, and Candid.
Is there training for nonprofit staff?
Yes. Anthropic and GivingTuesday offer a free “AI Fluency for Nonprofits” course, and the $150M Claude Corps fellowship provides hands-on implementation support.
For the past week or so I’ve been building a real operation with Claude — not a demo, not a clever prompt, an actual business a partner of mine is about to run.
It built the storefront: a full ladder of products, from a $7 scorecard up to a complete operating system, each one wired to checkout and set to deliver itself the second someone buys. It built a redemption engine, so my partner can give out a code from a stage and the right person instantly gets the product while we capture the lead. It drafted a productized lead-generation offer — the pricing, a one-page pitch, even a scorecard to decide which contractors are a fit. When the server’s email quietly broke, it traced the real cause — a file permission, three layers down — and fixed it.
That’s the part everyone wants to talk about: look what it can do. And it’s real. But it’s not what I’ll remember from this week.
The moment that mattered
The moment that mattered.
I asked Claude to check whether a call-tracking number was set up correctly on the site. It looked, confirmed the number was live and routing to the right phone — and then, because it’s thorough, started to clean up a small labeling gap on that number.
And then it stopped itself.
A safety layer caught the action before it ran and refused it. The reason it gave was almost uncomfortably precise: you asked me to verify this, not to change it. This is a live system other people depend on. That’s your call, not mine.
I’d only asked it to look. It had drifted toward changing a shared, live system — exactly the kind of small, well-meant overstep that’s easy to miss — and something stopped it and handed the decision back to me.
I’d spent a week watching this thing demonstrate real capability. The moment it earned my trust was the moment it demonstrated restraint.
Capability was never the scary part
Capability was never the scary part.
That’s backwards from how most people are sizing up AI right now. The whole conversation is capability — what can it do, how much, how fast. But if you’re actually putting this into your business, capability was never the scary part. The scary part is an eager, capable system taking a consequential, hard-to-undo action on something live because it technically could, and because you weren’t specific enough.
What protected me wasn’t that the AI was timid by personality. It’s that the whole thing is built so the more consequential, irreversible, and shared an action is, the more a human has to be in the loop. Reading something? Go ahead. Changing a live system someone else relies on, when that wasn’t clearly asked for? Stop and ask. The gate tightens exactly as the stakes rise.
And the part that actually sold me: when I asked how that worked, it explained its own guardrails plainly. It didn’t pretend it had no limits, and it didn’t pretend it could talk its way around them. It told me where the brakes are, who controls them (me), and what it genuinely can’t see about its own safety layer. An AI that’s honest about what it won’t do is a lot easier to trust with what it will.
What I’d take from it
What I’d take from it.
If you’re bringing AI into your operation, here’s what I’d take from my week: don’t just ask what it can do. Ask what it does when it isn’t sure. Ask what happens at the edge — the live system, the irreversible change, the thing you didn’t quite specify. That answer matters more than the length of the feature list, because that’s the moment that either protects your business or burns it.
The most capable AI in the room is impressive. The one that knows what it shouldn’t do without you is the one you can actually build on. I got to see both this week. Turns out they were the same one.
Setting up Claude Tag in Slack takes a few minutes. The clicks are easy. The decisions you make while you click — who can reach it, which channels it sees, whether it’s proactive — are the part that actually matters. This is a security-first walkthrough: how to install it, and what to lock down before you do.
The install, in plain steps
The install, in plain steps.
Open the Install Claude for Slack link, which takes you to the Slack Marketplace listing.
Click Add to Slack and approve the requested permissions.
Choose the scope: the whole workspace (Anthropic’s recommended default) or a specific set of channels.
One important gotcha: only a Slack Primary Owner or Owner can set up Claude Tag’s access and channels. The Admin role can’t do this part. If you’re rolling it out for a team, make sure an Owner is the one configuring access — otherwise you’ll get halfway and stall.
Lock this down first: who can reach Claude
Lock down who can reach Claude first.
Claude Tag gives you three Member Access modes. Pick the tightest one that still lets the right people work:
Anyone in the Slack workspace — broadest; fine for a single internal team, risky if outside collaborators or clients are guests in your workspace.
Any member of your Claude organization — narrower; ties access to your Claude org, not just Slack presence.
Role-based access — tightest; only members whose role allows it. This one is available on the Claude Enterprise plan.
Default to the narrowest mode that doesn’t block real work. You can always widen later; clawing access back after the fact is harder.
Then decide what Claude can see
Access is who can talk to Claude. Visibility is what Claude can read — and it’s the bigger lever. Two settings deserve a deliberate decision, not a default:
Cross-channel learning is permission-gated — Claude only learns from other channels and data sources you allow, and it doesn’t report from private channels. Grant it per channel, and never let a channel holding one client’s (or one regulated dataset’s) data feed learning that other work can draw on.
Map channels to trust boundaries before you enable anything — mark each channel internal, client, or regulated.
Set Member Access to the narrowest mode that works.
Ambient mode OFF by default; on only for internal-only channels.
Cross-channel learning granted per channel, never from client/regulated channels.
Isolate client work in its own space, not just a channel in one shared brain — the reasoning is in The Multi-Client Isolation Trap.
Keep a human on the ship button for anything that leaves the building.
If you’re migrating from the old app
Claude Tag replaces the legacy Claude in Slack app. The old app switches over on August 3, 2026, and administrators have a 30-day window to opt in and control channel-level access. Don’t treat the migration as a silent upgrade — it’s the moment to redo these access and visibility decisions from scratch. More on what changed: Claude Tag vs. the Old Claude in Slack App.
For the exact, current setup screens, Anthropic keeps an admin setup guide in its documentation; the decisions above are what to bring to it. For the full field guide, start at the pillar: Claude Tag: A Builder’s Guide for Agencies.
Ambient mode is Claude Tag’s headline feature and its single most consequential setting. Turn it on and Claude stops waiting to be asked — it starts watching the channels it’s in and speaking up when it thinks you’d want to know something. Whether you should enable it isn’t a yes-or-no question. It’s a where question, and getting the where right is the whole game.
What ambient mode actually does
What ambient mode actually does.
By default, Claude Tag is reactive: you @-mention it, it works, it replies. With ambient behavior enabled, it becomes proactive. Anthropic describes it as Claude keeping you updated about whatever it thinks you might need to know — flagging relevant information from across the channels it’s in and the tools it’s connected to, and following up on threads or tasks that have gone quiet.
In practice that means three things: it surfaces context you didn’t ask for, it connects information across more than one channel, and it chases loose ends nobody assigned it. Those are exactly the behaviors that make it feel like a teammate instead of a tool.
Where it’s a superpower
Inside a single team, ambient mode is close to magic. Every channel belongs to the same company, so “learning across channels” only ever connects your own dots. A proactive teammate that remembers the forgotten follow-up, links the spec to the standup, and flags the blocker before it bites is pure upside. This is the version Anthropic runs internally, and it’s why they can say a large share of their product team’s code now comes from their own version of the tool.
If your Slack workspace is one company’s data and one team’s work, turn ambient mode on and enjoy it.
Where it’s a risk
Where ambient mode is a risk.
Ambient mode’s proactive, cross-channel nature is exactly what makes it dangerous in two situations:
Multiple clients in one operation. The moment a proactive teammate is “surfacing relevant information from across channels,” relevance becomes the judge of what crosses the line between Client A and Client B. That’s a context-bleed risk we’ve lived — the whole subject of The Multi-Client Isolation Trap.
Regulated or sensitive data. Anywhere an unprompted message pulling context from elsewhere could expose something it shouldn’t — health, financial, legal, HR — proactive surfacing is a liability, not a convenience.
