A 34-Chapter Claude Code Operations Handbook Argues Only Two of Four Control Layers Are Actually Enforced
This handbook treats Claude Code as an agentic work environment with filesystem, shell, browser, scheduled and cloud execution, MCP connections and multi-agent orchestration, and argues its failure modes are systemic rather than local. Its four propositions: capability without a defined observable completion condition is not productivity; instruction, permission enforcement, sandboxing and OS isolation are four distinct layers of which only two are enforced, and conflating them is the most common cause of loss of control; third-party skills, plugins, marketplaces and MCP servers are supply-chain dependencies; and the correct unit of trust is observed evidence, not the agent's closing statement. Every product claim carries a primary-source citation, with unconfirmable claims labeled UNVERIFIED and controls mapped to seventeen external frameworks.
↳ Follow the thread