What
The sandbox limits which files commands run by Claude can read and write. Project and local settings files, which can be committed to a repository, can add grants to that list. Before, their allowWrite and allowRead entries were always merged in. Now they are checked first:
- Under an admin sandbox mandate (managed settings require the sandbox),
sandbox.filesystem.allowWrite, Edit allow-rule paths andallowReadpaths from project and local settings are dropped. A one-time log line says "[sandbox] filesystem grants restricted to trusted settings tiers: ignoring". - The same grants are also dropped when the path is under or inside a path you denied reading.
- With
blockReadsOutsideWorkingDirectorieson, repo-committedallowReadandallowWritegrants are withheld if they are globs (wildcard patterns), UNC paths (Windows network-share paths), automount paths, or lead through symlinks (shortcuts to other locations) into denied read paths. The log line starts "[sandbox] withheld".
Why
A repository's settings can no longer quietly widen what sandboxed commands may touch. If you relied on project or local settings to grant sandbox access, check the log for these lines when a command is refused.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Exactly when an administrator's sandbox requirement counts as active is not stated.