{"version":"2.1.282","anchor":"managed-settings-invalid-lock-values-and-nested-permission","canonical_anchor":"managed-settings-invalid-lock-values-and-nested-permission","heading":"Broken managed settings now fail safe, including permission and sandbox blocks","tier":"notice","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/managed-settings-invalid-lock-values-and-nested-permission","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Broken managed settings now fail safe, including permission and sandbox blocks\n\nAn invalid value in managed settings now becomes its most restrictive value, and a block with an unreadable deny rule loses its allow grants\n\n**Unclear.** It is not confirmed that the `sandbox` settings go through this new handling in every case.\n\n**What**\n\nManaged settings are rules an administrator enforces on Claude Code. When one of these values is invalid, Claude Code now replaces it with its most restrictive value and says so: \"\u2026treating it as X, its restrictive value, until it is fixed.\" Before, this only covered certain top-level settings. It now also reaches nested blocks: `permissions`, `autoMode` and the `sandbox` settings.\n\n- If a restriction in a block cannot be read (`permissions` deny or ask, `autoMode` soft_deny, hard_deny or deny), the grants in that same block are withheld: allow, additionalDirectories, defaultMode and environment\n\n- `defaultMode` is set to \"default\" rather than removed\n\n- A bad entry in a list is dropped on its own, leaving the rest\n\n- A setting set to null is reported as removed\n\n- A block that is not a proper object has its locks set to their most restrictive values\n\n**Why**\n\nA typo in an administrator's deny list can no longer quietly leave the matching allow rules in effect. A mistake in the policy now makes Claude Code more restricted, not less.\n\n- Area: Managed Settings\n- Names: `permissions`, `autoMode`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}