Skip to content

Build1 publisherNot yet confirmed elsewhere3 min readPublished

On Enterprise and API accounts, Claude Code's default mode meters a Sonnet 5 check per shell command

Claude Code v2.1.283 makes auto mode the default, so each shell command gets a Sonnet 5 safety check metered as tokens on Enterprise, API and cloud accounts. Teams on those accounts now pay for command approval unless they choose a different permission mode.

The Engineer · Build desk

How we use AISend a correction

What happened

  • The classifier runs on Claude Sonnet 5 by default, whatever model the user has selected with /model.
  • Each check sends a portion of the session transcript plus the pending action, adding a round-trip before the command executes.
  • Reads and working-directory edits outside protected paths skip the classifier, so the overhead falls mainly on shell commands and network operations.
  • Entering auto mode drops broad allow rules such as Bash(*), PowerShell(*), wildcarded interpreters, package-manager run commands, and Agent and Monitor rules.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • cost Choosing a cheaper model with /model leaves the classifier on Sonnet 5, so on metered accounts the check's cost does not fall when the main loop's does.
  • decision Leaving auto mode to stop the metered checks brings back any broad allow rules a team had written, such as Bash(*), so cutting token spend means accepting those standing permissions again.
  • capability Unattended runs can carry a limit typed in plain chat, such as no production deploys, and Claude cannot lift it by deciding on its own that the condition was met.
  • exposure A long unattended run can stall on missing verdicts and leave nothing under Recently denied, so whoever debugs the stopped agent starts with no record of what was refused.

The metered list in the documentation covers more than Enterprise plans and direct Claude API keys. It also names Claude Platform on AWS, Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry [5]. A dev.to post that walks through the permission-modes docs says a consumer subscription is not charged per command [18]. For accounts on the list, the post's author wrote, "every shell command and every network request now drags a slice of your transcript into a second model before the first one is allowed to finish" [17].

The default path used to show an approval prompt [2]. By the author's account, that click cost a second of attention and nothing on the invoice [22]. The exemptions now leave the classifier on the commands an agent runs over and over. The author wrote that "the cheap-looking activity, a loop of shell commands, is exactly the expensive one" [21].

The documentation does not say how much of the transcript a check carries [7]. The author declined to estimate: "I am not going to print a dollar figure, and you should be suspicious of anyone who does" [8]. I think that is the correct position. A per-check cost measured on one team's sessions transfers to another team only if the slice is a fixed size. If "a portion of the transcript" [4] grows as the session grows, a figure taken from short sessions will understate long ones.

Failures are handled unevenly. A blocked action raises a notification and lands under Recently denied in /permissions, where pressing r retries it with a manual approval [11]. When the classifier returns no verdict, Claude Code denies the action with neither [12]. Ten responses in a row without a verdict end the turn [13].

A limit typed in chat never becomes a rule. Every time it runs a check, the classifier goes back to the transcript to find it again [15]. The post argues they can be evicted [16]. That would follow if the slice a check sends can leave out the message where the limit was set [4].

Claude Code restores the dropped allow rules when the user leaves auto mode [10]. That is good engineering, and the author calls it a much better design than dropping them [20]. The ruleset still changes on a single click, and according to the post nothing in the interface says so [19]. In my view auto mode is a sensible default on a consumer plan, where the checks are off the meter [18]. On an API or Enterprise account running long shell loops, I'd pick the permission mode on purpose and measure a week of real sessions before trusting any estimate.

What to watch

  • Anthropic documenting the size of the transcript slice each classifier check sends, the missing input for any per-command cost estimate.
  • Whether the classifier can be moved off Sonnet 5, since the documentation describes that model only as the default.
  • Measured token usage from teams running long shell-heavy auto-mode sessions on API, Bedrock or Foundry accounts.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories