Claude Managed Agents vs Self-Hosted Coding Agents
If you are choosing between Claude Managed Agents, self-hosted execution, and owned open-source agent runtimes, the decision is not mainly about which agent feels smarter. It is about where the agent harness, filesystem, tool execution, network access, credentials, logs, state, and model context live.
The short answer: use Claude Managed Agents when speed, managed orchestration, and long-running cloud work matter more than strict control over state and data paths. Use self-hosted Claude execution when you need tools, repos, build artifacts, package registries, and network egress to stay in your infrastructure, while accepting that Anthropic still runs the control plane and receives tool inputs and outputs. Use owned or open-source self-hosted coding agents when your organization needs to control the runtime itself, model routing, audit design, sandboxing, and lifecycle operations.
The costly mistake is treating "self-hosted" as a synonym for private inference. In Anthropic's self-hosted Managed Agents model, execution can move into your infrastructure, but tool inputs and outputs still flow through Anthropic's control plane. That may satisfy some network isolation or data residency requirements. It does not automatically satisfy Zero Data Retention, HIPAA BAA, or fully local cognition requirements.
The Decision Is a Boundary Map
For an engineering leader, the practical question is: what boundary are you trying to move?
If your concern is developer velocity, a managed cloud harness is attractive. Anthropic describes Claude Managed Agents as a pre-built, configurable agent harness for long-running work, with agents, environments, sessions, and events. It includes built-in tools such as Bash, file read, file write, edit, glob, grep, web search, web fetch, and MCP servers.
If your concern is the execution environment, self-hosted execution is meaningful. Managed Agents self-hosted sandboxes move tool execution, code, filesystem, processes, and network egress into customer infrastructure. Claude Code self-hosted environments use an Anthropic control-plane queue and customer runners. Those runners make outbound HTTPS connections, and Anthropic does not connect inbound.
If your concern is the full runtime and model path, self-hosted execution is not enough by itself. Open-source or owned runtimes such as OpenHands, Aider, or a custom harness shift more responsibility to your team. You gain runtime control and model choice, but you also inherit sandboxing, secrets, approvals, logging, queueing, upgrades, reliability, and user experience.
Related reading: self-hosted coding agent runtime.
What Claude Managed Agents Gives You
Claude Managed Agents is built for asynchronous work that benefits from a managed harness. Anthropic runs the agent infrastructure, session model, environment management, event stream, and much of the operational surface. For platform teams, that removes a class of distributed-systems work before the first pilot begins.
The cloud sandbox profile is concrete. Anthropic's cloud sandboxes are isolated Linux containers running Ubuntu 24.04 LTS on x86_64, with up to 8 GB memory and 10 GB disk. They include common tooling and runtimes: Python, Node, Go, Rust, Java, Ruby, PHP, PostgreSQL, Redis, SQLite, git, ripgrep, Playwright, and Chromium.
That default tool richness is also the risk surface. Bash, writable files, web access, grep, package managers, browser automation, and MCP servers are valuable because they let an agent behave like a developer. The same capabilities define the damage path if the agent reads untrusted instructions, touches sensitive files, or runs with credentials that are broader than the task requires.
Managed Agents are stateful by design. Session history, sandbox state, files, and outputs persist server-side. Anthropic states that the feature is not currently eligible for Zero Data Retention or HIPAA BAA coverage. For internal maintenance work, this may be acceptable. For regulated workloads, it is a first-order design constraint.
What Self-Hosted Execution Changes
Self-hosted execution changes the location of the running process. It does not remove Anthropic from the workflow.
For Managed Agents, self-hosted sandboxes place code, filesystem operations, tool execution, processes, and network egress in your infrastructure. The operator must stage resources because Anthropic does not automatically mount GitHub repositories or files in self-hosted Managed Agents sessions. Workers require a Linux host with /bin/bash.
For Claude Code self-hosted environments, the feature is in public beta for Team and Enterprise, off by default, and currently limited in important ways. Anthropic lists no Zero Data Retention, no inference routing through Bedrock, Vertex, Microsoft, or gateways, GitHub repositories only, and Code Review or Security not yet routed through self-hosted runners.
The implication is direct: self-hosted execution can support customer network policy, private build systems, internal registries, and infrastructure logging. It does not by itself give you private model execution, provider-independent orchestration, or full compliance closure.
Claude Managed Agents vs Self-Hosted Coding Agents
| Dimension | Claude Managed Agents cloud | Claude self-hosted execution | Owned or open-source agents |
|---|---|---|---|
| Execution | Anthropic cloud container or VM | Customer runner or sandbox | Customer laptop, CI, VM, Kubernetes, or custom sandbox |
| Harness | Anthropic-managed | Anthropic orchestration with customer execution | Team-owned or open-source harness |
| Model path | Claude | Claude | Provider or local model choice depends on the tool |
| Network control | Anthropic environment controls | Customer network policy | Customer network policy, self-implemented |
| Compliance posture | Not currently ZDR or HIPAA BAA eligible for Managed Agents | Execution local, control plane and model visibility remain | Depends on gateway, model, logging, and runtime design |
| Operations burden | Low | Medium to high | Medium to high, sometimes high |
The table is the operating model in miniature. Managed cloud lowers the platform burden. Self-hosted execution moves the blast radius of tools and network closer to your controls. Owned runtimes move the most authority to your team, but they also move the most accountability.
