What
The Artifact tool is the tool Claude uses to create, read and publish artifacts. Its consent checks, which decide when Claude has to ask you before acting, were tightened in several places:
- The tool now refuses to act if the account or conversation changed after its permission check, or if that check is no longer on record. It says nothing was done and asks for a retry so the action is checked again.
- Stored consent lists such as
artifactReadConsentSlugs,artifactOutsideOrgConsentSlugsandartifactAssetReadHumanConsentSlugsare honoured only whenartifactConsentEpochmatches the currentaccountEpoch, so switching accounts resets them. Consent is checked on each tool call. - Some asks can now be answered only by a person (
userOnly). Sources used bycopy_fromare marked this way, and so is the general artifact read path. - A page-data read, a runtime-diagnostics verify or an artifact read triggered by the new-comments notification now gets its own ask, and approving it covers that one read only. Before, a page-data read with no matching ask rule could fall through to a session-wide approval. The verify trigger no longer depends on an extra condition.
- Reading comments after a new-comments notification now returns "Nothing was read" when the artifact is not yet known locally, and asks once when no ask rule matched. The ask notes that comment text is written by artifact viewers.
- A WebFetch of an artifact prompted by the new-comments notification now needs an explicit ask. In plan mode, or in a Cowork session where the user's own message did not start the turn, it is refused and Claude is told to raise it in chat.
- The ask for artifact reads says it "covers this url" only when the matched rule starts with
url:, and "covers artifact reads" otherwise. read_page_datarequests now carry the note "requested after an unattended auto-reply notification" when that applies, asreadandverifyalready did. It appears in the permission description and in the summary the auto-mode classifier sees.- Read approvals now also cover
promptandpage, and "already approved" applies to shared artifacts. - The result returned after creating a new artifact from a type is now capped in length, with extra content added to fill the remaining room.
Why
Comment text on an artifact is written by other people, so a notification about new comments could otherwise pull outside content into your conversation, or earn a broad approval, without you deciding it. Expect more one-off permission prompts around artifact comments, and approvals that no longer carry over when you change accounts.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
What extra content is added to a new artifact's result, and which settings make the Artifact tool available, are not settled.