Unclear It is not settled whether anything in this release uses the verdict to actually stop a session.
What
Managed settings are settings an organisation's administrator pushes to Claude Code from a server. Policy limits are a related set of rules fetched the same way. This release changes how both are fetched and how fetch problems are recorded.
- Prefetching managed settings at startup used to happen only when the environment variable
CLAUDE_CODE_MANAGED_CONFIG_PREFETCHwas set. If that variable is set, its value still decides. If it is not set, prefetching is now on for first-party users (people connecting straight to Anthropic) and off for other providers. A server-side switch,tengu_managed_config_prefetch_off, can turn it off. One call site now passes the prefetch option as a constant true, so the variable no longer controls it there. The flag server returned off fortengu_managed_config_prefetch_off, for this site's account and for the anonymous baseline, but no reading has been taken under this release yet. - A
stillWantedcheck is passed into the hedged fetch for managed settings and into the retry loop for policy limits. A hedged fetch sends a backup request if the first is slow, and this check can stop one that is no longer needed. The policy-limits retry delay is computed by a different helper. - The remote settings fetch report, which already recorded sign-in details, now also records
outcome_reason,response_kind,request_id_presentandresponse_content_type. The policy-limits fetch report gains the same four fields. Failures are sorted intono_credentials,credential_exchange,timeout,network,tls,parse,httpandother, and failure records also carryserverErrorType, pluscredentialStateon 401 and 403 responses. - Settings responses now say what kind they were:
responseKind: "not_modified"when nothing changed andresponseKind: "none_configured"when no settings are set. - A policy-limits parse failure now also reports
responseContentTypeandrequestIdPresent, not only the content type. Errors during managed-config prefetch are replaced by a fixed message. - A new org-config gate,
tengu_org_config_required, is defined with defaultsenabled:false,plans:[],percent:0,graceTtlHours:96,budgetMs:6000andexemptReasons:[]. It applies only to first-party Team and Enterprise users signed in with a stored login. Its verdict can be pass, pass_cached, pass_exempt, refused or blocked, depending on whether the policy-limits and remote-settings fetches succeeded. At startup it only works out what it would decide if switched on and reports that in a new shadow record (tengu_org_config_gate_shadow) with fields such ascandidate_if_armed,candidate_now,flag_enabledandtier. The finding saw nothing that uses the verdict to stop a session. Nothing has been read about this gate. - The org-config snapshot gains
policy_has_auth_token,policy_has_api_key_helper,policy_has_custom_base_url,policy_api_provider,policy_http_statusandpolicy_server_error_type.
Why
First-party users whose organisation pushes settings may now have them fetched earlier at startup without setting anything. When a fetch fails, the records say what kind of failure it was. The org-config gate is the shape of a check that could refuse to start Claude Code for Team and Enterprise users when their organisation's settings cannot be fetched. In this build it was only seen measuring, not blocking.
It is not settled whether anything in this release uses the verdict to actually stop a session.