Rolling out to your organization
Day 0 proves one verified setup on one engineer’s machine. Rollout is everything between that and “every engineer has it, identity is wired, and security has seen the audit trail” — several workstreams, each owned by a different team in your org. This section gives each owner their own task doc. Every capability is labeled self-service (your admin does it with these docs) or set up with us (done with your onboarding engineer, who has the runbook).
| Workstream | Who owns it in your org | The doc | How |
|---|---|---|---|
| Fleet-wide rollout in Claude Code (enterprise/managed) | Dev-tools / platform admin | Deploy with Claude Code enterprise controls | Self-service |
| Fleet-wide rollout in Cursor for Teams | Dev-tools admin | Deploy with Cursor for Teams | Self-service |
| SSO & SCIM (Okta, Entra, Google, and more) | Identity / IAM team | Connect your identity provider | Set up with us |
| Network & package management (npm proxies, egress, MDM, PrivateLink) | IT / network security | Network, packages & managed devices | Mixed — table inside |
| Audit & governance (events, retention, role mapping) | Security / compliance | Audit & governance | Included; reviewed at onboarding |
| Deployment shape (dedicated VPC, BYO-cloud, on-prem, air-gap) | Infra / security org | Enterprise deployment track | Set up with us |
| Procurement pre-clearance | Procurement / vendor risk | For procurement & security | Self-service |
Other coding agents and surfaces
Section titled “Other coding agents and surfaces”- Codex CLI / OpenCode: both read config files (
~/.codex/config.toml,opencode.json) that your device-management or dotfiles tooling can distribute fleet-wide; the per-client snippets are the payload. There is no vendor-side team console to integrate with today. - ChatGPT Enterprise: where your workspace enables them, the Data Workers ChatGPT apps install like any connector; self-hosters can expose an agent as a custom connector.
- Anything MCP-capable: the generic recipe plus whatever central-config mechanism that tool offers.
The order that works
Section titled “The order that works”- Procurement package cleared → pilot signed.
- Day-0 kickoff with one engineer, one schema — before any fleet rollout, so the fleet inherits a verified configuration.
- Identity wiring starts in parallel with day 0 — SSO/SCIM has the longest lead time, and until it lands, attribution and role policy run at workspace/team granularity rather than per user. Start it early.
- Fleet rollout through your coding-agent admin surface (Claude Code / Cursor docs above), pointing everyone at the same verified connection set — ideally after identity, acceptably alongside it.
- Deployment shape changes (VPC, on-prem) whenever your security org requires them — before or after fleet rollout, your call.