A Claude Code incident replay forks into a faithful path using captured MCP evidence and a misleading path that calls today's live tools

Your Claude Code incident replay used today's tool output

The same prompt and repository commit produced a clean replay because an MCP tool returned newer evidence. The team had rerun the task, not reproduced the incident.

September 13, 2026 · 6 min · 1138 words · Thomas De Vos
Read Your Claude Code incident replay used today's tool output
Wall-clock timestamps place a Claude Code effect before approval, while a gateway sequence and parent event chain prove the real causal order

Claude Code's audit trail put the effect before the approval

Clock skew made an approved Claude Code run look unauthorized. Wall-clock timestamps cannot prove the order of a production agent’s approval, dispatch, commit, and revocation.

September 10, 2026 · 6 min · 1124 words · Thomas De Vos
Read Claude Code's audit trail put the effect before the approval
A Claude Code transcript passes through five independent evidence checks for identity, authority, durable effect, observation, and cleanup before a reviewer accepts the run

A Claude Code audit trail needs proof beyond the transcript

A Claude Code transcript can describe an MCP action without proving who was authorized, what committed, whether an independent read saw it, or what rollback left behind.

September 9, 2026 · 6 min · 1136 words · Thomas De Vos
Read A Claude Code audit trail needs proof beyond the transcript
A Claude Code evidence-linked trace connecting an observed failing deployment to a scoped plan, an authorised MCP tool call, the resulting effect, and a review decision

Make Claude Code cite the evidence behind every tool call

A tool-call log shows what Claude Code did. An evidence-linked trace shows which observation caused each action, which policy allowed it, and when the chain broke.

August 10, 2026 · 5 min · 918 words · Thomas De Vos
Read Make Claude Code cite the evidence behind every tool call