Launch post · Claude Code Beachhead
Govern Claude Code before it surprises you
A PreToolUse hook that checks configured Bash, Edit, Write, MultiEdit, and MCP tool categories before execution. Policy-matched actions can pause for approval. I tap Approve or Deny, and the hook observes the server-side decision.
The problem
Claude Code is fast. Most of the time that is exactly what I want. Some of the time it is not. In the past few months it has rm -rf'd a node_modules I actually needed for a different checkout, force-pushed to main after a rebase I had not finished reviewing, and installed a package I had not vetted because an upstream snippet suggested it.
None of these are the agent's fault. The agent did what I told it to do, and sometimes what I told it to do was too broad. The question is not "how do I make the agent smarter"; the question is "how do I keep a small number of specific actions from running without me knowing."
Try the current demo
The home page has a live guard demo using the current decision shape. It shows policy results and the approval flow without relying on the retired launch video. Run the live demo.
How it works
DashClaw registers a PreToolUse hook on your Claude Code install. Configured, supported Bash, Edit, Write, MultiEdit, and mcp__* calls go through a policy check before they run. Three steps:
npm install && npm run hooks:installwires the hook into~/.claude/settings.json.- Paste a workspace token from /connect. That is the API key my deployment uses to recognize this laptop.
- Configure Discord: pick a server, pick a channel, drop in a bot token. I use my own account; you use yours.
Three commands and one paste. The Claude Code → DashClaw → Discord → phone loop is the only thing on the critical path.
What's free
The core runtime is MIT licensed and self-hostable. That includes:
- · The PreToolUse hook and the
claude-code-starterpolicy pack. - · Discord and Telegram approval bridges.
- · The
/decisionsledger with explicit identity verification, payload-signature, and receipt status on recorded decisions. - · Optional semantic guard integrations using your own provider key.
- · The
/activityand/my-agentsurfaces, where I check what the agent did today without scrolling through a terminal.
I self-host on Vercel free tier. Postgres on Neon free tier. Zero SaaS subscription. Deploy button on the GitHub repo.
What broke and what I fixed
Two things bit me early and both shipped fixes you will never see directly:
- CSP blocked the embed. The first time I put a Loom iframe on the homepage, Chrome refused to render it because my frame-src directive was self. Fixed by explicitly allowlisting loom.com and youtube-nocookie.com in next.config.js, and by having the embed component itself throw if someone tries a third host.
- The hook silently failed open when the guard was unreachable. If my deployment was down, a destructive action would just… run. Fixed with a block / warn / allow policy knob that defaults to block, plus an orphan-actions journal. Calls that reach the unavailable-guard handler are recorded locally and can be reconciled when the guard recovers.
Both of these are the kinds of things you only find by running DashClaw on your own laptop every day.
What's next
I'm building the rest of DashClaw's growth loop under DashClaw-governed agents. Research, content drafts, monitoring: each one is a Claude Code session with policies the public can read. The ledger adds evidence for the paths that reported to DashClaw. It does not prove unobserved external behavior.
Public status page coming. The first one will be a live board of how many Claude Code integrations are active this week, which policies fired most, and which denials I had to override because my own policy was wrong.
Try it
npm install
npm run hooks:install
# then open /connect for the workspace token + Discord setupThree commands. The guide walks you through the rest: /guides/claude-code.
If something breaks, open an issue on GitHub. I read all of them.