
Every time a new Cowork session starts, Claude is a stranger. It doesn’t know who Dennis is, what BlitzMetrics does, who our clients are, which sites we manage, or that we published a meta article on blitzmetrics.com yesterday. That stranger-at-the-door problem is the single biggest tax on working with an AI long-term — without a fix, you either re-brief the model every morning or you accept 20% of the work going to re-discovery. Neither is acceptable when we’re running weekly client builds and a publishing cadence on top.
The fix is what we call lockdown files — a tiered memory system on the user’s local disk that Claude reads before doing anything else. It’s the same content architecture Dennis applies to every other part of BlitzMetrics, just pointed at the AI’s context window instead of Google’s index. If you’ve read How to Create a Definitive Article for Any BlitzMetrics Concept, you already know the pattern — this article maps it onto Cowork sessions, and onto the meta-article loop we used to publish the carsonteagarden.com build log yesterday.
TL;DR
Give Claude three tiers of files in the Cowork workspace folder: a one-page CLAUDE.md hot cache, a memory/ directory with relevant people, projects, context, and credential-location metadata, and a <client>-site-bundle/ per engagement for site source files. Every substantive run leaves an internal receipt; an approved public-safe run may also become a meta-article. Secret values remain outside the memory tree in Keychain, an approved secret manager, or an injected environment.
Strategy: Definitive Articles, But for AI Memory
In How to Create a Definitive Article for Any BlitzMetrics Concept, Dennis names the problem behind content sprawl: content vandalism. Someone writes a new article on a topic that already has a definitive hub — not from bad intent, but because they didn’t know the hub existed. The new article competes with the old one, dilutes internal linking, and confuses both Google and AI agents about which page is canonical.
Cowork sessions have the exact same failure mode, just compressed to a single day. Claude writes a new draft of your strategy doc because it didn’t know you already had one. It asks which approved credential store and key the workflow uses. It re-explains a pattern you codified last week. That’s AI content vandalism — same disease, same cure: declare a canonical source and make every new agent read it first.
The lockdown pattern enforces exactly that: a canonical memory tree that lives on your local disk, that Claude reads at the start of every session, and that becomes the single place new information gets written. No scattered chat histories. No “I think we talked about this last week.” No credentials copied into context.
Use the vendor-neutral version. Start with the portable AI context migration guide and starter vault, browse the files through the Obsidian shared-Markdown system, then use the cross-agent shared-memory setup when ChatGPT, Claude, Codex, or another authorized agent must read the same working state. The folder architecture is the asset; CLAUDE.md is only one runtime adapter.
The Architecture: Three Tiers of Lockdown
The memory tree has three concentric layers, each with a different purpose and different rules about what belongs inside. Think of it the same way you’d think about your website’s SEO Tree — a homepage / category / article hierarchy — but for the AI’s context window.
| Tier | File(s) | Purpose | Size rule |
|---|---|---|---|
| 1. Hot cache | CLAUDE.md |
Loaded every session. Who you are, top ~30 people, top ~30 terms, active projects, preferences, pointers to deeper files. | ~50-80 lines |
| 2. Deep memory | memory/people/, memory/projects/, memory/context/ |
Full profiles, project state, company context, and credential-store locators without secret values. Only loaded when relevant to the current task. | Grows indefinitely |
| 3. Working artifact | <client>-site-bundle/ |
Per-engagement folder with pages, posts, schema, strategy, sponsor kit — everything the live site is made of. This is the republishable master. | One per client |
Each tier is lazy-loaded: Claude reads CLAUDE.md at the start of every session, reads individual memory files only when the current task needs them (writing to Todd means reading memory/people/todd-martinez.md, not all people files), and opens the bundle only when touching that specific client’s work.
Tier 1: CLAUDE.md — The Hot Cache
This is the one file that matters every single day. It lives at ~/local-agent-mode-sessions/CLAUDE.md on the user’s machine — the same folder Cowork already uses as its workspace — and Claude reads it automatically before running anything else. Think of it as the “definitive article for yourself” in Dennis’s framework: short, hub-shaped, pointing at everything else.
