AW-025

Type: Connector disposition

Subject: Claude Code (VS Code extension / CLI)

Decision requested: Approve the proposed disposition for Claude Code (VS Code extension / CLI) across its 8 assessed actions

Inherent / residual: Critical / Moderate

Control owner: InfoSec + Engineering (developer tooling) + IT (MDM)

Context: 8 assessed actions. Runtime settings proposed: Needs Approval x2, Always Allow x1, Blocked x1. Administrative actions proposed: Permit with restrictions x3, Permit x1. Proposed for Blocked: bypassPermissions mode. Class: Local execution surface (IDE extension or CLI running on the developer's endpoint, with filesystem and shell reach). Control point: Claude Code enterprise managed settings deployed by MDM (managed-settings.json), which cannot be overridden by user settings, project settings or command-line flags. Control owner: InfoSec + Engineering (developer tooling) + IT (MDM).

Risks: R-11 [High inherent / Low residual] Substitution by unmanaged third-party MCP servers for the same services | R-43 [High inherent / High residual] A third path to meeting content, reaching recordings and transcripts directly | R-46 [Critical inherent / High residual] Agentic coding tools reach everything the developer account can reach on disk | R-47 [Critical inherent / Low residual] Bypass modes remove every local control at once | R-49 [Critical inherent / High residual] The local surface is the host for every plugin and local MCP server

Open verification: V-41 [High] Which MCP servers can be registered locally, whether project MCP servers are auto-approved, and how that list compares with the approved connector list in this workbook. | V-43 [High] Whether managed instruction content and PreToolUse hooks are deployed, and whether locally defined hooks are restricted. Instruction content and hooks are separate mechanisms with different force - one is context, the other blocks a call.

Ruling:

Amendment or condition: