Claude Code (Anthropic)
What Claude Code’s own help pages, docs and terms said on 1 October 2026, by the same six questions we ask of every agent. We didn’t test it for this page. “Not documented” means we didn’t find it on the vendor’s pages; it doesn’t mean the feature is missing.
Coding agent
- Can you limit it?
- Allow, ask, deny rules
- Does it ask first?
- Manual, auto (a classifier), bypass
- Can you stop it?
- Esc mid-turn
- Is there a record someone outside can check?
- Not documented
- What about sub-agents?
- Inherit the parent's mode
- Can you test it yourself?
- Headless runs with MCP
What the vendor’s pages say
Rules are evaluated "deny, then ask, then allow", and an admin can turn off the bypass mode in managed settings (permissions). From v2.1.283, auto mode, where "a second model, the classifier, reviews actions instead of you", is the starting mode for interactive sessions. Anthropic writes that it "does not guarantee safety", and that bypass mode "offers no protection against prompt injection" (modes). Esc stops "the current response or tool call mid-turn", and "Claude keeps the work done so far" (interactive mode). Sub-agents inherit the main conversation's mode, and their tools can be narrowed (sub-agents).
Every statement above was checked on the vendor’s own page on 1 October 2026; each links to its source.
Run this test on yours
Delegus Check gives your agent a permission and a one-hour test server, then shows every action it tries and what was refused. It works today with agents that accept a custom MCP server, including Claude on any plan.
Corrections
Vendors and readers: if anything here is out of date, write to hello@delegus.ai and we’ll fix it. Each change is listed here with its date.
- 1 October 2026: first published. All vendor statements checked that day.