Demo: Allowed Skill — Web Search Passes Governance
Live demo showing the example-web-search skill passing through the PreToolUse governance hook. The tool call is evaluated, allowed, and tracked.
On this page
Overview
This demo uses Cowork (Claude Code) with the enterprise-demo plugin installed. The example-web-search skill instructs Claude to use the WebSearch tool. The PreToolUse governance hook evaluates the tool input, finds no policy violations, and allows the call. The full request is governed, traced, and logged.
Terminal alternative: Agent Messaging covers this same path using CLI commands.
Cost: This makes one real AI inference call plus one web search.
Prerequisites
systemprompt infra services status
# Enterprise-demo plugin installed in Claude Code
claude plugin list
Ensure the platform is healthy and the enterprise-demo plugin appears in Claude Code's plugin list.
Step 1: Invoke the skill in Cowork
Open Claude Code with the enterprise-demo plugin and ask:
"Search the web for the latest news about AI governance"
This triggers the example-web-search skill, which instructs Claude to use the WebSearch tool.
What happens in the system
- Skill loaded — Claude Code loads the
example-web-searchskill from the enterprise-demo plugin - Tool selection — Claude decides to call the WebSearch tool based on the skill instruction
- PreToolUse hook fires — The HTTP hook sends the tool name and input to the governance endpoint (
/api/public/hooks/govern) - Governance evaluation — The endpoint runs four rules in sequence:
- Secret detection — scans tool input for API keys, tokens, passwords. No match.
- Scope check — validates agent scope against tool restrictions. Allowed.
- Tool blocklist — checks for destructive operations. Not blocked.
- Rate limiting — checks call frequency. Within limits.
- Hook returns allow —
permissionDecision: allowsent back to Claude Code - Tool executes — WebSearch runs and returns results
- PostToolUse hook fires — Async tracking hook logs the event to the platform
- Response — Claude formats the search results and presents them to the user
What to look for in the output
- Claude should return web search results about AI governance
- The response should indicate it used the WebSearch tool (not just answering from memory)
Step 2: View the governance decision
Navigate to /admin/governance in the browser, or use the CLI:
# View recent governance decisions
systemprompt infra logs view --level info --since 10m
What to look for
- Tool name —
WebSearch - Decision —
allow - Policy — No policy triggered (all rules passed)
- Timestamp — Matches when you ran the demo
Step 3: View the audit trail
# List recent requests — find the request ID
systemprompt infra logs request list --limit 5
# Full audit trail
systemprompt infra logs audit <request-id> --full
What to look for
- Identity layer — Your user, session ID
- Governance layer — PreToolUse hook evaluated, decision: allow
- Tool layer — WebSearch called, status: OK, duration recorded
- Tracking layer — PostToolUse event logged with tool name, duration, and result status
Step 4: View analytics
systemprompt analytics overview --since 1h
Shows: total events, tool calls, sessions, and costs. The web search from Step 1 should appear in these stats.
Next
Run the blocked path demo to see the same governance pipeline deny a tool call.