Scheduled Claude Agents: Pick the Right Surface, Then Stop Them Failing Silently
Run repository work on Claude Code routines and production automations on Claude Managed Agents scheduled deployments, which add minute-level cron and a dollar cap per run. Whichever surface you pick, apply Anthropic's six rules: bookmarks, unreadable-not-quiet, re-check before posting, confirm then record, read-only preferences, least privilege.
Use Claude Code routines when the job is work on your repositories and you want it covered by your Claude plan. Use a Claude Managed Agents scheduled deployment when the automation is a product in its own right: it runs on a cron schedule with minute-level granularity, bills to your API organization, and caps each run in dollars. Then build it to fail loudly, because an unattended agent that loses a source looks exactly like one that found nothing.
That second half is the subject of Anthropic's October 8 post on building effective agent automations, written around a reference "daily brief" agent that reads Slack and GitHub and posts one short summary to Slack each weekday. This guide turns its failure modes into rules you can apply on any Claude surface. For the trigger and pricing details of routines, see our Claude Code routines guide; for other vendors' schedulers, see the scheduled agents comparison.
Key Takeaways
- Pick the surface by where the work lives and who pays. Routines for repository work on a subscription, Managed Agents scheduled deployments for API-billed automations with a dollar cap per run, Desktop tasks or
/loopfor your own machine, GitHub Actions orclaude -pfor CI. - Read each source from a bookmark, not a fixed "last 24 hours" window, so late and early runs neither skip nor repeat items.
- A failed read is unreadable, never quiet. Keep the bookmark, report from the other sources, and name the gap.
- Re-check every item against its live source just before posting, and drop what you cannot confirm.
- Count a post as sent only when the destination confirms it, then move bookmarks and the ledger.
- Keep preferences in a store the agent cannot edit and re-read them every run.
- Give read-only credentials wherever the agent only reads, and cap what each run can spend.
Which Claude Surface Should Run Your Automation?
Claude offers six ways to run an agent on a schedule, and the right one follows from where the work lives and which bill it should land on. Cloud routines need no machine; Desktop tasks and /loop need yours; Managed Agents and the CI options are built on the API.
| Surface | Where it runs | Fastest schedule | Billing | Pick it when |
|---|---|---|---|---|
| Claude Code routine | Anthropic cloud, fresh clone of your repos | Hourly | Claude subscription | The job reads or changes GitHub repositories |
| Managed Agents scheduled deployment | Anthropic cloud sandbox, or a self-hosted sandbox | Every minute | Claude API organization | The automation is a product: briefs, syncs, scans |
| Desktop scheduled task | Your machine, app open and awake | Every minute | Claude subscription | The job needs local files or tools |
/loop | Your open Claude Code session | Every minute | Claude subscription | You are polling a deploy or a PR while you work |
| GitHub Actions | GitHub runners | Workflow cron | API key or subscription token | The job belongs in a repository's CI |
claude -p on your own cron | Your server | Whatever your cron allows | API key or subscription | You already run infrastructure and want full control |
The minimum interval is one hour for cloud routines and one minute for Desktop tasks and /loop. A scheduled deployment takes a cron expression and a time zone, and its maximum granularity is one minute. Desktop tasks run only while the desktop app is running and your computer is awake, and /loop tasks are session-scoped, so neither suits an automation other people depend on.
The verdict: if a teammate would notice the automation missing, run it in the cloud. Choose a routine when the job is repository work you would otherwise do in Claude Code, and choose a scheduled deployment when you want versioned configuration files, a separate API bill, and a hard spend cap on every run.
Routines Limits You Will Hit
Routines are rate-limited per hour, separately from subscription usage. Scheduled runs, including one-off runs, are limited to 100 per hour per account, and a scheduled run over the limit waits until the limit resets. Run now, API fires, and re-running a one-off routine share a limit of 30 per hour for each routine. None of these hourly limits has overage.
Usage is the second limit. Routines draw down subscription usage the same way interactive sessions do, and when a routine hits your subscription usage limit, organizations with usage credits turned on keep running on metered overage. Routines are available on Pro, Max, Team, and Enterprise plans. They are also a research preview, so Anthropic says behavior, limits, and the API surface may change.
