What
A permission mode decides how much Claude does without asking you first, and auto mode lets it go ahead on more actions. When a session starts, Claude Code picks a starting mode. Before, it only re-checked that choice when its cache of server settings was empty. It now also waits on your organization's policy verdict, the policy decision for your account:
- Startup now records whether it is waiting on server settings, on a pending policy verdict, or both. It picks the mode again once the verdict arrives. The log line now says "startup resolved ... against a pending policy verdict" as well as the empty-cache case.
- The result gains
autoDefaultWithheldForPendingVerdict, which holds back auto mode as the default while the verdict is pending. - The result also gains
autoStartWithheldForHipaaTaint, which holds back starting in auto mode when the session is marked as affected by HIPAA, the US health-data privacy rules. Both flags are false in the default case. - A new message reads "Not shown under your organization's policy: measured by scanning the session transcripts saved on this machine."
- Remote sessions, those with
CLAUDE_CODE_REMOTEset, are now skipped when deciding whether to default to auto mode. - For non-interactive sessions, those run without you at the keyboard, the built-in fallback of
tengu_moss_anchoris now also on. This fallback is only used when the server sends no value.
Why
This stops auto mode being chosen before your organization's policy is known. Organizations with HIPAA restrictions may find auto mode held back at startup. Scripted or non-interactive runs may now start in auto mode when the server sends no setting.
It is not clear what marks a session as flagged under the HIPAA policy, or whether this behaviour is switched on remotely.