Accessibility Adjustments

Use these optional tools to adjust reading and display preferences. These tools cannot resolve every accessibility barrier. Please contact the website owner if you need assistance.

  • Text adjustments
  • Content scaling 100%
  • Font size 100%
  • Line height 100%
  • Letter spacing 100%
  • Colour adjustments
  • Orientation adjustments

Claude Code reinforces managed controls and teammate tracking

Claude Code 2.1.289 repairs policy checks and extends teammate events

Listen to this article

Anthropic released Claude Code 2.1.289 on October 3, repairing permission checks on managed machines and extending teammate tracking. The official release timestamp is 23.07 UTC.

On managed machines, a user modโ€™s approval no longer overrides deny or ask rules on nested parts of a compound shell command. Other repairs restore checks around shell variable prefixes during sandbox automatic approval and apply Read denials to IDE file references reached through symbolic links.

Another repair prevents user plugins from rewriting descriptions of managed MCP sign in tools. Anthropic also extends the agent.spawn hook to teammates, unifies agent identifiers across plugin events and adds idle and waiting states to the agent list.

These are vendor reported repairs. ByteForward has not independently tested them.

Where managed protections apply

Anthropicโ€™s administration guide says a built in guard protects managed instructions, hooks and MCP tools. It loads on machines with managed settings or for users signed in with Team or Enterprise plans. An API key or cloud provider connection alone does not activate that guard.

That distinction matters when the same organization runs coding agents on laptops, remote machines and provider hosted infrastructure. Administrators need to establish which environment actually receives the policy before relying on it.

The guide also draws a firm limit around these controls. Mods run with the userโ€™s operating system permissions and are not sandboxed. A rule that blocks Claudeโ€™s file tool does not automatically block a modโ€™s own file access. Organizations can restrict which mods load through managed policy.

Shell approval and isolation remain separate

The permissions reference separates application permission checks from operating system isolation. With sandbox automatic approval enabled, a broad request to confirm every Bash command can be replaced by the sandbox boundary. Explicit denials and rules covering particular command content still apply.

For file operations through symbolic links, the documented check covers both the requested path and the destination it resolves to. A useful rollout check should therefore include the paths and command forms a team actually uses, rather than only a simple terminal command.

Teammate events need accurate interpretation

The existing mods reference describes agent.spawn as a lifecycle event fired before a subagent starts. The new teammate support extends that event coverage. It should not be presented as the introduction of a general agent creation method.

The reference warns that published type declarations can lag the installed version. Developers adapting a mod should check the declarations supplied by their own installation before depending on the newer event fields.

Illustrative January 2018 code photograph by Markus Spiske, released under CC0. Resized and converted to WebP. The photograph does not depict Claude Code.

Jordan Reid
Jordan Reid

Jordan Reid is focused on AI tools, agents, developer products, and the way technology changes everyday work. Jordan approaches a launch from the userโ€™s side of the screen. What can it actually help someone finish? The voice is practical, conversational, and skeptical of products that turn a simple job into five new settings. Coverage follows coding assistants, creative software, browser agents, and the workflows around them, with attention to pricing, permissions, setup, and the human work that remains.

One comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Gravatar profile