Module 03 — Advanced configuration

In this module

You'll know how to configure Claude Code in depth: manage the 5 settings scopes, lock down permissions with allow/ask/deny, enable sandboxing, leverage automatic memory, and tune the model's reasoning effort.

3.1 — The five configuration scopes

Claude Code doesn't read a single config file. It merges up to five layers, each with a different priority level. Understanding this hierarchy lets you predict exactly which setting will be active in any situation.

Priority hierarchy (highest to lowest)

Priority Scope File / Source Shared?
1 Managed managed-settings.json or managed-settings.d/ Enterprise (MDM)
2 CLI Flags --model, --permission-mode, etc. Session only
3 Local .claude/settings.local.json (project root) No (gitignored)
4 Project .claude/settings.json (project root) Yes (git-tracked)
5 User ~/.claude/settings.json No (global personal)

Merge rule

Scalar values (strings, booleans) are overwritten by the highest-priority scope. Arrays merge across scopes. Concretely, if the Project scope defines permissions.allow: ["Edit(*.kt)"] and the User scope defines permissions.allow: ["Bash(git status)"], the final result contains both entries.

Claude Code
# Check the final merge result at any time
/status

Key takeaways

• 5 scopes: Managed > CLI > Local > Project > User

• Scalars overwrite, arrays merge

• .claude/settings.json = team, .claude/settings.local.json = personal

• /status to inspect the effective configuration

In this module

  1. 3.1 — The five configuration scopes Available
  2. 3.2 — settings.json in practice
  3. 3.3 — The permissions system: allow, ask, deny
  4. 3.4 — Permission modes
  5. 3.5 — Sandboxing
  6. 3.6 — Automatic memory
  7. 3.7 — Choosing and configuring your model
  8. 3.8 — Environment variables and personalization
  9. 3.9 — Team configuration: Project and Managed
  10. 3.10 — Debugging your configuration with /status

Locked content

Unlock the full course to access this module.

Unlock

Already purchased? Recover access