What
When the managed policy setting allowManagedPermissionRulesOnly is on, the allowed-tools list in skill and command frontmatter (the header at the top of a skill file) no longer grants tool permissions unless it comes from a trusted source. Until now the setting covered permission rules from settings files and --allowedTools.
- Ignored:
allowed-toolsfrom skills and custom commands in user, project and--add-dirsources, and from plugins adopted from a.claude-pluginmanifest inside those skills directories. - Kept, per the setting's description: other plugins, managed skills and bundled skills. Plugins from the official skills marketplace are exempt.
- Skills and plugin commands now look up their
allowed-toolseach time they run. When a grant is dropped, a warning is logged, and in text print mode a line on standard error tells you to ask an admin. - A plugin command whose frontmatter declares
PreToolUseorPermissionRequesthooks gets noallowed-toolsat all when policy setsdisableAllHooksorallowManagedHooksOnly. - The coordinator no longer tells its workers that a skill grants extra tool permissions when the skill's source or plugin is not trusted under this policy.
- The setting's description now says all of this.
Why
A skill or plugin placed by a user or a repository could previously hand itself tool permissions that the policy meant to keep in the administrator's hands. If you rely on a skill's allowed-tools under this policy, expect permission prompts for those tools, or ask your administrator to add managed rules.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
| [Permission lockdown](/docs/en/permissions#managed-only-settings) | Make managed settings the [only settings source of permission rules](/docs/en/settings-reference#allowmanagedpermissionrulesonly). Disable `--dangerously-skip-permission…admin-setup see the edit
Only the setting's description is known to have changed, so it is not settled whether the enforcement itself is new in this release.
Anthropic's documentation has since written up allowManagedPermissionRulesOnly, on Set up Claude Code for your organization.
Fixed Bash permission rules with a mid-pattern :* being skipped in settings files while --allowedTools honored them; they now work from…