You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.282,
ImprovementsSection of the release
What
In managed policy, permissions.deny and permissions.ask are lists of rules for tool use Claude must refuse or ask about. When such a list has rules in it but every one of them is invalid, Claude Code now marks the list as "unreadable" instead of quietly treating it as empty. A list where only some rules were invalid is marked "trimmed". Both produce a warning. Before, invalid rules were simply skipped, each with its own warning.
Why
A deny list that is broken throughout no longer silently turns into "nothing is denied" for an organization's policy.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed sinceAnthropic's documentation has since written up permissions.deny, on Set up Claude Code for your organization.| [Permission rules](/docs/en/permissions) | Allow, ask, or deny specific tools and commands | `permissions.allow`, `permissions.deny` |admin-setupsee the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat Claude Code does with a list marked unreadable, beyond warning about it, is not settled.
Anthropic's documentation agreesAnthropic's documentation has since written up permissions.deny, on Set up Claude Code for your organization.