Claude Code Restrict Access: The New Restricted Mode (2026)

Julian Goldie — founder, AI Profit Boardroom
By Julian Goldie · 8 min read
Get The AI Profit Stack Join AIPB →
🎯 1,000+ done-for-you AI agent workflows 📅 5 live coaching calls / week with me 🛡️ 7-day refund + 30-day ROI guarantee 👥 3,000+ AI operators inside

If you want Claude Code restrict access controls — locking the agent down so it cannot run commands, fetch from the web, or touch files outside one folder — Claude Code now ships exactly that: according to the official Claude Code changelog, version 2.1.248 added a new restricted mode, switched on with the restricted flag or the CLAUDE_CODE_RESTRICTED environment variable set to 1, which removes the built-in tools that run commands or code, removes web fetching unless you explicitly name it, keeps file tools inside the working directory, refuses the bypass-permissions mode, and ignores user, project and local settings files. That is the whole feature in one sentence, and it is the answer to a question I get constantly from people running agents on real business machines: how do I let Claude Code work on my files without giving it the keys to everything?

📺 Watch: Claude Code Just Fixed Remote Coding

🔥 Get the Agent OS as a free bonus: AI Profit Boardroom members get the full Agent OS zip, prompt libraries, daily tutorials and weekly live coaching calls. → Get inside

I run Claude Code across my whole content and SEO operation, often on machines that also hold client work, credentials and things an agent has no business reading. Below is what the changelog actually says restricted mode does, how it compares to the permission controls you already have, and where I would — and would not — use it.

Claude Code Restrict Access: What the New Restricted Mode Does

Per the official changelog entry for version 2.1.248, switching on restricted mode changes five things at once:

That last point is subtle and, to my mind, the most important. Permissions you configure normally live in settings files — and a locked-down session is only as locked down as every settings file it reads. Restricted mode cuts that whole class of surprise off at the source, which is what makes it a genuine sandbox switch rather than another rule to maintain.

Restricted Mode vs Normal Permission Rules

Claude Code has always asked permission before risky actions, and you can maintain allowlists per project. So where does restricted mode fit? Here is how I think about the layers:

ApproachWhat it gives youWhen I use it
Normal permission promptsCase-by-case approval of commands and editsDay-to-day dev work where I am watching the session
Allowlists in settingsPre-approved safe commands, fewer interruptionsRepeat workflows in trusted projects
Restricted mode (2.1.248)Command execution and web fetch removed entirely, file access fenced to one folder, settings ignoredUntrusted content, sensitive machines, read-and-edit-only jobs

The mental model: permission prompts are a seatbelt, restricted mode is a separate vehicle. When the job is purely read these files and rewrite them — editing content, reorganising notes, reviewing code without running it — there is no reason for the agent to have an engine at all.

One more detail from the same changelog worth knowing if you live in the permission system day to day: version 2.1.247 added a tip on Bash permission prompts pointing to auto mode, with a one-keystroke option to approve and switch to auto mode in one go. That is the opposite end of the control spectrum — smoother approvals for trusted work — and having both ends ship within two releases tells you the permission layer of Claude Code is getting real attention right now.

If you want my complete Claude Code setup — the permission configs, the safe-by-default project templates, and the Agent OS bundle as a free bonus — I hand it all to members inside AI Profit Boardroom → Get my Claude Code setup

Where I Would Actually Use It

Concrete situations from my own work where a fenced-in Claude Code session is the right call:

  1. Editing content in a vault. When Claude Code works inside my notes — the workflow I describe in my Claude Obsidian setup guide — the job is reading and writing markdown. Restricted mode fits that job exactly: full file access to the vault folder, nothing else.
  2. Working on machines with client data. On a laptop that also holds client credentials and financials, keeps file tools inside the working directory is the phrase that matters. The agent sees the project folder and only the project folder.
  3. Processing untrusted input. If an agent is reading files that arrived from outside — scraped pages, submitted documents — removing command execution and web fetch shrinks what a malicious instruction hidden in that content could ever achieve.
  4. Handing sessions to a team. A restricted launch means a colleague cannot accidentally approve something destructive, because the dangerous tools are not there to approve.

📺 Watch: Run Claude Code for Free: Here Is How

What I would not use it for: normal development. If the task genuinely needs tests run and packages installed, restricted mode will just be in your way — that is what the ordinary permission system is for. And if your goal is saving money rather than restricting risk, that is a different lever entirely — see my guide on reducing Claude Code token usage, and my walkthrough of running Claude Code free.

How This Fits My Agent Stack

My broader framework for running agents safely is the Agent OS — my own operating system for agent work, where every agent gets a defined lane: its files, its tools, its scope. Restricted mode is that philosophy shipped as a product feature, and I love seeing it land natively, because a lane the platform enforces beats a lane you merely document.

It also changes how I think about scale. When I benchmark models and agent setups on Goldie Bench, my own testing suite, the failure mode that worries me is never raw capability — it is an agent doing something correct-looking in the wrong place. Fencing the workspace is the cheapest insurance there is, and it is why I would rather run three restricted sessions in three folders than one all-powerful session with the run of the machine. If you prefer keeping everything local anyway, my Claude Code Local guide covers the offline route with local models — a different kind of control that pairs naturally with a fenced workspace. And once your fenced sessions are humming, my Claude Code AI SEO playbook shows what I actually run inside those lanes to make money with it.

Claude Code Restrict Access FAQs

How do I restrict Claude Code access to one folder?

Launch it in restricted mode — per the official changelog for 2.1.248, the restricted flag or the CLAUDE_CODE_RESTRICTED environment variable keeps file tools inside the working directory you started from. Start the session in the folder you want fenced and that folder is the agent's whole world.

Can Claude Code still run commands in restricted mode?

No. The changelog states restricted mode removes the built-in tools that run commands or code. The agent can read and edit files but cannot execute anything.

Does restricted mode block web access?

Web fetch is removed by default. The changelog notes one exception: it stays available if you explicitly name it in the tools flag at launch — so web access is off unless you deliberately opt it back in.

Why does restricted mode ignore my settings files?

Because settings files can contain permission rules that widen what the agent may do. Ignoring user, project and local settings means no forgotten configuration can quietly loosen the sandbox — the restrictions you launched with are the restrictions you get.

Is restricted mode the same as permission prompts?

No. Prompts ask before each risky action; restricted mode removes the risky capabilities entirely and refuses the bypass-permissions mode altogether. Prompts guard a session you are watching — restricted mode guards a session you are not.

Verdict: Turn It On Anywhere You Do Not Need the Engine

Restricted mode is the most useful kind of safety feature: one switch, five sensible defaults, nothing to maintain. For editing-only work, sensitive machines and untrusted content, there is now no excuse for handing an agent more machine than the job needs. Fence the workspace, keep the engine off unless the task demands it, and you get the productivity of Claude Code with a fraction of the blast radius.

Want to run agents that are safe enough to leave unattended and profitable enough to matter — with my configs, workflows, weekly coaching calls and the full Agent OS included? Join me inside AI Profit Boardroom → Run agents the safe way with me

Real wins from inside the AI Profit Boardroom

See all 3,000+ members →
AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot AIPB member win screenshot

Ready To Join The #1 AI Community?

Join 3,600+ entrepreneurs inside the AI Profit Boardroom. Get 1,000+ plug-and-play AI agent workflows, daily coaching, and a community that holds you accountable.

Join The AI Community →

7-Day No-Questions Refund • Cancel Anytime

← Back to all posts