What this means
The Portal shows what your organization’s policy says. The agent reads its own configuration file on the Mac. Turning a control off removes it from your policy, and AgenShield is then supposed to take the matching value back out of that file. In affected versions it did not: the value was written when the control was on and then left behind when the control was turned off. The agent kept reading the old value, so it stayed restricted. Nothing is broken or in an error state — the Mac is simply acting on a leftover value. This is most visible when your organization is in monitor mode, but it also occurs in enforce mode.Affected and fixed versions
Upgrading is the complete fix. After upgrading, the leftover value is cleared on
the next policy update — you do not have to re-apply anything.
How to confirm it
Ask the person who uses the Mac to check the agent’s own behaviour first: if the Portal reads Allow and the agent still refuses, that matches this issue. If you want to confirm before upgrading, look at the value the agent is reading. For Claude Code, that is:How to recover
Upgrade AgenShield.- Turn the control back on, then off again. The Mac re-applies the value, which re-establishes it as AgenShield’s, and turning it off then removes it. Allow a policy update between the two steps.
- Or remove just that one setting by hand on the affected Mac. Edit the
agent’s managed settings file (for Claude Code,
/Library/Application Support/ClaudeCode/managed-settings.json) and delete only the leftover key, leaving every other value in place.
When to escalate
Contact support if, after upgrading:- the value is still present more than 15 minutes after a policy change, or
- a control you never turned on appears to be applied on the Mac, or
- the agent’s behaviour and the Portal disagree in the opposite direction — the Portal shows a restriction that the agent is not applying.