{"version":"2.1.290","anchor":"read-rule-and-sandbox-settings-moved-to-root-sandbox-entrie","canonical_anchor":"read-rule-and-sandbox-settings-moved-to-root-sandbox-entrie","heading":"Read rules from your user settings are now tracked separately","tier":"internal","area":"Permissions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/read-rule-and-sandbox-settings-moved-to-root-sandbox-entrie","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Read rules from your user settings are now tracked separately\n\nClaude Code now keeps deny and ask read rules from your user settings separate and removes duplicates\n\n**Unclear.** Whether this changes which files are blocked is not known.\n\n**What**\n\nWhen Claude Code collects the rules that block or ask before reading files, it now keeps the deny and ask rules from your user settings in their own set and removes duplicates. Before, everything went into one merged list. It also tracks sandbox entries that were moved to the top level of settings. The sandbox is the restricted environment some commands run in.\n\n**Why**\n\nThis affects how sandbox read-deny rules are tracked.\n\n- Area: Permissions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}