Claude Code Workflows for EU Teams 2026
Claude Code workflows for EU teams: dynamic agents, GitHub Actions on Bedrock EU, governance and cost. How prompts stay in the Union and limits hold.
TL;DR
Claude Code workflows for EU teams are three layers: desk recipes, dynamic scripts that fan out agents, and anthropics/claude-code-action in CI. The Claude API has no EU inference. For processing in the Union use Bedrock eu.anthropic.claude-sonnet-5-5 or Google CLOUD_ML_REGION=eu, and pin the model.
What are Claude Code workflows in a team?
Claude Code workflows are repeatable ways to run Claude Code: plan before edit, parallel worktrees, claude -p in scripts, dynamic agent orchestration, and the GitHub Action. Governance is a pinned model, a pinned region, deny rules, and Ultracode off by default. The Claude API stores workspaces in the United States only.
The common workflows page is the desk cookbook. A developer starts claude, asks for an overview, attaches a file with @src/utils/auth.js (up to 25,000 tokens; text files over 256 KB are skipped), and switches to plan mode with Shift+Tab or claude --permission-mode plan. A second session stays isolated with claude --worktree feature-auth. For CI and hooks, claude -p "prompt" is a Unix filter: stdin in, stdout out.
Four schedulers sit side by side. Routines run on Anthropic-managed cloud, even when the laptop is off. Desktop scheduled tasks see local files. GitHub Actions live with the repo. /loop polls only inside an open CLI session. For a European company, Routines are the risky path: inference sits with Anthropic, inference_geo accepts only us and global, and workspace geo is us only.
We recommend this order. Desk recipes and plan mode first. Then dynamic workflows committed under .claude/workflows/. Then the GitHub Action on Bedrock or Google Cloud, not on ANTHROPIC_API_KEY. Repeatable knowledge with no live system belongs in Claude Skills for enterprise. Permissions and the sandbox sit in Claude Code security.
| Layer | Where it runs | When to use it |
|---|---|---|
| Recipes, plan mode, worktrees | Laptop or devcontainer | Daily work, review before the first edit |
Dynamic workflows (/workflows) |
Same session, script in the background | Audit, migration, cross-checked research |
claude -p |
Hook, cron, batch | One prompt, machine-readable output |
| GitHub Action / GitLab job | Runner | @claude on a PR, review, recurring jobs |
| Routines on claude.ai | Anthropic cloud | Only if US or global inference is acceptable |
How do dynamic workflows orchestrate many agents?
A dynamic workflow is a JavaScript script that starts many subagents. Claude writes the script, a runtime executes it, and the session stays usable. Reach for it when a handful of subagents is not enough: an audit, a 500-file migration, research that must cross-check sources. The default cap is 16 concurrent agents and 1,000 agents per run.
The workflows page splits four patterns. Subagents, skills and agent teams leave the next step to Claude. A workflow puts the loop in code. Intermediate results stay in script variables, not in the context window. The script can have agents review each other before it reports. Availability: every paid plan, the Anthropic API, Bedrock, Google Cloud Agent Platform, Microsoft Foundry. On Pro, turn the Dynamic workflows row on in /config.
/deep-research is the bundled run. It needs the WebSearch tool. Save your own runs under .claude/workflows/ (project) or ~/.claude/workflows/ (personal). The project copy wins on a name clash. A plugin ships the script in workflows/ and exposes it as /plugin:name. Ultracode (/effort ultracode or claude --effort ultracode, v2.1.203 or later) plans a workflow for every substantive task. That burns more tokens and hits session and weekly caps sooner. The keyword ultracode in a prompt you type starts one run. Before v2.1.210 it also fired from webhooks and pull request comments. It no longer does.
Runtime limits from the same page:
| Limit | Value |
|---|---|
| Concurrent agents | 16 by default, 1 to 256 via CLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS (v2.1.269+) |
| Agents per run | 1,000 |
Items in pipeline() / parallel() |
4,096 |
| Fan-out prompt cache | 5 minutes, or 1 hour with subagentPromptCacheTtl |
| Shared-cache stagger | 5,000 ms (CLAUDE_CODE_WORKFLOW_PREFIX_STAGGER_MS) |
| Structured-output retries | 5, override with MAX_STRUCTURED_OUTPUT_RETRIES |
A saved script looks like this. agent() starts one subagent, pipeline() starts one per list item, and Date.now() and Math.random() throw so a replay repeats the same calls.
export const meta = {
name: 'audit-routes',
description: 'Audit every route handler for missing auth checks',
}
const found = await agent('List every .ts file under src/routes/.', {
schema: {
type: 'object',
required: ['files'],
properties: { files: { type: 'array', items: { type: 'string' } } },
},
})
const audits = await pipeline(found.files, file =>
agent(`Audit ${file} for missing authentication checks.`, { label: file }),
)
return audits.filter(Boolean)
Without a pin, Claude Code on Bedrock and Google Cloud bills the primary model as Opus 5.5 from v2.1.207. For team audits, pin Sonnet. The /workflow-authoring skill (v2.1.248 or later) loads the writing reference before anyone edits the script.
