Permissions & Hooks: Gating the Agent
Gate a Claude agent: permission modes, disallowed_tools vs allowed_tools, deciding per call with can_use_tool, and using PreToolUse and PostToolUse hooks for audit logging and redaction.
Last updated
After this section you can
- Trace a tool call through hooks, deny rules, ask rules, permission mode, allow rules and can_use_tool
- Pick a permission mode and write a can_use_tool callback that denies, allows or rewrites a call
- Use hooks for audit and redaction, and scope a subagent's tools, mode and budget
Permissions & Hooks: Gating the Agent
An Agent SDK agent starts with a filesystem and a shell. Making it safe is a fixed order of checks you configure: rules, a mode, one callback, and hooks for what rules cannot express.
Each tool call passes through hooks, deny rules, ask rules, the permission mode, allow rules and finally your can_use_tool callback. The first step that decides wins. Hooks run first and see every call; the callback sees only what nothing earlier decided.