09 APRIL 2026 · NEWS

Anthropic Managed Agents: universal safety, zero organisational policy

Anthropic shipped Managed Agents this month. Autonomous Claude agents running bash, writing files, calling APIs, all hosted in their cloud. Brilliant for developers. Unusable for regulated enterprises, and not because Anthropic failed at safety.

Correction, 25 September 2026. The original post said Managed Agents had no pre-execution hook and no way to stop a tool call before it runs. That was wrong: Managed Agents permission policies include always_ask, which pauses the session for the customer's approval before a tool executes (Anthropic docs). The original also said HookBus ships a Managed Agents adapter; it does not. We could not confirm the list of attacks the post said Managed Agents blocks out of the box, so treat it as unverified. We have corrected those passages. Agentic Thinking now does independent research on runtime evidence and incident reconstruction: agenticthinking.uk. AgentProtect, AgenticStudio and HookBus Agent are not currently offered.

What Anthropic did well

Their safety layer is excellent. Managed Agents blocks universal catastrophic actions out of the box:

That is exactly what a model provider should block. It is the kind of safety that applies to every user, every organisation, every jurisdiction. It does not require any knowledge of your business.

What Anthropic cannot do

Anthropic cannot know your organisation's rules.

They will not block:

They cannot encode every enterprise policy into their guardrails. They should not try. The set of organisational rules is infinite, domain-specific, and changes per team, per project, per environment.

The gap

Tool execution in Managed Agents happens inside Anthropic's cloud container. Anthropic's permission policies let a customer have a tool call pause for approval before it runs, and custom tools run in the customer's own application. What those controls do not give you is one place to apply the same organisation-wide rules, and keep the same record, across Managed Agents and every other agent runtime you use.

For a startup shipping an AI product to end users, this is fine. Anthropic's safety layer is enough.

For a bank running agents against customer data, a hospital running agents on patient records, an insurer running agents on underwriting workflows, or any regulated business, it is a non-starter.

What HookBus does

HookBus is the organisational policy layer. Your rules, your knowledge base, your compliance requirements, your approval chains, your audit trail. Every enterprise needs a different set, and the only place to enforce them is external to the model.

HookBus does not currently ship a Managed Agents publisher. A publisher could route Managed Agents events, including approval requests, through the bus so the same subscribers see them as for other runtimes.

For on-premise agents such as Claude Code, OpenAI Agents SDK, LangChain, or CrewAI, HookBus does full pre-execution gating. Same bus, same subscribers, same rules.

Universal safety is generic. Organisational policy is specific to you. Anthropic built the former. HookBus fills the latter. They are different layers. Both are needed.

The mental model

Think of it like airline security. The TSA blocks knives, guns, explosives. That is universal safety, applied to everyone. It does not know that your company requires employees to show ID at gate 7 before boarding the private flight to the factory. That is your organisation's policy. It runs on top of the universal layer, not as a replacement.

HookBus is your organisation's security desk. Anthropic is the TSA.

What this means for your AI strategy

If you are evaluating Managed Agents for an enterprise use case:

  1. Anthropic handles the "model did something catastrophically unsafe" problem
  2. You still need to handle the "agent did something that violates our policy, breaks a compliance rule, or touches something it shouldn't" problem
  3. That second problem is not going away. It is going to get harder as models get more capable and more autonomous
  4. You need an external, mechanical enforcement layer that can encode your specific rules

That is what HookBus is for.

← All posts