Before you start
TraceRook is in an invitation-only private beta. Your invitation includes the TraceRook Cloud access code you'll enter in step 4. Don't have one yet? Request an invitation.
1. Download and verify
Download the ZIP, its manifest and SHA256SUMS from GitHub Releases. In the folder containing all three, verify the download:
shasum -a 256 -c TraceRook-0.1.0-beta.1-macOS-arm64-SHA256SUMSBoth entries report OK. Expand the ZIP and move TraceRook.app to your Applications folder.
2. Open the app
Beta builds are distributed outside the Mac App Store, so macOS asks you to confirm the first launch. Open TraceRook once, then go to System Settings → Privacy & Security and choose Open Anyway next to TraceRook. Apple explains the workflow in Safely open apps on your Mac.
3. Start the background service
Open Integrations → Enable Background Service. TraceRook shows the LaunchAgent it will install and the executable it will run; confirm to install ~/Library/LaunchAgents/com.tracerook.agent.local.plist and start the service. Integrations shows the service as connected once it is running. If macOS asks for background-item approval, allow TraceRook in System Settings → General → Login Items.
4. Connect TraceRook Cloud
Open Settings → AI Provider → TraceRook Cloud, enter the access code that came with your beta invitation, review the privacy consent and select Connect to TraceRook Cloud. You don't need an Anthropic API key; analysis runs on TraceRook's account.
The service keeps its device credential in memory, so you enter the access code again after the service restarts. Keep access codes out of agent configuration, shell history and screenshots.
5. Add the Claude Code hook
Add a synchronous PreToolUse command hook to your Claude Code settings, alongside your existing settings and hooks:
{
"hooks": {
"PreToolUse": [{
"matcher": "*",
"hooks": [{
"type": "command",
"command": "\"/Applications/TraceRook.app/Contents/MacOS/tracerook-hook\" --adapter claude_code --host-version 2.1.290 --timeout-ms 80000",
"timeout": 85
}]
}]
}
}Adjust the path if you installed the app somewhere else. The 85-second hook timeout leaves room for a full 45-second review. See the Claude Code hooks reference for settings scopes and reload behavior.
6. Run your first session
Start a new Claude Code session and give it a task. Each tool call appears in Sessions with its decision. To see a review, ask the agent to fetch and run a remote script: TraceRook pauses the call, shows it in the menu bar and the Approvals queue, and waits for Allow once or Block.