3 Claude Code Settings Every User Should Turn On (Deny Rules, Plan Mode, Sandbox)
TL;DR
Three settings built into Claude Code stop most costly agent mistakes before they happen. Deny rules block commands and files you never want touched, like git push and your .env file. Plan mode by default makes Claude explore and plan before it edits anything. The sandbox keeps shell commands inside your project folder. All three are documented by Anthropic, free, and take a few minutes to turn on.
👉 https://www.skool.com/claudecodeclub
3 Claude Code settings every user should turn on
Why this matters: in July 2025, Replit's AI coding agent deleted SaaStr founder Jason Lemkin's live production database during a code freeze, against explicit instructions (reported by Fortune, logged as AI Incident Database #1152). That was not Claude, but the lesson applies to every coding agent: decide what it is allowed to touch before it starts. All 3 settings below come from Anthropic's own Claude Code docs, and none of them cost anything.
1. Deny rules: block risky commands before Claude can run them
Official Anthropic docs. Built into Claude Code, nothing to install.
What it does: blocks risky commands before Claude can run them. Deny git push or reading your .env file, and Claude simply can't, even if it decides it should. The rule syntax and the .env example below are from Anthropic's docs.
How to turn it on: add this to ~/.claude/settings.json:
json"permissions": {"deny": ["Bash(git push *)", "Read(./.env)", "Read(./.env.*)"]}2. Plan mode by default: Claude explores and plans first, no file edits
Official Anthropic docs. Built into Claude Code, nothing to install.
What it does: Claude reads files and runs read-only commands to explore, but doesn't edit your source files. You read the plan before a single file changes, then switch modes when you are happy with it.
How to turn it on: add this to ~/.claude/settings.json:
json"permissions": {"defaultMode": "plan"}Or switch to it for one session with /plan, or by pressing Shift+Tab.
3. Sandbox: locks Claude's shell commands to your project folder
Official Anthropic docs. Built into Claude Code, nothing to install.
What it does: runs Claude's shell commands in a sandbox. Writes stay inside your working directory, and network access goes through an allowlist.
How to turn it on: inside Claude Code, type:
prompt/sandboxOr add this to ~/.claude/settings.json:
json"sandbox": {"enabled": true}Quick start
- 1Open ~/.claude/settings.json (create it if it does not exist).
- 2Add deny rules for the commands and files you never want Claude to touch, starting with git push and your .env files.
- 3Set defaultMode to plan so every session starts by planning.
- 4Run /sandbox to keep shell commands inside your project folder.
👉 https://www.skool.com/claudecodeclub
Common questions
Do these settings cost anything?
No. All three are built into Claude Code. You only need a Claude plan that includes Claude Code.
Where is the settings file?
Your user settings live in ~/.claude/settings.json and apply to every project. If the file does not exist yet, create it. Anthropic's settings docs also cover project-level settings files.
Will plan mode slow me down?
It adds one step: you read and approve the plan before Claude edits files. You can switch modes at any time with Shift+Tab when you want Claude to go ahead.
Was the database incident caused by Claude?
No. It was Replit's AI coding agent, in July 2025. We use it as an example of why any coding agent should have limits set before it starts work.
Keep going
- 3 Settings That Stop Claude From Wrecking ProdReliability · 5 min
- Keep Your API Keys and Secrets Safe with Claude CodeReliability · 6 min
- 10 Repos That Make Claude Code 10x Safer (Security Audits, Secret Scanners, Skill Checkers)Reliability · 9 min
- The Anti-Hallucination Stack: 3 Claude InstructionsReliability · 6 min
Get more setups like these inside Claude Code Club for $9/mo
Get 650+ plug-and-play skills, MCPs & prompts, plus 8,000+ members - $9/mo, cancel anytime.
Join the Club