Dennis’s CLAUDE.md after yesterday’s build looks like this:
# Memory
## Me
Dennis Yu — founder, BlitzMetrics. I run personal brand site builds
for clients and publish the build logs as meta articles on blitzmetrics.com.
## People
| Who | Role |
|-------|--------------------------------------------------------|
| Carson| Carson Teagarden, 21yo fitness YouTuber (724K subs) |
| Kirt | Kirt Box, sponsored bow hunter + Army vet |
## Terms
| Term | Meaning |
|--------------|-----------------------------------------------------|
| BlitzAdmin | Internal WordPress fleet dashboard |
| the bundle | Per-client `<name>-site-bundle/` folder |
| meta article | House-style build-log post on blitzmetrics.com |
| app password | WordPress Application Password, long-lived REST auth|
| WAF gotcha | WP Engine's Cloudflare firewall blocks non-browser |
| | UAs → always use Mozilla UA + Referer |
## Active Projects
| Name | What |
|---------------------------|----------------------------------------|
| Carson / carsonteagarden | Live; weekly content updates planned |
| BlitzMetrics.com | One case-study post per client build |
## Credential Locations
Secret values never enter this file.
- blitzmetrics.com — macOS Keychain service `blitzadmin-wp-app`; approved user and revocation path are maintained with the credential
## Preferences
- Public meta-articles are conditional; credential values stay in Keychain and are referenced only by store/key name
- House style is the kirtbox-meta-article.html template
- Bundle-as-source-of-truth — always draft in `<client>-site-bundle/`
before publishing
- Direct, honest updates — if blocked, say so and offer paths forward
That’s the whole file. It fits on one screen. It answers the questions “who are we, what are we working on, what are the bits of jargon I’ll hear, and where do I go for detail?” In Dennis’s definitive-article language, the tables at the top are the navigation, the Credential Locations and Preferences sections are the callouts, and the pointers to memory/ are the “read more” links.
Keep one canonical hot cache. Do not maintain separate full copies in CLAUDE.md, AGENTS.md, project instructions, and custom instructions. Keep the neutral context in AI-CONTEXT.md and companion Markdown files; make runtime-specific files short pointers plus only the rules unique to that runtime.
Tier 2: memory/ — The SEO Tree, But for AI
The deep memory directory is where detail lives. It’s structured by type so Claude always knows where to look:
memory/people/— one file per person.carson-teagarden.md,kirt-box.md,todd-martinez.md. Full profile, communication preferences, history, notes.memory/projects/— one file per project. For us,carsonteagarden.md(all 10 page IDs, slugs, the five Elementor workarounds, email contacts) andblitzmetrics-com.md(the meta-article workflow plus the running log of posts published).memory/context/— everything that is not a person or a project: company context, tool-specific gotchas, revocation playbooks, and names of approved credential stores and keys. Never secret values.
This mirrors exactly what Dennis describes in How to Document a Task — every recurring task gets its own step-by-step web page so anyone can pick it up and execute. The lockdown files are the same idea turned inward: every recurring piece of context gets its own markdown file so any Claude session can pick it up and execute.
The filenames use Dennis’s cross-linking discipline: lowercase, hyphens, predictable slugs. When yesterday’s session needed to know Carson’s coaching email address and which page ID Gallery lives on, it opened one file — memory/projects/carsonteagarden.md — and had both in under a second. No fresh web search. No re-asking Dennis.
