What
Artifacts that keep a shared database are read and changed with the read_db and write_db actions. Two kinds of calls are now handled more strictly:
- A
write_dbedit prompted by the new-comments notification, where the edit reads back rows written by the artifact's viewers, now goes through a check that answers "Nothing was written". The confirmation text names the risk. - Some
read_dbandwrite_dbcalls that used to ask for permission now fail with an explanation instead. This covers reads triggered by a notification, and reads of an artifact you do not own or whose owner could not be confirmed. - That failure happens when nobody is there to answer a permission prompt: a Cowork turn you did not start yourself, or plan mode. The message tells Claude to raise the matter with you in the chat.
- The consent checks were combined into one shared helper.
Why
Comments on an artifact are written by other people, so an edit that acts on what viewers wrote could carry instructions you never gave. Such edits are now blocked. Sessions that run without you watching no longer wait on a prompt nobody can answer, and Claude is told to ask you in the chat instead.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear whether such a write is refused outright or you are asked to approve it.