Claude Code governance

Claude Code now runs without asking. Did anyone pin that?

Auto mode is already the default on Pro, Max, and Team. Enterprise is next. We help engineering leaders write the permission policy — defaultMode, disableAutoMode, and what the next security questionnaire should actually say — before Anthropic flips the remaining default.

  • GitHub
  • Cursor
  • GitHub Copilot
  • Claude

Claude Code auto mode is a permission policy, not a preference

On August 14, 2026, new Claude Code sessions on Pro, Max, and Team started in auto mode: a classifier approves routine tool calls instead of a human clicking through prompts. Anthropic’s own data says developers already approve 97% of those prompts. Enterprise, API, Bedrock, and Foundry stayed opt-in — with a stated plan to make auto mode the default in the following month. That window is the work. A Slack reminder is not a control. Managed settings are. Maxiom reviews how your organization actually starts Claude Code sessions, which repos may run auto, and what evidence you will show when a buyer asks who approved agent actions. This is general software engineering. It is not a scanner report, and it is not limited to one industry.

2002
Founded
$100M+
Delivered
98%
Satisfaction

The problem

Team already flipped. Enterprise has not.

Pro, Max, and Team sessions started in auto mode on August 14 unless an admin had already pinned a default. Enterprise stayed opt-in — with a published plan to follow. Mixed seats mean two policies unless you write one.

Click-through was never a control

Anthropic published that users approve 97% of permission prompts. Turning off the prompts without pinning managed settings just makes the habit official. disableAutoMode is a policy. A Slack thread is not.

Questionnaires now ask who approved the action

Buyers ask which agents may run unattended, on which repos, with which data. “We use Claude Code” is no longer a complete answer if overnight agents can push, reset, or exfiltrate without a human in the loop.

What we review

Permission posture, not a model bake-off

Senior engineers map how Claude Code actually starts, which settings are pinned, and which environments may never run unattended — then write the decision you can defend to security, legal, and customers.

  • Plan split and defaults

    Who is on Team vs Enterprise vs API / Bedrock / Foundry, what the built-in default is today, and whether Anthropic’s next flip would change you without a pin.

  • Managed settings

    defaultMode versus disableAutoMode, who can override, and whether VS Code / CLI / desktop actually honor the same pin.

  • Repo classes

    Which codebases may run auto (app feature work) versus must stay manual or disabled (infra, secrets, production-adjacent, customer data paths).

  • Allow-rules and bypass habits

    Broad Bash allow-rules, bypassPermissions, and “don’t ask again” settings that skip review even when auto mode is off.

  • Contract and questionnaire fit

    Customer, IP, and SOC 2 language versus unattended agent actions, training terms, and what is still a classifier rather than a human control.

  • Handoff to code review

    Where permission policy ends and Copilot / Cursor / Claude output review begins — so governance and audit are not the same slide.

Is this right for you?

Team seats flipped on August 14

Nobody pinned managed settings. New sessions are already in auto mode. You need a written yes/no this week, not a poll in Slack.

Enterprise is still opt-in — for now

Anthropic said the Enterprise default is coming in about a month. That is a calendar, not a rumor. Pin before the vendor pins for you.

Security asked who approved the command

The AI-tools policy still says “human in the loop.” Reality may be a classifier. You need the gap closed before the next questionnaire.

How a Claude Code governance review works

Kickoff

  1. 01

    Align

    Scoping · 30 minutes

    We map which Claude Code plans you pay for, where auto mode is already the default, and whether managed settings exist.

    • Team vs Enterprise vs API seats
    • Current start mode vs pinned mode
    • Policy vs how sessions actually start

    You get: a permission-policy decision frame

  2. 02

    Access

    NDA · admin read-only

    Read-only look at Claude managed settings, related AI-tool policies, and a sample of how developers actually launch sessions.

    • NDA before admin access
    • Managed settings and plan mix
    • Existing AI-tool policy review

    You get: facts, not a policy rewrite in the dark

  3. 03

    Posture

    Written findings

    Approved modes by repo class, settings to pin, gaps in contracts and questionnaires, and a 30-day action list.

