06-reference

every headway eddy claude code sdk

2026-08-21·reference·source: Every·by Katie Parrott
claude-code-sdkbuild-vs-buyhealthcare-aiagent-architecturemcp

Why this is in the vault

Concrete case study of a regulated-industry company (mental healthcare, 900 people) building an internal AI agent on the Claude Code SDK after concluding vendor products couldn't meet its security/compliance bar — directly parallel to RDCO's own agent-infra build-vs-buy posture.

The core argument

Headway, a mental healthcare company, was about to sign a deal with a major AI vendor for a desktop-app rollout when it concluded that relying on that vendor to hit its compliance and workflow requirements for handling protected health information "felt like we were missing the train" (CTO Arnaud Ferreri). Instead, in roughly the last two months, a small team built "Eddy" — an internal AI assistant on Anthropic's Claude Code SDK, hosted in Headway's own AWS environment, connected via MCP to Snowflake, Google Workspace, GitHub, Glean, Jira, Sentry, and Datadog. The security model is the load-bearing detail: every conversation runs inside a sealed, disposable container with narrowly scoped connections to company systems, and a built-in PHI classifier blocks conversations containing protected health information from being shared with unauthorized users. That containment is what let Headway grant the agent unusual autonomy — acting without asking permission at each step — despite being in a heavily regulated industry. Per reporting cross-referenced from Headway's own engineering blog, the tool compounded fast: Ferreri reports merging roughly 60 pull requests in a recent month, most authored by Eddy itself, and Eddy was substantially used to build its own later versions.

Note on sourcing: the Every.to email hit a metered paywall after the second paragraph. The core-argument summary above is reconstructed from Headway's own engineering blog and Medium post (both by Ferreri) via web search, since WebFetch on both direct URLs returned 403. Treat the PR-count and MCP-integration-list details as attributed to Headway's blog, not verified against Every's full published text.

Mapping against Ray Data Co

Direct architectural parallel to RDCO's own agent stack: Eddy's pattern — Claude Code SDK core, MCP connections scoped per-tool, sealed/disposable execution context, autonomy earned through containment rather than permission-gating — is structurally the same shape as RDCO's brigade-station and skill-dispatch model (station-spec-author → station-test-author → station-code-author → station-critic), where scope containment (fresh-eyes subagents, no shared context) substitutes for step-by-step approval. It's also a live enterprise proof point for the phData cert push: a 900-person regulated company standardizing internal tooling on the Claude Code SDK is exactly the kind of deployment the Anthropic Claude Certified Architect credential is meant to validate fluency in, and useful concrete evidence if the "build vs. buy for AI agents in regulated industries" angle ever becomes a Sanity Check topic (needs an original re-frame per the no-derivative-pieces rule, not a rehash of this piece).

Related

⚠️ Sponsorship

Every.to discloses in-article: "Headway is an Every Consulting client; we delivered its leadership team a paid executive AI workshop. Headway was given an opportunity to fact-check details but had no editorial control over this article." This is a paid consulting relationship between the publisher (Every) and the article's subject (Headway) — not a traditional newsletter-ad sponsor, but a real bias vector: Every has a commercial incentive to portray a paying client's build favorably, and the subject reviewed the piece pre-publication for factual accuracy (though nominally without editorial control). Read the favorable framing with that in mind.