02 · What that line is
A request to the agent, not a control.
In the vocabulary every published behaviour policy uses, a line in the agent's instructions is an expectation: a rule in prose, enforced by nobody. A rule in prose is inside the boundary the agent operates in. All four major model providers stated in their own 2026 words that an instruction at this layer can be bypassed. It changes what the agent usually does, which is worth having; it does not hold when the agent is talked out of it, confused, or reading somebody else's instructions in a web page.
If you want more than a request, these are stronger, each quoted from the vendor's own page on the date shown.
setting · a switch the agent's own account can flipClaude Code's protected paths: writes to its own configuration are never auto-approved
Leave the permission mode on Manual, acceptEdits or auto; in dontAsk such writes are denied.
“Writes to a small set of paths are never auto-approved, except in bypassPermissions mode and in interactive terminal sessions in plan mode with bypass permissions available. This prevents accidental corruption of repository state and Claude's own configuration.”
code.claude.com/docs/en/permission-modes · read 8 October 2026
setting · a switch the agent's own account can flipManaged settings, set by the organisation, outrank the user's and the project's
An organisation sets permissions in managed settings; a key set there overrides the same key in any file the agent can edit.
“When the same key appears in more than one place, Claude Code uses the value from the highest level that sets it. … a key at a higher level overrides the same key anywhere below it. (Highest: managed settings, set by your organization.)”
code.claude.com/docs/en/settings · read 8 October 2026