Defense in Depth with Layered Mechanisms (Principle)

Description

Design principle #3. Answers 'Single safety boundary, or multiple overlapping ones using different techniques?' Claude Code stacks seven independent safety layers (tool pre-filter, deny-first rules, mode constraints, ML auto-mode classifier, shell sandbox, non-restoration of session permissions on resume, hook-based interception). Serves Safety, Authority, and Reliability.

Key claims

Relations

Sources

src-20260423-0cff68d3291b src-20260423-fd74bb3399e6