Claude Code Governance Lockdown — Bluefly Agent Platform¶
Core Insight¶
Claude Code enforcement is NOT markdown. It is: managed settings + plugin-only customization + sandbox + hooks + MCP Tool Search + tool-restricted subagents + policyHelper.
CLAUDE.md is guidance. Settings/hooks/policies are enforcement.
Priority Build Packets¶
P0: Managed Policy Baseline¶
managed-settings.jsonwith deny/ask/allow permission tiers- Sandbox with filesystem + network boundaries
strictPluginOnlyCustomization+allowManagedPermissionRulesOnly
P1: Bluefly Claude Plugin¶
- Skills: gascity-work-authority, drupal-ddev-validation, openclaw-gateway-operations, closeout-contract
- Agents: bluefly-build-operator, drupal-validator, gas-town-release-gatekeeper
- Hooks: gascity-session-start, bead-required-pretooluse, protected-path-pretooluse, config-change-auditor
P2: Gas City Policy Helper¶
/usr/local/bin/bluefly-claude-policy— computes managed settings from Oracle Gas City authority- Inputs: cwd, git remote, repo trust class, active bead, user identity, machine role
P3: Context Budget Profile¶
Implements Claude Code context window
together with llms.txt v2 and AGENTS.md.
See documentation-governance-standard.md §6 for the repository file contract.
ENABLE_TOOL_SEARCH=auto:5- MCP alwaysLoad audit
- Path-scoped
.claude/rules/(load on matching file reads; they do not survive/compactunless unscoped) CLAUDE.mdis the Claude Code auto-load surface: thin pointer toAGENTS.md, hard cap 200 lines (context window). Prefer a pointer plus only the rules that must survive compaction. Do not paste catalogs. Operating law lives inAGENTS.md.
P4: Delivery Pressure Hooks¶
- PostToolBatch drift detector
- SessionEnd closeout reporter
- ConfigChange auditor
Highest-Leverage Settings¶
1. Managed Settings (real lock, not CLAUDE.md)¶
Location:
- macOS: /Library/Application Support/ClaudeCode/managed-settings.json
- Linux/Oracle: /etc/claude-code/managed-settings.json
Managed settings outrank everything — command-line overrides, user settings, project settings.
2. strictPluginOnlyCustomization¶
Blocks skills, agents, hooks, MCP servers from user/project sources. Only plugin or managed sources allowed.
{
"strictPluginOnlyCustomization": ["skills", "agents", "hooks", "mcp"],
"strictKnownMarketplaces": [
{
"source": "github",
"repo": "blueflyio/claude-code-plugins"
}
]
}
Requires Claude Code v2.1.82+.
3. allowManagedPermissionRulesOnly¶
Blocks user/project settings from defining allow/ask/deny. Only managed rules apply.
{
"allowManagedPermissionRulesOnly": true,
"allowManagedHooksOnly": true,
"allowManagedMcpServersOnly": true
}
4. policyHelper — Dynamic Policy from Gas City¶
Admin-deployed executable that computes managed settings at startup. Claude Code only honors it from managed locations.
{
"policyHelper": {
"path": "/usr/local/bin/bluefly-claude-policy"
}
}
If it exits nonzero, Claude refuses to start.
5. Sandbox (real file/network boundary)¶
Permission deny rules do NOT cover arbitrary subprocesses. Sandbox does.
{
"sandbox": {
"enabled": true,
"failIfUnavailable": true,
"autoAllowBashIfSandboxed": true,
"allowUnsandboxedCommands": false,
"filesystem": {
"denyRead": ["~/.ssh", "~/.aws", "~/.config/op", "//**/.env", "//**/.env.*"],
"denyWrite": ["/", "~", "./UPstreams-DO-NOT-HACK", "./vendor", "./node_modules", "./.git"]
},
"network": {
"allowedDomains": ["gitlab.com", "*.gitlab.com", "packagist.org", "*.drupal.org", "registry.npmjs.org"],
"deniedDomains": ["api.openai.com"]
}
}
}
6. Hooks (deterministic gates, not advice)¶
Four hooks only: - SessionStart: inject Gas City authority state + active bead - UserPromptSubmit: classify packet type + required authority - PreToolUse: block forbidden mutations deterministically - PostToolBatch: detect drift, broad edits, unexpected staged files
7. MCP Tool Search (token saver)¶
{
"env": {
"ENABLE_TOOL_SEARCH": "auto:5"
}
}
Only tool names load at session start. Schemas load when needed.