What Anthropic's Reference Daily-Brief Agent Is Made Of
The reference agent is six resources declared as files and created with ant apply: an agent, an environment, two memory stores, a vault, and a deployment. You can clone it from the daily-brief quickstart or have Claude Code set it up by running /claude-api managed-agents-onboard with the post's URL.
| File | What it holds |
|---|---|
agent.md | Model, tools, MCP servers, and the run steps as the system prompt |
deployment.md | Cron schedule, time zone, budget, memory stores, vault, and the first message of each run |
environment.yaml | The sandbox's network allowlist |
memory_store_preferences.yaml | Your rules, mounted read-only |
memory_store_state.yaml | The agent's bookmarks, ledger, notes, and run records |
vault.yaml | The vault that holds the Slack and GitHub credentials |
Each time the schedule fires, the platform starts a fresh agent session. The quickstart's agent runs on claude-sonnet-5-5, and its deployment fires at 07:32 on weekdays in the America/New_York time zone. Vault files need ant CLI version 1.34.0 or later. Managed Agents is in beta, and access is enabled by default for all API accounts.
Read From a Bookmark, Not a Time Window
Give the agent one bookmark per source instead of asking it to read a fixed window. A late run with a fixed window leaves a gap, and an early run repeats items. In the reference build, the agent writes the timestamp of the newest item it read from each source to a bookmarks file at the end of each run, and the next run starts from there, so its window stretches or shrinks to cover everything since the last run.
The bookmarks live in a memory store, a folder of text files that the platform mounts under /mnt/memory/ in every run's sandbox and keeps between runs. A session can attach up to 8 memory stores. The same rule protects you on other surfaces: a Desktop task that missed several days runs once on wake, for the most recently missed time only, and a bookmark-driven prompt covers the whole gap where a "since yesterday" prompt would not.
Treat a Failed Read as Unreadable, Not Quiet
The most dangerous failure in a scheduled agent is a silent one. If an MCP server is down or its token has expired, the run still starts without that server's tools, the session logs an error, and the agent reports nothing new. A reader cannot tell that apart from a quiet day.
Write three rules into the run steps. When a source fails, the agent keeps that source's bookmark where it is, writes the report from the sources that worked, and ends with one line naming what it could not read. The same logic applies to the destination: if a post cannot reach its channel, record the run as held and change nothing else.
Confirm the Post Before Recording It
Count a post as sent only when the destination confirms it, and update bookmarks and the ledger only after that. If the agent records a post that never landed, the bookmarks move on and those items are never reported; if it re-posts because it is unsure, readers get the same brief twice.
The reference build uses three rules. It looks for today's edition in the channel first and does not post if it is already there. For Slack, a post counts as sent only if the response carries "ok": true and a message ts. If the result is unclear, the run is marked "maybe posted" and nothing else changes. A run record moves from "posting" to "posted" with the message ID, so the next run can see what happened.
Before posting, re-check every item against its live source. Drop anything resolved since the read, fix anything that changed, and drop anything you cannot confirm. Anthropic's run steps put the rule plainly: "assert it or drop it." Copy links from each source's own link field rather than building them by hand.
Keep Preferences Read-Only and Re-Read Them Every Run
Store your rules where the agent can read them but not change them, and have it read them fresh at the start of every run. A copy of the preferences baked into the prompt keeps applying rules you have already changed. If the agent cannot read the preferences file, it should stop and say so rather than run on defaults.
Split memory by owner. The reference build keeps two stores: preferences, which is yours and read-only to the agent, and state, which the agent writes. Memory stores attach with read_write access by default, so set read_only explicitly on anything the agent should only consult. Anthropic's memory docs warn that a prompt injection can write into a read-write store that later sessions trust.
State also needs a ledger: one line per reported item with the date, the source, a stable ID such as a Slack message timestamp or a pull request number, and its last known status. The ledger is what lets the agent report a change ("still waiting, day 3") instead of repeating yesterday's item.
Lock Down Permissions and Network Access
An unattended agent reads text other people wrote, and any of it can try to steer the agent, so limit what it could do if it followed a planted instruction. Give it read-only credentials wherever it only reads, an environment that reaches only the hosts it needs, and preferences it cannot edit.
Know the defaults before you rely on them. In Managed Agents the agent toolset, including bash, defaults to always_allow, while MCP toolsets default to always_ask. An unattended run has nobody to approve an MCP call, so the reference build sets its GitHub toolset to always allow and keeps the GitHub token read-only. An environment created through the API without a networking field gets unrestricted network access, so set limited networking with an explicit host list. The reference build also turns off the toolset's web_search and web_fetch tools.
