My vault is over a decade of thinking. Book notes, sermon prep, podcast ideas, half-formed thoughts I’m still working out. Letting an AI loose in there can feel a little like handing a stranger the keys to my house.
To be clear, I was never afraid that Claude would read my notes. I was worried it would change them. Those are my thoughts, my ideas. Working with those messy notes is how I think, and it’s an important part of the creative process for me. I don’t want AI messing with my notes. I don’t want to open a note 6 months from now and wonder: did I think this, or did the robot?
When that happens, your vault ceases to be a tool for thought. Not when it gets messy, but when the thinking isn’t yours.
So I’ve been testing this as I’ve spent the last few months building the prompt system for my Amplify cohort, which meant running Claude against my actual vault almost daily. And the payoff has been real. Connections I’d never have found. Old notes resurfacing at exactly the right moment.
The difference between “AI wrecked my vault” and “AI made my vault 10x more valuable” comes down to a couple of rules I codified into a Claude project before I let it loose in my vault.
This week, I want to share those rules with you.
Why let Claude in at all?
Let’s start with the job to be done, because if you’re not clear on that, guardrails won’t save you.
The job is not writing. If you point Claude at your vault and say “write me a newsletter,” you’ll get AI slop.
Your precious notes and ideas deserve better than that.
The job is connection. Thinking. Having an opinion and a point of view. Your vault is full of relationships you can’t see. That book note from 2021 that answers the question you asked in yesterday’s daily note. The three separate ideas that are actually one idea you captured in different ways at different times. You captured all of it because it resonated, but no human can hold thousands of notes in their head at once as context.
But Claude can.
Claude can search every filename, heading, and paragraph in your vault in seconds and come back with, “here are five notes that might relate to what you’re working on.”
Those aren’t 5 things it made up. Those are 5 connections you forgot were there, and you couldn’t see anymore.
That’s the key, though: connection, not generation. The AI surfaces potential connections. You judge them and forge the ones that mean something to you.
The thinking stays yours.
Which brings us to the rules that help keep it that way.
Setting Up the Rules
I created a dedicated Claude Project for working in my Obsidian vault, and the project instructions contain a specific set of rules. I’ve written them in a way that they could be used with another LLM if you wanted to use them somewhere else, but every conversation starts with the rules already loaded so I never have to re-explain them. That way, Claude never “forgets” them halfway through a session.
There are five rules in total, but the first two do most of the work.
Rule 1: Point it at your whole vault
This sounds obvious, but it’s where most people stop short. They copy and paste one note into a chat window, get a mediocre response, and conclude AI isn’t useful for developing their notes and ideas.
The real magic only shows up when Claude can search across everything — because the connections you can’t see are in the notes you didn’t think to paste.
Your vault is just a folder of Markdown files, which makes this part pretty easy. Claude Desktop can connect directly to a folder on your Mac. Once it’s connected, the first line of my project instructions is simply:
You have access to my Obsidian vault at [path].This is basically the same as opening a folder in Cowork, but it changes the entire relationship. Claude stops responding to fragments and starts working with your actual body of thought.
Note: This isn’t quite as useful if you have your vault split up. I keep all my notes in one giant vault, and that allows Claude to see connections across multiple domains.
Rule 2: Everything Claude writes goes to one temporary folder
This is the critical rule. If you only adopt one, make it this one.
I have a folder in my vault calledAI Inbox that is basically a temporary folder where all of the LLM output goes. Every single thing Claude proposes or produces — every list of connections, every draft, every summary — lands there. Never in my real vault. Never anywhere I do my own thinking.
The instruction looks like this:
When you create any note or write any output to the vault, it goes in AI Inbox/ — never anywhere else. Name files with the date so I can find them.Think of this as a staging area. Nothing in AI Inbox is part of my vault yet. It’s a pile of candidates waiting for a verdict. When I review the folder, ideas worth keeping get rewritten in my own words and filed by me. Everything else gets deleted.
The boundary does something subtle and important: it means I always know, with total certainty, which text in my vault came from my head. There is no ambiguity, ever. My notes are mine. The robot’s output lives in the robot’s inbox until I decide it’s worth paying attention to and making my own.
Rule 3: Never search the staging folder
If you let Claude write to AI Inbox and also search AI Inbox, you get a feedback loop: Claude surfaces its own past output as if it were your thinking. Ask for connections on Tuesday, and it confidently cites the summary it wrote on Monday. Your vault starts eating its own tail.
So the rule is explicit:
Exclude AI Inbox/ from every search and every result. Never surface your own past output as if it were my thinking.Your vault should be a curated collection of the non-average things you’ve collected because they piqued your curiosity. It’s the ideas that made you stop and pay attention.
Don’t let generated text muddy your thinking. Keep it quarantined until you’ve decided to own it and make it your own by writing what you think about it.
Rule 4: Candidates, not conclusions
When I ask Claude to find connections, I don’t want an essay about what my notes mean. I want a list: a link to each note, a one-line summary, and one line on why it might connect. Like this:
Return results as lists: a [[wikilink]], a one-line summary, and one line on why it might connect. I decide what’s interesting — never tell me what the “best” connection is.The distinction matters more than it looks. The moment AI starts ranking your ideas and declaring winners, you’re no longer doing the thinking. Judgment can’t be delegated. Half the value of a surfaced connection is the split second where you recognize it. That flash of “oh, wait, those actually go together” is where the actual thinking happens.
Rule 5: Read anything, modify nothing
The last rule is the one that ties it all together:
Don’t modify my notes. Read anything (except AI Inbox/), write only to AI Inbox/. Linking, rewriting, and filing is my job, not yours.Claude gets full read access and almost no write access. Adding the links, updating the notes, deciding where things live — that’s the work that keeps the vault mine.
The Bottom Line: The rules aren’t protecting your notes. They’re protecting your thinking.
Give your AI some intentional constraints, and it becomes a pretty incredible creative partner. But you have to protect the thinking.
Because the vault isn’t the asset. The thinking that built it is.
A vault with clear rules in place allows you to leverage the things AI is good at in service of doing your best creative work.
Here’s the version that fits on an index card:
- Give Claude real access to your vault. Searching the entire vault is how you surface those hidden connections.
- One staging folder for everything it writes. Nothing lands in your notes but your original thinking.
- Never let it search its own output.
- Ask for candidates, not conclusions. You do the judging.
- Read everything, modify nothing. Filing is your job.
Set those up once in a Claude Project, and every session starts with the house rules already in place.
And remember: Claude is great at making suggestions, but it has no idea which connection matters.
Don’t delegate the thinking. That’s the real creative work that AI can’t replace.