I work in financial services, which is a highly regulated space: we handle people’s banking data, and we plan to hold our own financial services licence. So obviously I have to be very careful about what I let an AI agent do. But what I’m building is an AI-native personal money agent, and the whole point of that is to take full advantage of what these tools can do. So there’s a tension there, not just in the solution we are building but in how I personally operate. I work within Claude Code day-in, day-out. So the issue for me personally is how I make the most of all of this while keeping a stringent risk posture?
In practice it has meant being pretty risk-averse when it comes to using Claude. This affects two things in particular: what parts of my computer it can get at, and what authority it has to do anything once it has access.
When I started out using Claude Code I set up a whole bunch of rules limiting both the scope of what it could touch and the level of authority it had to act. The consequence was that it used to ask me for permission… a lot.
Now in Claude Code that takes the form of a permission prompt: a pop-up (technical-looking) box that appears asking you to allow a specific action. And the really awkward thing, which frustrated me for ages before I worked out how to get used to it, is that the box sits over the top of the conversation.
I’d be in the middle of a discussion with Claude about something. It would respond with something like “okay, yes, I can go and do that.... blah blah”. And before I’d read more than the first line or two, the rest of the response, which might run to several paragraphs, would be obscured by the prompt. The more I worked with Claude Code, the more this got in the way, and the more frustrating it got.
Eventually I said: “Look, this isn’t working. These things are getting in the way of my understanding of the actual conversation, and furthermore I don’t even understand why they are happening so often. We need to do something about it.” (Actually I think my language may have been more colourful, but I prefer not to dwell on the past.)
The rule: explain before acting
The outcome was that I set up a new rule about how Claude tells me about anything it’s about to change that might need my consent.
Claude now has to present, in plain English, an explanation of what is about to happen and why. Then it has to stop and wait for me to say go. Only then does it act, which is when the prompt appears.
And that one thing changed a lot. The prompts were still there, but in an instant I wasn’t plagued by unexpected pop-ups getting in the way of reading the conversation. I had clarity about what was about to be done, because it had been explained to me before it was attempted. And when the prompts did appear, I was expecting them. Everything was understood, and the experience of working with Claude was substantially better.
Refining it
Now while that changed the experience of the approvals, the frequency was a separate matter, and after a while I started to tweak that too. I carved out some exemptions with Claude around a defined, limited set of routine activities which I pre-approved. So for those it doesn’t need to seek my permission before proceeding. It still tells me what changed, afterwards, but the prompts themselves have diminished.
Mind you, things go wrong sometimes. Claude once ran a publishing script which skipped the confirmation, so a broken version of an article went straight onto the website. I had to scramble to fix it up, which took a few minutes.
We tightened things up after that: anything reaching production, no matter what, requires my confirmation for that specific command.
What all of this helped with
I am pretty happy with all this. The conversational flow within Claude has improved a lot. And my understanding of what is happening has improved even more, along with my appreciation of, and confidence in, what is going on.
And all of it still sits within my fairly risk-averse posture. None of this would concern somebody who is happy to unleash an AI agent on their whole computer and trust it to do the right thing. But working in financial services, that’s the last thing I can do, or would want to anyway.