Tier 3: The Bundle — Every Engagement as a Source of Truth
This is the tier most agencies skip and it’s the one that pays compounding interest. Every client gets a <name>-site-bundle/ folder in the workspace — a flat, file-based mirror of everything the live website is made of. For Carson, that’s:
carsonteagarden-site-bundle/
├── pages/ 9 page drafts as ready-to-publish JSON
├── posts/ 5 blog post drafts, back-dated 8 weeks
├── schema/person.json Person JSON-LD
├── sponsor-kit/
│ ├── ONE-PAGER.md Sponsor pitch — Nick's Ice Cream first
│ └── NICKS-OUTREACH-EMAIL-v1.md
├── email-sequences/
│ └── COACHING-LEAD-WELCOME-3-EMAIL.md
├── social-calendar/
│ └── WEEK-1-2-LINKEDIN-FACEBOOK.md
├── research/RESEARCH-NOTES.md All public sources on Carson, attributed
├── STRATEGY.md Three-audience strategy + SEO/AEO plan
├── BLOG-POST-PLAN.md 16-post launch slate
├── CHECKPOINT-FOR-DENNIS.md Running status + open questions
└── META-ARTICLE.md Build log (feeds the meta article)
The live site can drift — a plugin update might re-trigger an Elementor override, a future edit might overwrite a section, a WordPress upgrade might silently change REST behavior. The bundle doesn’t drift. If any page on carsonteagarden.com ever looks wrong, the fix is re-run the publish against the bundle, not start over. And because everything is in .md and .json, Carson’s team can open any of it in a text editor, change copy, and hand it back for a republish. That’s the difference between a website and a content operation — and it’s the thread Dennis pulls in How to Inventory a YouTube Channel and How to Inventory a Podcast on YouTube, where the structured inventory is the asset.
Credentials: Locations Go In, Values Stay Out
No credential value belongs in the memory tree, even when the file is local and mode 600. Store WordPress Application Passwords, API tokens, private keys, recovery codes, and passwords in macOS Keychain, an approved secret manager, or an injected environment. The context file may record only the service, credential-store name, key name, intended scope, owner, revocation path, and last verification time.
What belongs in credential-locations.md
For example: “blitzmetrics.com WordPress REST credential — macOS Keychain service blitzadmin-wp-app; revoke in Users → Profile → Application Passwords.” That tells the next authorized agent where and how without copying the value.
What never belongs in context
Passwords, application-password values, API tokens, private keys, payment or identity data, recovery codes, cookies, or copied authorization headers. A revocable secret is still a secret.
The publishing workflow retrieves an approved application password directly from its credential store at execution time and keeps it out of logs and durable context. Revocation still happens in WordPress, and the memory file records that path without recording the credential.
A Walkthrough: Writing the Carson Meta Article From Session Two
Here’s what the lockdown pattern enabled in the session that published the Carson meta article yesterday.
- Session starts. Claude reads
CLAUDE.md. Knows immediately: this is Dennis, founder of BlitzMetrics, runs personal brand site builds, publishes build logs as meta articles. - Dennis says “did you post the meta article on blitzmetrics.com?” Claude checks
memory/projects/blitzmetrics-com.md. Sees the publish log is empty for Carson. Answers honestly: no, I haven’t. - Dennis says “yes, you look and do it.” Claude reads the credential-location metadata, then the authorized publishing tool retrieves the value directly from Keychain. The secret never enters the memory file or transcript.
- Claude reads
carsonteagarden-site-bundle/META-ARTICLE.mdfor the narrative source. Readskirtbox-meta-article.htmlfor the house style. Drafts the article. - POST to
/wp-json/wp/v2/postswith the browser UA and Referer. 201 Created. Status flipped to publish. Live URL verified with 14 content-landmark probes — all green. - Claude writes the publish to
memory/projects/blitzmetrics-com.mdso next session knows it’s there.
Total new context Dennis had to type: one sentence of authorization. The approved WordPress credential was already provisioned in Keychain, while the non-secret operating context — who Carson is, which page IDs matter, the WAF headers, the article pattern, and the author ID — came from the lockdown files.
How This Fits the Content Factory
In The Content Factory, Dennis describes the pipeline that turns one piece of long-form content into dozens of derivative assets across platforms. The lockdown files are what lets the factory run across sessions without a dedicated operator re-briefing everyone each morning.
