A Claude Code incident replay forks into a faithful path using captured MCP evidence and a misleading path that calls today's live tools

Your Claude Code incident replay used today's tool output

The same prompt and repository commit produced a clean replay because an MCP tool returned newer evidence. The team had rerun the task, not reproduced the incident.

September 13, 2026 · 6 min · 1138 words · Thomas De Vos
Read Your Claude Code incident replay used today's tool output
Wall-clock timestamps place a Claude Code effect before approval, while a gateway sequence and parent event chain prove the real causal order

Claude Code's audit trail put the effect before the approval

Clock skew made an approved Claude Code run look unauthorized. Wall-clock timestamps cannot prove the order of a production agent’s approval, dispatch, commit, and revocation.

September 10, 2026 · 6 min · 1124 words · Thomas De Vos
Read Claude Code's audit trail put the effect before the approval
A Claude Code transcript passes through five independent evidence checks for identity, authority, durable effect, observation, and cleanup before a reviewer accepts the run

A Claude Code audit trail needs proof beyond the transcript

A Claude Code transcript can describe an MCP action without proving who was authorized, what committed, whether an independent read saw it, or what rollback left behind.

September 9, 2026 · 6 min · 1136 words · Thomas De Vos
Read A Claude Code audit trail needs proof beyond the transcript
A Claude Code request for staging is blocked when the MCP gateway reveals that an adapter default would execute it against production

Claude Code asked for staging. The MCP adapter defaulted to production

A reviewer approved a staging MCP request, but the adapter filled an omitted environment with production. Authorize the normalized payload that will actually execute.

September 2, 2026 · 4 min · 843 words · Thomas De Vos
Read Claude Code asked for staging. The MCP adapter defaulted to production
Claude Code receives the first 100 of 8,742 records, follows every cursor against one snapshot, and produces a collection completeness receipt

Claude Code checked the first page and called the job done

An MCP tool returned 100 clean records, so Claude Code declared a migration complete. The other 8,642 records were still waiting behind a cursor.

August 29, 2026 · 5 min · 889 words · Thomas De Vos
Read Claude Code checked the first page and called the job done
A secret enters a Claude Code run, a data boundary replaces it with a safe reference, and a propagation receipt verifies every downstream surface

Claude Code redacted the secret after it had already spread

Redacting Claude Code’s final answer does not remove a secret from tool logs, traces, caches, and review packets. Track sensitive data through the whole run with a propagation receipt.

August 28, 2026 · 5 min · 971 words · Thomas De Vos
Read Claude Code redacted the secret after it had already spread
A Claude Code run completes while a cleanup gate revokes a temporary cloud role, token, and MCP session before handoff

Claude Code finished. Its temporary cloud access did not

A completed Claude Code run can leave cloud roles, tokens, and MCP sessions behind. Require a cleanup receipt that proves temporary authority has gone.

August 27, 2026 · 5 min · 980 words · Thomas De Vos
Read Claude Code finished. Its temporary cloud access did not
A timed-out Claude Code MCP request leaves a paid remote job running while a guarded retry looks up the operation and attaches to the existing job

Claude Code timed out, retried, and paid twice

A timed-out MCP call may still be running and charging your account. Give paid tool operations a stable ID, a spend ceiling, and a retry receipt before Claude Code tries again.

August 26, 2026 · 5 min · 1022 words · Thomas De Vos
Read Claude Code timed out, retried, and paid twice
A Claude Code patch enters an independent evidence review before the agent explanation is revealed in a second pass

Do not let Claude Code explain its patch to the evaluator first

A polished Claude Code handoff can anchor the reviewer before the evidence is checked. Give an independent evaluator the task contract, patch, and raw test results first, then reveal the agent’s explanation.

August 25, 2026 · 5 min · 997 words · Thomas De Vos
Read Do not let Claude Code explain its patch to the evaluator first
A human approval becomes a single-use capability bound to one Claude Code operation, and the tool gateway rejects any replay after redemption

Treat Claude Code approval as a single-use capability

A human approval should authorize one exact Claude Code effect, not every retry that follows. Issue a single-use capability and record its redemption at the tool gateway.

August 20, 2026 · 5 min · 931 words · Thomas De Vos
Read Treat Claude Code approval as a single-use capability