Anthropic's developer account shipped two Claude Managed Agents updates within a day of each other in September 2026 — one for watching what a running agent is doing, and one for deciding whether it should be allowed to do it. Together they round out the ant CLI's coverage of the Managed Agents lifecycle: define with ant apply, run it, watch it with the new session viewer, and let auto mode handle routine approvals along the way.
TL;DR
| Question | Answer |
|---|---|
| What's new? | Live session attachment via ant beta:sessions connect (plus --web), and intent-based auto mode for tool approvals |
| Session viewer command | ant beta:sessions connect; add --web for a localhost browser UI |
| Auto mode decision | Run, deny, or ask — judged against user.message intent, not a generic danger classifier |
| Same as Claude Code auto mode? | No — different product, different criteria (details below) |
| Stable? | beta: prefix on both features; expect breaking changes before GA |
| Prerequisite | Managed Agents API (managed-agents-2026-04-01 beta header; ant sets this automatically) |
| Feature | What it does | Command / trigger |
|---|---|---|
| Session viewer | Attach your terminal (or browser) to a running Managed Agents session | ant beta:sessions connect, add --web for a localhost UI |
| Auto mode | Reviews each tool call against your stated intent, then runs, denies, or asks | Enabled as a Managed Agents setting |
Where these updates sit in the Managed Agents lifecycle
Anthropic has been stacking Managed Agents capabilities in a predictable order since the public beta launch documented in platform release notes: define agents and environments, run sessions against them, stream events, confirm tools, review costs in Console. The September 10–11, 2026 pair closes two operational gaps that show up once you move from a demo session to something that runs for hours.
| Lifecycle stage | Surface | What you do today |
|---|---|---|
| Define | ant apply, YAML in repo | Sync agents, skills, deployments (Terraform-style) |
| Run | ant beta:sessions create, events send | Create session, send user.message to start work |
| Watch | ant beta:sessions connect (new) | Attach terminal or --web UI to a live session |
| Approve | Auto mode (new) or manual user.tool_confirmation | Resolve requires_action stops on the event stream |
| Review | Claude Console | Timeline minimap, per-thread cost inspector (August Console update) |
Production teams like ABC Legal's 50+ agent fleet already treat Managed Agents as infrastructure. These updates make that infrastructure easier to operate without writing a custom SSE client for every on-call engineer.
The session viewer: watching a running agent live
ant beta:sessions connect attaches your terminal directly to a Managed Agents session that's already running, rather than only being able to inspect logs after the fact. Add the --web flag and instead of a terminal attachment, it opens a web UI served from localhost — a browser-based view of the same live session, useful for anyone who'd rather watch a running agent's activity in a UI than scroll a terminal stream.
This sits next to the Console session viewer redesign Anthropic shipped in August 2026, which added a timeline minimap and per-thread cost inspector to the hosted Console — that's a post-hoc review surface for sessions after they run; ant beta:sessions connect is the live, CLI-native equivalent for watching one as it happens.
How the underlying event stream works
Managed Agents sessions are not request/response chat completions. They are state machines driven by an event stream. Official documentation describes a two-step lifecycle: create the session (optionally with up to 50 initial_events to start work immediately), then read and send events on GET /v1/sessions/{session_id}/events/stream — a server-sent event (SSE) feed.
The stream carries typed events: agent.message, agent.tool_use, agent.mcp_tool_use, session.status_idle, and others. When a tool needs human approval, the session pauses with stop_reason: requires_action and lists blocking event IDs in stop_reason.event_ids. You resolve each with a user.tool_confirmation event (result: "allow" or "deny"). That pattern existed before September 2026; what changed is that you no longer need to build the viewer yourself, and auto mode can substitute for hand-approving every call.
The session viewer wraps that same stream. Whether you attach a terminal or open --web on localhost, you are consuming the live SSE feed Anthropic already documents — not a separate telemetry channel. That matters for debugging: if the viewer shows a tool pause, your automation can still send user.tool_confirmation through the API in parallel.
Session viewer vs Console vs raw curl
| Surface | When to use it | Latency | Best for |
|---|---|---|---|
ant beta:sessions connect | Active run, engineer at laptop | Live | On-call, local dev, pairing |
--web flag | Same, but terminal-averse teammates | Live | PM/design review of agent behavior |
| Console timeline | Post-run audit, cost attribution | Historical | Compliance, billing, retros |
| Raw SSE + SDK | Custom dashboards, CI gates | Live | Platforms embedding Managed Agents |
Multi-agent sessions add thread-scoped streams (/threads/{thread_id}/stream). Subagent previews are opt-in via event_deltas[] query parameters on the stream URL — useful when a primary agent delegates to specialists and you need to watch the subagent thread without cross-posting previews to the main timeline.
Auto mode: intent-based tool call review
The second update brings auto mode to Claude Managed Agents. With it enabled, Claude reviews each tool call an agent is about to make, checks it against the intent expressed in your user.message events, and decides to run the tool call, deny it, or ask you for input — rather than surfacing every single tool call for manual approval by default.
It's worth being precise about naming here, because Anthropic already shipped something called "auto mode" in August 2026: Claude Code's default auto mode for Pro, Max, and Team plans, where a safety classifier screens tool calls in the interactive coding CLI — in Anthropic's own controlled study, that classifier caught 89% of planted dangerous commands versus a 13.6% human catch rate. This new Managed Agents auto mode uses the same run/deny/ask decision shape, but judges calls against your stated intent in a longer-running, more autonomous background agent context rather than screening for generically dangerous commands in an interactive session. Same pattern, different product, different judgment criteria — don't assume one write-up covers both.
