Claude Enterprise Now Inspects Every Prompt Before It Runs
Anthropic launched inference hooks this week, a Claude Enterprise feature that gives compliance and security teams real-time inspection and control over every prompt and tool-call response before Claude acts on it. Each request routes over a signed WebSocket connection to an organization’s own DLP server, which returns an allow-or-deny verdict Claude enforces immediately — and the same inspection covers tool responses coming back from MCP connectors, skills, and plugins, not just the chat turn itself.
The protocol is open and webhook-based, with a published schema, so security teams extend DLP programs they already run — Netskope, Palo Alto Networks, Proofpoint, Zscaler — rather than building a one-off integration. Admins get a shadow mode for testing without blocking traffic, role-based exclusions, percentage-based rollouts, and configurable failure-policy tolerances and timeouts, and one configuration applies across Claude chat, Claude Code, Claude Cowork, and the rest of the Enterprise surface. It’s available today in beta.
The move fits a pattern: enterprise AI and SaaS vendors are increasingly building governance into the platform rather than leaving it to a bolt-on product. Salesforce did the same thing with Security Center Essentials, making a slice of its paid security-visibility tooling — Health Check scoring on a rolling 30-day window, plus Third-Party Integrations and IP Ranges monitoring — free across every Salesforce org, not just full-license holders, and bundling it at no extra cost into Enterprise, Unlimited, and Performance Edition.
For organizations still treating “can we prove this is safe to deploy” as the blocker to enterprise AI rollout, that’s the real news here — not a feature, but a shift in who owns the answer. When the platform vendor ships inspection and control natively, the burden moves from “build your own guardrail” to “configure the one that shipped.”