Credentials go in a vault. With an environment-variable credential, the sandbox holds only an opaque placeholder and the real secret is substituted at egress, only for hosts you allow. On Claude Code routines the equivalents are the environment's network access, the connectors you include, and the repositories you select, and Anthropic advises scoping each to what the routine needs.
What a Run Costs and How to Set the Budget
A scheduled Managed Agents run costs about a dollar in Anthropic's own tests, and the budget field caps it per run. The quickstart's README reports about $1.50 a busy run on Claude Opus 5 and about $1.00 on Claude Sonnet 5, and $0.15 to $0.30 for a run that finds every source unreadable. Those tests ran before the default model moved to Sonnet 5.5, so measure your own runs.
Our estimate, from that README figure: a weekday schedule fires about 22 times a month, so at about $1.00 a run the brief costs about $22 a month. On Claude Max and Team plans, the monthly API credits cover Claude Managed Agents, and Max 5x includes $100 a month while Max 20x includes $200. See our monthly API credits guide for how to claim them.
| Budget fact | What the docs say |
|---|---|
| Starting cap | Three to five times a normal run, then tighten |
| Unit | Whole US cents written as a string, so "500" is $5.00 |
| Scope on a deployment | Copied onto each run, not a total across runs |
| At the cap | The run pauses with budget_reached; it does not fail |
| What is priced | Model tokens at list price, web searches at $10 per 1,000, running time at $0.08 per hour |
The pause is the trap. A run that reaches its cap goes quiet, which looks like a day with nothing to report, so check the deployment's runs before you tighten the cap further. On claude -p, the equivalent is --max-budget-usd, checked against a client-side cost estimate that can differ from your bill.
Test It Before the Schedule Fires
Trigger a run by hand before you trust the schedule. On Managed Agents, ant beta:deployments run with your deployment ID starts a session immediately, and pausing a deployment still allows manual runs. On routines, use Run now; on Desktop tasks, click Run now after creating the task and approve each tool once so later runs do not stall.
Then watch for the failures that produce no session at all. Each attempt to run a deployment creates a deployment run record, and ant beta:deployment-runs list with --has-error shows the ones that failed, such as a rate-limited session creation, which is not retried. Deployment run outcomes are also delivered as webhook events, so you can alert on a failed run without polling. Two scheduling details save confusion: execution applies jitter of up to 15% of the interval between runs, capped at 9 minutes, and an unpaused deployment does not backfill missed triggers.
For a dry run that cannot post or move a bookmark, the quickstart's tip is to set the state store to read_only. Fix the time zone too: the reference deployment sets the cron timezone and also tells the agent which zone to use for dates, because an agent computing dates in the server's zone can call this morning "yesterday."
Applying the Rules on Claude Code Surfaces
The six rules are surface-agnostic; only the storage changes. On Managed Agents, bookmarks and the ledger live in a memory store. On a routine, which starts from a fresh clone, keep them somewhere the next run can read, such as a file the routine commits to a branch or a connector it already uses. On a Desktop task or claude -p on your own cron, a local file works.
Two CI details matter for scheduled jobs. GitHub runs scheduled workflows only from the default branch, and in public repositories it disables the schedule after 60 days without repository activity. For claude -p, add --bare so a scripted run does not pick up hooks, MCP servers, or CLAUDE.md from the machine, and use --output-format json to read total_cost_usd for each run.
For a company-wide version of the same pattern, with scheduled jobs that post to Slack, see the internal AI workspaces playbook.
