Claude, Nutshell Series

CCAR-P Revision 1: Claude Code Configuration, MCP, Skills & Subagents

Quick revision notes for Claude Certified Architect – Professional.

Claude Code Configuration Scopes

Scope Use
Managed Organisation-wide security/compliance settings that must not be overridden.
Project Team-shared configuration committed to the repository.
User Personal preferences that follow an engineer across projects.
Local Machine/project-specific configuration not intended for the whole team.

Configuration Precedence

Highest → Lowest:

Managed → Command Line → Local → Project → User

Exam Memory:
Team shared → Project
Personal preference → User
Must not be overridden → Managed

MCP Servers

MCP is used when Claude needs tools or access to external/live systems.

Important exam points:

  • Too many MCP tool definitions loaded upfront consume context.
  • Use Tool Search to discover tools on demand.
  • Do not disable useful tools just to reduce context.
  • New MCP server missing? Check registration first, then reconnect/restart.
  • Use least-privilege tool permissions.

Tool Search

If 50–60+ tools are loaded before the user sends a message:

Best solution: Enable Tool Search / progressive tool discovery.

This preserves available capabilities while avoiding unnecessary tool definitions in the initial context.

Least Privilege

Give an agent only the tools needed for its defined responsibility.

Good: read knowledge base + write draft queue.

Bad: unrestricted Bash, database admin access, or unrelated tools.

Prefer:

Allow-list required tools + explicit deny rules for sensitive operations.

Claude Skill vs MCP vs Subagent

Requirement Best Choice
Reusable procedural knowledge Skill
Fixed procedure with examples Skill
No live external-system calls Skill
Live database/API/tool access MCP
Recurring specialised task Subagent
Focused prompt + narrow tools + specific model Subagent

When to Use a Subagent

A dedicated subagent makes sense when a task:

Recurs frequently + needs a specialised prompt + narrow permissions + specific model selection.

Do not create a subagent for a one-time generic task.

Persistent Project Context

If engineers repeatedly explain the same architecture and coding conventions:

Store them in project-scoped CLAUDE.md or equivalent project context.

Secrets

Never store API keys or credentials in version-controlled configuration.

Correct pattern:

Application → Runtime Secret Store → Credential

Fast Exam Recall

Shared config? Project.
Company security policy? Managed.
Personal preference? User.
Many MCP tools? Tool Search.
Reusable procedure? Skill.
Live external system? MCP.
Recurring specialist role? Subagent.
Credential? Secret store.

Leave a comment