Claude Code history: reviewing an incident
Which change caused this, and why did it look correct at the time?
Why this is hard
Git answers the first half of an incident question. The second half — what the author was trying to do, what constraint they gave the model, what the model quietly worked around — is in the conversation, and it is the half that stops the same failure recurring.
What Claude Code specifically does to you here
The JSONL contains the edit tool calls, so the diff each turn produced can be reconstructed exactly — the strongest incident material of any tool here. The constraint is time: an incident investigated more than 30 days after the change finds nothing.
grep -l 'payment' ~/.claude/projects/*/*.jsonl 2>/dev/null | head
Where Claude Code keeps this in the first place: ~/.claude/projects/<project>/<session>.jsonl. Transcripts older than 30 days are deleted by default, and nothing tells you it is happening.
What a working answer looks like
A working answer means going from a line of code to the prompt that produced it, months later, without depending on anyone's memory.
Start by measuring what you have. npx promptwake doctor reports what every AI tool on the machine is holding and how much of it sits inside a deletion window — no account, writes nothing, sends nothing anywhere. If the conclusion is that the record should not depend on one laptop, that is what PromptWake captures: prompt, response and the resulting diff, local by default and synced into a shared timeline on the paid tiers.
