The whole hunk
from line 130, old and new numbered
/
lines
from line 130
130130
131131The **Web search** card controls whether Claude can search the web in Claude Desktop. It is off by default. When you turn it on you are shown a short description of how search works and asked to acknowledge it before the setting is saved. A **Require approval for each search** sub-setting sits below the toggle and becomes available once web search is on; it is on by default, and turning it off lets each member choose whether to approve every search or allow searches to run automatically.
132132
133Once you turn web search on, each member's Claude Desktop picks it up the next time the app starts and shows it in the message box's **+** menu, under **Connectors**, as a **Web Search** switch that the member can turn off for themselves. If one member has no **Web Search** switch after restarting Claude Desktop while others do, select [**Compare config across levels**](/docs/government/config/overview#comparing-settings-across-levels) at the top of the Config page and type the member's name into the search box to check whether another level, such as a [directory group](/docs/government/config/overview#group-specific-settings), turns web search off for them. If every level shows web search on, check whether that member's network is blocking it, as described in the troubleshooting table in [Connect Claude Desktop to Claude for Government](/docs/government/deploy-desktop/configure#troubleshooting).
134
133135The **Web fetch** card controls whether Claude can fetch web pages in Claude Desktop. It is on by default, and fetches are subject to the Allowed network hosts list above. A **Require approval for each fetch** sub-setting sits below the toggle. Turning it on asks the member to approve every page fetch before it runs; when it is off (the default), each member chooses whether to approve fetches or allow them automatically.
134136
135137The **Shell commands** card controls whether Claude can run shell commands during tasks in Claude Desktop. It is on by default, and turning it off also turns off Advanced file analysis in Chat. A **Require approval for each command** sub-setting sits below the toggle. Turning it on asks the member to approve every shell command before it runs; when it is off (the default), each member chooses whether to approve commands or allow them automatically. Chat always asks before each command regardless of this setting.