3 Comments
User's avatar
Karen Boehme's avatar

I am trying to follow the instructions in your post. Claude keeps asking for permission to use PowerShell to answer questions that come up in the execution of the prompt. They are for access to files within the sandbox, so I was ok with allowing access (I allowed access one time only so I could see all the requests and approve them). Is this supposed to happen? It did keep me glued to the screen so I could see what was happening, but it also became a bit annoying and would not be a good option if I had to babysit the responses throughout my research. I read in your post that the skills.md needs to be in the GRA folder itself to allow for permissions. My skills.md file is in the GRA folder. Claude gave me a few suggestions to minimize this from adding an allow rule for PowerShell to launching with claude --dangerously-skip-permissions. I thought I'd see what your thoughts were about PowerShell permissions.

Steve Little's avatar

Great question, Karen--and yes, those PowerShell prompts are expected; the assistant is asking to touch files inside your sandbox, which is the safeguard working as designed.

Honestly, having used these tools since last November, I often run in Bypass permissions mode and just answer "Proceed as you recommend." But I genuinely don't advise you to adopt that yet--learning how far to trust these tools is the process, and the trust has to be earned. There was a well-publicized episode this week, with the new ChatGPT desktop app, of a user's hard drive being wiped. So the babysitting is tedious, but for now it's tedium in the right direction.

Richard Rudd's avatar

Steve — I've been following your journey with interest; our thinking has been converging on the same questions. Trifecta gets at something I think is exactly right: two engines, same evidence, read independently, with the disagreement treated as the signal rather than a problem. The 130-vs-180 weight catch is that whole idea in one example.

One distinction that's proven useful in my own work builds directly on your point that "a model personality is merely a story we may be tempted to tell." Personality is largely promptable, and GRA does a fine job flattening it. But a search-first architecture wired to a scholarly index, or one model's file-and-archive tooling, is structural — not something a prompt can conjure, and exactly what makes two engines read the same pixels differently. So I'd separate the two: flatten personality, but keep exploiting the plumbing.

Where I've landed, after a year of building this into a formal research methodology, is a two-layer picture. Your Trifecta workbench maps cleanly onto the adjudication layer — same evidence, same question — where independent reads are the heart of it. Above it sits a pipeline layer (discovery, retrieval, deep analysis, verification, drafting) where differentiated strengths matter most. Role reversal is one proven way to keep adjudication honest; I've leaned on external audit with a standing rule instead — but the governing principle is the same across both layers: no model grades its own homework.

I've just started putting some of this up at ruddresearch.com — the site's new and still evolving, so mind the dust. I'd genuinely value your read.

Richard E. Rudd

richard.rudd@ruddresearch.com