What is Claude Code auto mode?+
Auto mode routes each tool call through a classifier instead of prompting a developer to approve every command. Anthropic made it the built-in default for new Pro, Max, and Team sessions on August 14, 2026. Enterprise and cloud-marketplace surfaces remained opt-in, with a plan to flip those defaults about a month later. Admins pin the org default with managed settings — defaultMode to choose the start mode, disableAutoMode to remove the option entirely.
How is this different from AI coding platform governance?+
Platform governance answers where source of record lives — GitHub, Cursor Origin, a mirror. Claude Code governance answers what an agent may execute without a human click. Most teams that rolled out Claude Code, Copilot, or Cursor now need both. Start here if auto mode already flipped on Team seats, or if Enterprise is still opt-in and nobody wrote the pin.
How is this different from an AI code audit?+
An AI code audit inspects what merged. This engagement inspects the permission mode that produced it: managed settings, allow-rules, bypassPermissions habits, and which environments may run unattended. Pair them when the questionnaire also asks how Copilot or Claude output is reviewed.
Is this only for Claude Code?+
Claude Code auto mode is the forcing function this month. The engagement is the agent-runtime policy: Claude Code, Copilot agent sessions, Cursor agents, and anything else that can run commands without a prompt. We write language you can reuse when the next vendor ships a similar default.
Who is this for?+
CTOs, VPs of Engineering, and security leads at product companies that already pay for Claude Code — especially Team plans that flipped on August 14, and Enterprise orgs that still have a few weeks to pin a default. Typical triggers: developers on mixed Team/Enterprise seats, a questionnaire that now asks who approves agent actions, or a plan to leave overnight agents running on production-adjacent repos.
What do we get at the end?+
A written posture: which permission mode is approved where, managed-settings values to pin (defaultMode vs disableAutoMode), repo classes that may never run auto (infra, secrets, production-adjacent), contract and questionnaire gaps, and a 30-day action list. Optional next step is a Copilot / Cursor / Claude code audit on what already merged, or ongoing AI code oversight as the team keeps shipping.
How long does a Claude Code governance review take?+
Most reviews land in a week after a 30-minute scoping call and read-only admin / managed-settings access. You do not need to pause delivery. You do need someone who can confirm what is pinned in Claude Team or Enterprise managed settings versus what developers actually start sessions in.
Do you process our source through third-party AI?+
No. Client code stays in client environments. We inspect policy, managed settings, and architecture with senior engineers. We do not run proprietary source through external models as part of the engagement.
What if we already decided auto mode is fine?+
Then document it, pin defaultMode so a client update cannot silently change it, and name the repos where auto is forbidden. Anthropic still recommends human review for high-stakes production infrastructure. A verbal “we trust the classifier” is not a control if half the company is on Team defaults and the other half is still on Enterprise opt-in.
Can this feed SOC 2 or customer security reviews?+
Yes. Teams use the written posture to answer which AI coding agents are approved, whether actions require a human click, how org defaults are enforced, and what gets reviewed before merge. Pair with an AI code audit when the questionnaire also asks how Claude or Copilot output is inspected.