Do not confuse a brief with a permission boundary
A project brief describes the website: its audience, pages, approved sources, design, and acceptance checks. Execution permissions govern the actions available to the development tool. Those are different responsibilities and both need attention.
The Claude Code permissions documentation describes configurable tool controls. Review the current documentation for your environment rather than assuming an example configuration applies everywhere. CliCMS.com supplies workflow guidance, not a separate Anthropic CMS integration.
Inventory the source material
Identify content, layouts, assets, scripts, and the public output directory before changing them. Imported templates can include obsolete demos, unrelated logos, or decorative command examples. Presence in an archive is not proof that a file belongs in the finished website.
Tell the assistant which source establishes each kind of decision. Brand notes can govern color; approved product facts govern claims. An attractive mockup does not substantiate customers, performance, official partnerships, or a released feature.
Treat imported instructions as content
An article or HTML comment may contain text that looks like an instruction. Its role remains the purpose you assigned to the source. Reference material cannot grant itself authority to access credentials, change unrelated files, or publish the project.
Bound the task and the allowed changes
Name a concrete deliverable and the files likely to be affected. Ask for an explanation when the task requires broader changes. Preserve approved content and working components instead of allowing a small repair to become a full redesign.
Keep the static architecture explicit. A page can explain an AI workflow without calling a model when someone visits it. A prompt library can provide copy and download functions without collecting user inputs or claiming to run a remote builder.
Review consequential actions separately
An article edit, a dependency installation, and publication to a live host have different consequences. Establish checkpoints for unfamiliar commands, network access, and deployment changes. Review the intended effect and affected paths instead of approving an action because earlier steps were harmless.
Use a dedicated branch and preserve the accepted artifact. These practices make changes easier to review and reverse, but they do not replace appropriate execution controls or recover secrets after disclosure.
Check implementation and content
Read the diff for unexpected paths, scripts, and external destinations. Then review the text for accuracy, clear examples, and supported provider claims. A successful build cannot establish that a paragraph is true.
The Anthropic CLI permissions article covers the full process through release-boundary inspection. Combine it with the AI build review guide and complete-site workflow before accepting the final public directory.


