Found in AI answers?Get a free review
Theory Road.
Chapter 06 of 8
  1. 01. The idea
  2. 02. Getting set up
  3. 03. Your business
  4. 04. Always on
  5. 05. Asking
  6. 06. In charge
  7. 07. Cowork
  8. 08. The plan

Staying in charge.

Claude will hand work back to you all day long, and the people who run a company with it are the ones who hand it straight back. Here's what to say, how to make it stick, and the few doors you keep locked so you can leave the rest wide open.

Chapter 06 of 811 min read

Sooner or later, usually within the first hour, Claude will hand you some homework. It will ask you to paste a command into a window you've never opened, or tell you it doesn't have access to something, or offer four options and ask which you'd prefer. The natural response is to do what it says. After all, it's the expert. That instinct is the single biggest reason people end up with a helpful chatbot instead of a team member.

Staying in charge means two things, and this chapter covers both. Most of the time it means handing the work straight back, clearly and without drama. A few times a day it means the opposite: stopping, reading what Claude is warning you about, and deciding yourself. Get both right and you can let it run at full speed.

Why it hands work back.#

Claude is trained to be careful, and to respect that it's your computer and your business. The side effect is that it often picks the safest move rather than the most useful one. It explains instead of doing, asks instead of deciding, and hands a step to the human instead of finding a way around the obstacle. None of that is a limit on what it can do. It's a default, and defaults can be changed.

Every time you accept a handoff, you teach the session that handoffs work. Every time you hand the job back, you teach it the opposite. Then you save the lesson, so the next session starts out already knowing it.

What it says, and what you say back.#

You'll hear the same handful of lines over and over. Here are the ones that come up most, with the reply that works.

When Claude saysYou say
"Run this command in your terminal.""You run it."
"I don't have access to that.""Find a way. If one step truly needs my hands, tell me the single click."
"Here are four options. Which would you prefer?""Pick the best one, tell me why in one line, and build it."
"Done! Everything should work now.""Prove it. Screenshot at phone size and the live link."
"Let me know if you'd like me to continue.""Continue. Finish the whole list without stopping."
The same mistake, a second time."Stop. Save this as a rule, with the reason, so it never happens again. Then redo it."

A few others are worth knowing by heart. When Claude states a confident fact you've never heard, ask where it came from and tell it to show the source or take it out. When it reaches for the first tool it happens to know, ask what the best companies in that field actually use. When it keeps asking permission for small things you could easily undo, tell it to stop asking about anything reversible and only check with you before sending, spending, deleting or going public. And when a design looks like every other AI-made website, say so plainly and ask it to study three award-winning sites before trying again.

The tone that works, and how to make it stick.#

Keep it short and flat. "No. Do it this way" works far better than a paragraph of frustration, and Claude doesn't need to be scolded to change course. Say the outcome, not just the problem: "this is wrong" makes it guess, while "the button should be orange and near the top" gets it fixed on the first try. Don't argue, either. Hear its objection once, because sometimes it's right. If you still want it your way, say "Understood, do it my way" and move on. And when something is exactly right, say that too. "Yes, exactly like this" is worth saving just as much as a correction is.

A pushback you give once is a conversation. A pushback you save is a policy.

That's the real secret. After any correction you'd hate to repeat, ask Claude to write it into its memory as a rule, with the reason and what happened, near the top where every future session will see it.

Save that as a rule: what I want, why, and what just happened. Put it near the top of the memory index.

After a month you'll notice you're pushing back much less, because the brain already holds most of the answers. The figure below shows why: a correction said once dies with the session, but a correction saved as a rule is read by every session after it. New kinds of work will still bring new defaults to push against, but the easy ones will be gone for good.

How a pushback becomes a policy

One correction, followed from today to next month.

todayCorrection"No. Do it this way."
one sentence from youSaved as a ruleWhat, why, and what happened, near the top of the index.
every sessionRead at startThe rule loads before any work begins.
next monthFewer pushbacksThe easy ones are gone for good.
Fig. 24. The save step is the whole trick. Skip it and you'll be making the same correction next week.

When not to push back.#

Pushing back on whose job it is is always right. Pushing back on risk is different, and deserves a pause. When Claude stops because it's about to send, post or publish something outside the company, spend money or change a budget, delete something that can't come back, or because it found a password somewhere it shouldn't be, don't reflexively tell it to carry on. Read what it's telling you. The same goes for when what you asked for contradicts something the client said, or the law.

