tools-web-restrictions changedmanaged-agents/tools-web-restrictions
Nearest release: v2.1.296, published under an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Recorded here
Lines+17added
Lines−17removed
From line
463
where the diff opens
First seen
6 Oct 2026
this site's first read of the page
Recorded edits3to this page, all time
The whole hunk
from line 463, old and new numbered
/
from line 463
463463
464464## Multiagent and outcome-driven sessions
465465
466In a [multiagent session](https://platform.claude.com/docs/en/managed-agents/multiagent-orchestration), every domain list that applies to a thread is enforced at the same time. An agent in the coordinator's roster is bound by three sets of lists:
466In a [multiagent session](https://platform.claude.com/docs/en/managed-agents/multiagent-orchestration), every domain list that applies to a thread is enforced at the same time. An agent listed in `subagents.predefined_agents` is bound by three sets of lists:
467467
468468* Its own `allowed_domains` and `blocked_domains`
469469* Those of any agent that called it
470* The coordinator's current lists
470* The current lists of the agent that the session runs
471471
472472The settings combine as follows:
473473
474| Setting | How it combines |
475| ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
476| `allowed_domains` | The tool can reach a host only if every list covers it. |
477| `blocked_domains` | The lists add together. |
478| `max_content_tokens`, `user_location` | Not combined. A thread uses the value from its own tool configuration if set. Otherwise it uses the value from the agent that called it, and otherwise the coordinator's current configuration. |
474| Setting | How it combines |
475| ------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
476| `allowed_domains` | The tool can reach a host only if every list covers it. |
477| `blocked_domains` | The lists add together. |
478| `max_content_tokens`, `user_location` | Not combined. A thread uses the value from its own tool configuration if set. Otherwise it uses the value from the agent that called it, and otherwise the current configuration of the session's agent. |
479479
480A roster agent can therefore narrow what a tool reaches but never widen it:
480A listed agent can therefore narrow what a tool reaches but never widen it:
481481
482* A roster agent that sets `blocked_domains` keeps the coordinator's `allowed_domains` and blocks those hosts within it.
483* A roster agent that sets its own `allowed_domains` can reach only the hosts that both its list and the coordinator's list cover.
482* A listed agent that sets `blocked_domains` keeps the `allowed_domains` of the session's agent and blocks those hosts within it.
483* A listed agent that sets its own `allowed_domains` can reach only the hosts that both its list and the list of the session's agent cover.
484484
485A `{"type": "self"}` roster entry has no web settings of its own and follows the coordinator's current settings.
485A `{"type": "self"}` entry in `subagents.predefined_agents` has no web settings of its own and follows the current settings of the session's agent.
486486
487If the combined `allowed_domains` lists have no domain in common, the tool stays available to that agent but every call fails. Each call returns a `url_not_allowed` error stating that no domain is permitted. The tool description tells the model the same. To avoid this, keep each roster agent's `allowed_domains` inside the coordinator's.
487If the combined `allowed_domains` lists have no domain in common, the tool stays available to that agent but every call fails. Each call returns a `url_not_allowed` error stating that no domain is permitted. The tool description tells the model the same. To avoid this, keep each listed agent's `allowed_domains` inside the `allowed_domains` of the session's agent.
488488
489489The grader in [outcome-driven sessions](https://platform.claude.com/docs/en/managed-agents/define-outcomes) runs without `web_search` and `web_fetch`, regardless of these settings.
490490
from line 492
492492
493493You can change the lists on an idle session by [updating its tools](https://platform.claude.com/docs/en/managed-agents/session-operations#updating-the-agent-configuration). The new lists apply to the rest of the session.
494494
495In a multiagent session, every thread applies the new lists from its next turn. The update does not change a roster agent's own lists. Those stay as the agent's definition set them when the session was created.
495In a multiagent session, every thread applies the new lists from its next turn. For an agent listed in `subagents.predefined_agents`, the update does not change the agent's own lists. Those stay as the agent's definition set them when the session was created.
496496
497497## Differences from the Messages API tools
498498
No line in this hunk matches that.