Fulcrum Boundary · Open source

Auto mode decides.Boundary keepsthe receipts.

Boundary is the OSS action boundary for routed agent tools. It decides a routed tool call before it runs and writes the decision record first.

Boundary governs only calls whose route goes through it. Direct access to the same tool is a bypass unless the deployment removes that path.

Apache-2.0 · v0.13.1 · Released 2026-09-02

Install the Claude Code hookv0.13.1
1Terminalcurl -fsSL https://raw.githubusercontent.com/Fulcrum-Governance/Fulcrum-Boundary/main/scripts/install-claude-code.sh | sh
2In Claude Code/plugin marketplace add fulcrum-governance/boundary-plugins /plugin install boundary@boundary-plugins
3Restart Claude Code, then/boundary:drill
Other ways ingo install github.com/fulcrum-governance/fulcrum-boundary/cmd/boundary@v0.13.1 docker run --rm ghcr.io/fulcrum-governance/boundary:v0.13.1 selftest
Fig. 1 — The boundaryIllustration, not live traffic

What happens on a routed call

  1. 01

    Decided before execution.

    The hook hands the tool call to Boundary before the tool runs. A deny means nothing reached a shell or a file on that route.

  2. 02

    Recorded first.

    The decision record is written to disk before the verdict returns.

  3. 03

    Checked by you.

    boundary verify-record recomputes the hash and checks the covered fields against the stored decision hash.

  4. 04

    Alongside, not instead.

    Boundary runs next to Claude Code's own permission handling. It does not replace it.

What it shows, and what it does not

What it shows

  • The routed call was decided (allow, warn, ask, or deny) before it ran.
  • The covered fields of the record match its stored hash.
  • A denied call's record reports upstream_called=false.
  • Boundary's gate runs independently of the permission prompt.

What it does not show

  • That every tool call was governed: only Bash/Shell and Edit/Write/MultiEdit/NotebookEdit route through the hook.
  • That the verdict was correct, or who produced the record. Integrity is not authenticity.
  • Anything beyond this route. The upstream field is the hook's own report.
  • That Boundary sandboxes the agent or detects prompt injection.

Allow, warn, ask, and deny are Boundary's hook verdicts.

Routes and readiness

MCP

Production route

The first production route through Boundary.

Command Boundary · Edit Boundary

Delivered preview

The Claude Code hook routes Bash/Shell and Edit/Write/MultiEdit/NotebookEdit calls through them.

Secure GitHub · CLI · CodeExec · gRPC · Managed Agents · Webhook · A2A

Preview

Each adapter documents its own readiness.

Validate against your own policy before relying on a preview verdict.

Boundary is the gate. Fulcrum is the platform.

Fulcrum is the prelaunch management platform for policies, budgets, approvals, and captured decisions across routed agent actions. Boundary is available now and works on its own.