    • Where auto is allowed or forbidden
    • Contract and questionnaire gaps
    • 30-day action list

    You get: a written posture you can defend

  4. 04

    Debrief

    Next engagement

    Live walkthrough with engineering and security. Optional Copilot / Cursor / Claude audit or ongoing oversight on the code those sessions already wrote.

    • Engineering and security walkthrough
    • Optional code audit on agent-touched repos
    • Optional monthly oversight

    You get: a path from policy to evidence

  • NDA signed before access
  • Read-only repository only
  • Senior engineers every time
  • Report in 10 business days

Frequently asked questions

What is Claude Code auto mode?

Auto mode routes each tool call through a classifier instead of prompting a developer to approve every command. Anthropic made it the built-in default for new Pro, Max, and Team sessions on August 14, 2026. Enterprise and cloud-marketplace surfaces remained opt-in, with a plan to flip those defaults about a month later. Admins pin the org default with managed settings — defaultMode to choose the start mode, disableAutoMode to remove the option entirely.

How is this different from AI coding platform governance?

Platform governance answers where source of record lives — GitHub, Cursor Origin, a mirror. Claude Code governance answers what an agent may execute without a human click. Most teams that rolled out Claude Code, Copilot, or Cursor now need both. Start here if auto mode already flipped on Team seats, or if Enterprise is still opt-in and nobody wrote the pin.

How is this different from an AI code audit?

An AI code audit inspects what merged. This engagement inspects the permission mode that produced it: managed settings, allow-rules, bypassPermissions habits, and which environments may run unattended. Pair them when the questionnaire also asks how Copilot or Claude output is reviewed.

Is this only for Claude Code?

Claude Code auto mode is the forcing function this month. The engagement is the agent-runtime policy: Claude Code, Copilot agent sessions, Cursor agents, and anything else that can run commands without a prompt. We write language you can reuse when the next vendor ships a similar default.

Who is this for?

CTOs, VPs of Engineering, and security leads at product companies that already pay for Claude Code — especially Team plans that flipped on August 14, and Enterprise orgs that still have a few weeks to pin a default. Typical triggers: developers on mixed Team/Enterprise seats, a questionnaire that now asks who approves agent actions, or a plan to leave overnight agents running on production-adjacent repos.

What do we get at the end?

A written posture: which permission mode is approved where, managed-settings values to pin (defaultMode vs disableAutoMode), repo classes that may never run auto (infra, secrets, production-adjacent), contract and questionnaire gaps, and a 30-day action list. Optional next step is a Copilot / Cursor / Claude code audit on what already merged, or ongoing AI code oversight as the team keeps shipping.

How long does a Claude Code governance review take?

Most reviews land in a week after a 30-minute scoping call and read-only admin / managed-settings access. You do not need to pause delivery. You do need someone who can confirm what is pinned in Claude Team or Enterprise managed settings versus what developers actually start sessions in.

Do you process our source through third-party AI?

No. Client code stays in client environments. We inspect policy, managed settings, and architecture with senior engineers. We do not run proprietary source through external models as part of the engagement.

What if we already decided auto mode is fine?

Then document it, pin defaultMode so a client update cannot silently change it, and name the repos where auto is forbidden. Anthropic still recommends human review for high-stakes production infrastructure. A verbal “we trust the classifier” is not a control if half the company is on Team defaults and the other half is still on Enterprise opt-in.

Can this feed SOC 2 or customer security reviews?

Yes. Teams use the written posture to answer which AI coding agents are approved, whether actions require a human click, how org defaults are enforced, and what gets reviewed before merge. Pair with an AI code audit when the questionnaire also asks how Claude or Copilot output is inspected.

Pin the permission default before the vendor pins it for you.

Most Claude Code governance reviews deliver a written posture within a week of access. Start with a 30-minute scoping call.

  • NDA signed before access
  • Read-only repository only
  • Senior engineers every time
  • Report in 10 business days