Claude Code restarted. Its old MCP worker kept writing.
A replacement worker does not silence the old one. Fence stale MCP writes at the resource boundary before a resumed job overwrites newer work.
Topic archive
19 essays tagged Permissions. Practical notes on what happens after the demo: prompts, tools, review packets, evals, rollback, and production ownership.
A replacement worker does not silence the old one. Fence stale MCP writes at the resource boundary before a resumed job overwrites newer work.
A saved snapshot can undo the agent’s change and somebody else’s repair. Make recovery conditional on the revision the agent wrote.
A reviewer approved a Claude Code change against resource version 41. By execution time, version 42 existed, but the MCP write replaced it anyway.
A permitted CI retry reached production through an artifact event and a more powerful release service. Tool permissions missed the effect that mattered.
Clock skew made an approved Claude Code run look unauthorized. Wall-clock timestamps cannot prove the order of a production agent’s approval, dispatch, commit, and revocation.
A Claude Code transcript can describe an MCP action without proving who was authorized, what committed, whether an independent read saw it, or what rollback left behind.
A stable operation ID can stop duplicate MCP writes while still allowing an action after its approval expires. Recheck authority where the effect occurs.
A new Claude Code run selected the right tenant, but its pooled MCP session kept the previous tenant context. Bind every session to the authority it carries.
A reviewer approved a staging MCP request, but the adapter filled an omitted environment with production. Authorize the normalized payload that will actually execute.
Revoking Claude Code access is useless if an MCP gateway keeps serving an old allow decision. Bind cached authorization to policy version, resource state, and a short expiry.