Claude Code v2.1.291 is not a flashy release. It fixes two things:

1. Cloud sessions dropping answers to permission prompts
   (regression from 2.1.290)
2. Losing final session messages on quit
   (regression from 2.1.288)

Boring? For anyone running coding agents in production, it is the opposite. A lost approval answer means "the user allowed it but it did not run — or something ran that was never allowed." A lost final message means "there is no record of what happened." Both strike at the heart of reliability.

Yesterday (v2.1.290) matters more: permission plumbing

The day-earlier release carries the real substance — a continuation of our Mods article:

serverToolUses
→ added to a mod's turn.step hook result
→ the tool calls the API ran itself,
   each with id, name, input, start and end
→ work done off your machine lands on the ledger too

agentId
→ added to the tool.check event of plugin hooks
→ tells a subagent's permission check
   apart from the main session's
→ never confuse "whose decision is this" again

ceiling
→ added to the question and verdict a tool.check hook reads
→ names the approval level the organization
   requires for a tool
→ pass "this needs higher sign-off" into the decision
Addition Where it lands Problem it solves
ceiling Approval question and verdict Express org sign-off chains in code
agentId Approval request event Separate subagent from main-session requests
serverToolUses Turn execution result Include server-side runs in audit trails

The shift: approval decisions move from binary yes/no toward decisions that account for org rules, the acting agent, and where execution happened. Production-touching work can carry a high ceiling, subagent-originated requests get their own policy — all writable on the hook side.

Why "who called what, approved by what" beats UX

As coding agents grow stronger, background execution outgrows what humans watch on screen. Reliability then rests on four recorded fields, not pretty UI:

agentId    who (main session or which subagent)
tool call  what (which tool, which arguments)
approval   by what (which approval, which ceiling)
result     how it ended (success, failure, side effects)

That is why the two v2.1.291 bugs hurt: dropped approval answers empty the approval column, lost quit-time messages empty the result column. With two columns empty, nobody can later answer "so what happened in production."

CodeBridge mini lab: log traces, not just outputs

Turn the briefing's action into an experiment. When you build a Claude Code plugin or Mod, start with the trace schema — not output logging.

One line per tool execution (JSONL recommended):
{
  "ts":         "execution time",
  "agentId":    "main | subagent name",
  "tool":       "tool name",
  "args":       "argument summary (mask secrets)",
  "ceiling":    "applied approval level",
  "decision":   "allow | deny | ask",
  "result":     "exit code / summary",
  "serverSide": "server execution (serverToolUses)"
}

Weekly review questions:
[ ] any unexpected subagent-originated calls?
[ ] did high-ceiling work run under proper approval?
[ ] any server-side runs missing from local logs?
[ ] any repeated denials to promote into rules?

Combined with step-up approvals from our MCP re-auth article and execution grouping from our observability article, the approve-execute-observe loop is complete.

One practical update tip: check claude --version, and native installs need claude update plus a restart. Self-hosted cloud runners need the host binary upgraded and runners restarted. "Up to date" on the stable channel does not necessarily mean 2.1.291.

Conclusion: strong agents need ledgers first

One line to close:

Models decide an agent's capability; records decide its reliability.

v2.1.290 laid the recordable material, v2.1.291 stops records from vanishing. The order is right. Take your plugins and Mods in the same order: trace structure of agentId + tool call + approval + result first, automation second.

One sharp next step: attach the 8-field JSONL logging above to this week's Claude Code work. Read the log in a week, and the approval gate you need next will show itself.

Further reading

References

Go deeper with a course

To practice building approval gates and trace structures by hand, stack CLAUDE.md, skills, hooks, subagents, and MCP on real projects — exactly like this article's mini lab.