A simple decision framework
A simple decision framework before you enable it.
Don’t decide ambient mode globally. Decide it per surface, with one question: is everything this Claude can see owned by the same trust boundary?
Surface
Ambient mode
Why
Internal team channels (one company)
ON
Cross-channel proactivity only connects your own data
Client-facing / multi-tenant channels
OFF
Proactive surfacing is where one client’s context leaks into another’s
Regulated / sensitive-data channels
OFF
Unprompted context-pulling is a compliance liability
The rule of thumb: ambient mode should be on where the data is all yours, and off everywhere a human should still be pulling, not the AI pushing.
If you do turn it on
Enable it deliberately, not by default. Map which channels hold which trust boundary before you flip the switch, keep client and regulated channels out of cross-channel learning, and audit what the assistant can actually see. That sequencing — boundaries first, then ambient — is exactly how we walk through it in How to Set Up Claude Tag in Slack.
The bottom line
Ambient mode isn’t good or bad — it’s powerful, and power needs a boundary. For internal teams, it’s the best part of Claude Tag. For client work, it’s the part to leave off until isolation is airtight. For the full picture, start at the pillar: Claude Tag: A Builder’s Guide for Agencies.
If your team already used the “Claude in Slack” app, Claude Tag is not an add-on — it’s the replacement. Anthropic has said Claude Tag replaces the existing Claude in Slack app, administrators have a 30-day window to opt in, and the legacy app is retired on August 3. So this isn’t a “should we try it” decision. It’s a migration with a clock on it. Here’s what actually changed, and what to check before you flip the switch.
What’s genuinely new
What is genuinely new in Claude Tag.
The old integration was, in practice, a way to summon Claude in a thread. Claude Tag changes the model from “a chatbot you call” to “a teammate that stays.” Four things are new:
Multiplayer per channel. Within a given Slack channel, there’s one Claude that interacts with everyone. Anyone can tag it in and pick up where the last person left off, instead of each person holding a private session.
Ambient mode. When enabled, Claude proactively keeps people updated about what it thinks they need to know — flagging relevant information, following up on forgotten threads — rather than waiting to be asked.
Cross-channel learning. With permission, Claude can learn from other Slack channels and data sources. (Anthropic notes it doesn’t report from private channels.)
Opus 4.8 underneath. Claude Tag runs on Opus 4.8, so the reasoning behind the delegation is the current-generation model, not whatever the old app was pinned to.
The migration timeline, plainly
Migration timeline, plainly.
Three dates and facts matter:
Claude Tag is available today in beta for Claude Enterprise and Team customers.
Administrators have 30 days to opt in and migrate.
The old Claude in Slack app is retired on August 3. If you do nothing, that capability goes away.
Anthropic is also issuing an introductory launch credit to eligible Enterprise and Team organizations, which makes the trial period genuinely low-stakes for internal use.
What to check before you switch — especially if you serve clients
What to check before you switch — especially for clients.
For a single-company team, migrating is close to a no-brainer: you get a better model and a more capable teammate, and the launch credit covers the experiment. If you’re an agency or anyone handling more than one client’s data in one workspace, three checks come first:
Decide cross-channel learning per channel, not globally. The new superpower is also the new risk. A channel that holds one client’s data should never feed learning that another client’s work can draw on. Map your channels to trust boundaries before you grant any cross-channel permission.
Default ambient mode OFF for client-facing channels. Proactive surfacing is wonderful internally and dangerous across tenants. Turn it on where the data is all yours; leave it off where it isn’t.
Keep your approval gate. Whatever human sign-off you had on outbound work in the old setup, carry it forward. A more autonomous teammate raises the stakes on “who hits send.”
Our take
Adopt it internally now — the model upgrade and the multiplayer surface are worth it, and the clock makes the decision for you anyway. For client delivery, migrate deliberately: the same features that make Claude Tag better make isolation harder, and isolation is the thing you can’t get wrong. We unpack exactly that failure mode in The Multi-Client Isolation Trap, and the on/off call for proactive behavior in Claude Tag Ambient Mode.
