Enterprise Team — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Enterprise Team (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<p align="center"> <img src="https://img.shields.io/badge/Claude_Code-Plugin-blueviolet?style=for-the-badge" alt="Claude Code Plugin"/> <img src="https://img.shields.io/badge/Agents-75-green?style=for-the-badge" alt="75 Agents"/> <img src="https://img.shields.io/badge/Departments-10-blue?style=for-the-badge" alt="10 Departments"/> <img src="https://img.shields.io/badge/Model-Opus-purple?style=for-the-badge" alt="Opus Powered"/> </p>
<h1 align="center">Enterprise Team</h1>
<p align="center"> <strong>Hire a whole company with one plugin.</strong><br/> 75 specialized AI agents across Engineering, Product, Infrastructure, Data, Security, Marketing, Sales, Finance, Legal, and People. </p>
<p align="center"> <img src="assets/brain-meme.jpg" alt="Evolution: ChatGPT → Claude Code → Claude Code with skills → 75 AI employees auto-routing your requests" width="100%"/> </p>
When you ask Claude Code to "build me a dashboard," it does its best. But Claude is trying to be everything at once: frontend developer, backend engineer, database architect, and UI designer. The result? Competent but generic work.
The real issue is context switching at scale. A generalist agent:
You end up with code that works but doesn't reflect what a dedicated specialist would produce. The API design a backend-focused engineer would craft. The component architecture a frontend specialist would build. The security hardening an AppSec engineer would insist on.
Skills help, but they're manual. You have to know which skill to invoke, when to switch contexts, and how to coordinate handoffs between different specialties. That cognitive load is on you.
What if Claude Code could operate like an actual company?
The key insight: departments exist for a reason. Real organizations don't have one person doing everything. They have specialists who go deep, orchestrated by managers who route work to the right people.
Enterprise Team replicates this structure:
When you say "build me a settings page with dark mode," Enterprise Team doesn't just write code. The orchestrator recognizes this needs:
Each specialist contributes their expertise. The result is closer to what a real team would produce.
<p align="center"> <img src="assets/no-more-guessing.png" alt="No More Guessing - Enterprise Team Routes to the Right Specialists" width="100%"/> </p>
When you make a request, the orchestration layer analyzes it:
User: "Set up authentication with OAuth and add a login page"The orchestrator identifies:
Each specialist receives:
The Backend Engineer focuses on:
The Frontend Engineer focuses on:
The Security Engineer reviews:
Work products from specialists are integrated with awareness of each other. The frontend engineer knows what endpoints the backend engineer created. The security engineer's requirements are applied to both.
Cross-functional work is common:
| Request | Flow |
|---|---|
| "Create a pricing page" | Product Manager (positioning) → UI Designer (layout) → Frontend Engineer (implementation) → Growth Marketer (conversion optimization) |
| "We need SOC2 compliance" | Compliance Officer (requirements) → Security Engineer (implementation) → Technical Writer (documentation) |
| "Launch the new feature" | Product Manager (GTM plan) → Marketing (campaign) → Engineering (feature flags) → Support (training) |
User: Build a user settings page where users can update their profile,
change their password, and manage notification preferences.
Orchestrator: This request spans multiple specialties. Routing to:
- UI Designer: Settings page layout and component design
- Frontend Engineer: Implementation and state management
- Backend Engineer: API endpoints for settings CRUD
- Security Engineer: Password change flow review
[UI Designer]
Designing settings page structure:
- Tab-based navigation (Profile | Security | Notifications)
- Form sections with clear hierarchy
- Inline validation feedback
- Responsive layout for mobile
[Frontend Engineer]
Implementing settings components:
- useSettings hook for state management
- Form validation with react-hook-form
- Optimistic updates with rollback
- Tab routing with URL sync
[Backend Engineer]
Creating settings API:
- GET/PATCH /api/settings/profile
- POST /api/settings/password (requires current password)
- GET/PATCH /api/settings/notifications
- Rate limiting on password endpoint
[Security Engineer]
Security review:
✓ Password change requires current password verification
✓ Password strength requirements enforced
✓ Session invalidation option after password change
⚠ Recommend: Add email notification on password change
⚠ Recommend: Add 2FA prompt for security settings
Orchestrator: Implementation complete. Security recommendations
flagged for your review.1. Add the marketplace
In Claude Code, run:
/plugin marketplace add Chipagosfinest/enterprise-team2. Install the plugin
/plugin install enterprise-team@enterprise-pluginsThat's it. The plugin is now available in any project. Then just ask for what you need:
"Design and build a settings page with dark mode"
"Set up CI/CD with GitHub Actions"
"Create a financial model for our Q2 projections"
"Review this code for security vulnerabilities"
"Plan our product launch campaign"The orchestrator routes to the right specialists automatically.
By default, the plugin now activates enterprise-orchestrator as the main agent through settings.json, so you are dropped into the routing layer instead of hoping Claude picks the right specialist on its own.
| Specialist | Expertise |
|---|---|
backend-engineer | APIs, Node.js, Python, PostgreSQL, REST, GraphQL |
frontend-engineer | React, Vue, TypeScript, CSS, accessibility |
fullstack-engineer | End-to-end development across all layers |
mobile-developer | iOS, Android, React Native, Flutter |
embedded-engineer | Firmware, IoT, C/C++, microcontrollers |
blockchain-engineer | Smart contracts, Solidity, Web3, DeFi |
ml-developer | PyTorch, TensorFlow, ML pipelines |
solutions-architect | System design, architecture decisions |
qa-engineer | Testing, test automation, quality assurance |
technical-writer | Documentation, API docs, tutorials |
| Specialist | Expertise |
|---|---|
devops-engineer | Docker, Kubernetes, Terraform, CI/CD |
sre | Monitoring, incidents, SLOs, reliability |
database-engineer | PostgreSQL, Supabase, migrations |
systems-admin | Linux, Windows Server, cloud admin |
| Specialist | Expertise |
|---|---|
product-manager | Roadmaps, prioritization, PRDs |
ux-researcher | User interviews, personas, testing |
ui-designer | Visual design, design systems |
design-strategist | Design systems, experience strategy |
instructional-designer | Learning design, course development |
| Specialist | Expertise |
|---|---|
data-engineer | ETL, pipelines, data warehouses |
data-analyst | SQL, dashboards, business intelligence |
data-scientist | ML models, statistical analysis, experiments |
| Specialist | Expertise |
|---|---|
security-engineer | Secure coding, vulnerability fixes |
security-auditor | Penetration testing, risk assessment |
compliance-officer | SOC2, GDPR, regulatory compliance |
| Specialist | Expertise |
|---|---|
growth-marketer | Acquisition, conversion, paid ads |
content-marketer | Blog posts, SEO content, content strategy |
product-marketer | Positioning, launches, competitive analysis |
brand-marketer | Brand strategy, identity, guidelines |
social-media-manager | Social content, community, engagement |
seo-specialist | Search optimization, keywords, technical SEO |
email-marketer | Email campaigns, automation, newsletters |
pr-specialist | Media relations, press releases |
communications-specialist | Internal/external comms, messaging |
community-manager | Community building, forums, advocacy |
events-manager | Conferences, webinars, trade shows |
video-producer | Video content, production, editing |
graphic-designer | Visual design, collateral, graphics |
web-designer | Website design, landing pages |
| Specialist | Expertise |
|---|---|
account-executive | Sales cycles, negotiations, closing |
sales-engineer | Technical sales, demos, POCs |
business-developer | New markets, lead gen, opportunities |
partnerships-manager | Strategic partnerships, alliances |
customer-success-manager | Onboarding, retention, expansion |
| Specialist | Expertise |
|---|---|
financial-analyst | Modeling, forecasting, unit economics |
accountant | General ledger, reconciliations, close |
controller | Financial reporting, compliance |
corporate-development | M&A, strategic investments |
| Specialist | Expertise |
|---|---|
legal-counsel | Contracts, compliance, IP |
compliance-officer | Regulatory, SOC2, GDPR |
contract-manager | CLM, negotiations, vendor management |
paralegal | Document prep, research, support |
| Specialist | Expertise |
|---|---|
recruiter | Hiring, sourcing, candidate experience |
hr-manager | HR operations, policies, employee relations |
compensation-analyst | Salary, equity, benefits benchmarking |
talent-development | Learning, performance, career growth |
hris-analyst | HR systems, people analytics |
payroll-specialist | Payroll processing, tax compliance |
| Specialist | Expertise |
|---|---|
it-support | Helpdesk, systems, endpoint security |
support-engineer | Technical support, issue diagnosis |
developer-relations | Developer community, SDKs, docs |
technical-trainer | Training programs, workshops |
| Specialist | Expertise |
|---|---|
technical-consultant | Client solutions, implementations |
technical-business-analyst | Requirements, process mapping |
| Specialist | Expertise |
|---|---|
technical-program-manager | Agile, sprint planning, delivery |
| Approach | How It Works | Best For |
|---|---|---|
| Single Agent | One generalist handles everything | Quick tasks, exploration |
| Individual Skills | Manual invocation of focused skills | When you know exactly what you need |
| Swarms/Parallel | Dependency-based parallel execution | Large projects with clear task breakdown |
| Enterprise Team | Automatic routing to domain specialists | Cross-functional work, expert-level output |
Enterprise Team shines when:
The tradeoff: More comprehensive responses, slightly more tokens. If you know exactly what you need and just want a quick answer, a single skill or direct prompt might be faster.
Enterprise Team ships with a formal inter-agent collaboration protocol for multi-agent work. Every orchestrator follows the same rules, so routing, review, and escalation stay auditable.
