Enterprise agents enter service across four operating boundaries
Announcements from GitHub, Anthropic, and Instacart show enterprise agents being managed through installation, activity measurement, execution environment, and human authority during incidents.
Artificial Intelligence··Evening
Installation rights meet measurable activity
Two GitHub announcements address entry into an enterprise account and the activity trail left inside it as separate layers. Enterprise owners can now install public GitHub Apps built outside their enterprise on the enterprise account, opening enterprise permissions to external app builders. Apps carrying the `Enterprise organization installations` or `Enterprise organization installation repositories` permission cannot be installed across enterprise boundaries, and an app already installed in more than one enterprise cannot add those permissions later. The second announcement adds an optional array to the Copilot usage metrics API, breaking third-party agent-app activity down by agent. Alongside a display name and an identifier that remains stable across reporting periods, the array gives the number of jobs started and, in enterprise and organisation reports, a session count. One-day and twenty-eight-day reports are available at several administrative levels. Access depends on being an enterprise owner, billing manager, organisation owner, or holding the required custom role. Installation authority and observable activity therefore remain separate controls: one determines which boundary an app may enter, while the other defines how the work it starts inside can be counted.[1], [2]
Company hardware does not keep every data flow inside
Anthropic's self-hosted environments, now in public beta, show that choosing a place to run a workload does not define the whole data boundary. Organisations on Team and Enterprise plans can run Claude Code sessions on infrastructure they provide instead of Anthropic's servers; the option is off by default. Repository checkouts, build artefacts, and files created by a session stay on company machines. Prompts, responses, tool results, and session transcripts still go to Anthropic. Keeping source files in place therefore does not keep all content read by the model in the same location. Organisations using the zero-data-retention setting cannot enable the option. The announcement also sets out the operating work that accompanies customer-provided infrastructure: companies need engineers to build runner images, update the infrastructure, and operate an orchestration layer for scaling on demand. This choice separates session files, model-bound content, and scaling responsibility. Enterprises must decide what data leaves the environment and who will keep it running.[3]
Incidents get faster support while engineers retain authority
Instacart's Blueberry system offers an internal example of these boundaries meeting during a production incident. According to InfoQ, an alert causes the system to launch about 10 subagents in parallel, gather information, generate hypotheses, and post a grounded root-cause suggestion in the Slack thread used by engineers within about three minutes. Diagnosis, mitigation, and remediation decisions remain with the engineer, and the system makes no automatic production changes. Instacart reports roughly 25,000 diagnostic passes during April across more than 270 Slack channels, and says using more than 14 years of incident history lifted accuracy from the mid-60 per cent band to the high-90 per cent band. The figures are company-reported and no independent measurement has been published. Read together, the four announcements present enterprise agent operations as a linked set of boundaries rather than one enablement switch. Installation authority, activity counting, execution location, and ownership of a high-consequence decision are defined separately. The products address different jobs, while their shared operating requirement is to give each boundary a clear owner and an observable trail. That arrangement keeps the agent useful while making the point at which human judgement becomes mandatory visible to the organisation.[1], [2], [3], [4]