You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What
The sandbox limits which files commands run by Claude can read and write. Project and local settings files, which can be committed to a repository, can add grants to that list. Before, their allowWrite and allowRead entries were always merged in. Now they are checked first:
Under an admin sandbox mandate (managed settings require the sandbox), sandbox.filesystem.allowWrite, Edit allow-rule paths and allowRead paths from project and local settings are dropped. A one-time log line says "[sandbox] filesystem grants restricted to trusted settings tiers: ignoring".
The same grants are also dropped when the path is under or inside a path you denied reading.
With blockReadsOutsideWorkingDirectories on, repo-committed allowRead and allowWrite grants are withheld if they are globs (wildcard patterns), UNC paths (Windows network-share paths), automount paths, or lead through symlinks (shortcuts to other locations) into denied read paths. The log line starts "[sandbox] withheld".
Why
A repository's settings can no longer quietly widen what sandboxed commands may touch. If you relied on project or local settings to grant sandbox access, check the log for these lines when a command is refused.