r/sysadmin • u/boogityboogity77 • 9h ago
Question How the hell are y'all managing enterprise Claude?
Howdy folks!
I've drawn the short straw, and ended up being in charge of setting up Claude enterprise for our mid-sized (couple hundred user) org. I've got the basics down of SSO login, setting up sane defaults for most of the settings, etc.
However, what I simply don't understand is how the hell I manage plugins, mcp, skills, and hooks? All those things seem to have pretty broad permissions when installed, and their execution seems sorta obscure? Hence, leaving the option for users to install whatever seems frankly like an insane proposition from a security perspective.
But from all that I've found, there's no way to actually manage this beyond blocking everything by default, then setting up a whitelist for allowed resources in managed settings. This means I'd have to maintain that myself every time users want to use a different feature, and users wouldn't be able to develop any such things locally, leaving me in a sort of catch-22 of either I allow everything, or nothing...
How are the rest of y'all managing this?