Scope: Access & provisioning, credits/usage, system setup, updates/releases. Last reviewed: 26 August 2026.
Access and Provisioning
Claude seats follow the formal SaaS/application-access process: manager approval triggers Okta provisioning and budget assignment; department budget delegates decide seat funding. AI Ops does not unilaterally grant budgets. [[Claude Tag]] uses dedicated service accounts provisioned by an Owner, with access bundles determining capability access.
Credits and Usage
Claude Enterprise usage relies on department groups, executive approvers, and operating delegates. The API Access Governance Framework proposes a $500,000 annual budget per department; interim historical controls (e.g., $40k/mo org limit, $60/mo user limit) are deprecated. [[Claude Tag]] operates on dedicated pilot budgets per channel rather than requester inheritance.
System Setup
[[Claude Tag]] uses service accounts with 1Password-managed access and manual credential rotation (30-day initial cycle). Claude Code and citizen-development workflows utilize governed GitLab/Vercel infrastructure, including CATO protection, security checks, and mandatory human review for CI/CD.
Updates and Releases
Changes require feature branches, merge requests, and automated security scans (Wiz, dependency checks). Vibe Coding workflows mandate company-approved configurations and governed release paths.
Governance Gaps
- No general Claude seat-offboarding workflow.
- Missing Claude-admin release calendar, configuration-change procedure, model-deprecation process, and rollback runbook.