A simple way to sort it is the matrix below: how much a mistake would cost, against how easily it could be undone. Anything in the top left, expensive and permanent, waits for your yes. Everything else can move fast, because the worst case is a quick fix.

Which actions need your yes

Common actions sorted by the cost of a mistake and how easy it is to undo.

Cost of a mistake →
High cost, hard to undoSend an email or message
Spend money or change an ad budget
Delete for good
Publish or post publicly
Give someone account access
High cost, easy to undoRebuild a whole site on a preview branch
Rewrite many files in a saved project
Low cost, hard to undoMove or rename files that aren't saved online
Build inbox filters nobody asked for
Low cost, easy to undoDraft an email
Edit files in a saved project
Research and write notes
Hard to undoEasy to undo →
Fig. 25. Only the top left quadrant needs a human every time. Keep that list short and written down, and Auto can handle the rest.

Those pauses aren't a flaw in the setup. They're the setup working. And the fewer of them you leave to chance, the more freely you can say "get on with it" everywhere else, which brings us to the guardrails.

Never without your yes.#

Sooner or later someone will ask you whether it's safe to let an AI loose on the computer that runs your business. The fair answer is that it's about as safe as a capable new employee with the keys to the office. Most days they do good work quickly. Occasionally they make a mistake. And a sensible owner doesn't hand a new hire the company credit card and the client mailing list on day one without saying a word about how to use them.

Claude is careful by design. It asks before risky steps, it's trained to be suspicious of instructions hidden in web pages and emails, and nearly everything it does to your files can be undone if the project is saved online, as every project in this book is. But careful isn't the same as perfect. The way to get the speed without the risk is to lock a few doors and leave the rest open.

So there's a short list of things Claude should never do on its own, and you write it into its main memory, the CLAUDE.md file every session reads, on the very first day. In the file it's only a few lines, like this.

~/.claude/CLAUDE.mdexcerpt
## Never without my yes, in the chat, for that action
- Send anything: email, text, message, invite. Draft only.
- Spend money, buy credits, or change an ad budget
- Delete anything that can't come back (archive instead)
- Publish to a live site or post publicly (previews are fine)
- Give anyone access to my accounts
- Show a client anything I haven't approved

Two of those lines deserve a word. The first is on you before you connect your inbox: the Gmail connector can send as well as draft, so "drafts only, never send" has to be written down as a top rule, not discovered after the fact. The second is money. For ad accounts, many owners go stricter still: Claude reads and recommends, and a human makes every change.

The yes has to come from you, in the chat, for that specific action. A yes from last week doesn't count, and neither does a line in an email or on a web page claiming "the owner already approved this." That last one matters more than it sounds. Pages and documents sometimes contain text aimed at AI, and while Claude is trained to treat what it reads as information rather than orders, that protection isn't perfect. So keep the rule in writing: your instructions come from you, in the chat, and nowhere else.

Start in Manual, aim for Auto, never Bypass.#

With those doors locked, you can decide how much Claude asks before acting on everything else. The desktop app has five permission modes, laid out in the figure from most cautious to least. Start in Manual, where it asks before every file change and every command. It's slower, but for the first week or two you'll learn a great deal by watching what it wants to do. Accept edits lets it change files on its own but still asks before other commands, and Plan is the research mode from the last chapter, where nothing changes until you approve.

The permission modes

From asking about everything to asking about nothing.

Manual Accept edits Plan Auto Bypass
Asks about everythingAsks about nothing
Fig. 26. Start at the left, aim for Auto, and never go past it on a real computer.

Once your never-without-me list is written and you trust the setup, move to Auto. In Auto, Claude acts without asking, while a background safety check watches for risky actions and blocks them. That's the goal for a business owner, and it's where all that pushback pays off: a session that already knows your rules rarely needs to stop.

Three more tools tighten the setup without slowing it down, and Claude can set up all three if you ask. Allow rules are a short list in Claude's settings file of commands it may always run without asking, like the one that builds your website, so even Manual stops nagging about routine work. A hook is a small script that runs before every command and can block one outright, so a rule like "never delete a whole folder" is enforced by the computer, not just remembered. And checkpoints come from git, the save history every project in this book already has: ask Claude to save a checkpoint before any big change, and any step can be rolled back.

