Bringing the Org's Approval Chain into "Permissions"──Claude Code v2.1.290 Puts Subagent Decisions and "Server-Side Tool Runs" on the Ledger
Claude Code v2.1.290 (October 5) adds ceiling to indicate an organization's approval level, agentId to identify subagents, and serverToolUses to record server-side tool runs to its approval hooks. It also rolls up fixes for "silent failures" in unattended operation, such as scheduled tasks stopping
On October 5, 2026, Anthropic released v2.1.290 of its coding agent, Claude Code. Rather than a flashy new model or a batch of new commands, the focus is on unglamorous changes that make it visible who approved what, which agent ran it, and what exactly was executed. This is an operations-side update that pays off more and more as auto-approval (Auto mode) and routine use of subagents spread.
You can now write the "organization's approval chain" into the material used for approval decisions
Claude Code has a mechanism that hands off processing to hooks on the plugin (mod) side when deciding whether a tool run is permitted. This release adds three pieces of information that matter for organizational operations to that decision path. Rather than reproducing the raw list from the source, here is each item organized in turn.
| What was added | Where it applies | Why it helps |
|---|---|---|
ceiling | The query and decision read by the approval hook (tool.check) | Lets you name the approval level (the height of sign-off) that the organization requires for that tool. You can pass "this operation needs higher-level approval" to the decision side |
agentId | Likewise, the approval hook event | Lets you distinguish whether an approval request came from a subagent or from the main session itself. You won't mistake "whose decision is this" in branched automated processing |
serverToolUses | The hook that receives each turn's execution results (turn.step) | Lets you see the tool calls the API side (server) made on its own, complete with ID, name, input, and start/end times. Tools that ran outside your own machine also land on the ledger |
The key point is that approval decisions can now move away from a binary "yes/no" toward decisions that account for the organization's rules and the actor doing the work. For example, you can tie a high approval level (ceiling) to operations that touch production, and change how you handle requests originating from subagents (agentId) alone—control you can now write on the hook side. The plugin hook types also gained ThemeKey and Color types, rounding out type support when writing extensions.
Stamping out, all at once, the "it had quietly stopped without anyone noticing"
The other pillar is tackling the "silent failures" that crop up in unattended, long-running operation. Left alone, these produce the nastiest kind of breakage: you think it's working when it has actually stopped. Several such bugs were fixed.
- Scheduled tasks (/loop, reminders) not coming back after a resume: Fixed a bug where, after a conversation was auto-compacted (compaction), scheduled tasks would quietly fail to resume. This applies to compactions performed from this version onward.
- Foreground-scheduled reserved tasks not firing: Fixed a bug where a reserved task set in the foreground after handoff to the background would never run even once, and a bug where a recurring task would run one extra time on each resume, regeneration, or fork.
- Resumed subagents losing their memory: Fixed a bug where, when a message arrived mid-execution, a resumed subagent or teammate would lose its prior reasoning and prompt cache.
- WebFetch's "silent truncation": Fixed behavior where, if a fetched page exceeded 100,000 characters, the body was silently truncated. It now tells you how much is unread and lets you read the rest by specifying an offset.
- Dropped results in unattended runs: Fixed a bug where headless
--json-schemaruns were treated as abnormal exits despite finishing normally. Also resolved an issue where long conversations containing hundreds of images would hang as "unprocessable," and a problem where requests failed across proxies that reject the beta header.
Beyond these, there are also changes that lighten day-to-day handling: claude attach <name> / claude logs <name> for pointing at a session by partial name match rather than a full ID, a path for standing up a Managed Agents configuration via /claude-api managed-agents-onboard, and a fix for rendering that had crashed on nested lists and quotes.
An update that pays off the more you expand automation
In business terms, the value here sorts into two. First, you can map approvals onto your existing sign-off structure. By declaring the approval level each tool requires as a ceiling and separating out subagent-originated requests via agentId, you can nudge operations one step away from "a human presses 'yes' on everything" toward "the organization's rules take effect automatically." serverToolUses, which records even the tool calls that ran on the server side, also carries meaning as an audit trail. Second, the reliability of unattended operation. The more you run agents in parallel for long stretches, the more bugs like scheduled tasks stopping after compaction or losing context on resume accumulate damage while staying hard to spot. Closing those off pays off most for teams scaling up.
That said, there are caveats. These approval and visibility features only work once you write them into a hook—organizational rules are not enforced by default. The more subagents and server-side tools there are, the harder it becomes for a human to fully track "what actually ran," and the very increase in means of observation becomes a burden of configuration and inspection. Behind the convenience, there is a risk that more complex approvals could, ironically, breed oversights. Whether the user can read the added gauges and build them into their operation looks set to be the dividing line.
References: Claude Code changelog (official) / anthropics/claude-code Release v2.1.290 / Releasebot: Claude Code Updates / havoptic: Claude Code release summaries


