A procurement office must guarantee that an agent can never execute a command against the live vendor-payment system, and that the attempt is stopped before anything runs. Which hook event provides that control?
Select an answer to reveal the explanation.
Short Explanation
To stop something you have to stand in the doorway before it walks through. PreToolUse is that doorway; every hook that fires later is a witness, not a guard.
Full Explanation
A guardrail is only a guardrail if it sits upstream of the effect it prevents. The procurement requirement here is strict—the command must never run against the live vendor-payment system—which rules out every mechanism that observes or reacts after dispatch, however quickly it reacts.
PreToolUse fires after the model has decided to call a tool but before the call is dispatched, and it receives the tool name and input, which is exactly the evidence a policy check needs. Returning a deny decision stops the call and hands a reason back to the model, which can then choose another approach. Because the check is deterministic code rather than a prompt instruction, it holds regardless of how the model is steered.
PostToolUse runs after execution, so it can flag the payment command but the side effect has already landed and there is no general rollback facility to undo it; Stop fires when the agent tries to end its response, far later than the call and with no power to retract completed actions; SessionStart runs once at session setup to inject context or prepare state and is not an enforcement point for individual tool invocations.
Exam caveat: a deny is only as good as its matcher—a hook scoped to the wrong tool name or argument pattern silently permits the call it was written to block. Operational check: attempt the forbidden vendor-payment command in a test session and confirm nothing executed by reading the payment system's own logs rather than the agent's transcript.