What
Managed settings are settings an organisation's administrator enforces on Claude Code. When a managed value is invalid, Claude Code can fail closed: it swaps in the most restrictive value instead of ignoring the setting. This release tracks those substitutions more closely:
- Settings warnings now carry
substitutedandonlySubstitutesflags that mark values replaced this way. - A managed settings source whose only content is such substituted values is no longer marked as authored policy. It gets a status-only message saying the source "holds nothing that could be applied as written and is this source's only policy content", and that its fail-closed reading binds until the source is fixed.
- When remote managed settings are salvaged after validation errors, the raw value from the payload is now kept for
cleanupPeriodDaysanddesktopSessionCleanupPeriodDays, and for any setting whose errors are all markedonlySubstitutes. Before, only those two cleanup keys were restored.
Why
Administrators get a clearer signal when a broken managed-settings file is being enforced only through restrictive fallbacks. Some settings pushed by an organisation may also now apply where they were previously dropped as invalid.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is unclear what else in Claude Code depends on whether a source is marked as written policy.