8. Tool-Restricted Subagents¶
agents:
drupal-builder:
tools: [Read, Glob, Grep, Edit, Write, Bash]
model: sonnet
policy-reviewer:
tools: [Read, Glob, Grep]
model: fable
release-gatekeeper:
tools: [Read, Glob, Grep, Bash]
model: sonnet
docs-curator:
tools: [Read, Glob, Grep, Edit]
model: haiku
9. Thin Main Thread Pattern¶
The hidden gem: Don't optimize the giant session. Stop creating giant sessions.
Main thread = operator/control only. Subagents = disposable heavy work. Focused compaction after every gate.
Main thread holds ONLY:
- current packet
- active Oracle bead
- branch
- approval gates
- next action
- blockers
Subagents handle:
- large file inspection
- broad grep
- upstream research
- test log triage
- diff review
- return limit: 40 lines
Complete Managed Settings Baseline¶
{
"$schema": "https://json.schemastore.org/claude-code-settings.json",
"minimumVersion": "2.1.173",
"autoUpdatesChannel": "stable",
"strictPluginOnlyCustomization": ["skills", "agents", "hooks", "mcp"],
"strictKnownMarketplaces": [
{
"source": "github",
"repo": "blueflyio/claude-code-plugins"
}
],
"allowManagedPermissionRulesOnly": true,
"allowManagedHooksOnly": true,
"allowManagedMcpServersOnly": true,
"permissions": {
"defaultMode": "dontAsk",
"disableBypassPermissionsMode": "disable",
"disableAutoMode": "disable",
"deny": [
"Edit(**/UPstreams-DO-NOT-HACK/**)",
"Write(**/UPstreams-DO-NOT-HACK/**)",
"NotebookEdit(**/UPstreams-DO-NOT-HACK/**)",
"Read(//**/.env)",
"Read(//**/.env.*)",
"Read(//**/secrets/**)",
"Bash(*doctor --fix*)",
"Bash(*--dangerously-skip-permissions*)",
"Bash(*rm_rf_governed*)"
],
"ask": [
"Bash(git push *)",
"Bash(glab mr merge *)",
"Bash(*systemctl restart*)",
"Bash(*openclaw gateway restart*)",
"Bash(*dolt sql*)",
"Bash(*drush cex*)"
],
"allow": [
"Bash(git status*)",
"Bash(git diff*)",
"Bash(git log*)",
"Bash(git fetch*)",
"Bash(npm test*)",
"Bash(npm run lint*)",
"Bash(npm run typecheck*)",
"Bash(composer validate*)",
"Bash(ddev describe*)"
]
},
"sandbox": {
"enabled": true,
"failIfUnavailable": true,
"autoAllowBashIfSandboxed": true,
"allowUnsandboxedCommands": false,
"filesystem": {
"denyRead": ["~/.ssh", "~/.aws", "~/.config/op", "//**/.env", "//**/.env.*", "//**/secrets/**"],
"denyWrite": ["/", "~", "./UPstreams-DO-NOT-HACK", "./vendor", "./node_modules", "./.git"]
},
"network": {
"allowedDomains": ["gitlab.com", "*.gitlab.com", "packagist.org", "*.drupal.org", "registry.npmjs.org", "*.npmjs.org"],
"deniedDomains": ["api.openai.com"],
"allowLocalBinding": true
}
},
"env": {
"ENABLE_TOOL_SEARCH": "auto:5",
"OTEL_LOG_TOOL_DETAILS": "0",
"OTEL_LOG_TOOL_CONTENT": "0",
"OTEL_LOG_RAW_API_BODIES": "0"
},
"cleanupPeriodDays": 7
}
Repo CLAUDE.md (Target: <10 lines)¶
# Bluefly Runtime Contract
Oracle Gas City is work authority.
Mac is workstation only.
DDEV is validation only.
Drupal is implementation/presentation target.
UPstreams-DO-NOT-HACK is read-only reference.
Procedures live in skills. Enforcement lives in managed settings/hooks.
Token Discipline Lock (paste into agent instructions)¶
Main thread is operator/control only. Do not load large files, full logs, broad grep output, or upstream docs into the main context.
Use disposable subagents for heavy discovery and return only: conclusion, exact files/line ranges, commands run, validation evidence, next action.
Keep MCP Tool Search enabled with ENABLE_TOOL_SEARCH=auto:5. Do not always-load large MCP servers.
After every major gate, run focused compaction: keep only packet, Oracle bead, branch, files changed, tests, approval gates, blockers, and next command.
Reports over 40 lines are failures unless explicitly requested.