Advanced workflows
Advanced Claude workflows combine structured planning, isolated execution, verification, human approval, and controlled parallelism.
Select the right execution pattern
Single session
Use one Claude Code session for a focused task that can be explored, implemented, and verified within one context.
For: Small and medium changes
Subagents
Delegate research, testing, security analysis, or documentation into isolated contexts that return concise summaries.
For: Focused delegated work
Worktrees
Run independent Claude Code sessions in separate Git working directories so their file changes do not collide.
For: Parallel implementation
Dynamic workflows
Orchestrate larger numbers of specialised agents through a repeatable script for audits, migrations, and cross-checked research.
For: Large-scale automation
Claude Code supports subagents, isolated Git worktrees, agent teams, and dynamic workflows. Worktrees isolate file changes, while subagents and agent teams coordinate specialised work. Dynamic workflows are intended for large, repeatable activities requiring many agents or independent verification.
Use a gated delivery workflow
- Discover — Understand the business outcome, existing architecture, dependencies, constraints, and affected users.
- Plan — Define scope, affected files, implementation steps, risks, validation, security, and rollback.
- Build — Implement only the reviewed plan with focused changes, tests, validation, and periodic human checkpoints.
- Validate — Run automated checks, inspect the complete diff, and complete technical, security, and human review.
Start an isolated worktree session
From the repository root:
claude --worktree feature-auth
Claude Code creates an isolated working directory and branch under:
.claude/worktrees/feature-auth/
Run another independent session:
claude --worktree fix-validation
Each worktree has its own files and branch while sharing the same Git repository history and remote. This allows parallel sessions to work without editing the same working directory.
Add the generated worktree directory to .gitignore:
.claude/worktrees/
A worktree is a fresh checkout. Install dependencies, create approved local configuration, and run the baseline validation commands before making changes.
Do not copy secrets into the worktree unless enterprise policy explicitly permits the action.
Delegate independent reviews
Use focused subagents after implementation:
Delegate the following independent read-only reviews:
1. Security reviewer
- Review input validation, access control, secrets, injection risks,
dependencies, and sensitive-data handling
2. Test analyst
- Review test coverage, edge cases, failure paths, and regression risks
3. Maintainability reviewer
- Review architecture, readability, duplication, complexity, and
consistency with project conventions
Return separate findings by severity.
Do not modify files.
Cross-check the findings
Compare the independent review findings.
For each finding:
- Confirm whether evidence exists in the code
- Identify the affected file and behavior
- Remove duplicate or unsupported findings
- Classify severity
- Recommend a focused remediation
- Identify the validation required after remediation
Do not modify files.
Manage context carefully
Claude Code's context includes conversation history, files read, and command output. Long debugging sessions or broad repository exploration can consume substantial context, so use focused tasks, subagents, fresh sessions, and verification commands to preserve useful context.
Useful commands include:
/context
/compact
/clear
/resume
Use them as follows:
/context: Inspect what is consuming the current context/compact: Summarise the conversation and release context space/clear: Start a fresh task while retaining project-level instructions/resume: Continue an earlier session
Command availability can vary by Claude Code version and enterprise configuration.
Apply permission controls
Inside Claude Code:
/permissions
Claude Code supports allow, ask, and deny rules for controlling tool use. Deny rules take priority over ask and allow rules. Read-only operations generally require less approval than shell commands or file modification.
Recommended approach:
- Allow only trusted read-only operations by default
- Ask before file changes and shell commands
- Deny destructive operations and protected paths
- Require approval for database writes, deployment, and external communication
- Review saved permissions periodically
- Keep local permission overrides outside shared configuration
Give Claude, hooks, MCP servers, and subagents only the tools required for the current responsibility.
Avoid broad permanent approvals added only to reduce prompts.
Production-readiness review
Before considering work complete, verify:
- The business requirement is satisfied
- The approved plan and scope were followed
- Input validation and expected failures are handled
- Authentication and authorisation remain correct
- Secrets and restricted information are excluded
- Tests cover successful and failure scenarios
- Linting, type checks, and the production build pass
- Dependency and configuration changes are understood
- Logs and monitoring are adequate
- Deployment and rollback steps are documented
- The complete Git diff has received human review
Complete one gated workflow using planning, isolated implementation, automated verification, independent review, and final human approval.