{"version":"2.1.280","anchor":"serverpopulated-compliance-restrictions-killable-by-remote","canonical_anchor":"serverpopulated-compliance-restrictions-killable-by-remote","heading":"serverPopulated marker extended to more compliance restrictions, including Artifacts","tier":"internal","area":"Compliance","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/serverpopulated-compliance-restrictions-killable-by-remote","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### serverPopulated marker extended to more compliance restrictions, including Artifacts\n\nMore compliance-policy restriction entries, including the Artifacts permission, can now be marked server-populated and killed remotely\n\n**What**\n\n- Several HIPAA-restriction entries (for example `allow_account_plugins_sync`) gained a `serverPopulated: true` marker. A helper treats a restriction as server-populated only when that marker is set and a remote kill-flag is not served true, which changes how compliance taints are merged when deciding whether an action is allowed.\n\n- The `allow_cobalt_plinth` policy entry (labeled \"Artifacts\", denied under hipaa\/zdr) also gained `serverPopulated: true`, matching the pattern already used by `allow_remote_control` (\"Remote Control\").\n\n**Why** Marking these restrictions as server-populated lets them be controlled and killed remotely rather than being fixed at build time, giving more flexibility in how compliance policies are enforced for features like Artifacts.\n\n- Area: Compliance\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 2\/5"}