Managed configuration is designed for organization-wide security and compliance controls that individual users and repositories must not override. Applying the hardening flag centrally establishes an administrative policy boundary and prevents engineers from disabling the control through user, project, or local settings.
Anthropic identifies managed scope as the appropriate location for security policies, non-overridable compliance requirements, and standardized configurations deployed by IT or DevOps. Managed values ordinarily take precedence over command-line arguments and every user-controlled settings scope. Claude Code Settings
Option A depends on every engineer maintaining the setting and allows the user to edit or delete it. Option B affects only pipeline execution and does not protect local, interactive, IDE, or other execution paths. Option D standardizes the setting within the repository but does not make it tamper-resistant; contributors with repository write access could alter the file, use higher-precedence local settings where permitted, or operate outside the repository configuration.
The implementation should also verify active policy delivery, monitor configuration-change events, and test that startup or execution fails safely if the managed setting is absent or invalid. Central definition without enforcement and verification would not fully satisfy the requirement.
Study Guide references/topics: Managed settings; non-overridable controls; enterprise hardening; policy enforcement; configuration governance; defense against local override.
===============
Submit