Three recent Coach Yu episodes reinforce the same operating pattern from different angles — and they map almost one-to-one onto tiers of the lockdown tree:
Your Playbook When Starting a New Cowork Session (or a New Client)
- Open your workspace folder. On the user’s machine this is whatever directory Cowork is pointed at. For us it’s
~/local-agent-mode-sessions. - Create or update
CLAUDE.md. Keep it under 80 lines. Top-of-file: one sentence about who you are. Tables for people, terms, active projects. Pointers tomemory/for everything else. - Create
memory/. Three subdirectories:people/,projects/,context/. Keep secret values out of all three; filesystem permissions are defense in depth, not permission to store secrets there. - Provision credentials outside memory. Create the narrowly scoped credential in the service, store its value in Keychain or the approved secret manager, and put only the store/key name plus revocation path in
memory/context/credential-locations.md. - Create the bundle. For each active client, a
<client>-site-bundle/folder withpages/,posts/,schema/,STRATEGY.md, and aMETA-ARTICLE.mddraft. - Close the loop with a meta article. When the client site ships, publish a build-log meta article to blitzmetrics.com using the Carson template as the section pattern. Add the row to
memory/projects/blitzmetrics-com.md. - Keep private context out of public Git. A private, access-controlled repository may hold authorized team records, but no repository or context pack may hold secret values. Use
.gitignoreas a backstop, never as the credential boundary.
Why This Creates Value for BlitzMetrics (and for Every Team Using AI Seriously)
The lockdown pattern is what moves AI from useful assistant to actual team member. A useful assistant needs re-briefing every morning. An actual team member reads their inbox, checks the standing docs, and gets to work. CLAUDE.md is the standing docs. memory/ is the team’s shared drive. The bundle is the client folder. The meta article on blitzmetrics.com is the case study that proves the work happened and attracts the next client — the same way Every Digital Audit Dennis Yu Has Done (Master List) accumulates proof across years of live audits, and the same way the DigiMarCon conference audit series turned live on-stage work into a content library.
For a small team running at BlitzMetrics’s cadence — a new client site every week or two, a meta article per build, daily work inside tools that need credentials — the lockdown pattern compounds. Session 1 saves 30 minutes of re-briefing. Session 20 saves the difference between “do this by Friday” and “sure, already done.”
The Takeaway
AI memory is a content architecture problem. The same discipline that prevents content vandalism on a public website — one definitive hub, a supporting tree of linked articles, clear rules about where new content lives — prevents session vandalism inside a Cowork workflow. CLAUDE.md is the definitive article. memory/ is the SEO Tree. The client bundle is the case study. The meta article on blitzmetrics.com is the public proof. Ship all four, and the AI stops being a stranger.
Everything else — credential-store permissions, the browser-UA WAF workaround, the 10KB stash pattern, the slug-swap-and-menu-repoint drill — is scaffolding around that core pattern. The pattern itself is boring. That’s the point. Boring is what compounds.
Related Meta Articles and Recent Episodes
- How we built carsonteagarden.com when Elementor hijacked every page — the case study that ran through yesterday’s Cowork session and exercised every tier of the lockdown tree
- How to Create a Definitive Article for Any BlitzMetrics Concept — the parent SOP this article inherits from
- The Content Factory: How to Turn One Video Into Dozens — the pipeline the lockdown files plug into
- How to Document a Task — the discipline that every memory file is written in
- Documenting Expertise — why capturing tacit knowledge into files is the move
- How to Inventory a YouTube Channel — same inventory mindset applied to a back catalog
- How to Inventory a Podcast on YouTube: The Definitive SOP — the structured-inventory discipline in podcast form
- Human vs AI: The Quick-Audit Challenge — what AI does well and where it stumbles without structured context
- Stand Out as an Entrepreneur Using AI — Coach Yu Show with Josh Collier
- Every Digital Audit Dennis Yu Has Done (Master List) — the pattern of accumulating case studies over years, applied to AI memory over sessions
- DigiMarCon Conference Audits: Dennis Yu’s Live Digital Marketing Breakdowns
- How We Built the Yaamava’ Casino Audit at DigiMarCon — the sister “how we built” piece from the DigiMarCon run
Originally published .

