Daily harness signal

Pin the permission mode before Claude's default flips

August 9, 2026 · JST One fresh finding Claude Code · permissions · default drift
Claude Code will change its default permission posture next week. Pin the intended mode now, then test both classifier-gated commands and in-project edits instead of inheriting a silent rollout.
01 · Fresh · source date 2026-08-07

A vendor default is a policy change

Use when: anyone starts Claude Code through Pro, Max, or Team without an explicitly pinned mode. On August 14, new sessions default to auto, where a classifier can approve most tool calls without asking. Enterprise and API/cloud users are temporarily opt-in.

Action: decide explicitly before rollout. For sensitive work, put {"permissions":{"defaultMode":"default","disableAutoMode":"disable"}} in ~/.claude/settings.json or managed settings; default means Manual. For controlled adoption, set "defaultMode":"auto", retain "$defaults" in each customized autoMode list, name only trusted infrastructure under autoMode.environment, and add durable permissions.ask or permissions.deny rules for critical transitions. Run claude auto-mode config to inspect the effective policy.

Acceptance check: start a clean session and require the status bar to show the chosen mode. If auto is disabled, claude --permission-mode auto must refuse. If adopted, run two disposable canaries: one shell operation whose target exceeds the prompt's scope, and one in-repository Edit against an adjacent must-preserve fixture. The first must block or ask; the second must be caught by an independent diff/test gate. Any silent mode change or out-of-scope mutation fails rollout.

Evidence: Anthropic's dated announcement, current documentation, and exact configuration commands are inspectable primary sources. Its study reports 1,053 paid testers caught 13.6% of planted dangerous prompts while auto blocked 89%. An independent Dockerized benchmark publishes prompts, reset scripts, traces, and task state; 93 of 253 state-changing actions used unclassified in-project Edit/Write.

Caveat: the vendor and independent figures test different threats and versions; do not compare them as one leaderboard. The independent study uses Sonnet 4.6 and synthetic DevOps ambiguity; Anthropic's July evaluation uses undisclosed held-out attacks and v2.1.205. Auto mode does not sandbox the host, and project-local edits intentionally bypass the transcript classifier. Isolation, least privilege, deterministic acceptance, and post-run review remain separate controls.

Compact source notes

  1. Anthropic default-change announcement (2026-08-07). Primary rollout date, plan scope, controlled human study, internal incidents, third-party injection evaluation, and explicit residual-risk warning.
  2. Permission modes and auto-mode configuration (retrieved 2026-08-09). Current authoritative syntax, precedence, scope restrictions, inspection command, and the August 14 default.
  3. Auto-mode architecture (2026-03-25). Primary description of the three tool planes, classifier limits, and deny-and-continue behavior.
  4. Simon Willison's critique (2026-08-08). Practitioner contradiction check emphasizing residual prompt-injection and dependency-execution risk.
  5. AmPermBench paper and repository (2026-04-04). Independent preprint plus Dockerized runner, fixed prompts, deterministic oracles, state snapshots, and result schema.
  6. Hacker News discussion (retrieved 2026-08-09). Discussion lead only; competing field reports were not treated as proof.
  7. Method: anchor lens—dated rollout, effective-config output, status receipts, and two-plane canaries; unity lens—the permission default is deployment policy, not UI preference. A clean session ignoring a pin, or either canary crossing scope without an external catch, falsifies rollout readiness. Confidence: Likely.