before, not after
Stop it happening, not just find out
An audit tells you what already went wrong. The guard refuses the command while it is still a proposal — and puts back the nested and path-scoped rules that Claude Code, by its own docs, drops after a compaction.
PreToolUse — blocked before it ran
$ rm -rf / --no-preserve-root
Blocked by your own rule. Retrying will produce the same block — the rule has not changed.
Block
A forbidden command never runs. The model is told why, in your own words, and told not to retry.
Repair
Root CLAUDE.md already survives compaction natively. Nested and path-scoped rules do not — the guard puts those back.
Record
Every allow, warn and deny is appended to a local ledger you own.
Your rules411 chars