Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.283 ·

New managed settings deniedModels and availableModelsMatch restrict which models people can use

Admins can now deny specific models and match availableModels exactly; the default model, /model picker and SDK switches all follow the policy

Group of 5 Use it now Notable New Features
JSON All of v2.1.283
Use it nowTier: how much it should matter to you
5Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
New FeaturesKind: in v2.1.283,
What probably matters to youSection of the release

What

Managed settings are settings an organization deploys to its users. They gain two keys for restricting models, and both are read from managed settings only:

  • deniedModels blocks models even when availableModels allows them. A family alias blocks the whole family, and a model ID blocks that version in every spelling. Deny matching now also checks the host-managed provider's modelOverrides (stored as deniedModelsOverrides), including when availableModels is set, so provider-specific IDs cannot slip past the list.
  • availableModelsMatch takes "prefix" (the default) or "exact". With "exact", a model ID in availableModels no longer allows later versions: "claude-opus-5" allows Opus 5 and its dated and -fast IDs, but not Opus 5.5. Family aliases still allow the whole family. Aliases whose model depends on the release or settings (best, opusplan, default) are ignored.

The policy now applies in more places:

  • The /model picker filters out denied models.
  • Choosing the default model in /model, or switching to "default", checks the policy first. If it is blocked, the switch is refused with a message saying it is blocked in deniedModels, or that none of the availableModels can be the default. The switch is also refused if the managed settings cannot be read, and the SDK model switch returns an error with code restricted_by_org.
  • When the default model is blocked, Claude Code steps down through the Opus, Sonnet and Haiku families, then tries the first usable availableModels entry. If nothing is usable, Claude Code will not start. The startup error reason managed_settings_invalid now covers this case too.
  • Settings validation shows warnings, for example for an empty deniedModels entry, for aliases that "exact" ignores, or for a family entry that still allows every future release.

Why

Admins can forbid specific models and pin allowlists to exact versions. Before, choosing "default" could get around these restrictions. A policy that leaves no allowed model stops Claude Code from starting, so check it before rolling it out. Hosts and IDEs get a clear reason when that happens.

Read from
Names in the bundledeniedModels
How sure we are
Two sources agreeTwo things we can check say the same as this entry.
Anthropic's release notes agreeAdded availableModelsMatch managed setting: with "exact", an availableModels entry allows only the model version it names, so new releases…
The name it cites is new in this buildNew in this build: deniedModels

See this entry in the whole of v2.1.283 →

Feedback