Claude Code 2.1.285 changed one startup failure. If the operating system denies access to the managed settings file, the client now warns and starts without that file's policies. Other read errors and malformed managed files still stop the session.
That split is reasonable product behavior. It also creates a security state that operators must name. "Started" no longer proves "started under the expected policy." A launcher, status line, session log, or support playbook that records only process success loses the important part.
The same release added a switch to disable WebFetch and a managed setting that limits API providers. It also tightened sandbox inheritance so project settings cannot weaken an administrator-required sandbox. These controls belong in the policy receipt, but none repairs a policy source that was never loaded.