Managed settings are rules an administrator enforces on Claude Code. When one of these values is invalid, Claude Code now replaces it with its most restrictive value and says so: "…treating it as X, its restrictive value, until it is fixed." Before, this only covered certain top-level settings. It now also reaches nested blocks: permissions, autoMode and the sandbox settings.
- If a restriction in a block cannot be read (
permissionsdeny or ask,autoModesoft_deny, hard_deny or deny), the grants in that same block are withheld: allow, additionalDirectories, defaultMode and environment defaultModeis set to "default" rather than removed- A bad entry in a list is dropped on its own, leaving the rest
- A setting set to null is reported as removed
- A block that is not a proper object has its locks set to their most restrictive values
A typo in an administrator's deny list can no longer quietly leave the matching allow rules in effect. A mistake in the policy now makes Claude Code more restricted, not less.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Set `autoMode.classifyAllShell` to `true` to suspend every Bash and PowerShell allow rule while auto mode is active, so the classifier evaluates every shell command regardless of your allow list, except [critical-path removals](/docs/en/pe…auto-mode-config see the edit
The classifier doesn't read `autoMode` from project settings in `.claude/settings.json` or `.claude/settings.local.json`. Both files live in the repo directory, so a checked-in repo or a build step could otherwise inject its own allow rule…auto-mode-config see the edit
Files in this directory are written with owner-only permissions so other OS accounts on the same machine cannot read them. The app encrypts stored sign-in tokens and similar secrets with the operating system's secure storage (see [Credenti…third-party/claude-desktop/data-storage see the edit
On a scheduled task, the approval prompt for an MCP tool that has no [`toolPolicy`](#tool-permissions-for-managed-mcp-servers) entry can offer a standing approval: **Allow for all scheduled runs** in Cowork, **Always allow** in the Code ta…third-party/claude-desktop/configuration see the edit
It is not confirmed that the `sandbox` settings go through this new handling in every case.
Anthropic's documentation has since written up permissions, on Configuration reference.
Fixed managed permissions, autoMode, worktree and attribution settings being ignored entirely when one nested value was invalid; the rest of…