Agents no longer escalate up an org chart. They route by capability. Each agent declares capabilities in frontmatter using a controlled vocabulary (25 domains + freeform qualifiers):
capabilities:
- auth: [oauth2, pkce, jwt]
- backend: [nodejs, python]
- database: [postgresql, supabase, rls]When a task needs auth work, the orchestrator matches on the auth domain first, then refines by qualifier (oauth2 beats jwt for OAuth tasks). Every routing decision produces an auditable Routing Decision artifact: requested capability, matched agents, selected, rejected, tie-break rule.
Qualifiers are normalized (lowercase, trim, alias-mapped) so postgres, Postgres, postgresql, and pg all match. See capability-aliases.yaml.
Honest note on implementation: capabilities: is NOT a Claude Code runtime config field — the runtime ignores it. It is a protocol convention. The orchestrator reads capability-index.yaml, which is auto-generated from agent frontmatter by scripts/build-capability-index.sh. Regenerate after any frontmatter change; CI should diff-check the generated index to catch drift.
Tie-break rules (deterministic from current task context):
Load-balancing ("fewer current assignments") is intentionally excluded: no durable assignment ledger exists, so any such rule would be non-auditable across sessions.
Every task gets an orchestrator-issued ID (DEPT-NNN, e.g., ENG-042) and a declared file scope at dispatch. Agents must file a scope-expansion record before touching undeclared files. Undeclared changes are rejected — you either expand the scope with justification or revert.
Three tiers of enforcement (use what fits your setup):
| Tier | Mechanism | Binding |
|---|---|---|
| 0 | Protocol convention — Interaction Records, declared scope, risk class | Prompt-level; model behavior, not runtime constraint |
| 1 | Orchestrator verifies at completion — reads git diff, compares against declared scope | Prompt-level with tool-backed verification (Grep, Read, Bash) |
| 2 | Optional PostToolUse hook — hooks/verify-task-scope.sh | Deterministic; shell script rejects work products on scope violation |
The Tier 2 hook requires the orchestrator to declare both ## Expected file scope: [...] and ## Baseline SHA: <sha> in the Task prompt. The hook diffs against that baseline, not the full working tree, so it does not produce false violations from unrelated dirty state. If either declaration is missing, the hook gracefully degrades to Tier 1.
Risk is classified at dispatch by the orchestrator, not self-reported by the agent:
| Risk | Triggers | Reviewer | Evidence Required |
|---|---|---|---|
| Low | docs, configs, typo fixes | none | files changed + brief description |
| Medium | features, refactors, API changes | qa-engineer | files + test output mapped to criteria + before/after |
| High | auth, payments, migrations, security, env vars | reality-checker | files + tests + security implications + rollback plan + reviewer sign-off |
Evidence is conjunctive — all listed items required, not a menu. High-risk work cannot be auto-approved; it blocks to the user if no reviewer is available.
Reclassification: risk is re-evaluated on completion. A task dispatched as LOW that ends up touching auth middleware gets upgraded to HIGH, and the higher evidence requirements apply retroactively.
When a specialist escalates, they classify the failure type:
wrong-capability → reroute to the right capabilitytask-too-large → decompose into subtasksconflicting-requirements → escalate to product-manager for spec clarityenvironment-issue → route to devops-engineer or sreinsufficient-context → route to the knowledge holderunknown → orchestrator investigatesRetry count is a fallback signal. Failure-reason is the primary routing input.
Every consequential exchange produces an Interaction Record (see skills/handoff-protocol/SKILL.md). Same schema regardless of transport:
CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1): delivered via SendMessage between teammatesTask tool prompt to subagentsAgent Teams mode allows peers to message each other directly, but authority stays with the orchestrator: peers may propose, not commit. Consequential agreements must be recorded before any code changes.
Make sure the plugin is reloaded after upgrade:
/reload-pluginsThis version ships a default settings.json that activates enterprise-orchestrator automatically. If you are still seeing generalist behavior, confirm the plugin is enabled and that another plugin is not overriding the active default agent.
This repo also ships enterprise-team/AGENTS.md so the same department-routing model can be reused in Codex-style environments. Claude Code uses the plugin manifest and settings.json; Codex-style agents can read the AGENTS instructions as the equivalent orchestration entrypoint.
If /plugin install enterprise-team@enterprise-plugins returns nothing, a folder or symlink with the same name likely already exists:
# Check for existing installation
ls -la ~/.claude/plugins/enterprise-team
# If it's a symlink (for local development), remove it first
rm ~/.claude/plugins/enterprise-team
# Then retry install
/plugin install enterprise-team@enterprise-pluginsMake sure you've added the marketplace first:
/plugin marketplace add Chipagosfinest/enterprise-teamRestart Claude Code after installation to ensure the plugin is loaded.
Want to add plugins to this marketplace? See CONTRIBUTING.md.
MIT © Alec Gutman
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.