1:1 mentoring with Big Tech AI engineers
LLM & Agentic

Permissions & Hooks: Gating the Agent

Gate a Claude agent: permission modes, disallowed_tools vs allowed_tools, deciding per call with can_use_tool, and using PreToolUse and PostToolUse hooks for audit logging and redaction.

Last updated

After this section you can

  • Trace a tool call through hooks, deny rules, ask rules, permission mode, allow rules and can_use_tool
  • Pick a permission mode and write a can_use_tool callback that denies, allows or rewrites a call
  • Use hooks for audit and redaction, and scope a subagent's tools, mode and budget
29

Permissions & Hooks: Gating the Agent

An Agent SDK agent starts with a filesystem and a shell. Making it safe is a fixed order of checks you configure: rules, a mode, one callback, and hooks for what rules cannot express.

Key idea

Each tool call passes through hooks, deny rules, ask rules, the permission mode, allow rules and finally your can_use_tool callback. The first step that decides wins. Hooks run first and see every call; the callback sees only what nothing earlier decided.

Every tool call is checked in the same order. Your hook sees all of them; your callback sees only what is left
ONE TOOL CALL, CHECKED IN THIS ORDER approved: the tool runs, then PostToolUse hooks 1 · hooks PreToolUse sees every call 2 · deny rules disallowed_tools scoped deny rules 3 · ask rules settings files force a prompt 4 · mode permission_mode bypass, acceptEdits 5 · allow rules allowed_tools reads inside cwd 6 · callback can_use_tool dontAsk: denied an ask rule skips straight to the callback denied: the reason goes back to Claude as the tool result A hook can deny anything. An allow from a hook does not skip the deny and ask rules after it.

Related

More in LLM & Agentic

Get full access to all 74+ sections with code examples, diagrams, and interactive animations.

Unlock Premium