Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.282 ·

Broken managed settings now fail safe, including permission and sandbox blocks

An invalid value in managed settings now becomes its most restrictive value, and a block with an unreadable deny rule loses its allow grants

You'll notice Improvements
JSON All of v2.1.282
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.282,
ImprovementsSection of the release
What

Managed settings are rules an administrator enforces on Claude Code. When one of these values is invalid, Claude Code now replaces it with its most restrictive value and says so: "…treating it as X, its restrictive value, until it is fixed." Before, this only covered certain top-level settings. It now also reaches nested blocks: permissions, autoMode and the sandbox settings.

  • If a restriction in a block cannot be read (permissions deny or ask, autoMode soft_deny, hard_deny or deny), the grants in that same block are withheld: allow, additionalDirectories, defaultMode and environment
  • defaultMode is set to "default" rather than removed
  • A bad entry in a list is dropped on its own, leaving the rest
  • A setting set to null is reported as removed
  • A block that is not a proper object has its locks set to their most restrictive values
Why

A typo in an administrator's deny list can no longer quietly leave the matching allow rules in effect. A mistake in the policy now makes Claude Code more restricted, not less.

Read from
Names in the bundlepermissionsautoMode
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Added since A small documentation edit on Configure auto mode touched a line naming autoMode after this was published. Set `autoMode.classifyAllShell` to `true` to suspend every Bash and PowerShell allow rule while auto mode is active, so the classifier evaluates every shell command regardless of your allow list, except [critical-path removals](/docs/en/pe… auto-mode-config see the edit
Confirmed since Anthropic's documentation has since written up autoMode, on Configure auto mode. The classifier doesn't read `autoMode` from project settings in `.claude/settings.json` or `.claude/settings.local.json`. Both files live in the repo directory, so a checked-in repo or a build step could otherwise inject its own allow rule… auto-mode-config see the edit
Added since A small documentation edit on User identity and local data touched a line naming permissions after this was published. Files in this directory are written with owner-only permissions so other OS accounts on the same machine cannot read them. The app encrypts stored sign-in tokens and similar secrets with the operating system's secure storage (see [Credenti… third-party/claude-desktop/data-storage see the edit
Confirmed since Anthropic's documentation has since written up permissions, on Configuration reference. On a scheduled task, the approval prompt for an MCP tool that has no [`toolPolicy`](#tool-permissions-for-managed-mcp-servers) entry can offer a standing approval: **Allow for all scheduled runs** in Cowork, **Always allow** in the Code ta… third-party/claude-desktop/configuration see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not confirmed that the `sandbox` settings go through this new handling in every case.
Anthropic's documentation agreesAnthropic's documentation has since written up permissions, on Configuration reference.
Anthropic's release notes agreeFixed managed permissions, autoMode, worktree and attribution settings being ignored entirely when one nested value was invalid; the rest of…

See this entry in the whole of v2.1.282 →

Feedback