A vendor default is a policy change
Use
when:
anyone
starts
Claude
Code
through
Pro,
Max,
or
Team
without
an
explicitly
pinned
mode.
On
August
14,
new
sessions
default
to
auto,
where
a
classifier
can
approve
most
tool
calls
without
asking.
Enterprise
and
API/cloud
users
are
temporarily
opt-in.
{"permissions":{"defaultMode":"default","disableAutoMode":"disable"}}
in
~/.claude/settings.json
or
managed
settings;
default
means
Manual.
For
controlled
adoption,
set
"defaultMode":"auto",
retain
"$defaults"
in
each
customized
autoMode
list,
name
only
trusted
infrastructure
under
autoMode.environment,
and
add
durable
permissions.ask
or
permissions.deny
rules
for
critical
transitions.
Run
claude
auto-mode
config
to
inspect
the
effective
policy.
Acceptance
check:
start
a
clean
session
and
require
the
status
bar
to
show
the
chosen
mode.
If
auto
is
disabled,
claude
--permission-mode
auto
must
refuse.
If
adopted,
run
two
disposable
canaries:
one
shell
operation
whose
target
exceeds
the
prompt's
scope,
and
one
in-repository
Edit
against
an
adjacent
must-preserve
fixture.
The
first
must
block
or
ask;
the
second
must
be
caught
by
an
independent
diff/test
gate.
Any
silent
mode
change
or
out-of-scope
mutation
fails
rollout.
Edit/Write.
Caveat: the vendor and independent figures test different threats and versions; do not compare them as one leaderboard. The independent study uses Sonnet 4.6 and synthetic DevOps ambiguity; Anthropic's July evaluation uses undisclosed held-out attacks and v2.1.205. Auto mode does not sandbox the host, and project-local edits intentionally bypass the transcript classifier. Isolation, least privilege, deterministic acceptance, and post-run review remain separate controls.