How do you put Claude Code in CI?
The GitHub Action anthropics/claude-code-action@v1 runs Claude Code on the runner. With no prompt, it waits for @claude on an issue or PR. With a prompt, it runs on the event. For EU inference set use_bedrock: "true" or use_vertex: "true" and OIDC, not a long-lived cloud key.
The GitHub Actions docs give two paths. /install-github-app in a github.com repo installs the app, stores ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKEN, and opens the workflow pull request. Manual path: install the app, add the secret, copy examples/claude.yml into .github/workflows/. The official app asks for Actions, Administration, Checks, Contents, Discussions, Issues, Members, Merge queues, Metadata, Pull requests, Repository hooks, Statuses and Workflows. GitHub will not let you accept a subset. A custom app with Contents, Issues and Pull requests covers only this Action. Code Review and web auto-fix still need the official app.
Two checks run first: write access on the repo (skipped for schedule) and a human actor. List bots in allowed_bots or you get a loop. Commits made with GITHUB_TOKEN do not trigger follow-on workflows. Use the Claude app or a custom app token. Before v2.1.229 a review wrote only to the run log, not the pull request.
For Bedrock, Google Cloud and Foundry, the cloud providers page uses OIDC. AWS needs the IdP https://token.actions.githubusercontent.com, audience sts.amazonaws.com, and a role with bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, bedrock:ListInferenceProfiles, bedrock:GetInferenceProfile plus two Marketplace actions. Google needs IAM Credentials, STS, aiplatform.googleapis.com, a workload identity pool and a service account with roles/aiplatform.user. Foundry needs an Entra app with a federated credential and the Azure AI User role.
- Scope the IAM role to the exact repository (
repo:org/name:*). - Store
AWS_ROLE_TO_ASSUME. Do not store an access key. - Grant the workflow
id-token: write. - Pin the model to an EU profile, not the US sample in the docs.
- Add
--max-turnstoclaude_args.
name: Claude PR Action
permissions:
contents: write
pull-requests: write
issues: write
id-token: write
on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
jobs:
claude-pr:
if: contains(github.event.comment.body, '@claude')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_ROLE_TO_ASSUME }}
aws-region: eu-central-1
- uses: anthropics/claude-code-action@v1
with:
use_bedrock: "true"
claude_args: "--model eu.anthropic.claude-sonnet-5-5 --max-turns 20"
The official Bedrock sample uses us-west-2 and us.anthropic.claude-sonnet-4-6. For Union processing, replace region and model with the EU geo ID on the Sonnet 5.5 model card. Env vars and the IAM deny against global. live in Claude Code on Bedrock in the EU.
How do Claude Code workflows stay in the EU?
Claude Code workflows stay in the EU when inference goes through Bedrock eu. or Google CLOUD_ML_REGION=eu. The Claude API has no EU inference. Workspace geo is us only. Routines on claude.ai and an ANTHROPIC_API_KEY in Actions send prompts to Anthropic. Pinning is mandatory: without a pin Claude Code picks Opus 5.5.
On Bedrock, Claude Code maps every eu-* region to the eu. prefix. Also set ANTHROPIC_BEDROCK_REGION_PREFIX=eu. The prefix is a preference, not a guarantee. If no matching profile exists, Claude Code falls back. If no region is set at all, the default is us-east-1. The Claude Code Bedrock page resolves AWS_REGION, then AWS_DEFAULT_REGION, then the profile, then the US default.
export CLAUDE_CODE_USE_BEDROCK=1
export AWS_REGION=eu-central-1
export ANTHROPIC_BEDROCK_REGION_PREFIX=eu
export ANTHROPIC_MODEL=eu.anthropic.claude-sonnet-5-5
export ANTHROPIC_DEFAULT_SONNET_MODEL=eu.anthropic.claude-sonnet-5-5
export ANTHROPIC_DEFAULT_OPUS_MODEL=eu.anthropic.claude-opus-5-5
claude
Sonnet 5.5 launched on Bedrock on 28 September 2026. Context is 1 million tokens, output 128,000, knowledge cutoff June 2026, EOL no sooner than 28 September 2027. The EU geo ID eu.anthropic.claude-sonnet-5-5 from Frankfurt routes to Frankfurt, Stockholm, Milan, Spain, Ireland and Paris. London joins only when the source is eu-west-2. That stays in Europe. It is not a single-region pin. You do not get single-region plus dynamic workflows with Sonnet 5.5 on bedrock-runtime.
On Google Cloud, CLOUD_ML_REGION=eu uses aiplatform.eu.rep.googleapis.com. The Sonnet 5.5 page lists Europe multi-region at 1,250 QPM, 12,500,000 uncached input TPM and 1,250,000 output TPM. Global doubles those figures. Role: roles/aiplatform.user. Without a pin the primary model is claude-opus-5-5.