Related reading: agent harness for coding agents.
Security: Permissions Are Not Sandboxes
Anthropic Managed Agents permission policies include always_allow, always_ask, and auto. Agent toolsets default to always_allow, while MCP toolsets default to always_ask. Anthropic warns that auto is not a human checkpoint: if the evaluator allows a call, the call runs before human review.
That distinction matters. Permission policy decides whether a tool call is allowed to start. Agent sandboxing decides what the process can reach after it starts. Neither changes what gets sent to the model provider. Anthropic's sandboxing guidance also warns that network egress can leak readable data and writable mounts can mutate code.
The risk is not theoretical. GitInject reported real-world prompt injection attacks in AI-powered CI/CD pipelines where agents ingest untrusted PRs, issues, and repository content while holding repository credentials. One attack path used config-file injection through CLAUDE.md, AGENTS.md, and GEMINI.md.
For platform teams, the practical control is to treat repository instructions as code with provenance. Instructions from a trusted default branch are different from instructions arriving through a fork, issue, or unreviewed branch. The agent may see all of them as text. Your workflow has to preserve the trust boundary.
Related reading: agent sandboxing.
Cost Control Needs Runtime Controls Too
Managed Agents session budgets can cap spend per session at public list rates. Anthropic lists session runtime at $0.08 per hour and web search at $10 per 1,000 searches, alongside model token costs. Budget enforcement happens between model requests, which means caps can overshoot by one in-flight request or thread.
That makes budgets useful but incomplete. You still need monitoring, kill switches, and policy for retry loops, multiagent sessions, prompt stuffing, broad web search, and long-running tasks that continue after the original developer has context-switched.
GitInject gives a concrete cost exposure pattern. The paper reports an attack campaign that could inflate victim bills by $32 to $111 in two hours. In one Claude Code Action case, even a refusal cost $0.32 in input tokens. Cost controls have to account for malicious input, not only enthusiastic internal usage.
Adoption Has Already Outgrown Ad Hoc Policy
A 2026 arXiv census of 180 million repositories found 850,157 Claude Code commits in one snapshot. A bot-account lookup found only 28,154. The signal for leaders is not the exact market share. It is that coding-agent usage can be broad while remaining hard to measure with simple bot labels.
This changes governance. If your organization waits until every agent commit is labeled cleanly, policy will lag actual usage. Platform teams need approved execution paths, repository trust rules, credential boundaries, logging requirements, and cost monitoring before informal adoption becomes the default workflow.
Security results also argue for review discipline. SecureAgentBench reported that the best evaluated correct-and-secure score was only 15.2%, and explicit security instructions did not significantly improve secure coding in that benchmark. Functional tests are not a substitute for security review.
Use Case Guidance
Choose Claude Managed Agents when the work is low-risk, asynchronous, and benefits from managed state: dependency updates, broad repository chores, internal cleanup, draft branches, issue reproduction, or tasks where cloud setup is faster than recreating a local environment. The trade-off is provider-managed persistence, provider-visible context, and managed-environment constraints.
Choose Claude Code self-hosted environments or Managed Agents self-hosted sandboxes when the task needs internal network access, customer-controlled egress, private package registries, infrastructure logs, or execution near sensitive build systems. The trade-off is that Anthropic orchestration and model context remain part of the path, and current limitations include no ZDR and no alternate inference routing through Bedrock, Vertex, Microsoft, or gateways.
Choose owned or open-source self-hosted coding agents when runtime ownership is the requirement. This includes teams that need local models, custom approval flows, strict audit design, custom sandboxes, or provider flexibility. The trade-off is operational: your platform team becomes responsible for the harness, queueing, isolation, credentials, logs, upgrades, memory, artifact retention, and developer experience.
The Evaluation Checklist
- What exact data enters model context: full files, diffs, logs, environment variables, dependency manifests, generated artifacts, or test output?
- Where do session history, sandbox files, event logs, outputs, and artifacts persist?
- Does the workflow require Zero Data Retention, HIPAA BAA coverage, private inference, or only local tool execution?
- Can untrusted PRs, issues, branch files, or repository instruction files influence agent behavior?
- Which credentials are available during checkout, build, test, package install, and push?
- What can network egress reach from the sandbox or runner?
- Who can approve tool calls, and when does approval happen relative to execution?
- What is the kill switch for runaway sessions, retry loops, and cost amplification?
- How will generated code be reviewed for security, not only for passing tests?
Bottom Line
The platform choice is conditional. If your main constraint is delivery speed, Claude Managed Agents gives you a ready long-running agent platform with rich tools and low operational burden. If your main constraint is execution locality, self-hosted Claude execution moves important work into your infrastructure while preserving Anthropic orchestration. If your main constraint is control over the runtime and model path, you need owned or open-source self-hosted coding agents, plus the engineering capacity to operate them.
The decision should not be framed as managed versus self-hosted in the abstract. Frame it as a boundary map. Decide where execution, data, credentials, network, state, audit, cost control, and human approval must live. Then choose the smallest operating model that satisfies those boundaries without hiding the remaining exposure.