Smartflow for Claude Code

Smartflow for Claude Code puts runtime governance between Claude Code and everything it touches. Model calls route through Smartflow, tool calls reach your systems through Smartflow, and actions that change production pause for a person with authority to approve them.

Smartflow for Claude Code puts APERION's runtime governance between Claude Code and everything it touches. Model calls route through Smartflow, tool calls reach your systems through Smartflow, and actions that change production pause for a person with authority to approve them. Every step lands in a tamper-evident record inside your infrastructure.

What can Claude Code reach?

Claude Code runs in a developer's terminal with that developer's access. It reads the repository, edits files, runs shell commands, and calls any MCP server it is configured to use: the CI pipeline, the ticketing system, the cloud console, the observability stack. In most organizations that access was granted to a person. The agent now uses it at machine speed.

The failure mode is documented. In July 2025 a coding agent deleted a production database during a declared code freeze. In April 2026 another agent found an API token with broad permissions, unrelated to its task, and deleted a company's production database and its backups in nine seconds. Neither event needed an attacker. Each needed an agent with authority and no one asked before the command ran.

Supervisors have noticed. In May 2026 the New York Department of Financial Services recommended human oversight of AI-generated code before it reaches production. The letter is guidance. It also tells you what examiners will ask.

Where does Smartflow sit?

Claude Code offers three places to govern it. Smartflow covers two directly and records the third.

The model path. Claude Code supports an enterprise LLM gateway. Set ANTHROPIC_BASE_URL to Smartflow's Anthropic-compatible endpoint through managed settings, and every prompt and response passes through Smartflow on your infrastructure. Smartflow redacts personal identifiers, such as Social Security and card numbers, before they leave, attributes each call to a developer through a per-developer key, applies your routing policy, and passes the prompt-cache markers Claude Code sets through unchanged. The model's requests to run tools arrive in its responses, so Smartflow's record includes every command Claude Code was asked to run.

The tool path. MCP servers are how Claude Code reaches your systems. Point the managed MCP configuration at Smartflow's MCP gateway and set allowManagedMcpServersOnly so developers cannot add their own. Smartflow terminates each MCP call, reads the tool name and arguments, and checks them against your policy. For MCP servers that run on the laptop, APERION Shield wraps them locally with the same rule schema.

The shell. Commands Claude Code runs directly in the terminal do not pass through MCP. Govern them with Claude Code's own managed controls: deny rules, which apply in every permission mode; disableBypassPermissionsMode; and managed hooks with allowManagedHooksOnly. Use both layers. Anthropic's settings decide what can run on the laptop. Smartflow decides what can reach your systems and keeps the record.

One configuration detail matters. Anthropic's documentation states that when ANTHROPIC_BASE_URL points at a gateway, Claude Code bypasses server-managed settings. Deliver policy through your device management tool or the managed settings file.

Which actions pause for a person?

Most controls for coding agents stop at three outcomes: allow, block, or ask the developer at the keyboard. The developer is rarely the person who owns production, and blocking every production action makes the agent safe and leaves the work undone. Smartflow adds a fourth outcome. When an action is outside policy, it pauses in the path as an approval ticket. A person with approval rights approves or denies it, and you can require that person to step up and re-verify their identity first. The agent proceeds only on approval. Each ticket is redeemed once when the action runs, and expires after 24 hours if no one answers. The same ticket covers tool calls through Smartflow's MCP gateway and calls wrapped by Shield on the laptop.

Action the agent prepares The approver sees
Deploy to production Service, version, diff reference
Roll back a release Service, target version, incident reference
Merge to a protected branch Repository, branch, pull request
Change production configuration or a feature flag Key, old value, new value
Mute or change a monitor Monitor, change, duration
Run a schema migration Migration, target database

Routine work does not pause. Reading code, running tests, opening a pull request and querying logs pass straight through and are recorded. You decide where the line sits, per repository and per environment.

What does the record show?

Every decision produces one record: the developer's key, the tool and its arguments, the policy that applied, the approver if there was one, and the time. Records are hash-chained, and every sealed record carries an RFC 3161 timestamp from a public timestamp authority or your own. Smartflow exports to Splunk, Datadog, OTLP, and JSON logs your SIEM can ingest. Turn on the WORM archive to write records to Azure immutable blob storage in your own account, and set retention to your schedule; the audit default is 365 days. When an auditor asks who approved last Tuesday's production change, the answer is a query.

Rollout in four steps

  1. Observe. Route model and MCP traffic through Smartflow with approvals off. Two weeks of records show what your agents do.
  2. Lock the configuration. Deploy managed settings through device management: the gateway URL, managed MCP servers, deny rules, and bypass mode disabled.
  3. Turn on approvals for production. Start with deploys and production configuration. Grant approval rights to the owners of production services.
  4. Expand by repository. Add protected branches, migrations and monitors as teams are ready.

Related: Smartflow for IT covers the same controls for operations and service desk agents.

Quick answers

Does Claude Code support an enterprise gateway?

Yes. Claude Code sends model traffic to any gateway that implements the Anthropic Messages API, set with ANTHROPIC_BASE_URL, and also supports the Bedrock and Vertex formats. Credentials come from ANTHROPIC_AUTH_TOKEN, ANTHROPIC_API_KEY or an apiKeyHelper script, so each developer can carry a personal key.

Can developers turn the controls off?

Not when policy is delivered as managed settings. Anthropic's documentation states that no user, project or local setting overrides them. Disable bypass permissions mode, allow managed hooks only, and restrict MCP servers to the managed list.

Does Smartflow replace Claude Code's permission prompts?

Keep both. The permission prompt asks the developer at the keyboard to confirm intent. Smartflow holds production actions for a person with approval rights and records that decision.

Download the full guide

The PDF adds the configuration reference for managed settings and managed MCP, the full decision map for engineering actions, a rollout checklist, and the questions to ask any vendor that proposes to govern coding agents.

Sources

Verified as of September 25, 2026.

Claude, Claude Code and Claude Cowork are products of Anthropic. OpenClaw is maintained by the OpenClaw Foundation. Hermes Agent is a project of Nous Research. APERION is not affiliated with or endorsed by these organizations.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs