In auto mode, Claude Code runs a classifier: a check that decides whether an action Claude wants to take may go ahead without asking you. One of its rules says that when you have set an explicit limit, such as "don't deploy", an action crossing that limit is blocked.
That rule used to be a single fixed sentence. It now comes in two versions:
- One keeps the original wording.
- The other adds commits in a connected app or account to the list of actions this rule can block, alongside things like credentials and deploys.
The labels the classifier uses to tag a blocked action also gain two new categories. One covers changes to account standing rules. The other covers commits in a connected app that you did not ask for.
Where the second version applies, a limit you set, such as "don't send", now also counts for actions inside connected apps. Before, those actions were not on the list this rule could block.
It is not clear which part of Claude Code uses the version that covers connected apps.