Claude Code reinforces managed controls and teammate tracking
Claude Code 2.1.289 repairs policy checks and extends teammate events

Anthropic released Claude Code 2.1.289 on October 3, repairing permission checks on managed machines and extending teammate tracking. The official release timestamp is 23.07 UTC.
On managed machines, a user mod’s approval no longer overrides deny or ask rules on nested parts of a compound shell command. Other repairs restore checks around shell variable prefixes during sandbox automatic approval and apply Read denials to IDE file references reached through symbolic links.
Another repair prevents user plugins from rewriting descriptions of managed MCP sign in tools. Anthropic also extends the agent.spawn hook to teammates, unifies agent identifiers across plugin events and adds idle and waiting states to the agent list.
These are vendor reported repairs. ByteForward has not independently tested them.
Where managed protections apply
Anthropic’s administration guide says a built in guard protects managed instructions, hooks and MCP tools. It loads on machines with managed settings or for users signed in with Team or Enterprise plans. An API key or cloud provider connection alone does not activate that guard.
That distinction matters when the same organization runs coding agents on laptops, remote machines and provider hosted infrastructure. Administrators need to establish which environment actually receives the policy before relying on it.
The guide also draws a firm limit around these controls. Mods run with the user’s operating system permissions and are not sandboxed. A rule that blocks Claude’s file tool does not automatically block a mod’s own file access. Organizations can restrict which mods load through managed policy.
Shell approval and isolation remain separate
The permissions reference separates application permission checks from operating system isolation. With sandbox automatic approval enabled, a broad request to confirm every Bash command can be replaced by the sandbox boundary. Explicit denials and rules covering particular command content still apply.
For file operations through symbolic links, the documented check covers both the requested path and the destination it resolves to. A useful rollout check should therefore include the paths and command forms a team actually uses, rather than only a simple terminal command.
Teammate events need accurate interpretation
The existing mods reference describes agent.spawn as a lifecycle event fired before a subagent starts. The new teammate support extends that event coverage. It should not be presented as the introduction of a general agent creation method.
The reference warns that published type declarations can lag the installed version. Developers adapting a mod should check the declarations supplied by their own installation before depending on the newer event fields.
Illustrative January 2018 code photograph by Markus Spiske, released under CC0. Resized and converted to WebP. The photograph does not depict Claude Code.




[…] For background, ByteForward covered the previous Claude Code update and managed controls. […]