{"version":"2.1.283","anchor":"managed-policies-deniedmodels-from-the-catch-all-policy-is","canonical_anchor":"managed-policies-deniedmodels-from-the-catch-all-policy-is","heading":"Models denied in the catch-all managed policy now apply to every policy","tier":"use","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/managed-policies-deniedmodels-from-the-catch-all-policy-is","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Models denied in the catch-all managed policy now apply to every policy\n\n`deniedModels` in the catch-all `managed.policies` entry is now combined with each specific policy's list instead of being replaced by it\n\n**Unclear.** Which program or command runs this policy merge is not confirmed.\n\n**What**\n\nIn `managed.policies`, an entry with `match: {}` is the catch-all base that other entries are merged with. `deniedModels`, the list of models that are not allowed, is now combined when that merge happens: the base list and an entry's own list are joined and duplicates removed. Before, an entry that set its own `deniedModels` replaced the base list entirely.\n\nThis is how `disabledMcpjsonServers`, `deniedMcpServers` and `blockedMarketplaces` were already merged.\n\n**Why**\n\nAn admin who denies a model in the catch-all policy can no longer have that silently undone by a more specific policy that sets its own `deniedModels`.\n\n- Area: Managed Settings\n- Names: `managed.policies`, `deniedModels`\n- Tier: Use it now\n- Useful: 3\/5\n- Signal: 1\/5"}