Policy

Settings an administrator can enforce: the cost-related managed settings for Claude Code

Managed settings are settings an organisation deploys to every developer's machine, and Anthropic's documentation read on 4 October 2026 says Claude Code applies them above every other level, so no user, project, local or command-line value overrides them. The cost-related ones Anthropic names are modelPricing, which reports spend at contracted rates and works only as a managed setting; the default model and the availableModels restriction; autoContinueAtUsageLimit, which decides whether a session waits and continues after a usage limit; the prompt cache lifetime, set in the env block; the variable that turns agent teams on; and crossSessionInbound. This page gives each one, where it can be set, which version it needs, and which should stay a team choice.

Published October 4, 2026. Editorial.

Key takeaways

  • Managed settings reach a developer's machine in one of four ways, by Anthropic's documentation read on 4 October 2026: server-managed settings from the claude.ai admin console or a self-hosted gateway, an MDM or operating-system policy, a managed-settings.json file in a system directory, or the user-writable Windows HKCU registry.
  • modelPricing is read from managed settings only; Anthropic says Claude Code ignores it in user, project and local settings, in --settings and in the HKCU registry, and it requires Claude Code version 2.1.242 or later.
  • A managed model value sets the model each session starts on, and --model and ANTHROPIC_MODEL still pick the model for that session; Anthropic says to deploy availableModels to restrict the choice.
  • autoContinueAtUsageLimit is read from user settings, --settings and managed settings only, defaults to true, and requires Claude Code version 2.1.234 or later.
  • The prompt cache lifetime settings promptCacheTtl and subagentPromptCacheTtl take 5m or 1h, can go in any settings file including a managed one, and require Claude Code version 2.1.242 or later.

Most of what Claude Code costs, counted in tokens, the pieces of text the model reads and writes, is decided by what each developer does in a session. A smaller set of decisions can be made once, for everyone, by an administrator, and Anthropic's documentation names the mechanism for that: managed settings. This page is for the manager who approves the policy and the administrator who deploys it. It lists only the settings Anthropic's documentation, read on 4 October 2026, connects to cost, gives the exact key name and scope for each, and says which Reveneau recommends enforcing and which should stay with the team. It is part of the guide to Claude Code costs for teams.

Managed settings in plain words

Claude Code reads its settings from files. Anthropic's settings reference describes four: a user file at ~/.claude/settings.json that applies to one person in every project, a shared project file at .claude/settings.json that applies to everyone in that project, a local project file at .claude/settings.local.json for one person in one project, and managed settings, which Anthropic defines as what the organisation deploys [2]. Managed settings are the settings an organisation deploys to every developer's machine, and Anthropic's managed settings page says Claude Code applies them above every other level, so no user, project, local or --settings value overrides them, apart from a few security-sensitive exceptions where a stricter value from a lower level still counts [1]. The --settings flag is a way to pass settings on the command line for one session.

There are four ways to deliver them, and Anthropic's page gives each one's timing [1]. Server-managed settings are set in the claude.ai admin console or on a self-hosted Claude apps gateway, and Claude Code fetches them at startup and polls hourly. An MDM or operating-system policy is a macOS configuration profile or a Windows HKLM registry value delivered through a device-management tool such as Jamf, Intune or Group Policy, read at startup and checked for changes every 30 minutes. A file called managed-settings.json in a system directory, which is /Library/Application Support/ClaudeCode/ on macOS, /etc/claude-code/ on Linux and WSL, and C:\Program Files\ClaudeCode\ on Windows, is read at startup and reloaded when it changes. The fourth, a Windows HKCU registry value, is user-writable, and Claude Code uses it only when no administrator source is present above it [1]. When more than one source reaches a machine, Claude Code by default uses the highest-ranked source that delivers at least one policy key and ignores the rest, in the order server-managed, MDM, file, HKCU; an opt-in that merges every source requires Claude Code version 2.1.242 or later [1]. Server-managed settings are fetched only when the session authenticates to Anthropic's API directly, so on Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry the policy has to come from MDM or a file [1][4].

One timing detail affects cost settings delivered through the env block. Anthropic says a server-managed change to a setting that needs approval, such as a hook or an env variable, waits for the developer to accept a dialog in an interactive session [1]. An environment variable is a named value the operating system passes to a program when it starts, and the env block in a settings file is where Claude Code lets an administrator set such variables for every session. So a cache lifetime or an agent teams variable pushed from the admin console applies only after each developer clicks accept.

