docs(reference): add Individual/Teams/Enterprise tier breakdown to Claude digest

Expands §1.2 into a proper three-tier section: positioning per tier, a
capability × tier table (with source + whether the doc is explicit), the
billing differences, and the documented contradiction (authentication lists
"managed policy settings" as Enterprise-only while the server-managed-settings
feature page says Teams+ can use it). Also flags that most controls hinge on
provider (Anthropic-direct + admin write access) rather than subscription tier.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-06-05 16:41:58 +08:00
co-authored by Claude Opus 4.8
parent edb7090055
commit 12f3cf21df
@@ -29,12 +29,46 @@ Claude Code 的企业管控可拆成三层 + 两条贯穿能力:
- **Google Vertex AI**(继承 GCP)
- **Microsoft Foundry**(继承 Azure)
### 1.2 计划层级 [AU]
- **个人**:Pro / Max。
- **Teams**:自助计划,含协作、管理工具、计费管理,适合小团队。
- **Enterprise**:在 Teams 之上**增加** SSO、域名捕获(domain capture)、基于角色的权限(role-based permissions)、合规性 API(compliance API)、托管策略设置(managed policy settings)。
### 1.2 计划层级:个人 / 团队 / 企业(核心分水岭)[AU]
> server-managed-settings 需要 **Teams/Enterprise** 计划。[SM]
这是整个管控体系的**主线**——「谁能用哪些管控/分配能力」首先由订阅层决定。
**三层定位(authentication 原文,唯一权威出处):**
- **个人 Pro / Max**:用 Claude.ai 账户登录的**个人**订阅。文档对个人层**只描述登录**,不赋予任何组织管控能力(没有管理控制台、没有成员/座位、不能下发策略)。
- **Claude for Teams**:「**自助服务计划,具有协作功能、管理工具和计费管理。最适合较小的团队。**」——有管理员仪表板、集中按座位计费、能邀请成员。
- **Claude for Enterprise**:「**在 Teams 之上添加 SSO、域名捕获(domain capture)、基于角色的权限(role-based permissions)、合规性 API(compliance API)、托管策略设置(managed policy settings),用于组织范围配置。最适合有安全/合规要求的大型组织。**」
> Teams 与 Enterprise **共享**:团队成员可用 Claude Code + 网页版 Claude、集中计费、团队管理。Enterprise 是在 Teams 上**叠加**那 5 项。
### 1.3 能力 × 层级 对照表(来源已标注;文档未点名层级的标「未明确」)
| 能力 | 个人 Pro/Max | Teams | Enterprise | 出处 / 是否明确 |
|---|---|---|---|---|
| Claude.ai 账户登录 | ✅ | ✅ | ✅ | [AU] 明确 |
| 管理员仪表板 / 邀请成员 | ❌ | ✅ | ✅ | [AU] 明确 |
| 集中计费 / 按座位订阅 | n/a(个人订阅) | ✅ | ✅ | [AU][AS] 明确 |
| 用量看板 Analytics(每用户指标/贡献/排行榜) | ❌ | ✅(仅 Anthropic 提供商) | ✅(仅 Anthropic 提供商) | [AS] 明确「Teams 和 Enterprise」 |
| 支出上限 spend limits / Cost tracking | n/a | ✅(仅 Anthropic 提供商) | ✅(仅 Anthropic 提供商) | [AS] 仅注明「仅 Anthropic」,未细分 Teams/Ent |
| **server-managed-settings(服务端托管设置)** | ❌ | ✅ | ✅ | [SM][AS] **明确:Teams 和 Enterprise 均可**(Teams 2.1.38+ / Ent 2.1.30+)。见下「⚠️ 矛盾」 |
| **SSO / SAML** | ❌ | ❌ | ✅ | [AU] 明确 Enterprise 专属 |
| **域名捕获(domain capture)** | ❌ | ❌ | ✅ | [AU] 明确 Enterprise |
| **基于角色的权限(role-based permissions)** | ❌ | ❌ | ✅ | [AU] 明确 Enterprise |
| **合规性 API(compliance API)** | ❌ | ❌ | ✅ | [AU] 明确 Enterprise |
| **ZDR(零数据保留)** | ❌ | ❌ | ✅ | [AS] 明确「Enterprise 可用」 |
| SCIM 自动配置 | ❌ | 未明确 | 未明确(强烈指向 Enterprise) | [AS] 只说「在账户级配置」,未点名层级 |
| `managed-mcp.json`(固定 MCP 集,独占控制) | ❌ | ✅ | ✅ | [MCP] **与订阅层无关**,靠 MDM/管理员写系统路径;**无法经 server-managed 下发** |
| `allowedMcpServers`/`deniedMcpServers` 策略下发 | ❌ | ✅ | ✅ | [MCP][SM] 经 server-managed → 故 Teams+ |
| auto-mode 本身 | ✅(经 Anthropic API) | ✅ | ✅ | [AM] 明确「所有用户」 |
| auto-mode **组织级管控**(`autoMode` 经托管设置下发) | ❌ | ✅ | ✅ | [AM] 依赖 server-managed → Teams+ |
> **⚠️ 文档内部矛盾(需知道)**:authentication 的市场定位句把「**托管策略设置(managed policy settings)**」列为 **Enterprise 专属**;但功能页 server-managed-settings 与 admin-setup 明确写「**Claude for Teams 或 Enterprise** 均可用」。**以更具体的功能页为准:server-managed-settings 这个具体功能 Teams 即可用**;authentication 那句更像笼统概述。
> **关键认知**:六篇文档**大多按「提供商」(Anthropic 直连 / Console / 云) 而非「订阅层」组织内容**。很多管控(managed-mcp、permissions、沙箱)能不能用,**更取决于「是否走 Anthropic 直连 + 有无管理员写盘权限」,而非 Teams/Enterprise 之分**。订阅层主要卡的是:成员/座位/计费(Teams+)、server-managed 下发(Teams+)、SSO/SCIM/域名捕获/角色权限/合规 API/ZDR(Enterprise)。
### 1.4 计费方式差异 [AS]
- **Teams / Enterprise**:Claude Code 与 claude.ai 同在**一个按座位订阅**下,无需自建基础设施(默认推荐)。
- **Console**:API 优先 / **按量付费**。
- **Bedrock / Vertex / Foundry**:继承对应云的合规与计费,支出经 AWS Cost Explorer / GCP Billing / Azure Cost Management 查看。
---