Follow Discord
Sweep 01 Oct 2026 · 17:27Z Build v2.1.287 508 read Stable v2.1.285 Latest v2.1.287 Next v2.1.287 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.286 ·

More policy features are denied when the org policy check fails open

The plugin directory and connector suggestions are now denied for HIPAA orgs when the org policy check can't complete

Group of 2 You'll notice Improvements
JSON All of v2.1.286
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.286,
ImprovementsSection of the release

What

Claude Code checks your organisation's restrictions before allowing some features. Sometimes the check cannot finish, for example when the restrictions cannot be fetched, and Claude Code falls back to a default ("fails open").

  • Policy entries can now carry onFailOpenVerdict: "deny", meaning deny the feature in that situation.
  • "The plugin directory" and "Connector suggestions" now carry it. Both are denied under HIPAA. Before, they had only onCacheMiss: "deny".
  • Every entry marked this way is collected into a set that is denied when the check fails open, alongside the set that was already handled this way.
  • For these features, the denial now gives the reason as a missing route or a cache miss.

Why

In an organisation under HIPAA restrictions, the plugin directory and connector suggestions stay off when the policy check fails, rather than possibly being allowed. More features may be unavailable while the org restrictions cannot be fetched.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhich features are marked to be denied, and the exact condition that triggers the refusal, are not known.

See this entry in the whole of v2.1.286 →

Feedback