Claude Code compacts its conversation while an external control-state checkpoint preserves authority, denied actions, pending effects, and evidence bindings

Keep Claude Code's safety state outside its context window

Context compaction can preserve the task while losing the decision that blocked a dangerous tool call. Store authority, denials, and unresolved effects in a control checkpoint outside the transcript.

August 23, 2026 · 5 min · 989 words · Thomas De Vos
Read Keep Claude Code's safety state outside its context window
Three individually valid Claude Code MCP reads are rejected because their source versions form a mixed production snapshot

Reject a Claude Code plan built from a mixed snapshot

Claude Code can read three correct facts and still build a plan for a system state that never existed. Record a coherent read set and reject evidence that crosses a consistency boundary.

August 21, 2026 · 5 min · 898 words · Thomas De Vos
Read Reject a Claude Code plan built from a mixed snapshot
A human approval becomes a single-use capability bound to one Claude Code operation, and the tool gateway rejects any replay after redemption

Treat Claude Code approval as a single-use capability

A human approval should authorize one exact Claude Code effect, not every retry that follows. Issue a single-use capability and record its redemption at the tool gateway.

August 20, 2026 · 5 min · 931 words · Thomas De Vos
Read Treat Claude Code approval as a single-use capability
MCP tool output is labelled untrusted, reduced to evidence, checked against the original Claude Code scope, and recorded in a reviewable trace

Do not let MCP tool output rewrite Claude Code's instructions

An MCP response can contain instruction-shaped text that pushes Claude Code beyond its approved task. Put a trust boundary between tool evidence and agent authority.

August 17, 2026 · 6 min · 1129 words · Thomas De Vos
Read Do not let MCP tool output rewrite Claude Code's instructions
A Claude Code stop request revokes run authority, drains queued MCP work, reconciles in-flight effects, and produces a verified stop receipt

Stopping Claude Code does not cancel queued MCP work

A stopped Claude Code run can leave queued MCP calls and provider jobs alive. Use a cancellation barrier to revoke authority, drain pending work, and prove the run is quiet.

August 16, 2026 · 6 min · 1207 words · Thomas De Vos
Read Stopping Claude Code does not cancel queued MCP work
A Claude Code run pins an MCP capability manifest and stops when the live server schema, implementation, target scope, or side effects differ

Pin the MCP tool contract before Claude Code uses it

An MCP method can keep the same name while its schema, target scope, or side effects change. Pin a capability manifest so Claude Code cannot inherit a different tool after approval.

August 12, 2026 · 6 min · 1090 words · Thomas De Vos
Read Pin the MCP tool contract before Claude Code uses it
A Claude Code permission workflow where request, grant, and evidence lead to automatic expiry

Claude Code permissions need expiry dates

Claude Code permissions are safest when they are temporary. Treat every extra file, command, MCP tool, and network path as a task-scoped grant that must expire unless a human renews it with evidence.

May 26, 2026 · 6 min · 1134 words · Thomas De Vos
Read Claude Code permissions need expiry dates