Persistent instructions are not permission controls
You will create a concise CLAUDE.md, inspect whether it loads and distinguish it from automatic memory and settings. Examples are illustrative.
Sources checked September 30, 2026 describe CLAUDE.md as user-authored instructions and auto memory as learned notes. These guide behavior; they are not a hard security boundary. Actual settings and permission mechanisms govern enforcement.
Choose the right scope
Project CLAUDE.md or .claude/CLAUDE.md contains shared project guidance. ~/.claude/CLAUDE.md applies to your projects globally. CLAUDE.local.md is personal project guidance and should be ignored by Git. Organizational managed instructions are separate; do not edit or bypass them.
Keep project facts in the project, not global configuration. Do not include credentials, temporary deadlines or guessed build commands.
Write a small test file
Preserve the existing file if any. For the fictional static page:
# Practice course project
This is a single static index.html, not a deployed service.
Preserve the course title, three units and “Date not yet set.”
Use dependency-free HTML, CSS and JavaScript for small changes.
Before editing, identify the file and proposed behavior.
After editing, show the diff and test keyboard operation.
Do not publish or connect external services in practice tasks.
This is practice instruction data, not a guarantee that prohibited actions are technically blocked. Inspect available permission settings separately.
Verify loading and behavior
Open a new session in the correct folder and use /memory to inspect loaded instruction files. The official memory guide says root/user files are loaded at session start; editing a root file mid-session does not immediately apply the new text. Restart, /clear or /compact reloads appropriate project context according to documentation. Do not infer a reload merely because the file exists.
Using the project guidance, propose a plan for a show/hide-units button.
Do not implement. Identify preserved content, dependencies and tests.
Illustrative output:
Preserve: title, three units and unset date.
Change: index.html only, with no dependencies.
Tests: two toggles, keyboard activation and correct aria-expanded.
Compare with the actual instruction file and source code. Compliance on one prompt does not prove a permanent enforcement layer.
Inspect automatic memory separately
Use /memory to view its toggle and storage link. Current sources describe repository-scoped auto memory shared across worktrees, with the first 200 lines or 25KB of MEMORY.md loaded at startup, whichever comes first. Detailed notes can live in separate topic files.
Do not reset real memory for an exercise. If a harmless practice preference was saved, inspect and remove only that detail when finished. Auto memory is not the chat history, a complete backup or an exact record of approved actions.
Organize without adding clutter
Small project instructions are enough here. For larger projects, .claude/rules/ can hold topic/path-specific rules and Skills can hold reusable procedures. Imported files still consume context; splitting one long file is not automatically a token reduction.
Check contradictory guidance before adding another rule. /init can propose initial project instructions, but review discovered commands and proposed files before accepting them.
Graded practice
Easy: correct scope
Place the test guidance in the project. Success: no accidental global rule.
Intermediate: loaded and followed
Inspect /memory, request a plan and compare it. Success: visible loading plus a fact-preserving plan.
Challenging: conflicting instruction
Identify a fictional conflicting rule and repair only that rule. Success: concise, testable guidance without touching administrator controls.
Troubleshooting
File not loaded: check location, directory and /memory list.
Mid-session edit ignored: reload through the documented route rather than assuming immediate application.
Rule not followed: remove ambiguity and test again; use permission mechanisms for required blocks.
Secrets in guidance: remove them and handle exposed credentials appropriately, not by repeating them.
Too much context: keep universally needed rules short and move scoped procedures to their proper mechanism.