Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One capture · claude-docs

One read of Claude Documentationclaude-docs-20260925T163705Z

2 pages moved out of 243 read.

Pages moved 2 significant first
Pages read 243 in this capture
Captured 16:37 UTC
Corpus hash 9919ff057509 corpus-hash

What this read moved

1-2 of 2

government/config/settings Changed · +8 / -0 lines

### Block reads outside workspace folders

from line 174
174174 
175175If your agency redirects Desktop and Documents to OneDrive or another sync client, consider listing a local folder that is not synced, such as `~/ClaudeWork`, for Code sessions and other work that creates many files or scripts. Keep synced folders for documents and finished work. A member can start a Code session in any folder the list permits, synced or not. One list applies to Cowork and Code sessions alike, so ask members to choose the local folder when they start a Code session. To point at the synced Documents folder on Windows, use `%OneDriveCommercial%` or `%OneDrive%`, for example `%OneDriveCommercial%\Documents\ClaudeOutput`, because `~/Documents` refers to the local Documents folder in the user profile, not the redirected one. What the sync client uploads, including whether it skips particular file types, is controlled by your sync client's policies rather than by Claude for Government.
176176 
177### Block reads outside workspace folders
178 
179Turn this on to stop Claude's file tools in Claude Desktop Code sessions from reading files outside the session's project folder and any folders listed in [**Allowed workspace folders**](#allowed-workspace-folders). The setting is off by default and sets Claude Desktop's [`blockReadsOutsideWorkingDirectories`](/docs/third-party/claude-desktop/configuration#blockreadsoutsideworkingdirectories) key. Its effect on the shell commands Claude runs differs by operating system, and that key's entry describes it.
180 
181<Note>
182 **Block reads outside workspace folders** needs Claude Desktop 1.46388.1 or later. Earlier versions ignore it.
183</Note>
184 
177185## Tool and connector cards
178186 
179187Alongside the settings list, the Config page shows cards for the built-in tools (Web search, Web fetch, and Shell commands), the built-in connector (Microsoft 365), a **Connectors** card for the ones you add yourself, and a **Plugins** card for plugin packages you upload. A connector is an integration that lets Claude reach an external service on a user's behalf.

government/security/security-and-data-handling Changed · +1 / -1 lines

from line 36
3636 
3737Code sessions use Claude Code built into the desktop application and run on the user's workstation itself, not in the virtual machine. The shell commands Claude runs during a Code session execute on the workstation's own operating system under the user's own account.
3838 
39On macOS and Linux, those shell commands run inside an operating-system-level sandbox that the application builds from your organization's **Allowed network hosts** and **Allowed workspace folders** settings on the [Config](/docs/government/config/settings#allowed-network-hosts) page. The sandbox is in place whenever either setting restricts access, which the default configuration does. Inside the sandbox, a command can create or change files only in the session's folder, the other folders **Allowed workspace folders** permits, and temporary locations, but the sandbox does not limit which files the command reads: it can read any file on the device that the user's account can open, and by default it runs without asking the user first. A user can exempt specific commands from this sandbox in a Claude Code settings file, and an exempted command runs outside the sandbox under the permission mode the user selects for the session.
39On macOS and Linux, those shell commands run inside an operating-system-level sandbox that the application builds from your organization's **Allowed network hosts** and **Allowed workspace folders** settings on the [Config](/docs/government/config/settings#allowed-network-hosts) page. The sandbox is in place whenever either setting restricts access, which the default configuration does. Inside the sandbox, a command can create or change files only in the session's folder, the other folders **Allowed workspace folders** permits, and temporary locations. Unless [**Block reads outside workspace folders**](/docs/government/config/settings#block-reads-outside-workspace-folders) is on, it can read any file on the device that the user's account can open. By default it runs without asking the user first. A user can exempt specific commands from this sandbox in a Claude Code settings file, and an exempted command runs outside the sandbox under the permission mode the user selects for the session.
4040 
4141On Linux, the sandbox requires the `bubblewrap` and `socat` packages, so install both on each workstation as described under [Set up Linux and WSL2](https://code.claude.com/docs/en/sandboxing#set-up-linux-and-wsl2) in the Claude Code documentation. If either package is missing, shell commands run outside the sandbox as they do on Windows.
4242 
Feedback