What
Claude Code's permission checks decide what Claude may do on its own and what needs your approval. They get stricter in two places:
- Network paths: a file on a network location (UNC paths such as
\\server\share, automounted folders, or paths outside trusted network directories) is now flagged as a network path. It is never approved automatically, and the prompt gives the new reasonnetwork_path. - Served sessions: when a session runs tools on this computer for a remote session, any tool that would edit or write a settings file is refused.
- Ask prompts in served sessions now open with
ask.outside_sandboxandask.settings_person_onlytext, and your own settings now take part in those permission checks. - New messages explain why a person must approve, for example "This can delete files or discard changes for good, so a person needs to approve it." These are chosen by the gate
tengu_reactive_zephyr, which has not been read, so whether they appear for any given account is unknown.
Why
Network paths and settings files are places where an automatic action could reach further than expected or change how Claude Code itself behaves. These changes put a person back in the loop for them.
tengu_violin_purfling On for this account, and not off by defaultThe flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.
This account: on · anonymous baseline: on · compiled default in v2.1.288: not a boolean we can read
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
tengu_reactive_zephyr Not enough to sayNothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.
This account: no value returned · anonymous baseline: off · compiled default in v2.1.288: not a boolean we can read
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.288. It isn't a statement about your account. What a flag value here can and cannot tell you
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
It is not clear when a session counts as served or exactly what you see when an edit is refused.