{"version":"2.1.293","anchor":"managed-config-telemetry-outcome-reasons-and-an-org-config","canonical_anchor":"org-config-gate-dark-launched-check-that-blocks-startup-whe","heading":"Managed settings fetching: prefetch on by default, sharper failure reporting, and a shadow org-config gate","tier":"notice","area":"Managed Settings","scope":"org","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/managed-config-telemetry-outcome-reasons-and-an-org-config","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Managed settings fetching: prefetch on by default, sharper failure reporting, and a shadow org-config gate\n\nManaged settings are now prefetched by default for first-party users, fetch failures are classified, and a dark-launched org-config check is measured\n\n**Unclear.** Whether the organization settings check being measured is enforced for anyone is not shown.\n\n**What**\n\nManaged settings are settings an organisation's administrator pushes to Claude Code from a server. Policy limits are a related set of rules fetched the same way. This release changes how both are fetched and how fetch problems are recorded.\n\n- Prefetching managed settings at startup used to happen only when the environment variable `CLAUDE_CODE_MANAGED_CONFIG_PREFETCH` was set. If that variable is set, its value still decides. If it is not set, prefetching is now on for first-party users (people connecting straight to Anthropic) and off for other providers. A server-side switch, `tengu_managed_config_prefetch_off`, can turn it off. One call site now passes the prefetch option as a constant true, so the variable no longer controls it there. The flag server returned off for `tengu_managed_config_prefetch_off`, for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.\n\n- A `stillWanted` check is passed into the hedged fetch for managed settings and into the retry loop for policy limits. A hedged fetch sends a backup request if the first is slow, and this check can stop one that is no longer needed. The policy-limits retry delay is computed by a different helper.\n\n- The remote settings fetch report, which already recorded sign-in details, now also records `outcome_reason`, `response_kind`, `request_id_present` and `response_content_type`. The policy-limits fetch report gains the same four fields. Failures are sorted into `no_credentials`, `credential_exchange`, `timeout`, `network`, `tls`, `parse`, `http` and `other`, and failure records also carry `serverErrorType`, plus `credentialState` on 401 and 403 responses.\n\n- Settings responses now say what kind they were: `responseKind: \"not_modified\"` when nothing changed and `responseKind: \"none_configured\"` when no settings are set.\n\n- A policy-limits parse failure now also reports `responseContentType` and `requestIdPresent`, not only the content type. Errors during managed-config prefetch are replaced by a fixed message.\n\n- A new org-config gate, `tengu_org_config_required`, is defined with defaults `enabled:false`, `plans:[]`, `percent:0`, `graceTtlHours:96`, `budgetMs:6000` and `exemptReasons:[]`. It applies only to first-party Team and Enterprise users signed in with a stored login. Its verdict can be pass, pass_cached, pass_exempt, refused or blocked, depending on whether the policy-limits and remote-settings fetches succeeded. At startup it only works out what it would decide if switched on and reports that in a new shadow record (`tengu_org_config_gate_shadow`) with fields such as `candidate_if_armed`, `candidate_now`, `flag_enabled` and `tier`. The finding saw nothing that uses the verdict to stop a session. Nothing has been read about this gate.\n\n- The org-config snapshot gains `policy_has_auth_token`, `policy_has_api_key_helper`, `policy_has_custom_base_url`, `policy_api_provider`, `policy_http_status` and `policy_server_error_type`.\n\n**Why**\n\nFirst-party users whose organisation pushes settings may now have them fetched earlier at startup without setting anything. When a fetch fails, the records say what kind of failure it was. The org-config gate is the shape of a check that could refuse to start Claude Code for Team and Enterprise users when their organisation's settings cannot be fetched. In this build it was only seen measuring, not blocking.\n\n- Area: Managed Settings\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 4\/5\n- Scope: org\n- Heads-up: no"}