Recommended settings for running Claude Code safely on managed endpoints. These restrict what Claude Code can do on your machine — preventing destructive commands, privilege escalation, and credential access — even when running in permissive mode (--dangerously-skip-permissions).
Option A — Let Claude do it: Paste this into Claude Code: