Govern Claude Code Tool Calls¶
Put Boundary in front of Claude Code
with a PreToolUse hook so an agent's tool calls are decided before they
run. Claude Code fires the hook after a tool is selected but before it executes;
the hook runs Boundary's preview classifiers and blocks the tool call on a
deny verdict — adding portable, redaction-aware policy that a raw hook config
lacks.
Boundary governs Claude Code only for the tool calls this hook is wired to intercept — that routed interception is the boundary. A tool call that does not reach the hook (an un-wired tool, an MCP tool, a subprocess Claude spawns, direct shell use outside Claude Code) is a bypass and is not governed. Closing those paths is a deployment responsibility, not a hook flag.
The shipped pretooluse-boundary.sh is a thin wrapper: it probes for a
boundary binary that carries the hook lane, then execs boundary hook
pretooluse. It parses no JSON, so jq is not used and not required.
Routed surfaces:
Bash / shell tool -> Command Boundary (preview)
Edit / Write / MultiEdit / NotebookEdit -> Edit Boundary (preview)
Command Boundary and Edit Boundary are delivered previews, not production GA.
Treat their verdicts as preview-grade. Every decided call leaves a
hash-verifiable decision record under .boundary/hook (integrity, not
authenticity); the hook does not re-run the tool, makes no claim of total
coverage, and does not emit proved decisions.
Verdict mapping — the hook never emits permissionDecision: "allow", because
that value grants rather than merely permits:
deny -> "deny" (plus the legacy {"decision":"block"} keys)
require_approval -> "ask"
warn -> "ask", carrying the warning as the reason
allow -> nothing at all; the host's own permission flow runs
Expected deny signal:
{ "decision": "block", "reason": "Fulcrum Boundary (Command Boundary preview) denied this command [C4]: destructive local mutation. ..." }
Canonical walkthrough: docs/integrations/CLAUDE_CODE_HOOK.md
Related references:
- integrations/claude-code/
— the hook script, the
settings.jsonsnippet, and install steps. - docs/command-boundary/ — the Command Boundary preview the Bash route uses.
- docs/edit-boundary/ — the Edit Boundary preview the Edit/Write route uses.
- LIMITATIONS.md — the routed-only constraint in full.