The GDPR cut is the same as in our provider comparison: a processor contract with AWS or Google, not an Anthropic workspace in the United States. The platform itself is in Amazon Bedrock in the EU. Per-key spend, when many laptops sit outside cloud billing, goes through LiteLLM as an EU gateway.
What do Claude Code workflows cost?
Claude Code workflows cost tokens, not a separate SKU. Anthropic cites 13 USD per developer per active day and 150 to 250 USD per month. Ninety percent stay under 30 USD per active day. Dynamic runs and Ultracode push those figures up. Sonnet 5.5 is 2 / 10 USD per million tokens. EU endpoints add 10 percent.
From the cost docs and the pricing page fetched on 11 October 2026:
| Item | Amount |
|---|---|
| Mean per developer per active day | 13 USD |
| Mean per developer per month | 150 to 250 USD |
| 90 percent cap per active day | under 30 USD |
| Sonnet 5.5 input / output | 2 / 10 USD per million tokens |
| Opus 5.5 input / output | 4 / 20 USD per million tokens |
| Haiku 5.5 (prompt up to 100,000 tokens) | 0.10 / 0.50 USD |
| Cache read on Sonnet 5.5 | 0.10 USD per million (0.05x) |
| Regional / multi-region from Sonnet 4.5 | plus 10 percent |
US-only inference_geo |
1.1x |
| Background work per session | typically under 0.04 USD |
A 500-file audit with one agent per file on Sonnet 5.5, roughly 4,000 input and 1,500 output tokens per file: 500 × (0.008 + 0.015) = 11.50 USD plus cache. The same run on Opus 5.5 doubles the token bill. Ultracode in a Team session can empty the session and weekly windows before the afternoon. On subscription plans those tokens share the same windows as chat, see Claude usage limits. Seat and API prices without orchestration sit in Claude Code pricing.
TPM guidance is organisational, not per head: 5 to 20 users get 100k to 150k TPM and 2.5 to 3.5 RPM per user. Two hundred users: 20k TPM each, 4 million TPM in total. On Bedrock, Google Cloud and Foundry, Anthropic analytics do not see the traffic. Measure with OpenTelemetry, a self-hosted Claude apps gateway, or an LLM gateway. The first Console login creates a workspace named “Claude Code”. It has no API keys, only usage.
We recommend Sonnet 5.5 as the team default, Opus only for architecture, --max-turns in CI, and Ultracode off once the run is saved.
FAQ
What do dynamic Claude Code workflows cost on top of the seat?
Tokens only. There is no workflow licence. A multi-agent run pays the same 2 / 10 USD (Sonnet 5.5) or 4 / 20 USD (Opus 5.5) per million tokens. The 13 USD mean per active day is mixed use. A 500-file audit can push a single day well above that mean.
Claude Code workflows vs Skills: which one?
Skills are folders of SKILL.md plus scripts. Claude loads the name and description first, the rest on demand. A dynamic workflow is an executable script that starts many agents and cross-checks results. Use Skills for repeatable knowledge that does not touch a live system. Use workflows for audits, migrations and verification. Use MCP only when Claude must write into tickets or repos.
Do Claude Code workflows run on Bedrock in the EU?
Yes. Dynamic workflows are enabled on Bedrock, Google Cloud Agent Platform and Foundry. Residency is still your job: AWS_REGION=eu-central-1, ANTHROPIC_BEDROCK_REGION_PREFIX=eu, model eu.anthropic.claude-sonnet-5-5. Without a pin, Claude Code may pick Opus 5.5 or a us. or global. profile.
May the GitHub Action use an Anthropic API key?
Technically yes. For processing in the Union, no. ANTHROPIC_API_KEY and CLAUDE_CODE_OAUTH_TOKEN call the Claude API. inference_geo is only us or global. Use use_bedrock: "true" or use_vertex: "true" with OIDC.
How do you stop a runaway workflow?
/workflows opens the list. x stops the selected agent or the whole run, p pauses, r restarts one agent. A relaunch replays completed agents from cache and reruns from the first changed or failed one. import() in the script fails before the run starts.
Do deny rules apply in CI and inside subagents?
Yes. Subagents fire the same PreToolUse and PostToolUse hooks. claude -p and the Action show no confirmation dialog. Put Workflow in the allow rules, use auto mode, or approve the launch with a hook. A managed deny is still the hardest edge.
Sources
- Claude Code: Common workflows (11 October 2026)
- Claude Code: Dynamic workflows (11 October 2026)
- Claude Code: GitHub Actions (11 October 2026)
- Claude Code: GitHub Actions with cloud providers (11 October 2026)
- Claude Code: Amazon Bedrock (11 October 2026)
- Claude Code: Google Cloud Agent Platform (11 October 2026)
- Claude Code: Manage costs (11 October 2026)
- Anthropic: Pricing (11 October 2026)
- Anthropic: Data residency (11 October 2026)
- AWS: Claude Sonnet 5.5 model card (11 October 2026)
- Google Cloud: Claude Sonnet 5.5 (11 October 2026)