You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
Bug FixesKind: in v2.1.281,
Bug FixesSection of the release
What
The sandbox is a restricted environment that limits what commands can reach. Entries in permissions.allow (actions you have approved to run without asking) are converted into sandbox rules. If an entry cannot be worked out during that conversion, Claude Code now reports a configuration error that names the entry. Before, the failure was not handled.
Why
A bad entry is now refused instead of being trusted. The error tells you which entry to fix.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed sinceAnthropic's documentation has since written up permissions.allow, on Set up Claude Code for your organization.| [Permission rules](/docs/en/permissions) | Allow, ask, or deny specific tools and commands | `permissions.allow`, `permissions.deny` |admin-setupsee the edit
How sure we are
Two sources agreeTwo things we can check say the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up permissions.allow, on Set up Claude Code for your organization.
Anthropic's release notes agreeImproved screen-reader output in /mcp: a disabled server is read as "off" instead of "pending"