The cost-related settings in one table

Every key below is named in Anthropic's documentation read on 4 October 2026. Scope is Anthropic's own column in its settings index: any file means user, project, local and managed; managed means Claude Code reads the key from a managed source only.

Setting What it controls Where it is set Version
modelPricing Reports every cost figure Claude Code shows at contracted rates: /usage, the status line, the OpenTelemetry cost metric, --max-budget-usd [2] Managed only. Ignored in user, project and local settings, in --settings and in the HKCU registry [2] 2.1.242; a markup above 1 needs 2.1.271 [2]
model The model each new session starts on; a managed value is a starting default, and --model or ANTHROPIC_MODEL still picks the model for one session [2] Any file [2] None stated
Organization default model The model the Default option resolves to for Enterprise members, organisation-wide or per custom role; can be set to override user selection [4] claude.ai admin console, Enterprise plan; reaches only sessions authenticated with the Anthropic API [4] 2.1.196 [4]
availableModels, with enforceAvailableModels Which models can be selected anywhere a model is chosen; enforceAvailableModels extends the list to the Default option [2] Any file; deploy in managed settings to enforce it [2] enforceAvailableModels needs 2.1.175 [2]
deniedModels Blocks specific models or versions even when availableModels would permit them [2] Managed only; ignored elsewhere with a warning [2] 2.1.283 [2]
maxEffortLevel Caps the effort level, the amount of reasoning the model does before answering; the lowest cap in any scope applies, on every provider [2] Any file; deploy in managed settings to enforce it [2] 2.1.267 [2]
autoContinueAtUsageLimit Whether a session waits in place and continues the task on its own after a claude.ai usage limit resets [2] User settings, --settings and managed settings only [2] 2.1.234 [2]
promptCacheTtl and subagentPromptCacheTtl The prompt cache lifetime, 5m or 1h, for the main conversation and for everything else [2] Any file; the matching environment variables and FORCE_PROMPT_CACHING_5M rank above them [5] 2.1.242 [2]
CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS Whether agent teams, several Claude Code instances working together, can run; off by default [3] The env block of a settings file, or the shell [3] None stated
crossSessionInbound Whether an idle session receives messages from the developer's other sessions as new turns: accept, hold or refuse [2] Any file; managed is read first, then --settings, then user; a project or local value applies only when stricter [2] 2.1.224 [2]
autoCompactWindow How full the context window gets before Claude Code compacts; a managed value is a default, and --autocompact or CLAUDE_CODE_AUTO_COMPACT_WINDOW still sets it for a session [1] Any file [2] None stated

Reporting at contracted rates: modelPricing

By default Claude Code computes every cost figure it shows developers at list price, so an organisation on contracted rates sees figures in /usage, the status line and OpenTelemetry that differ from its bill [3]. The modelPricing setting makes them match. Anthropic's settings reference says Claude Code applies the rates in /usage, the status line, the Agent SDK's total cost field, the --max-budget-usd limit and the OpenTelemetry cost metric and events, that the administrator supplies the rates because Claude Code does not read them from the contract or the Claude Console, and that it requires Claude Code version 2.1.242 or later [2]. Its scope is managed: Claude Code ignores the key in user, project and local settings, in --settings, and on Windows in the HKCU registry [2]. The value is a multiplier greater than 0 and at most 10, an overrides map of per-model rates with all four of input, output, cacheRead and cacheWrite required, or both; a multiplier above 1, a markup, needs version 2.1.271 or later [2]. The setting changes the figures Claude Code shows, and Anthropic bills at the contracted rate whatever the setting says [3]. With server-managed delivery, each session reports at list price until its settings fetch has confirmed the setting [2]. The page on where to see Claude Code spend covers what the figures then show.

The default model, and the difference between a default and a restriction

Anthropic's cost documentation names Opus left as the default model as one of the two usual causes of unexpectedly high spend on an API or cloud-provider plan, and says Sonnet handles most coding tasks well and costs less than Opus [3]. On Anthropic's pricing page, read on 4 October 2026, Claude Opus 5.5 is listed at $4 per million input tokens and $20 per million output tokens, and Claude Sonnet 5.5 at $2 and $10 [6]. So the default model is the policy decision with the clearest effect on cost, and Anthropic's documentation is careful about what each key does.

