{"version":"2.1.293","anchor":"automodeenabled-semantics-changed-auto-mode-in-code-now-on","canonical_anchor":"automodeenabled-semantics-changed-auto-mode-in-code-now-on","heading":"Managed policy: Bash rules also cover PowerShell, Auto mode offered in Code unless set false, empty folder lists allow nothing","tier":"notice","area":"Auto Mode","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/automodeenabled-semantics-changed-auto-mode-in-code-now-on","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Managed policy: Bash rules also cover PowerShell, Auto mode offered in Code unless set false, empty folder lists allow nothing\n\nAdmin policy now applies a bare Bash rule to PowerShell too, offers Auto mode in Code unless autoModeEnabled is false, and treats an empty folder list as none\n\n**What**\n\nThese changes are to managed settings that administrators set for their organisation's desktop deployments.\n\n- In `builtinToolPolicy`, a bare `Bash` key now also governs the `PowerShell` tool. Scoped keys such as `Bash(\u2026)` do not. Disabling Bash in the built-in tool settings now disables PowerShell as well, where before only Bash and WebFetch were mapped this way.\n\n- `autoModeEnabled` changed meaning. Auto mode lets Claude act without asking permission for each step. Left unset, Auto mode is now offered in the Code tab and new Code sessions start in it. Cowork gets it only when the key is `true`, and `false` removes it from both. Before, it defaulted to off and covered both selectors. The default is now display-only, with a separate fail-closed value of false.\n\n- The chat and Cowork surfaces are now worked out by a helper called `surfacesOf`.\n\n- `allowedWorkspaceFolders` now treats an empty list as written on purpose: an empty list allows no folder at all, while leaving it unset leaves access unrestricted.\n\n**Why**\n\nAn admin who blocked Bash expecting shell access to be off now also blocks PowerShell. Deployments that never set `autoModeEnabled` will find Code sessions starting in Auto mode unless the admin sets it to `false`. An empty folder list now locks folder access down rather than leaving it open.\n\n- Area: Auto Mode\n- Names: `autoModeEnabled`\n- Tier: You'll notice\n- Useful: 4\/5\n- Signal: 3\/5\n- Scope: both\n- Heads-up: yes"}