Runtime as featured inForbesRead the article

Runtime vs Claude Managed Agents

Runtime vs Claude Managed Agents compared: Anthropic's hosted agent harness for Claude vs a multi-cloud, multi-sandbox, multi-model agent harness with guardrails and teams for payment operations.

Updated October 7, 20266 min read

TL;DR: Claude Managed Agents is a strong hosted harness for developers building Claude agents. Runtime can run Claude too, but adds what payment teams need on top: no dependency on one cloud, sandbox, or model vendor, guardrails set before money moves, and shared agents and memory across every team, with a forward-deployed engineer.

Feature
RuntimeRuntime
Claude Managed AgentsClaude Managed Agents
What it isAgent harness for payment teamsHosted agent harness API for Claude
Model providersAnthropic, OpenAI, Google, open-weightClaude models
Harness routingClaude Code, Codex, OpenCode, with fallbacksAnthropic's harness
Where tools runYour AWS, GCP, Azure, or self-hostedAnthropic sandbox or self-hosted worker
Orchestration and model callsFully self-hostable via HelmAnthropic control plane
ApprovalsBuilt in, routed in Slack or Teamsalways_ask policy, you build the UI
Card and SSN handlingStripped from prompts and logsYou build redaction
Who builds agentsOps, risk, finance, with an FDEDevelopers via API, CLI, SDKs
Agent quality toolingEvals, deterministic scriptsOutcomes, dreaming, multiagent

Claude Managed Agents and Runtime at a glance

Claude Managed Agents is Anthropic's hosted agent harness, launched in public beta on April 8, 2026. Instead of building your own agent loop, tool execution, and sandbox, you define an agent (a Claude model, system prompt, tools, MCP servers, and skills) and run sessions in an Anthropic-managed cloud sandbox or a self-hosted sandbox. Built-in tools cover bash, file operations, web search and fetch, and MCP. Since launch Anthropic has added memory stores with versioned history, credential vaults, webhooks, scheduled runs, and in May 2026 outcomes (a separate grader checks work against your rubric) and multiagent orchestration, both in public beta, plus dreaming in research preview. It is built for developers who want long-running Claude agents without running the infrastructure.

Runtime is the AI agent harness for payment and fintech teams: an operating system for building and running many agents across the org. Anyone on payment ops, risk, compliance, finance, underwriting, onboarding, or support builds agents from their SOPs. Agents work on isolated computers in your cloud, reach your ledger, processor, and bank portals through APIs, databases, CLIs, MCP servers, and a browser, and stop for a person before anything moves money.

Good products, different jobs. Runtime can run Claude models and Claude Code. The difference is one model vendor's harness and cloud versus a harness that spans clouds, sandboxes, and model providers, with guardrails and teams built in for payment operations.

How they differ

One model vendor vs no single-vendor dependency

Claude Managed Agents runs Claude models, orchestrated on Anthropic's side. It is available on the Claude API and on Claude Platform on AWS, which Anthropic operates; Anthropic's pricing docs say it is not available on partner clouds such as Amazon Bedrock or Google Cloud. Self-hosted sandboxes are a real option, with guides for AWS Lambda MicroVMs, Cloudflare, Daytona, E2B, Modal, Vercel, and GKE, but the agent loop, skills, and memory stores still live with Anthropic, and tool inputs and outputs pass through its control plane.

Runtime is multi-cloud, multi-sandbox, and multi-model. Agent computers run in your AWS, GCP, or Azure account, or fully self-hosted via Helm. You bring your own sandbox provider, with fallbacks. Models come from Anthropic, OpenAI, Google, or open-weight models served in your cloud for PCI and PII work, with harness routing across Claude Code, Codex, and OpenCode. If one provider has an outage, changes pricing, or deprecates a model, your agents keep running on another.

Permission primitives vs guardrails for money movement

Claude Managed Agents gives developers good primitives. Permission policies set each tool to always allow, always ask, or auto, where the server evaluates each call. The built-in toolset defaults to always allow and MCP tools default to always ask. Vaults keep credentials out of the session, and the Console traces every tool call. Custom tools are outside permission policies, and deciding which payment actions need a human, who approves, and where the request shows up is your team's design work.

Runtime ships those decisions for payment operations. Agents start read-only. Releasing a payout, applying a reserve, booking a ledger entry, or replying to a sponsor bank waits for an approver in Slack or Teams. Credentials are masked, card numbers and SSNs are stripped from prompts and logs, and RBAC controls who builds, runs, and approves. Every run is recorded end to end, from trigger through every query, tool call, approval, cost, and result, and the record your sponsor bank or examiner asks for stays with you.

