1.4 Implement multi-step workflows with enforcement and handoff patterns
Choose programmatic enforcement (hooks, prerequisite gates, tool-handler checks) over prompt guidance when workflow ordering must be guaranteed, decompose multi-concern requests, and escalate with structured handoffs that a human without the transcript can act on.
Key points
- 1
Programmatic enforcement versus prompt guidance: system-prompt rules, few-shot examples, tool descriptions and self-check lists all shape behaviour probabilistically and keep a non-zero failure rate. Hooks and prerequisite gates run in your code and cannot be skipped by the model.
- 2
When deterministic compliance is required (identity verification before financial operations, blocking refunds over a policy threshold), enforce it programmatically. "Add MUST to the prompt", "add few-shot examples" and "use a bigger model" are the standard distractors.
- 3
A prerequisite gate blocks downstream tool calls until the prerequisite has completed: for example a
PreToolUsehook onprocess_refund(andlookup_order) that returnspermissionDecision: "deny"unless session state holds a verified customer ID fromget_customer. The tool handler itself can also require a verification token that only the prerequisite tool issues. - 4
Gate on verified outcomes, not on invocations. "
get_customerwas called" is not the same as "get_customerreturned a verified customer whose ID matches the order"; the former still lets refunds reach the wrong account. - 5
Give denials an actionable
permissionDecisionReason("call get_customer to verify the customer, then retry"). The reason is returned to the model, so it can complete the missing step within the same loop instead of giving up or escalating needlessly. - 6
A routing classifier that restricts which tools are available addresses tool availability, not tool ordering; it is not a fix for skipped prerequisite steps.
- 7
Multi-concern requests (damaged item + double charge + wrong address): decompose into distinct items, investigate each in parallel using the shared context (the verified customer, order history), then synthesise one unified resolution. Handling only the first concern, replying per concern, or escalating every multi-concern message all hurt first-contact resolution.
- 8
Structured handoff protocol for mid-process escalation: verified customer ID and verification status, root cause analysis, actions already taken with outcomes, refund or dispute amount and the policy clause involved, recommended action, and open questions.
- 9
Human agents receiving an escalation typically lack access to the agent's transcript and tools, so the handoff must be self-contained and quickly consumable. Raw tool JSON, a full transcript dump, a one-line "please help", or sentiment and priority alone are not actionable handoffs.
- 10
Hooks and gates complement, not replace, the model-driven loop: enforce the few invariants deterministically and leave the rest of the flow to Claude's judgment so the agent still handles varied requests.
Read the source
Test yourself on 1.4 Implement multi-step workflows with enforcement and handoff patterns
Ten questions, with the answer and explanation after each one.