Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.293 ·

Managed settings fetching: prefetch on by default, sharper failure reporting, and a shadow org-config gate

Managed settings are now prefetched by default for first-party users, fetch failures are classified, and a dark-launched org-config check is measured

Group of 7 You'll notice Nothing to try yet In Development
JSON All of v2.1.293
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
4Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
In DevelopmentKind: in v2.1.293,
What probably matters to youSection of the release

Unclear It is not settled whether anything in this release uses the verdict to actually stop a session.

What

Managed settings are settings an organisation's administrator pushes to Claude Code from a server. Policy limits are a related set of rules fetched the same way. This release changes how both are fetched and how fetch problems are recorded.

  • Prefetching managed settings at startup used to happen only when the environment variable CLAUDE_CODE_MANAGED_CONFIG_PREFETCH was set. If that variable is set, its value still decides. If it is not set, prefetching is now on for first-party users (people connecting straight to Anthropic) and off for other providers. A server-side switch, tengu_managed_config_prefetch_off, can turn it off. One call site now passes the prefetch option as a constant true, so the variable no longer controls it there. The flag server returned off for tengu_managed_config_prefetch_off, for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.
  • A stillWanted check is passed into the hedged fetch for managed settings and into the retry loop for policy limits. A hedged fetch sends a backup request if the first is slow, and this check can stop one that is no longer needed. The policy-limits retry delay is computed by a different helper.
  • The remote settings fetch report, which already recorded sign-in details, now also records outcome_reason, response_kind, request_id_present and response_content_type. The policy-limits fetch report gains the same four fields. Failures are sorted into no_credentials, credential_exchange, timeout, network, tls, parse, http and other, and failure records also carry serverErrorType, plus credentialState on 401 and 403 responses.
  • Settings responses now say what kind they were: responseKind: "not_modified" when nothing changed and responseKind: "none_configured" when no settings are set.
  • A policy-limits parse failure now also reports responseContentType and requestIdPresent, not only the content type. Errors during managed-config prefetch are replaced by a fixed message.
  • A new org-config gate, tengu_org_config_required, is defined with defaults enabled:false, plans:[], percent:0, graceTtlHours:96, budgetMs:6000 and exemptReasons:[]. It applies only to first-party Team and Enterprise users signed in with a stored login. Its verdict can be pass, pass_cached, pass_exempt, refused or blocked, depending on whether the policy-limits and remote-settings fetches succeeded. At startup it only works out what it would decide if switched on and reports that in a new shadow record (tengu_org_config_gate_shadow) with fields such as candidate_if_armed, candidate_now, flag_enabled and tier. The finding saw nothing that uses the verdict to stop a session. Nothing has been read about this gate.
  • The org-config snapshot gains policy_has_auth_token, policy_has_api_key_helper, policy_has_custom_base_url, policy_api_provider, policy_http_status and policy_server_error_type.

Why

First-party users whose organisation pushes settings may now have them fetched earlier at startup without setting anything. When a fetch fails, the records say what kind of failure it was. The org-config gate is the shape of a check that could refuse to start Claude Code for Team and Enterprise users when their organisation's settings cannot be fetched. In this build it was only seen measuring, not blocking.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not settled whether anything in this release uses the verdict to actually stop a session.

See this entry in the whole of v2.1.293 →

Feedback