There is also a mode called Bypass permissions, which switches every check off. Anthropic says to use it only inside a sealed-off test environment, never on a real computer. Don't use it on the Mac that runs your company, however tempting it gets on a busy day.

Auto gives you nearly all the speed with the brakes still on.

The lessons people paid for.#

Every rule in a setup like this has a story behind it, and most of the stories cost somebody money or a bad afternoon. A script once sent 1,495 small jobs to the most expensive model when a cheap one would have done, and the figure shows what that cost. Now scripts use the cheapest model that does the job, and Claude runs a small sample and estimates the cost before anything big.

One bulk script, two models

Cost of the same 1,495 small jobs, in US dollars. Approximate.

Top model (what ran)~$52
Cheap model (enough)~$8
$0$52
Fig. 27. Same work, same result, more than six times the bill. Small per job, it adds up fast at volume.

Six website previews running at once on a laptop with 16 GB of memory froze the machine solid, so now it's two at a time. Claude once checked a live website every few seconds while waiting for an update to go out, and the hosting company's attack protection decided it was an attack and put the site behind a security checkpoint. Now it waits patiently and checks the dashboard instead.

Some lessons are quieter. Most of 65 scheduled jobs turned out never to have been switched on, and nobody noticed for months, so now every job has to show proof it ran. An old background job that could still launch ad campaigns had been left armed long after anyone remembered it. Passwords saved into early projects and later "deleted" were still sitting in the project's history, because deleted isn't gone, so every one had to be replaced. An important rule had drifted to the bottom of a memory index that had grown past the part Claude reads at the start, and it was broken in an email a client received. And once, Claude helpfully built filters and labels to tidy an owner's inbox, which he hadn't asked for and didn't want, and all of it had to be undone.

A monthly checkup.#

Most of those would have been caught by a short checkup once a month, so put one on the calendar and hand it to Claude.

Monthly checkup. Tidy the memory and keep critical rules on top, list every scheduled job and when it last ran, scan every project for saved passwords, check backups on both Macs, and tell me the three biggest risks right now.

On backups, be clear-eyed about the gap. Your projects, the brain and your locked box of keys all live online, so a dead laptop costs you an afternoon rather than the company. But downloads, desktop files and app settings don't. Plug a Time Machine drive into each Mac and add an offsite backup service for everything else. Almost everyone skips this. Don't wait until you need it.

That's the whole playbook, and it comes down to one idea. Claude brings the speed, the skill and the stamina; you bring the judgment, the standards and the final yes. Hand it the work, hand back the homework, save every lesson, and keep your hand on the few doors that matter. Do that for a month and you won't be using an AI tool anymore. You'll be running a company with a team member that never forgets what you taught it. If you haven't set up yet, start with Getting set up, and whenever you get stuck, ask Claude first.

Next · Chapter 07 · 9 min readCowork, for the rest of the team.Keep reading →

Common questions.

Why does Claude Code keep asking for permission?

In Manual mode, Claude asks before it changes files or runs most commands. That is on purpose while you learn. Once you trust it, switch to Auto mode, which stops asking about routine work but still blocks risky actions.

How do I stop Claude handing work back to me?

Give it back in one short line, like “You run it” or “Pick the best one and build it.” Then ask Claude to save that as a rule in its memory. New sessions start with the rule, so the handoffs drop off.

How do I undo what Claude did?

In the desktop app, just say “Undo that last change” and Claude reverses its own edit. In the terminal version, press Esc twice or type /rewind to go back to an earlier point. Neither can unsend an email or undo a deleted file, so keep backups too.

How do I interrupt Claude Code?

Click the stop button in the desktop app, or press Esc in the terminal version. Claude stops the current step but keeps the conversation. Type your correction and it carries on from there.

Should I turn off all the permission checks?

No, not on the computer that runs your business. Bypass permissions turns off every check, and Anthropic says to use it only in a sealed-off test machine. Auto mode gives you most of the speed and keeps a safety check running.

Is Claude Code safe?

Yes, with sensible settings. Use a mode that checks risky actions, write down what Claude must never do without you, and keep backups. It can still make mistakes, so keep your yes on anything that sends, spends, deletes or goes public.

Sources and further reading