
The agent runbook needs a buyer's question
AI agent teams often ask whether the demo worked. Buyers, auditors, and production owners ask a harder question: can we trust the run when authority, evidence, and rollback are visible?
Topic archive
47 essays tagged MCP. Practical notes on what happens after the demo: prompts, tools, review packets, evals, rollback, and production ownership.

AI agent teams often ask whether the demo worked. Buyers, auditors, and production owners ask a harder question: can we trust the run when authority, evidence, and rollback are visible?

Claude Code review packets and enterprise agent security are often treated as separate problems. They are two parts of the same operating stack: evidence for the work, boundaries for the authority.
Teams keep asking whether an AI agent is ready for more autonomy. A better question is whether the review path is clear enough before the next permission is added.
A good prompt can shape agent behavior, but production teams need a control plane around identity, tool scope, approval, logs, revocation, and review.
Production AI agents need a fast way to stop action and a plain receipt after every meaningful run. Without both, autonomy becomes trust without evidence.
Agent permissions that helped a pilot can become hidden production authority. Put expiry, renewal evidence, and removal paths around AI agents before access drifts.

For the Claude Architect exam, product knowledge helps, but boundary judgment matters more: tool scope, context provenance, permissions, review, and recovery.
AI agent demos fail quietly when teams hand them to real workflows without scope, authority, evidence, and rollback. This is where Claude Code practice and enterprise agent security meet.
Claude Code can start with a narrow task and end up with broad tool access. Treat permission changes like production changes: log them, review them, and tie them to rollback.
The hardest CCA-F distractors are often almost right. Learn to spot the architectural boundary they quietly cross.