Sources
- Anthropic, "Building effective agent automations," Lance Martin and CJ Avilla, October 8, 2026: https://claude.dev/blog/building-effective-agent-automations/
- Anthropic, daily-brief quickstart for Managed Agents (README, agent and deployment files): https://github.com/anthropics/claude-quickstarts/tree/main/managed-agents/daily-brief
- Anthropic, daily-brief deployment file (schedule, time zone, budget): https://github.com/anthropics/claude-quickstarts/blob/main/managed-agents/daily-brief/agents/daily-brief/deployment.md
- Claude Managed Agents overview: https://platform.claude.com/docs/en/managed-agents/overview
- Scheduled deployments: https://platform.claude.com/docs/en/managed-agents/scheduled-deployments
- Session budgets: https://platform.claude.com/docs/en/managed-agents/budgets
- Agent memory: https://platform.claude.com/docs/en/managed-agents/memory
- Vaults: https://platform.claude.com/docs/en/managed-agents/vaults
- Environments: https://platform.claude.com/docs/en/managed-agents/environments
- Permission policies: https://platform.claude.com/docs/en/managed-agents/permission-policies
- Manage resources as code with ant apply: https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply
- Claude Code routines: https://code.claude.com/docs/en/routines
- Claude Code scheduled tasks and
/loop: https://code.claude.com/docs/en/scheduled-tasks - Claude Code Desktop scheduled tasks: https://code.claude.com/docs/en/desktop-scheduled-tasks
- Run Claude Code programmatically (
claude -p): https://code.claude.com/docs/en/headless - Claude Code CLI reference: https://code.claude.com/docs/en/cli-reference
- Claude Code GitHub Actions: https://code.claude.com/docs/en/github-actions
- Anthropic Help Center, monthly API credits for Max and Team plans: https://support.claude.com/en/articles/17154008-monthly-api-credits-for-max-and-team-plans
Read next
More practices and workflows- Claude Code
Claude Code Routines: Schedule, API, and GitHub-Trigger Your AI Agents
Claude Code Routines is Anthropic's new way to run saved Claude Code configurations automatically -- by schedule, API call, or GitHub event. Routines run on Anthropic's cloud infrastructure with a prompt, repo, and MCP connectors. Available in research preview on Pro, Max, Team, and Enterprise plans.
- Claude Code
Scheduled AI Coding Agents in 2026: Claude Code Routines vs Cursor Automations vs Codex vs Warp vs Gemini CLI
Claude Code Routines and Cursor Automations both ship schedules, API calls and native source-control events, and Cursor's trigger set is widest. ChatGPT scheduled tasks add Gmail, Slack and GitHub pull-request triggers but no API or webhook. Warp orchestrates other vendors' agents. Gemini CLI has no scheduler and lost its free individual tier on June 18, 2026.
- Claude
Claude's ant CLI Can Now Manage Agent Resources as Code
Anthropic added `ant apply` to the Claude CLI, letting teams declare Managed Agent environments, agents, skills, memory stores, and deployments in a repository and reconcile them with the Claude API.
- Claude
Claude Max and Team Plans Now Include Free Monthly API Credits: $100, $200, or Up to $500
Claude Max and Team plans now include monthly Claude API credits at no extra cost: $100 on Max 5x, $200 on Max 20x, and up to $500 pooled on Team. You claim them in claude.ai billing settings by linking one Console organization. They cover the API, Managed Agents, and the Agent SDK, not interactive Claude Code.
Ramp Glass Playbook: Internal AI Workspaces for Company-Wide AI Adoption
Glass is Ramp's internal AI productivity suite, built after the company had already hit 99 percent AI adoption and found most employees still stuck on setup. One Okta SSO sign-in wires up every tool, a marketplace called Dojo holds 350+ shared skills, memory is mined from Slack, Notion, Linear and Calendar, and jobs run on cron. Here is the playbook other companies can borrow.
Frequently Asked Questions
What is the difference between Claude Code routines and Managed Agents scheduled deployments?
Routines run saved Claude Code sessions against your GitHub repositories and draw down your claude.ai subscription. Scheduled deployments run a Managed Agent from the Claude API on a cron schedule, bill to your API organization, and take a hard dollar budget on each run.
What are the Claude Code routines limits?
Routines have hourly start limits, separate from subscription usage: 100 scheduled runs per hour per account, and 30 manual or API starts per hour per routine. None of these hourly limits has overage. Routines also draw down subscription usage like interactive sessions.
How do I stop a scheduled agent from reporting nothing when a source is down?
Make a failed read visible. When a source errors, keep its bookmark where it was, write the report from the sources that worked, and end it with one line naming what could not be read, so a reader never mistakes an outage for a quiet day.
How much does a scheduled Managed Agents run cost?
Anthropic's daily-brief quickstart measured about $1.50 a busy run on Claude Opus 5 and about $1.00 on Claude Sonnet 5, before the default moved to Sonnet 5.5. A run that could read none of its sources cost $0.15 to $0.30.
How should I set the spending cap on a scheduled agent?
Anthropic advises starting the cap at three to five times the cost of a normal run, then tightening it as you see real numbers. A run that hits its cap pauses with a budget_reached stop reason rather than failing, so a cap set too low looks like silence.