Managed policy: Bash rules also cover PowerShell, Auto mode offered in Code unless set false, empty folder lists allow nothing
Admin policy now applies a bare Bash rule to PowerShell too, offers Auto mode in Code unless autoModeEnabled is false, and treats an empty folder list as none
You'll noticeTier: how much it should matter to you
4Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Auto ModeArea: what it touches
ImprovementsKind: in v2.1.293,
What probably matters to youSection of the release
What
These changes are to managed settings that administrators set for their organisation's desktop deployments.
In builtinToolPolicy, a bare Bash key now also governs the PowerShell tool. Scoped keys such as Bash(…) do not. Disabling Bash in the built-in tool settings now disables PowerShell as well, where before only Bash and WebFetch were mapped this way.
autoModeEnabled changed meaning. Auto mode lets Claude act without asking permission for each step. Left unset, Auto mode is now offered in the Code tab and new Code sessions start in it. Cowork gets it only when the key is true, and false removes it from both. Before, it defaulted to off and covered both selectors. The default is now display-only, with a separate fail-closed value of false.
The chat and Cowork surfaces are now worked out by a helper called surfacesOf.
allowedWorkspaceFolders now treats an empty list as written on purpose: an empty list allows no folder at all, while leaving it unset leaves access unrestricted.
Why
An admin who blocked Bash expecting shell access to be off now also blocks PowerShell. Deployments that never set autoModeEnabled will find Code sessions starting in Auto mode unless the admin sets it to false. An empty folder list now locks folder access down rather than leaving it open.