Sometimes nobody is available to answer a permission prompt, for example when Claude Code runs unattended. A permission prompt is the question Claude Code asks before doing something that needs your approval.
In that situation, Claude Code refuses the first read of an artifact. It now also refuses when one of your "ask" permission rules matches. The refusal message now separates two cases: an artifact whose ownership couldn't be confirmed, and an artifact that belongs to someone else. Before this change, the message always said it was someone else's artifact.
Reading an artifact through the WebFetch tool while network access is off also gains a way to ask for permission through a hook. A hook is a command you configure to run at certain points.
In sessions that run without anyone watching, the refusal message now says more precisely why the read was blocked.
It is unclear exactly what condition triggers the new refusal and how the hook-based ask for WebFetch is decided.