Claude Operator: Prompt to Autonomy · 20 min · 140 XP
Bounding a run: directories, tools, and turns
Give a run exactly the reach it needs and no more.
Everything so far assumed you're watching. Once a run is unattended — a script, a scheduled job, anything non-interactive — the bounds have to be in the command instead of in your judgement. There are three worth knowing.
claude --add-dir ../shared # one extra folder, not the whole disk claude --allowedTools Read,Grep # a read-only investigation claude --disallowedTools Edit,Write # or block what isn't needed claude -p "audit the config" --max-turns 5
--add-dir extends the working directory to a named folder — the right tool when a task genuinely spans two projects. Add the one folder you need, not its parent. Note that it grants file access; it doesn't pull in most .claude/ configuration from that directory.
--allowedTools and --disallowedTools decide which tools exist for the run. An allow list is the stronger statement: Read,Grep describes an investigation that cannot edit, which is a different kind of promise from an investigation that has simply been asked not to. Reach for the allow list when you can name what's needed, and the deny list when you only want to remove something specific.
--max-turns caps how many agentic turns a print-mode run may take. It's the ceiling that stops a confused run from continuing indefinitely — the loop that can't find the file and keeps looking. --verbose is the companion for when a run does something surprising and you need to see why.
Practice. Grant access to exactly one additional safe folder and confirm nothing broader came with it. Run a read-only exercise with an explicit allow list, then repeat it with a deny rule blocking a tool the exercise doesn't need, and watch a denied action get refused while safe work continues. Bound a non-interactive practice run with --max-turns and observe how it stops. Turn on --verbose for one harmless run and name one thing it revealed.
Loading your workspace…