{"version":"2.1.285","anchor":"org-policy-denial-helper-checks-remote-control-taints","canonical_anchor":"org-policy-denial-helper-checks-remote-control-taints","heading":"New check for when organization policy blocks remote control","tier":"internal","area":"Remote Control","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/org-policy-denial-helper-checks-remote-control-taints","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### New check for when organization policy blocks remote control\n\nClaude Code now treats remote control as blocked by organization policy only when the denial is final and the policy disallows it with markers present\n\n**Unclear.** What uses this check, what the markers are, and whether an oddly valued remote default nearby is related is not clear.\n\n**What**\n\nClaude Code now has a check that decides whether your organization's policy blocks remote control. It answers yes only when all of these hold:\n\n- the policy's verdict is \"denied\"\n\n- the denial is authoritative, meaning final\n\n- the `allow_remote_control` policy does not allow remote control while the session carries certain markers, which the code calls taints\n\n**Why**\n\nThis narrows when remote control counts as blocked by policy. It ties the block to these markers rather than to a denial alone.\n\n- Flag `tengu_org_policy_denied`: Not enough to say (read for one account on one subscription tier against v2.1.285; this account: no value returned, anonymous baseline: no value returned, compiled default: not a boolean we can read) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Remote Control\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5"}