Skip to content

Govern Claude Code Tool Calls

Put Boundary in front of Claude Code with a PreToolUse hook so an agent's tool calls are decided before they run. Claude Code fires the hook after a tool is selected but before it executes; the hook runs Boundary's preview classifiers and blocks the tool call on a deny verdict — adding portable, redaction-aware policy that a raw hook config lacks.

Boundary governs Claude Code only for the tool calls this hook is wired to intercept — that routed interception is the boundary. A tool call that does not reach the hook (an un-wired tool, an MCP tool, a subprocess Claude spawns, direct shell use outside Claude Code) is a bypass and is not governed. Closing those paths is a deployment responsibility, not a hook flag.

The shipped pretooluse-boundary.sh is a thin wrapper: it probes for a boundary binary that carries the hook lane, then execs boundary hook pretooluse. It parses no JSON, so jq is not used and not required.

Routed surfaces:

Bash / shell tool                          -> Command Boundary (preview)
Edit / Write / MultiEdit / NotebookEdit    -> Edit Boundary (preview)

Command Boundary and Edit Boundary are delivered previews, not production GA. Treat their verdicts as preview-grade. Every decided call leaves a hash-verifiable decision record under .boundary/hook (integrity, not authenticity); the hook does not re-run the tool, makes no claim of total coverage, and does not emit proved decisions.

Verdict mapping — the hook never emits permissionDecision: "allow", because that value grants rather than merely permits:

deny             -> "deny" (plus the legacy {"decision":"block"} keys)
require_approval -> "ask"
warn             -> "ask", carrying the warning as the reason
allow            -> nothing at all; the host's own permission flow runs

Expected deny signal:

{ "decision": "block", "reason": "Fulcrum Boundary (Command Boundary preview) denied this command [C4]: destructive local mutation. ..." }

Canonical walkthrough: docs/integrations/CLAUDE_CODE_HOOK.md

Related references: