What probably matters to youSection of the release
What
The managed-settings option allowManagedHooksOnly ("Run only the hooks your organization deploys") now covers plugin hooks too. When turned on, only hooks defined directly in managed settings, or hooks belonging to plugins that managed settings explicitly enable, are allowed to run. Hooks from plugins a user installed on their own are excluded, while Claude Code's own built-in features are exempt from this restriction.
Why
This lets organizations lock down which hooks can execute more completely, closing a gap where a user-installed plugin's hooks could previously run even with allowManagedHooksOnly enabled.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Added sinceA small documentation edit on Customize your status line touched a line naming allowManagedHooksOnly after this was published.The same trust, `disableAllHooks`, and [`allowManagedHooksOnly`](/docs/en/settings-reference#allowmanagedhooksonly) gates that apply to `statusLine` apply here. Plugins can ship a default `subagentStatusLine` in their [`settings.json`](/do…statuslinesee the edit
Confirmed sinceAnthropic's documentation has since written up allowManagedHooksOnly, on Set up Claude Code for your organization.| [Hook restrictions](/docs/en/settings-reference#allowmanagedhooksonly) | Restrict which hooks run and restrict HTTP hook URLs; see [what runs under `allowManagedHooksOnly`](/docs/en/settings-reference#what-runs-under-allowmanagedhooksonl…admin-setupsee the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up allowManagedHooksOnly, on Set up Claude Code for your organization.