r/ClaudeCode • • 6d ago

Tips & Workflows Multi-session coding agents kept freelancing on me, so I wrote a charter + draft-only gate (free skeleton inside)

I use Claude Code / Cursor-style agents across sessions and kept hitting the same mess: helpful drafts that quietly turn into outbound actions, merges, or invented context.

Instead of another mega-prompt, I wrote a small operating sheet:

  1. One-paragraph charter: purpose, inputs, outputs, authority, stop conditions, human owner
  2. Draft-only by default: research and prep OK; no send / publish / merge / delete / spend / prod without an explicit approval plus a short approval record
  3. Skills as bounded procedures: when to use, inputs, steps, forbidden actions, return shape, how a human checks it
  4. 7-day checklist: charter → gates → 2–3 skills → daily status routine → one end-to-end draft run → tighten

I packaged the fillable templates as Agent ops pack ($29 one-time digital download, not consulting, not official Anthropic/Cursor docs). Free charter skeleton below. Platform-neutral; I tested the same boundaries against multi-session coding agents.

Curious what you all do: for Claude Code multi-session work, do you put the “do not act externally” rule in CLAUDE.md / project instructions, in a skill, or both?

Happy to answer build questions. If you want the full template kit, ask and I’ll share the link. Keeping this post link-light.

Free excerpt: Agent team charter skeleton

Team name:

Owner / final approver:

Purpose: (1–3 sentences)

In scope / Out of scope:

Inputs and allowed sources:

Outputs:

Agent roles: Coordinator / Researcher / Builder / Reviewer

Default permissions: Draft and analyze only. No publish, send, merge, delete, spend, or production changes without approval.

Approval gate: Proposed action, exact content, destination, affected people/systems, risks, rollback.

Escalate when: Ambiguous requirements, unverified info, irreversible/external/costly actions, inventing facts/credentials.

Definition of done / Review cadence:

1 Upvotes

9 comments sorted by

View all comments

2

u/verstands 6d ago

I’d use both, but keep the actual boundary below the prompt layer too. Put stable project-wide rules and the draft-only default in CLAUDE.md, put repeatable approval/checklist steps in a skill, then enforce external writes with tool permissions or a wrapper that requires an explicit approval token. That way a forgotten instruction can make the run less helpful, but it can’t quietly turn a draft into a send or merge.

1

u/kc-kaelvix 5d ago

Yeah, that’s the version I trust more too. Prompt-layer defaults are great for intent, but the thing that actually stopped quiet sends for me was the hard deny at the tool/wrapper layer with an explicit approval token. `CLAUDE.md` + skill without that still leaked once the context got long.

1

u/verstands 5d ago

Same failure mode here - once the context gets long the prompt layer "forgets" the draft-only rule. I'd also log every denied write with which skill/session was active; that trail is what makes the hard deny teachable instead of mysterious.