{"version":"2.1.283","anchor":"switching-to-the-default-model-now-checks-managed-availablem","canonical_anchor":"new-managed-settings-deniedmodels-and-availablemodelsmatc","heading":"New managed settings deniedModels and availableModelsMatch restrict which models people can use","tier":"use","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/switching-to-the-default-model-now-checks-managed-availablem","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### New managed settings `deniedModels` and `availableModelsMatch` restrict which models people can use\n\nAdmins can now deny specific models and match availableModels exactly; the default model, \/model picker and SDK switches all follow the policy\n\n**What**\n\nManaged settings are settings an organization deploys to its users. They gain two keys for restricting models, and both are read from managed settings only:\n\n- `deniedModels` blocks models even when `availableModels` allows them. A family alias blocks the whole family, and a model ID blocks that version in every spelling. Deny matching now also checks the host-managed provider's `modelOverrides` (stored as `deniedModelsOverrides`), including when `availableModels` is set, so provider-specific IDs cannot slip past the list.\n\n- `availableModelsMatch` takes `\"prefix\"` (the default) or `\"exact\"`. With `\"exact\"`, a model ID in `availableModels` no longer allows later versions: `\"claude-opus-5\"` allows Opus 5 and its dated and -fast IDs, but not Opus 5.5. Family aliases still allow the whole family. Aliases whose model depends on the release or settings (`best`, `opusplan`, `default`) are ignored.\n\nThe policy now applies in more places:\n\n- The `\/model` picker filters out denied models.\n\n- Choosing the default model in `\/model`, or switching to \"default\", checks the policy first. If it is blocked, the switch is refused with a message saying it is blocked in `deniedModels`, or that none of the `availableModels` can be the default. The switch is also refused if the managed settings cannot be read, and the SDK model switch returns an error with code `restricted_by_org`.\n\n- When the default model is blocked, Claude Code steps down through the Opus, Sonnet and Haiku families, then tries the first usable `availableModels` entry. If nothing is usable, Claude Code will not start. The startup error reason `managed_settings_invalid` now covers this case too.\n\n- Settings validation shows warnings, for example for an empty `deniedModels` entry, for aliases that `\"exact\"` ignores, or for a family entry that still allows every future release.\n\n**Why**\n\nAdmins can forbid specific models and pin allowlists to exact versions. Before, choosing \"default\" could get around these restrictions. A policy that leaves no allowed model stops Claude Code from starting, so check it before rolling it out. Hosts and IDEs get a clear reason when that happens.\n\n- Area: Managed Settings\n- Names: `availableModels`, `deniedModels`, `\/model`\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 2\/5"}