The write path
Claude Code invokes FlowRail's registered PreToolUse hook for Write, Edit and MultiEdit. The hook examines the proposed content before allowing the supported operation to continue.
Local and server checks
Local pattern checks can deny known secret shapes without a model call. For supported code files, the hook sends candidate content to FlowRail's backend for analysis against applicable universal and design-derived rules.
When a write is denied
Claude receives a finding and its reason before the proposed write is saved. Ask it to address the issue and retry. FlowRail evaluates the correction; receiving guidance is not a guarantee that the next proposal will pass.
When a check is incomplete
Under the default scoped posture, an incomplete design-bound check pauses the write. Wait and retry the unchanged write to collect its result. A pause does not itself mean the code is vulnerable. Unbound writes can still proceed on operational failures.
When a write passes
A pass is evidence for the rules and context evaluated. It does not resolve requirements whose evidence is unavailable, such as authorization implemented in another service. The review dashboard preserves those distinctions.
Supported scope
The general verifier recognizes supported code extensions and selected build filenames. Configuration and infrastructure formats such as JSON, YAML, TOML and Terraform do not receive the same general code analysis; dedicated checks cover some of those paths. Changes through other tools or direct shell writes are not equivalent to the registered Write/Edit path.