What
Claude Code checks your organisation's restrictions before allowing some features. Sometimes the check cannot finish, for example when the restrictions cannot be fetched, and Claude Code falls back to a default ("fails open").
- Policy entries can now carry
onFailOpenVerdict: "deny", meaning deny the feature in that situation. - "The plugin directory" and "Connector suggestions" now carry it. Both are denied under HIPAA. Before, they had only
onCacheMiss: "deny". - Every entry marked this way is collected into a set that is denied when the check fails open, alongside the set that was already handled this way.
- For these features, the denial now gives the reason as a missing route or a cache miss.
Why
In an organisation under HIPAA restrictions, the plugin directory and connector suggestions stay off when the policy check fails, rather than possibly being allowed. More features may be unavailable while the org restrictions cannot be fetched.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Which features are marked to be denied, and the exact condition that triggers the refusal, are not known.