Source-backed facts for citing this resource, derived directly from the registry — also available as plain text for AI assistants.
- Source URLs
- https://code.claude.com/docs/en/server-managed-settings, https://github.com/JSONbored/awesome-claude/blob/main/content/agents/claude-code-enterprise-rollout-agent.mdx
- Safety notes
- Server-managed settings are a client-side control; on unmanaged devices, users with admin access can modify the binary or network. For stronger enforcement, use endpoint-managed settings on MDM-enrolled devices., Recommend permissions.deny for must-never-run actions, disableBypassPermissionsMode to block bypass, and allowManagedPermissionRulesOnly to prevent users widening rules., Managed hooks execute shell commands and trigger a user security-approval dialog; review hook commands before distributing them org-wide.
- Privacy notes
- Settings are delivered from Anthropic's servers at authentication; review what configuration (hooks, env vars) is distributed and to whom., Server-managed settings are bypassed when users configure a third-party provider (Bedrock, Vertex, Foundry) or a custom base URL; account for that in the threat model., Audit-logging hooks can capture file paths and command output; ensure their destinations meet your retention and access policy.
- Author
- JPette1783
- Submitted by
- JPette1783
- Claim status
- unclaimed
- Last verified
- 2026-06-05