Per-app tools each require a permission tier, so a low grant lets Claude look but not act.
Tier mapping for per-app tools exists inside the host-gated computer-use feature.
What's wrong with this entry?
The existing read, click and full permission tiers are mapped onto the individual per-app tools, so a low-tier grant permits looking but not acting. Calls below the required tier come back as tier_insufficient with guidance to request a higher tier.
- Read tier: app_list_windows, app_screenshot, app_ax_find, app_batch, app_bring_to_current_space.
- Click tier: app_click, app_scroll.
- Full tier: app_drag, app_type, app_key, app_menu.
- app_menu additionally refuses Services submenu items and Apple-menu system actions; app_key refuses key combinations that would touch the system clipboard.
tier_insufficient
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.248
Computer-use app blocklists extended on Windows
Both mention computer