Three "auto modes" builders confuse
| Product | Trigger | Judgment criteria | Human fallback |
|---|---|---|---|
| Claude Code auto mode | Interactive CLI session | Danger classifier: irreversible/destructive/exfiltration patterns | Manual mode, 3-strike fallback, permission modes |
| Managed Agents auto mode (new) | Background session event stream | Alignment with user.message intent | user.tool_confirmation, ask path |
| Claude Code plan-mode auto | Planning phase only | Classifier on shell commands when useAutoModeDuringPlan is on | Prompt per command |
Managed Agents also expose per-tool permission_policy on toolset configs (documented in platform release notes for web_search / web_fetch domain restrictions). Auto mode sits above that stack: even when a tool is enabled, the session may still pause at requires_action until auto mode or a human allows the specific invocation.
Anthropic's September 2026 cyber-safety research noted that Claude Code auto mode would have blocked a majority of misaligned actions in synthetic red-team scenarios — a different threat model from "does this git push match the ticket I filed in user.message?" Managed Agents auto mode is closer to policy-as-intent: you seed the session with what you want, and the harness rejects tool calls that drift.
What auto mode changes in the approval loop
Before auto mode, every permission_policy that required confirmation meant an engineer watched the SSE stream (or polled Console) and sent user.tool_confirmation for each agent.tool_use pause. That does not scale when ABC Legal-style fleets run dozens of concurrent sessions.
Auto mode inserts a model judgment step:
- Agent emits
agent.tool_use(oragent.mcp_tool_use). - Session hits
session.status_idlewithrequires_action. - Auto mode evaluates the call against prior
user.messageevents → run, deny, or escalate to ask. - On allow, the harness sends confirmation; on deny, the tool is blocked with optional
deny_message; on ask, you still get a human checkpoint.
The "ask" path preserves the safety valve Anthropic built into Claude Code auto mode after red-team findings — full autonomy without an escape hatch is how you get rubber-stamped rm -rf at 2 a.m.
Builder takeaways: operating Managed Agents in production
Open the stream before you send work. Official guidance recommends connecting to the event stream before delegating tasks so you do not miss early events — especially requires_action pauses that happen within seconds on fast agents.
Pin agent versions for anything beyond experiments. Sessions default to the latest agent version when you pass a bare agent ID. Production rollouts should pin {type: agent, id: ..., version: N} in ant beta:sessions create, the same way you would pin a container image tag.
Treat user.message as your policy document. Auto mode reads intent from those events, not from Slack threads or Jira tickets unless you copy that context into the session. Teams using loop engineering patterns already encode goals in structured prompts — the same discipline applies here.
Combine viewer + auto mode + Console. Live attach for debugging; auto mode for throughput; Console for cost and timeline forensics after incidents. None replaces the others.
Know the API-key boundary. Developer replies on the announcement thread asked whether subscription accounts work or API keys are required. Managed Agents has historically been API-first; verify current billing docs before promising finance a subscription-only rollout.
Limitations and open questions
beta:commands —ant beta:sessions connectmay rename, change flags, or merge into non-betaant sessionsbefore GA. Pin your automation to documented API endpoints if you need stability.- Auto mode transparency — the announcement does not specify whether denials log a reason code you can audit. Until that exists, keep Console exports for compliance-sensitive workloads.
- IDE gap — session viewer is CLI/web, not VS Code integrated. Teams wanting in-editor live agent panels still need custom SSE clients or Console.
- Not a substitute for sandbox policy — domain allowlists on
web_fetch, memory store mounts, and environment isolation remain the hard security boundary; auto mode is intent alignment, not network segmentation. - Name collision risk — internal runbooks should say "Managed Agents auto mode" vs "Claude Code auto mode" explicitly. Onboarding docs that say only "auto mode" will confuse new hires within a week.
What people are asking
Reactions on the announcement thread ranged from feature requests to access confusion — worth addressing directly:
"Can we use our subscription, or do we need an API key?" A developer replied to the announcement specifically asking this, noting docs they'd seen pointed to API-key-based access rather than a standard Claude subscription. Anthropic's announcement doesn't resolve this directly — check current Claude Managed Agents documentation for the authoritative answer on billing and access for these beta commands.
"I wish computer use worked in VS Code, not just the Claude app." A separate reply raised this as a workflow gap — the session viewer and auto mode both ship as ant CLI and Managed Agents features, not IDE-integrated ones, so this specific request isn't addressed by either update.
Is ant beta:sessions connect stable? The beta: prefix in the command itself signals Anthropic doesn't consider it finished — expect the interface to change before it graduates out of beta, the same caution that applies to any ant beta:* subcommand.
The bottom line
These two updates target different failure modes in running Managed Agents: the session viewer solves "I can't see what my agent is doing right now," and auto mode solves "I don't want to manually approve every tool call, but I still want a checkpoint that isn't a rubber stamp." Combined with ant apply's declarative agent definitions from earlier in September, the ant CLI is quickly becoming the same kind of infrastructure-as-code surface for agents that Terraform is for cloud resources — define it, run it, watch it, and let policy handle the routine approvals.
Command names, behavior, and dates above reflect Anthropic's September 10-11, 2026 announcement — check Anthropic's official developer documentation for the current, non-beta command syntax as these features mature.
Related reading
- Function Hooks and ant apply: Claude Code's Terraform moment
- Claude Managed Agents: memory, domain controls, and a new Console
- Auto mode becomes the default in Claude Code for Pro, Max, and Team
- How ABC Legal runs 50+ Claude Managed Agents as code
- Claude Community Build Days: Fable 5.1 buildathons worldwide
- Claude Code permission modes explained
- What is an agent harness? Complete guide
- Loop engineering for coding agents
- Official: Managed Agents sessions · Session event stream · ClaudeDevs announcement on X