A developer API vs a platform built for teams

Claude Managed Agents is an API, CLI, and SDK surface. Your engineers build the interface, the routing, and the workflow your ops teams will use.

Runtime is built for teams: shared agents, templates, and memory across support, payment ops, finance, risk, and compliance, with real-time collaboration, spend controls, and role-based access, called from Slack, Teams, email, SMS, voice, or the dashboard. A single stuck payment touches four teams: support gets the ticket, payment ops traces it, finance sees a reconciliation break, risk or compliance may review it. On Runtime it is one investigation with one record.

Build it yourself vs a forward-deployed engineer

The first agent on Claude Managed Agents is quick. Running agents on payment data also needs approvals wired to your workflow, RBAC, PII and PCI stripping, an exportable audit trail, evals, multi-provider fallbacks, and an interface for analysts. An engineering team can spend two quarters on that before the first agent touches real data.

Runtime gives it to you on day one, with a forward-deployed AI engineer from a team that built payment and fintech infrastructure at Hulu's payments team at Disney, Finix, Modern Treasury, and BlackRock's AI quant group. The FDE maps your processes, builds the first agents with your team, sets up guardrails, and trains admins. Solved processes can become deterministic scripts in your repos. Rain replaced $250k in vendor spend with Runtime.

Where Claude Managed Agents is stronger

  • Depth on Claude. The harness is built by the model maker, with prompt caching, compaction, and other optimizations built in.
  • Agent quality features. Outcomes with a separate grader, multiagent orchestration, and dreaming to curate memory.
  • Memory with history. Every memory change creates an immutable version you can audit, restore, or redact.
  • Developer experience. Clean API, CLI, and SDKs in many languages, with tracing in the Console.
  • Transparent usage pricing. Tokens plus a small runtime fee, billed only while a session runs.

Pricing

Claude Managed Agents: tokens at standard Claude API rates, plus $0.08 per session-hour, metered to the millisecond while the session is running. Idle time is not billed. Web search is $10 per 1,000 searches. The engineering time to build approvals, audit export, and ops-facing interfaces is not on the price list.

Runtime has public tiers: Free ($0, one session), Teams from $99 per seat per month, and Enterprise with custom pricing and self-hosting. The value to weigh it against is the work of the analysts you were about to hire.

Which should you choose

Choose Claude Managed Agents if

  • Your engineers are building Claude agents into a product
  • You are comfortable standardizing on one model vendor
  • You want to design your own approvals, UI, and audit model
  • Outcomes and multiagent orchestration are central to the job

Choose Runtime if

  • Payment ops, risk, compliance, or finance need agents on real queues soon
  • You need to run across clouds, sandboxes, and model providers
  • Approvals before money moves and an examiner-ready record are requirements
  • You want a forward-deployed engineer who knows payments

The two are not either-or: Runtime can route work to Claude models and Claude Code, so you keep Claude without depending on a single vendor.

See Runtime on your busiest queue

Bring one SOP. A forward-deployed AI engineer builds the first agent with your team, inside your cloud.

Frequently asked questions

What is Claude Managed Agents?

Claude Managed Agents is Anthropic's pre-built, configurable agent harness running on managed infrastructure, launched in public beta on April 8, 2026. You define an agent (model, system prompt, tools, MCP servers, skills), an environment, and sessions, and Claude reads files, runs commands, browses the web, and runs code in a sandbox. All endpoints require the managed-agents-2026-04-01 beta header.

How much does Claude Managed Agents cost?

Tokens are billed at standard Claude API rates, plus $0.08 per session-hour while a session is running. Idle time does not count. Web search inside a session is $10 per 1,000 searches.

Can Claude Managed Agents run in my own cloud?

Partly. Self-hosted sandboxes move tool execution, files, and network traffic into infrastructure you control, but orchestration stays on Anthropic's side and tool inputs and outputs flow through Anthropic's control plane. It is also available through Claude Platform on AWS, which Anthropic operates. Runtime runs the harness itself in your AWS, GCP, or Azure account, or fully self-hosted.

Does Runtime support Claude?

Yes. Runtime runs Claude models and Claude Code alongside OpenAI, Google, and open-weight models, with routing and fallbacks across providers. Choosing Runtime does not mean giving up Claude; it means not depending on any single vendor.

Is Claude Managed Agents eligible for zero data retention?

Not currently. Anthropic's docs say Managed Agents is stateful by design and is not eligible for Zero Data Retention or HIPAA BAA coverage, though you can delete sessions and files through the API.

Related comparisons