Skip to content

Rolling out to your organization

Day 0 proves one verified setup on one engineer’s machine. Rollout is everything between that and “every engineer has it, identity is wired, and security has seen the audit trail” — several workstreams, each owned by a different team in your org. This section gives each owner their own task doc. Every capability is labeled self-service (your admin does it with these docs) or set up with us (done with your onboarding engineer, who has the runbook).

WorkstreamWho owns it in your orgThe docHow
Fleet-wide rollout in Claude Code (enterprise/managed)Dev-tools / platform adminDeploy with Claude Code enterprise controlsSelf-service
Fleet-wide rollout in Cursor for TeamsDev-tools adminDeploy with Cursor for TeamsSelf-service
SSO & SCIM (Okta, Entra, Google, and more)Identity / IAM teamConnect your identity providerSet up with us
Network & package management (npm proxies, egress, MDM, PrivateLink)IT / network securityNetwork, packages & managed devicesMixed — table inside
Audit & governance (events, retention, role mapping)Security / complianceAudit & governanceIncluded; reviewed at onboarding
Deployment shape (dedicated VPC, BYO-cloud, on-prem, air-gap)Infra / security orgEnterprise deployment trackSet up with us
Procurement pre-clearanceProcurement / vendor riskFor procurement & securitySelf-service
  • Codex CLI / OpenCode: both read config files (~/.codex/config.toml, opencode.json) that your device-management or dotfiles tooling can distribute fleet-wide; the per-client snippets are the payload. There is no vendor-side team console to integrate with today.
  • ChatGPT Enterprise: where your workspace enables them, the Data Workers ChatGPT apps install like any connector; self-hosters can expose an agent as a custom connector.
  • Anything MCP-capable: the generic recipe plus whatever central-config mechanism that tool offers.
  1. Procurement package cleared → pilot signed.
  2. Day-0 kickoff with one engineer, one schema — before any fleet rollout, so the fleet inherits a verified configuration.
  3. Identity wiring starts in parallel with day 0 — SSO/SCIM has the longest lead time, and until it lands, attribution and role policy run at workspace/team granularity rather than per user. Start it early.
  4. Fleet rollout through your coding-agent admin surface (Claude Code / Cursor docs above), pointing everyone at the same verified connection set — ideally after identity, acceptably alongside it.
  5. Deployment shape changes (VPC, on-prem) whenever your security org requires them — before or after fleet rollout, your call.