Permission prompts marked person-only can now only be answered by a human
Permission asks marked personOnly now skip the classifier, hooks, the coordinator check and prompt-tool hook races, and guard against accidental keypresses
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.283,
ImprovementsSection of the release
Unclear It is not fully clear which prompts are marked person-only, though some safety checks that the automatic check may not approve appear to be among them.
What
A permission ask is the prompt Claude Code shows before Claude does something that needs your approval. Some asks are now marked person-only (personOnly), meaning a person must answer them. One example is Claude reading someone else's artifact that was created outside your organization. For these asks:
The automatic resolver, the classifier that can approve actions on its own in auto mode, is no longer consulted.
Permission-request hooks (commands you configure to run automatically on certain events) are no longer run to answer the ask.
The coordinator's automated permission check is skipped. The ask carries askIsPersonOnly so that check can return early.
With --permission-prompt-tool, which hands permission prompts to an MCP tool in non-interactive mode, the hooks that normally race that tool are skipped, as they already were for remote execution. The ask must be answered by the prompt tool.
The internal confirmWithUser helper, built on AskUserQuestion, takes a new personOnly option. It sets classifierApprovable to false, so the classifier cannot answer the question.
The dialog opens with placement "under" and an input grace period, so keys you were typing just before it appeared do not answer it by accident.
Why
Before, a hook, the classifier or the coordinator could settle a prompt that was meant for a person. Person-only prompts now always wait for a human, and are harder to approve by accident while typing.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not fully clear which prompts are marked person-only, though some safety checks that the automatic check may not approve appear to be…