The model key sets the model every new session uses, and its scope is any file [2]. Anthropic's managed settings page says a managed model is a default: --model and ANTHROPIC_MODEL still pick the model for that session, so an organisation that wants to restrict the choice deploys availableModels [1]. On a Claude Enterprise plan there is a second way to set the default: the organization default model, set from the claude.ai admin console for the whole organisation or per custom role, which the /model picker shows with the label Org default [4]. Anthropic says it is a starting point, that --model, ANTHROPIC_MODEL, a managed model and a model in the developer's own files all take precedence over it, and that administrators can configure it to override user selection, after which a model the developer saves applies for the current session and the organisation default returns at the next launch [4]. It requires Claude Code version 2.1.196 or later and reaches only sessions authenticated with the Anthropic API; for a gateway or cloud deployment, Anthropic says to use the model key in managed settings instead [4].

The restriction is availableModels. Anthropic's settings reference says a managed list constrains /model, --model and the model key in a developer's own files, that a model outside it cannot be selected, and that Claude Code hides excluded models from the /model picker [2]. On its own it leaves the Default option on the account's usual default, so Anthropic says to pair it with enforceAvailableModels, which requires version 2.1.175 or later and makes Default resolve to the first available model in the list [2]. deniedModels, a managed-only key that needs version 2.1.283 or later, blocks a specific version even when the list permits it [2]. A fourth key, maxEffortLevel, caps the effort level, the amount of reasoning the model does before it answers, and Anthropic's cost page says thinking tokens are billed as output tokens; the lowest cap in any scope applies, so a developer cannot raise it, and it applies on every provider; it requires version 2.1.267 or later [2][3]. The sister guide's page on which model and effort level covers the developer's side of the same choice.

Waiting at a usage limit: autoContinueAtUsageLimit

On Claude Code version 2.1.234 or later, when a claude.ai usage limit stops a task in an interactive session on a subscription, Claude Code waits in the open session and continues the task after the reset; this is on by default [2][7]. Anthropic's cost page says that to control for a fleet whether Claude Code starts that wait on its own, an administrator sets autoContinueAtUsageLimit in managed settings [3]. The settings reference gives the scope as user or managed: the key is read from user settings, --settings and managed settings only, and when none of those sets it, a project or local file that sets it turns the feature off [2]. It appears in /config as Continue automatically at usage limit, and Claude Code hides that row while managed settings or --settings set the key [2]. The continued task still asks for permissions, so it can stop on a prompt while the developer is away, and Anthropic describes the setting as one that grants unattended execution [7]. The page on what each limit message means describes the wait itself.

The cache lifetime, set through the env block

The prompt cache is a store of request text the model service has already processed; while the start of a request matches the store, that part is read at a lower price. Anthropic's pricing page gives the multipliers: a five-minute cache write costs 1.25 times the base input price, a one-hour cache write costs 2 times, and a cache read costs 0.1 times, with lower read multipliers on Claude Opus 5.5 and Claude Fable 5.1 [6]. Anthropic's prompt caching page says the lifetime an organisation gets by default depends on billing: on a Claude subscription within the plan's included usage, the main conversation gets one hour; on usage credits (the paid usage a subscription member draws on after the allowance included in their seat, their paid place on the plan), an API key or a cloud provider, every request gets five minutes [5]. The one-hour lifetime helps when a developer leaves a session idle and comes back, and it costs more on short bursts of work that never pause for five minutes [5].

Two settings choose the lifetime: promptCacheTtl for the main conversation and subagentPromptCacheTtl for everything else, each taking 5m or 1h, each with the scope any file, and each requiring Claude Code version 2.1.242 or later [2]. Their environment variable forms are CLAUDE_CODE_PROMPT_CACHE_TTL and CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL, and two older variables, ENABLE_PROMPT_CACHING_1H and FORCE_PROMPT_CACHING_5M, also apply [5]. Anthropic gives the order when several are set: FORCE_PROMPT_CACHING_5M=1 first, then the bucket's environment variable, then the bucket's setting, then a subagent's own value on version 2.1.248 or later, then ENABLE_PROMPT_CACHING_1H=1, then the default [5]. Anthropic names FORCE_PROMPT_CACHING_5M=1 as the way to override a longer lifetime set in managed settings, so an administrator who sets 1h in a managed env block has set a default, and a developer can still force five minutes for a session [5]. The sister guide's page on the cache lifetime of five minutes or one hour works through when the hour costs less overall.

