Build1 distinct publisher3 min readPublished
A frozen Claude Code session moved cleanly into seven rival agent formats. The approval and audit machinery wrapped around it moved into none of them.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
The loss manifest is the part worth reading twice, and not for its size. Across seven separate targets the dropped totals sat in a band three items wide, 54 to 57 [5][2]. If target design governed preservation, picking a better destination would buy something measurable. It buys three records. The author's reading is that the source session's own event vocabulary decides what can enter the intermediate model at all [7], and the documented design agrees: the validated event timeline in the middle is deliberately narrow, wide enough for ordered conversation events and closed to client-resident configuration [8].
That is where the approval story ends. Approval gates and audit settings sit on the client side of that boundary, which is why the transcript arrives and the controls do not [2]. It is not a gap that a later release closes by adding a field.
Private thinking makes the size of the hole legible. The frozen source carried 11 thinking blocks [3], and every one of the seven targets dropped 9 of them [5], roughly 82 percent [1]. Tool-use and tool-result blocks numbered 20 and 20 [3], so the record of what the agent touched survives better than the record of why it decided to. For a developer resuming work, that trade is fine. For the question the author says keeps arriving at engineering leadership, "three months from now, where can we see why this agent made that change" [10], it is close to a total loss.
Note what the manifest itself is: a count of omissions and transformations carrying no content [8]. It can tell you that 57 things did not survive. It cannot tell a reviewer which 57, which makes it a migration receipt rather than an audit record.
The contrast the author draws is with Slack Code, and it is Slack's own account. Slack says a coding-agent mention can create a channel that gathers the relevant people, the diffs and the planning documents, then archives as a searchable record [11], and that important changes can be routed to a person for approval inside that channel [12]. The mechanism, not the product, is the transferable part: the durable record and the approval event live somewhere that already has an administrator, instead of being stood up again inside whichever harness a developer adopts next quarter.
Two caveats on the numbers. Freezing the session was not fastidiousness; the live file kept growing during the first attempt, so each conversion was being measured against a different source [14]. And the run happened in a Python 3.12 environment on macOS while the README claims Python 3.11 or later and Linux [13], so this is one sample, taken outside the stated support boundary. The shape holds even if the decimals do not: seven destinations produced one loss profile, and the thing an auditor would ask for was in none of them.
Ranked by verification strength, evidence, and original report placement.
The author froze one real Claude Code session, inspected it, and transferred it into seven target formats using session-migrate 0.8.0, to test whether portable coding-agent sessions materially reduce vendor lock-in.
The useful conversation and tool context traveled surprisingly well, but the controls that make agent work safe in an organization did not move at all.
Freezing the session was essential because a live session file continued to grow during the first attempt, meaning each target conversion was being compared against a different source population.
The source was one frozen Claude Code session of 341,646 bytes and 90 records, containing 20 tool-use blocks, 20 tool-result blocks and 11 thinking blocks.
The session was transferred into Codex, Pi, GitHub Copilot CLI, Qwen Code, Kimi Code, Muse Code and Mistral Vibe, each target home isolated under /tmp; targets produced 33 to 50 records, a spread the author attributes to target formats splitting equivalent content into different record units rather than to different information preservation.
Dropped totals clustered tightly between 54 and 57 across all seven targets, while the dropped-thinking count stayed fixed at 9.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-hand measurements, single session, single observer
The core technical findings are unusually concrete for a blog post: exact source size and block composition, named targets, isolated target homes, per-target record counts and drop manifests, and a disclosed methodological correction (freezing the growing session file). Method limits are also disclosed: install outside the published Python 3.11+/Linux boundary, two adapters that could not run, and five of twelve formats untested. What caps the score is that everything rests on one frozen session, one operator and one publisher, with the decisive non-transferability finding sourced from the project's own compatibility table rather than independent verification.
One practitioner experiment, no organisational deployment evidence
Observed adoption is limited to the author's own controlled test of a 0.8.0 tool plus the tool's self-documented format coverage; two adapters could not even run without their native clients. No user counts, organisational deployments, or third-party usage of either session migration or the Slack Code approval pattern appear in the supplied material, and the Slack capability description is vendor messaging rather than observed use.
Central finding well grounded, surrounding generalisation runs ahead of it
Slightly overstated overall. The load-bearing conclusion — transcripts move, enforcement does not — is directly supported by tightly clustered loss data plus the project's own compatibility table, and the piece deflates rather than inflates portability marketing. The overshoot is in scope: 'meaningful portability' and vendor-negotiation guidance are extrapolated from one frozen session on seven of twelve formats, resume fidelity is asserted rather than shown, and the Slack Code alternative is presented on vendor claims alone.
Individual practitioner post with executive framing and relayed vendor copy
Moderate distortion pressure. This is a personal developer-platform post that doubles as thought-leadership positioning ('a CTO should optimize for...'), promotes a specific 0.8.0 tool, and reproduces Slack's own product copy as the architectural alternative, with no disclosure of any relationship to session-migrate or Slack. Offsetting factors keep the score below the midpoint: the author publishes limitations against interest, including the out-of-support install, the growing-file error, the failed adapters, and the finding that the tool cannot move the controls that matter.
Directionally solid, weakly replicated
Confidence is moderate. The architectural conclusion is convergent — measured loss manifests, the project's compatibility table, and the client-bound Antigravity/Cursor adapters all point the same way — so the 'controls don't migrate' finding is likely to hold. But it comes from a single publisher, a single session, a pre-1.0 tool, and partial format coverage, with adoption essentially unmeasured, so quantitative specifics should not be treated as generalisable.
build
Superpowers makes spec-driven work a precondition, then ships it to twelve harnesses1 distinct publisher
build
LoreKit puts agent memory in Markdown files you can grep, not a vendor's database1 distinct publisher
invest
Binance gives AI agents their own subaccounts, and no loss limit1 distinct publisher
build
255 tool schemas, 91K tokens: pricing the two MCP costs nobody budgets1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 26, 2026