9efba1ed9e
boss pointed at 'the project's CLAUDE.md' as the sole source of universal rules, in both the Iron Law and the cross-references. That misses the user-level ~/.claude/CLAUDE.md identity/security layer, which the dev architecture documents as loaded in every session above the project file — and which carries the most autonomy-relevant binding of all: external-service-consent rules that explicitly name /boss and that autonomy does not lift. The asymmetry was one-directional: the user-level file is boss-aware (it constrains /boss by name), but boss was not user-level-aware. Reference both layers so a reader deriving 'what binds me' from boss alone cannot miss the top layer. No user-specific content is encoded — the consent rule is named generically and portably. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>