What
Claude Code's permission checks decide what Claude may do on its own and what needs your approval. They get stricter in two places:
- Network paths: a file on a network location (UNC paths such as
\\server\share, automounted folders, or paths outside trusted network directories) is now flagged as a network path. It is never approved automatically, and the prompt gives the new reasonnetwork_path. - Served sessions: when a session runs tools on this computer for a remote session, any tool that would edit or write a settings file is refused.
- Ask prompts in served sessions now open with
ask.outside_sandboxandask.settings_person_onlytext, and your own settings now take part in those permission checks. - New messages explain why a person must approve, for example "This can delete files or discard changes for good, so a person needs to approve it." These are chosen by the gate
tengu_reactive_zephyr, which has not been read, so whether they appear for any given account is unknown.
Why
Network paths and settings files are places where an automatic action could reach further than expected or change how Claude Code itself behaves. These changes put a person back in the loop for them.
tengu_reactive_zephyr Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.288: not a boolean we can read
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.288. It isn't a statement about your account. What a flag value here can and cannot tell you
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Where the new approval-message wording is shown, and when the remote setting enables it, was not established.