Agent teams and messages between sessions: two sources of idle spend

Two more settings govern spend that happens while a developer is doing something else. Agent teams are several Claude Code instances working together, each with its own context window, the set of text the model reads on every request. Anthropic's cost page says token usage scales with the number of active teammates, that agent teams use what Anthropic puts at 7 times more tokens than a standard session when teammates run in plan mode (a mode in which Claude explores the code and proposes an approach before it edits anything), and that they are disabled by default: the CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS environment variable set to 1 in settings.json or the environment turns them on [3]. Anthropic's managed settings page says managed settings apply above every other level, and that a nested block such as env merges key by key, with each key following the same rule [1]. Those two statements are all Anthropic gives on managing the variable for a fleet.

crossSessionInbound chooses what a session does with messages arriving from the developer's other Claude Code sessions: accept delivers them, hold shows a notice without delivering, refuse drops them [2]. It is on the cost page because Claude Code delivers such a message as a new turn while the session is idle, sending the full context each time, and Anthropic's advice for holding inbound messages is to set the key to hold [3]. Its scope is any file; Claude Code reads managed settings first, then --settings, then user settings, and a project or local value applies only when it is stricter; it requires Claude Code version 2.1.224 or later [2]. An unrecognised value in managed settings is treated as refuse until an administrator fixes it [2].

What should stay a team choice

Reveneau's recommendation, from the scopes Anthropic gives, is to enforce the settings that only work when managed and to leave the rest as defaults. modelPricing has to be managed, so deploy it on the day the contract is signed and update it when the contract changes, which Anthropic says Claude Code will not do for you [3]. availableModels with enforceAvailableModels is the restriction that decides the price per token, and an organisation that wants Sonnet as the everyday model should deploy it instead of relying on a model default that any session can change. autoContinueAtUsageLimit is a decision about unattended execution, so decide it once in managed settings.

The model default, the compaction window, the cache lifetime and the effort level are, by Anthropic's own descriptions, defaults or caps that a session can still move, and Reveneau recommends leaving them to the team that knows its codebase. A managed autoCompactWindow, which sets how full the context window gets before Claude Code compacts the conversation, that is, summarises older history to free space, is a default, and --autocompact and CLAUDE_CODE_AUTO_COMPACT_WINDOW still set the window for a session [1]. Two cautions. Managed settings bind Claude Code only, so a developer who calls the API from another tool is outside them [1]. And the DISABLE_TELEMETRY variable, which Anthropic's page shows as an env block example for turning off operational telemetry, also stops the usage data that feeds the organisation's analytics dashboard for the developers it reaches, so a privacy setting can remove the adoption figures a manager relies on [1].

How to confirm a setting is in force

Anthropic gives one check for the policy and one for the price table. On a developer's machine, run /status and read the Setting sources line, which shows Enterprise managed settings with the source Claude Code selected in parentheses, such as (remote), (plist), (HKLM) or (file); when the line is missing, Claude Code found no managed source that delivers a policy key [1]. For modelPricing, run /usage in a session that has received the managed settings and look for the note at your organization's configured rates on the Total cost line [3]. Because so many of these keys require a minimum version, Anthropic's requiredMinimumVersion key, which blocks an outdated binary from starting, is the way to make sure every machine is on a version that reads them [1]. The page on per-developer usage reporting covers what the figures show once the settings are in place.

Reveneau is an AI software development consultancy. All of its code is written by AI, and every change must pass an eval suite, a set of automated tests written from the specification, before release, so token use is a running cost of every Reveneau build. Reveneau is independent of Anthropic, and every key name, scope and version number on this page is taken from Anthropic's own documentation read on 4 October 2026. If you want help writing a managed settings file for your organisation, contact Reveneau.

Common questions

What are managed settings in Claude Code?

Managed settings are the settings an organisation deploys to every developer's machine, by Anthropic's documentation read on 4 October 2026. Claude Code applies them above every other level, so no user, project, local or --settings value overrides them, apart from a few security-sensitive exceptions where a stricter value from a lower level still counts. They use the same JSON shape as a developer's own settings.json file, and the settings reference says for each key whether a managed source can set it.

How are managed settings delivered to a developer's machine?

Managed settings are delivered in one of four ways, by Anthropic's documentation read on 4 October 2026: server-managed settings set in the claude.ai admin console or on a self-hosted Claude apps gateway, fetched at startup and polled hourly; an MDM or operating-system policy, read at startup and checked every 30 minutes; a managed-settings.json file in a system directory, reloaded when it changes; or a Windows HKCU registry value, which Claude Code uses only when no administrator source is present above it.

Which Claude Code settings only work in managed settings?

Among the cost-related keys, modelPricing, deniedModels and availableModelsMatch are read from managed settings only, by Anthropic's settings reference read on 4 October 2026. Claude Code ignores modelPricing in user, project and local settings, in --settings and in the Windows HKCU registry, and it ignores deniedModels and availableModelsMatch in user, project and local settings and in --settings with a warning. The managed settings page lists the permission, plugin and delivery keys with the same rule.

Can a developer override a managed setting in Claude Code?

In general no: Anthropic's documentation, read on 4 October 2026, says a developer's own settings files, --settings values and project files never override a managed value. It names cases outside that rule. A managed model is a default, so --model and ANTHROPIC_MODEL still pick the model for a session; a managed autoCompactWindow is a default too; a developer with administrator rights on the machine can edit the managed source itself; and managed settings bind Claude Code only.

Does a managed model setting stop developers switching to Opus?

No. Anthropic's documentation, read on 4 October 2026, says a managed model value sets the model each session starts on, and that --model and the ANTHROPIC_MODEL environment variable still pick the model for that session. The restriction is availableModels, which constrains /model, --model and the model key in a developer's own files. Pair it with enforceAvailableModels, which requires Claude Code version 2.1.175 or later, so the Default option also resolves inside the list.

What is the organization default model in Claude Code?

The organization default model is a model that an administrator on a Claude Enterprise plan sets from the claude.ai admin console for the whole organisation or per custom role, by Anthropic's documentation read on 4 October 2026. The Default row in /model then shows it with the label Org default. It requires Claude Code version 2.1.196 or later and reaches only sessions authenticated with the Anthropic API; elsewhere, Anthropic says to use the model key in managed settings.

What is availableModels in Claude Code?

availableModels is a settings key that restricts which models people can select for the main session, subagents, skills and the advisor, by Anthropic's settings reference read on 4 October 2026. A managed list constrains /model, --model and the model key in a developer's own files, and Claude Code hides excluded models from the /model picker. On its own it leaves the Default option untouched; enforceAvailableModels extends the list to Default. Deploy it in managed settings to enforce it for an organisation.

Can an administrator cap the effort level for every developer?

Yes. Anthropic's settings reference, read on 4 October 2026, describes maxEffortLevel, which caps the effort level a session can use and leaves lower levels available; Claude Code applies the cap before each request, so it applies on every provider including Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry. When several scopes set a cap the lowest applies, so a developer cannot raise it. It requires Claude Code version 2.1.267 or later. Anthropic also says organization admins on a Claude Enterprise plan can set per-role effort limits.

Can an administrator set the prompt cache lifetime for the whole organisation?

An administrator can set promptCacheTtl and subagentPromptCacheTtl, each 5m or 1h, in a managed settings file, because Anthropic's settings reference read on 4 October 2026 gives their scope as any file; both require Claude Code version 2.1.242 or later. Anthropic also says a developer can set FORCE_PROMPT_CACHING_5M=1 to override a longer lifetime set in managed settings, and that variable takes precedence over every other cache lifetime control, so the setting is a default and a developer can still force five minutes.

Can managed settings turn off agent teams in Claude Code?

Agent teams are off unless the CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS environment variable is set to 1, by Anthropic's documentation read on 4 October 2026, so an organisation that deploys nothing keeps them off by default. Anthropic's managed settings page says managed settings apply above every other level and that a nested env block merges key by key under the same rule. Anthropic gives no managed recipe for teams; Reveneau recommends leaving the default off.

Why would an administrator set crossSessionInbound to hold?

An administrator would set crossSessionInbound to hold because Anthropic's cost documentation, read on 4 October 2026, lists cross-session messages among the reasons usage climbs in a long session: Claude Code delivers a message from another of the developer's sessions as a new turn while this session is idle, sending the full context each time. With hold, Claude Code shows a notice for each message without delivering it. The key requires Claude Code version 2.1.224 or later.

How do I check that a managed setting reached a developer's machine?

Run /status inside Claude Code on that machine and read the Setting sources line, by Anthropic's documentation read on 4 October 2026. When a managed source is in effect the line shows Enterprise managed settings with the source in parentheses, such as (remote), (plist), (HKLM) or (file). For modelPricing in particular, Anthropic says to run /usage and look for the note at your organization's configured rates on the Total cost line, which confirms the rates are in effect.