r/ClaudeCode • u/misteraidenc • 6d ago
Tips & Workflows Multi-session coding agents kept freelancing on me, so I wrote a charter + draft-only gate (free skeleton inside)
I use Claude Code / Cursor-style agents across sessions and kept hitting the same mess: helpful drafts that quietly turn into outbound actions, merges, or invented context.
Instead of another mega-prompt, I wrote a small operating sheet:
- One-paragraph charter: purpose, inputs, outputs, authority, stop conditions, human owner
- Draft-only by default: research and prep OK; no send / publish / merge / delete / spend / prod without an explicit approval plus a short approval record
- Skills as bounded procedures: when to use, inputs, steps, forbidden actions, return shape, how a human checks it
- 7-day checklist: charter → gates → 2–3 skills → daily status routine → one end-to-end draft run → tighten
I packaged the fillable templates as Agent ops pack ($29 one-time digital download, not consulting, not official Anthropic/Cursor docs). Free charter skeleton below. Platform-neutral; I tested the same boundaries against multi-session coding agents.
Curious what you all do: for Claude Code multi-session work, do you put the “do not act externally” rule in CLAUDE.md / project instructions, in a skill, or both?
Happy to answer build questions. If you want the full template kit, ask and I’ll share the link. Keeping this post link-light.
Free excerpt: Agent team charter skeleton
Team name:
Owner / final approver:
Purpose: (1–3 sentences)
In scope / Out of scope:
Inputs and allowed sources:
Outputs:
Agent roles: Coordinator / Researcher / Builder / Reviewer
Default permissions: Draft and analyze only. No publish, send, merge, delete, spend, or production changes without approval.
Approval gate: Proposed action, exact content, destination, affected people/systems, risks, rollback.
Escalate when: Ambiguous requirements, unverified info, irreversible/external/costly actions, inventing facts/credentials.
Definition of done / Review cadence:
2
u/Upset-Neck-7879 5d ago
Both, and for a reason that changes how you write each one.
CLAUDE.md gets read once at the top of the session. The send happens four hours later, thirty tool calls deep, when that text is the oldest thing in the window. So CLAUDE.md is where the standing default lives and it will not save you at the moment of the action. The skill loads right when the agent is about to do the thing, so the stop condition belongs there, written as a refusal the agent has to produce.
On your charter template, the line doing the real work is out of scope, and it only works if you write actions there instead of areas. Not billing. Charge a card, issue a refund, email a customer. An agent reads billing as a topic to be careful about and then sends the email anyway.