The whole hunk
from line 597, old and new numbered
/
lines
from line 597
597597* `env` variables that require the developer's approval, such as proxy and base-URL variables
598598* shell-execution settings such as `apiKeyHelper` and `statusLine`
599599* the sandbox binary settings `sandbox.bwrapPath`, `sandbox.socatPath`, and `sandbox.ripgrep`
600* Sandbox settings that intercept traffic, inject credentials, or weaken isolation, such as `sandbox.network.tlsTerminate` and the proxy port settings. [Security approval dialogs](/docs/en/server-managed-settings#security-approval-dialogs) lists them all.
600601* managed CLAUDE.md content
601602
602603[Approval memory](/docs/en/server-managed-settings#approval-memory) covers how long an approval lasts and when the dialog appears again.