Manage mods for your organization changedplugins/mods/admin
Nearest release: v2.1.287, published 5 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 1 Oct 2026 22:58 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 1 Oct 2026 23:07 UTC.
Upstream edited
Recorded here
Lines+47added
Lines−0removed
From line
151
where the diff opens
First seen
1 Oct 2026
this site's first read of the page
Recorded edits3to this page, all time
### Allow only your organization's mods ### Apply your plugin controls to mods
The whole hunk
from line 151, old and new numbered
/
from line 151
151151
152152A user whose mod didn't load finds the reason in their debug log. [Refusal messages](/docs/en/plugins/mods/troubleshoot#refusal-messages) lists the lines for `allowManagedHooksOnly` and `disableAllHooks`, and [Messages from the built-in guard](/docs/en/plugins/mods/troubleshoot#messages-from-the-built-in-guard) has the line for `allowManagedModsOnly`.
153153
154### Allow only your organization's mods
155
156To run your organization's mods and block the ones users bring, deploy the settings from the **Only your organization's mods** row of the [policy table](#choose-how-much-to-allow), plus `disableSideloadFlags`. With this complete `managed-settings.json`, Claude Code refuses users' own mods, so none of their hooks run, and your policy mod runs ahead of other mods:
157
158```json managed-settings.json theme={null}
159{
160 "extraKnownMarketplaces": {
161 "acme-tools": {
162 "source": { "source": "directory", "path": "/opt/acme/claude-plugins" }
163 }
164 },
165 "enabledPlugins": { "acme-guard@acme-tools": true },
166 "prependPlugins": ["acme-guard@acme-tools", "sec-default@builtin"],
167 "pluginConfigs": {
168 "cc-plugin-sec-default@builtin": {
169 "options": { "allowManagedModsOnly": true }
170 }
171 },
172 "disableSideloadFlags": true
173}
174```
175
176Each group of keys does one job:
177
178* **`extraKnownMarketplaces`, `enabledPlugins`, and `prependPlugins`**: install your mod so that it counts as yours, and run it first with the guard after it. [Install your organization's mods and set the order](#install-your-organizations-mods) covers the directory these keys point at.
179* **`pluginConfigs`**: sets the guard's `allowManagedModsOnly` option, so Claude Code refuses users' own mods. Their settings hooks, status lines, and `/goal` keep working.
180* **`disableSideloadFlags`**: see [`disableSideloadFlags`](/docs/en/settings-reference#disablesideloadflags) for the flags it rejects at startup
181
182To confirm the policy on a test machine, in your shell start a session with `claude --debug` and read the debug log:
183
184* **Your mod**: its `hooks module` line has `tier prepend`
185* **A mod the user installed**: a line reads `refused by cc-plugin-sec-default: mods are limited to your organization's by policy (allowManagedModsOnly)`. An earlier line says that mod's hooks module `loaded`, so look for the refusal.
186* **A plugin directory**: `claude --plugin-dir ./any-mod` exits with a message that starts `--plugin-dir is disabled by your organization's managed settings (disableSideloadFlags)`
187
188To also limit which marketplaces users can add, combine this file with your [marketplace restrictions](/docs/en/plugins/org#restrict-what-users-can-install).
189
190### Apply your plugin controls to mods
191
192A mod is a plugin, so the ways you [manage plugins for your organization](/docs/en/plugins/org) also apply to a plugin that holds a mod:
193
194* **See which plugins load across your fleet**: [Audit and review](/docs/en/plugins/org#audit-and-review)
195* **Decide when a plugin you reviewed can update**: [Set update policy](/docs/en/plugins/org#set-update-policy)
196* **Give one group a different policy, such as a pilot**: [Plan for what managed settings can't enforce](/docs/en/plugins/org#plan-for-what-managed-settings-can’t-enforce)
197* **Check which apps and session kinds apply the plugin keys**: [When each surface applies the plugin keys](/docs/en/plugins/org#when-each-surface-applies-the-plugin-keys)
198* **Set up CI and containers**: [Seed containers and CI](/docs/en/plugins/org#seed-containers-and-ci)
199* **Offer mods your users may install**: [Host a marketplace](/docs/en/plugins/host-marketplace). A mod that Claude Code copies from a GitHub, git, URL, or npm source counts as a user's, not as [your organization's](#install-your-organizations-mods).
200
154201### Set options on the built-in guard
155202
156203The built-in guard takes two options. Set them in managed settings under `pluginConfigs`, keyed by `cc-plugin-sec-default@builtin`, as the example in [Stop user-installed mods from loading](#stop-user-installed-mods-from-loading) does.
No line in this hunk matches that.