Diagram showing Claude Code MCP blast radius controls with allowed tools, write scope, audit trail, and approval gate

Claude Code MCP tools need a blast radius

MCP tools make Claude Code far more useful, but broad access turns a weak prompt into a production risk. Treat every tool as blast radius, not convenience.

May 18, 2026 · 7 min · 1361 words · Thomas De Vos
Read Claude Code MCP tools need a blast radius
Diagram showing Claude Code cost loop controls: task budget, retry evidence, stop rule, and human review

Claude Code cost loops start as helpful retrying

Claude Code can waste more than tokens when it keeps retrying a weak task. Production teams need budgets, stop rules, and evidence before another agent attempt is allowed.

May 17, 2026 · 6 min · 1192 words · Thomas De Vos
Read Claude Code cost loops start as helpful retrying
Diagram showing a Claude Code handoff record from task boundary to patch evidence, risk note, rollback, and reviewer decision

Claude Code handoffs fail when the run record is vague

Claude Code can produce a working patch and still leave the next human with a weak handoff. Production teams need run records that show scope, evidence, risk, and rollback before review turns into archaeology.

May 16, 2026 · 6 min · 1275 words · Thomas De Vos
Read Claude Code handoffs fail when the run record is vague
Cover of Securing Enterprise AI Agents by Thomas De Vos

Securing Enterprise AI Agents is live

I published Securing Enterprise AI Agents, a practical book on bounded AI autonomy, AgentSecOps, MCP security, RAG governance, identity, evals, policy, and evidence.

May 15, 2026 · 3 min · 466 words · Thomas De Vos
Read Securing Enterprise AI Agents is live
Diagram showing Claude Code permissions as a control loop: scope first, run narrow, leave evidence, and adjust access

Claude Code review is too late if permissions are wrong

Human review matters, but it cannot fix every bad Claude Code boundary after the run. Production teams need scoped permissions, MCP limits, hard stops, and evidence before widening access.

May 15, 2026 · 6 min · 1262 words · Thomas De Vos
Read Claude Code review is too late if permissions are wrong
Diagram showing that Claude Code output needs a run record before it is reviewable

Claude Code output is not evidence

Claude Code patches can look ready before they are reviewable. Production teams need a run record with task boundaries, commands, checks, risks, and rollback notes.

May 14, 2026 · 6 min · 1222 words · Thomas De Vos
Read Claude Code output is not evidence
Diagram showing a Claude Code permission budget across scope, tools, spend, and approval

Claude Code permissions should have a budget

Claude Code gets safer when permissions are treated like a budget: scoped files, allowed tools, spend limits, stop rules, review packets, and rollback notes before wider autonomy.

May 13, 2026 · 6 min · 1264 words · Thomas De Vos
Read Claude Code permissions should have a budget
Diagram showing the operating gap between an AI POC and production AI

From AI POC to production: the part teams keep skipping

The AI POC is not the hard part anymore. The hard part is turning a promising demo into a service with ownership, evals, traces, cost controls, and a rollback path.

May 12, 2026 · 7 min · 1336 words · Thomas De Vos
Read From AI POC to production: the part teams keep skipping
Diagram showing metric-only LLM observability versus a replayable production AI trace

LLM observability is not a dashboard. It is a replayable trail.

A latency chart will not explain why an AI answer was wrong. Production LLM systems need traces, sources, tool calls, prompt versions, eval results, and human decisions.

May 10, 2026 · 4 min · 812 words · Thomas De Vos
Read LLM observability is not a dashboard. It is a replayable trail.
A Claude Code review packet showing objective, permission boundary, tool trace, tests, cost, and rollback path before human approval

The Claude Code review packet I want before approving agent work

A Claude Code diff is not enough evidence for production review. Ask for the objective, permission boundary, tool trace, tests, failures, cost, and rollback path before approving agent work.

May 4, 2026 · 7 min · 1299 words · Thomas De Vos
Read The Claude Code review packet I want before approving agent work