Artifact database access asks permission first, with reads and writes scoped differently.
The consent prompts only appear behind CLAUDE_CODE_ARTIFACT_DB and its remote gate.
tengu_umber_lattice Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.224: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.224. It isn't a statement about your account. What a flag value here can and cannot tell you
What's wrong with this entry?
The new artifact database actions ask before first use, and the prompt spells out how far approval reaches: approving a write covers database writes to any artifact for the rest of the session, approving a read covers that one artifact for the rest of the conversation. Writes persist and are visible to everyone who can open the artifact. The actions are gated behind CLAUDE_CODE_ARTIFACT_DB and the tengu_umber_lattice gate.
- In plan mode the request is always routed to the user rather than the automatic permission classifier.
Claude wants to write to this artifact's database \u2014 writes persist and are visible to everyone who can open the artifact; approving covers database writes to any artifact for the rest of this session.
Strings lifted out of the shipped bundle, so the claim above can be checked against them.