Five layers — ordered the way the agent actually works, from boot to audit trail. Each layer builds on the last. Click any row to go deep. Arrow keys navigate.
Before the agent executes a single action, this layer decides what it is, what capabilities it can hold, and what's permanently off-limits. It runs once at startup. Get it wrong and every layer above becomes unpredictable — capability leaks, permission gaps, and attack surface you didn't know existed.
FileRead, FileWrite, Bash, WebFetch, MCP, Agent (subagent spawner). Each tool carries three metadata fields: schema (accepted inputs), permission requirements (trust level needed), and responsibility description (injected into the system prompt so the model understands its own toolkit).bun:bundle feature flag system strips entire tool subsystems from the binary at build time. What's stripped cannot be re-enabled by any runtime prompt or instruction — it literally doesn't exist in the binary.~/.claude/agents/ (user-level, all projects) or .claude/agents/ (project-level, team-shareable).The QueryEngine is the heart of Claude Code — 46,000 lines handling the complete LLM interaction lifecycle. This is where thinking happens, tools get called, and results feed back into the next decision. Simple in principle. Everything complex lives around it, not inside it.
QueryEngine.ts) assembles the system prompt from four sources on every turn:filterInjectedMemoryFiles() for safetyToolResult object and appends it to the message array — exactly like a successful result.Long-running agents fail in three predictable ways: context overflow, lost task state, and unrecoverable crashes. This layer prevents all three — and includes a background memory consolidation daemon (autoDream) that Anthropic built but hasn't publicly shipped yet.
filterInjectedMemoryFiles() before injection — a safety filter that screens for adversarial content. The system explicitly distrusts its own memory files. This is the single highest-leverage customization point in the entire architecture.PreCompact lifecycle hook fires before compaction, giving you an intervention point.Making agents capable is the easy part. Making them stoppable, impossible to manipulate, and impossible to run over-budget — that's the engineering. This is Claude Code's most sophisticated layer. It's also the one that maps most directly to enterprise procurement conversations.
Enterprise clients ask four questions: what did it do, when, why, and who approved it? This layer answers all four. It's also the layer most AI vendors skip or bolt on as an afterthought. In regulated industries — healthcare, finance, real estate — this layer is the difference between a pilot and a production contract.
tool_match, message_start, crash_reason, context_load, routing_decision, and more. Each is a structured object with a defined schema.PreToolUse — fires before any tool runs; can block execution by returning an errorPostToolUse — fires after any tool completes; log results, trigger downstreamSubagentStart / SubagentStop — subagent lifecycleStop — agent session endPreCompact — fires before context compactionNotification — agent-generated alertsWhat actually happens when a user sends a message. Every layer fires in sequence. This is the complete picture — from boot through audit — stitched into a single trace. Study this until you can narrate it from memory.
~/.claude/agents/ and .claude/agents/. The agent now knows what it is and what it can do. Nothing has executed yet.filterInjectedMemoryFiles(). The safety filter screens for adversarial content before anything touches the system prompt. Approved content is queued for injection. Git status, branch info, recent diff, and commit history are captured as system context. The date is noted. These four sources are ready to be concatenated into the prompt.FileRead("./src/utils.ts"). The loop is now running.FileRead is a read-only tool with standard permissions — pass. Gate 3: read-only tools don't require human confirmation — pass. In Auto mode, Gate 4 fires: a second LLM call evaluates the action. "Would the user approve reading the file they asked to refactor?" — yes, obviously. All gates clear. FileRead executes.PreToolUse hook fires. Any registered callbacks execute: logging to audit trail, rate limit checks, data access policy enforcement. The typed streaming event tool_match is emitted to any subscriber (Cockpit dashboard, webhook). The tool runs. File contents return. The result is scanned for prompt injection patterns. PostToolUse hook fires. Permission decision logged with context: who, what, when, which mode.ToolResult and appended to the message array. API call #2 fires. The model now has the file. It generates the refactored version and emits a write tool call: FileWrite("./src/utils.ts", refactoredContent). Read operations ran in parallel if multiple files were needed. This write runs serially — no concurrent mutations.FileWrite requires elevated trust — checked. Gate 3: writes are high-risk operations — execution pauses. The human is shown the diff and asked to approve. Human approves. In Auto mode, Gate 4 would have evaluated: "user asked for a refactor, write is the expected outcome" — approve. Token budget is checked: still within limits. All gates clear. Write executes.Bash("npm run test -- utils.spec.ts"). Tests run. Results return as a ToolResult. If tests fail, the error is feedback — not a crash. The model reads the failure, reasons about what went wrong, and iterates. This is the self-correction loop. It runs until tests pass or the model determines it cannot fix the issue and escalates.PreCompact hook fires first, giving registered callbacks a chance to act. Session state is also persisted to disk — a crash here is recoverable.Stop lifecycle hook fires. The audit trail contains every action: which tools ran, in which order, with which permissions, approved by whom, in which context. The full message array is persisted. The streaming event log is complete. Any compliance query — "what did this agent do and who approved each step?" — is answerable from the audit trail without touching the agent.Three products. One architectural foundation. Kestrel orchestrates workflows. Arc structures decisions. Minstrel threads context across the entire SDLC lifecycle. This is how Claude Code's architecture becomes Lumi's build decisions.