Claude Tag’s two best features are ambient mode and cross-channel learning. Inside a single company, they are close to magic: one AI teammate that quietly learns how the whole organization works and surfaces the right thing at the right moment. If you run an agency, those same two features are a trap. This piece is about why, and exactly what to build instead.
Why an agency is a different shape of problem
Why an agency is a different shape of problem.
A company is one tenant. Every channel, every document, every thread belongs to the same entity, so an AI that “learns across channels and data sources” is only ever connecting your own dots. That is the design Claude Tag is optimized for, and Anthropic’s own number — 65% of their product team’s code now comes from their internal version — shows how well it works when all the data is yours.
An agency is the opposite shape. You are many clients sharing one operation. Client A and Client B may be competitors. The instant your AI teammate is allowed to learn across channels, the wall between those two accounts depends on the model’s judgment about what is “relevant” — and relevance is exactly the thing it’s designed to be generous about. Cross-channel learning isn’t a bug here. It’s a feature pointed in the wrong direction.
The lesson we learned by living it
We didn’t reason our way to this. We hit it. In an early pilot, running a single shared context across more than one account, the assistant produced a client deliverable that pulled in details from the wrong account. Nothing left the building — the human review caught it — but the signal was unmistakable. For client work, ambient cross-channel learning is not a feature. It’s a breach waiting for a deadline, because the day it slips through is the day someone is moving too fast to catch it.
That single near-miss reorganized how we build. It is the reason we treat isolation as architecture, not etiquette.
Why “don’t mix clients” in a prompt is not a control
The tempting fix is to tell the assistant, in its instructions, to keep clients separate. Don’t rely on it. A prompt is a request for good behavior; it is not a boundary. Under deadline pressure, with a helpful model trying to surface everything relevant, “please don’t cross the streams” is the first thing to bend. Isolation that matters is enforced in the structure of the system — in what the assistant can even see — not in what you politely ask it not to do.
The pattern that works: split by surface
Split by surface — the isolation pattern that works.
The move that resolved it for us was to stop treating “internal” and “client-facing” as the same problem. They get different architectures:
Surface
Use
Why
Your internal team
Adopt Claude Tag fully
Ambient mode and cross-channel learning are features when all the data is yours
Client-facing delivery
Isolated room + approval gate
Per-client isolation and human sign-off are the product, not overhead on it
Internally, turn everything on. Let it learn across your channels, run ambient, follow up on your forgotten threads. For client work, each client gets a walled room that cannot see any other client’s context, and nothing leaves that room without a human approving it.
Do this instead: a concrete checklist
Concrete checklist instead of prompt hope.
One isolated space per client — not one shared brain with channels. The boundary should be the space itself, enforced by what data the assistant is connected to, so there is nothing to “accidentally” pull from another account.
Cross-channel learning OFF for anything client-facing. It is the single setting most likely to cause a bleed. Reserve it for internal-only surfaces.
Ambient mode OFF on client rooms by default. Proactive surfacing is where unrequested context shows up. Let humans pull in a client room; let the AI push only where the data is all yours.
A human on the ship button for everything that leaves the building. The AI drafts; a person reviews and approves; only then does it go to the client. This is the control that caught our near-miss.
Audit what the assistant can see, deliberately. Permissions are the real boundary. Set them on purpose, write them down, and review them when you add a client.
Map every channel to a trust boundary before you turn anything on. Decide, per channel, whether it is internal or client data — and never let a client-data channel feed cross-channel learning.
The one sentence to take with you
The two things that make Claude Tag magical inside a company — ambient mode and cross-channel learning — are the two things you must wall off to use it safely for clients. Get that right and you get the upside without betting the client relationship on a model’s judgment about relevance.