{"version":"2.1.286","anchor":"fail-open-deny-set-for-policyrestriction-keys-refactored","canonical_anchor":"fail-open-deny-set-for-policyrestriction-keys-refactored","heading":"More policy features are denied when the org policy check fails open","tier":"notice","area":"Managed Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/fail-open-deny-set-for-policyrestriction-keys-refactored","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### More policy features are denied when the org policy check fails open\n\nThe plugin directory and connector suggestions are now denied for HIPAA orgs when the org policy check can't complete\n\n**Unclear.** Which features are marked to be denied, and the exact condition that triggers the refusal, are not known.\n\n**What**\n\nClaude Code checks your organisation's restrictions before allowing some features. Sometimes the check cannot finish, for example when the restrictions cannot be fetched, and Claude Code falls back to a default (\"fails open\").\n\n- Policy entries can now carry `onFailOpenVerdict: \"deny\"`, meaning deny the feature in that situation.\n\n- \"The plugin directory\" and \"Connector suggestions\" now carry it. Both are denied under HIPAA. Before, they had only `onCacheMiss: \"deny\"`.\n\n- Every entry marked this way is collected into a set that is denied when the check fails open, alongside the set that was already handled this way.\n\n- For these features, the denial now gives the reason as a missing route or a cache miss.\n\n**Why**\n\nIn an organisation under HIPAA restrictions, the plugin directory and connector suggestions stay off when the policy check fails, rather than possibly being allowed. More features may be unavailable while the org restrictions cannot be fetched.\n\n- Area: Managed Settings\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5"}