{"version":"2.1.290","anchor":"hipaa-policy-allow-channels-denied","canonical_anchor":"hipaa-policy-allow-channels-denied","heading":"Channels now wait on a server-side allow_channels verdict, denied under HIPAA","tier":"notice","area":"Channels","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/hipaa-policy-allow-channels-denied","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Channels now wait on a server-side allow_channels verdict, denied under HIPAA\n\nChannels now also need a server allow_channels verdict besides tengu_harbor, and that verdict is denied for HIPAA policy (HIPAA-R71)\n\n**What**\n\nWhether Channels is available used to depend only on the `tengu_harbor` flag. It now also depends on a policy verdict about `allow_channels` that comes from Anthropic's servers:\n\n- A new check, `cdt()`, treats Channels as off unless `tengu_harbor` is on and an `allow_channels` verdict is present that is not `cache_miss` or `route_missing`. `nL()` now also requires `nn(\"allow_channels\")`.\n\n- A new policy entry, `allow_channels`, labelled Channels (HIPAA-R71), is denied under the `hipaa` policy. It is also denied when the verdict is not cached yet (cache miss) and when the verdict is a fail-open one.\n\n- The startup dialog now asks `isChannelsOffForSession`, which is the reverse of the old `isChannelsEnabled` question.\n\n- The Channels status has a new `verdictPending` field. While the verdict has not arrived, it reads `cache_miss` or `route_missing`.\n\n- The waiting text shown on screen is now \" \u00b7 web fetch, design sync and Channels wait for it\".\n\n**Why**\n\nTurning the flag on is no longer enough to get Channels. Organisations under the HIPAA policy will not get it, and anyone may see Channels held back at startup until the server verdict arrives.\n\n- Area: Channels\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 4\/5\n- Scope: both\n- Heads-up: yes"}