Summary
A few weeks before writing this, I asked Claude Code to attack a design I had already prepared, not to write code but to find what was wrong with my thinking. The feature was a redesign of how my application handles periods and years. I thought it was ready. It was not: the review found a validation rule colliding with a new mapping rule on seven routes, a migration that copied one of two tables and would have left whole organisational levels empty, and a pre-existing security gap on asset routes that nobody had asked about.
The context is a real platform, not a demo: an enterprise software assets platform built alone over two months, a Spring Boot backend and an Angular frontend, with role-based access to financial information. None of the three bugs was a syntax error. A compiler would not have caught them, and a test suite written from the same wrong assumptions would have passed. That is the point of the article: AI does not remove the need for engineering skill, it moves it from writing code to catching the design-level, cross-cutting problems that only judgement finds.
The article also shows how I work: no code first but a concise CLAUDE.md and rule files, an AI team of specialised agents with one responsibility each, a review loop in which a fix that has not been verified is only a claim. And it lists the times the AI was wrong with confidence, from an unnecessary migration strategy to a one-character change in an audit-logging call that would have written records under the previous user’s name.
The conclusion I draw is a question to keep asking: not whether AI can write your code, but whether you would know if it was wrong. A good default is not automatically a good decision for your system; that knowledge is the engineer’s responsibility.
Key ideas
- Ask the AI to attack your design before it builds it: an adversarial review moves bugs from production into the design phase.
- The bugs worth finding are not syntax errors: a rule collision across seven routes, a half-done migration that looks finished, a visibility rule enforced on one set of routes and not another.
- Start with a concise CLAUDE.md and focused rule files, then an AI team of specialists: one agent, one responsibility; one skill, one purpose; one task, one scope.
- A fix that has not been verified is not a fix, it is a claim: audit, prioritise, ask, fix one file, re-audit.
- AI is an architectural proposer, not an autonomous architect: a good default is not automatically a good decision for your system.
Why I wrote this
A few weeks earlier I had asked Claude Code to attack a design I had already prepared, a redesign of how my application handles periods and years. I thought the design was ready. It was not, and that is where this article starts.