I run several agent sessions in parallel, each in its own project, all on the same machine. For a while I believed that was safe because every session had its own repo. It wasn't. Sessions reach outside their home tree more often than you think, a memory file here, a shared config there, a quick fix in a sibling project because the finding happened to surface elsewhere.

The collisions, five of them when I sat down and audited the record, all had the same shape. The second session was never blind. It saw the signs of the first one working, a fresh claim in a status file, a half-written directory, and it proceeded anyway. Claims existed then; each project noted them its own way, in its own status file, and nothing read them back. I want to be clear that this is not a model being careless. Under context pressure, an agent treats another agent's presence as noise.

- Politeness is not a mechanism, so it doesn't survive.

Also worth telling, my staging rule failed the same week, broken again 67 minutes after I recorded it, by a session that had never lived the incident. That story owns its own piece, because the fix turned out to be nothing like better prose.

So the claim went from a courtesy to a protocol. Not a new idea, a standardized one: one format, one place, one mechanical refusal, instead of five projects each writing notes nobody was bound to honour. Before any session writes outside its own tree, it takes a claim, a small JSON file named after the target, holding who, when, and what for. The whole file is five fields: