Context
MARGINAL is adding privacy-preserving, model-specific shared evidence through Marginal Commons.
Claude Code should participate without exporting private session context and without allowing shared evidence to bypass local Earned Enforcement.
Contribution wanted
Integrate Claude Code into the Commons lifecycle using the existing MARGINAL privacy architecture and shared-evidence protocol.
Target flow:
SessionStart
→ resolve a safely canonical public Claude model identity
→ load only that model namespace prior
→ run normally
SessionEnd
→ finalize local evidence
→ Evidence Compiler
→ Privacy Gate
→ durable local outbox
→ Marginal Ingress
→ matching model namespace in Marginal Commons
Model isolation
- Claude model A evidence must never enter model B.
- Public model versions/snapshots remain distinct when reliably known.
- Never export arbitrary user-supplied model strings.
- Never export private deployment aliases.
- Never export organization-specific endpoint names.
- Never export fine-tune IDs or local model aliases.
- If model identity cannot be proven canonical and public, evidence stays local.
- Ambiguous multi-agent/subagent attribution stays local.
- Do not guess model identity.
Privacy requirements
Commons contribution must not contain raw:
- prompts;
- source code;
- command text;
- tool output;
- filenames or paths;
- repository identity;
- user identity;
- session identity;
- device/install identity;
- credentials;
- arbitrary metadata;
- arbitrary free text;
- local state/evidence hashes that could become linkable identifiers.
No empty heartbeat should be sent when a session produces no privacy-safe evidence.
Modes
Preserve the three user modes:
- Local Only — no Commons contribution;
- Commons Read-Only — may consume Commons, uploads nothing;
- Commons Contributor — contributes only privacy-safe evidence.
The mode is explicit and persisted locally. Existing users must not be silently opted in.
Authority rule
Commons evidence is a prior, not authority.
Even validated/promoted Commons evidence must not independently:
- enable enforcement;
- increment local promotion counters;
- forge local Decision Receipts;
- bypass local coverage/trust gates;
- count as local false-stop review evidence.
Local evidence always has precedence.
Reliability
- Offline SessionEnd queues safe evidence locally.
- Retry survives restart.
- ACK removes the queued item.
- Invalid 4xx contribution is quarantined.
- 5xx/timeout remains retryable.
- Network/Commons failure must fail open and never block Claude Code.
Acceptance criteria
Add synthetic end-to-end coverage proving:
- Claude model A loads only A Commons prior.
- A privacy-safe SessionEnd contribution reaches only A namespace.
- Model B never sees A evidence.
- Unknown/private/custom model identity does not upload.
- Local Only performs zero contribution.
- Read-Only performs zero contribution.
- Contributor mode with no safe evidence performs zero remote call.
- Offline evidence is queued and later retried.
- Commons evidence cannot independently enable enforcement.
- Synthetic privacy canaries never reach Commons.
Non-goal
This issue does not promote Claude Code beyond its current capability label and does not make Commons a source of enforcement authority.
Context
MARGINAL is adding privacy-preserving, model-specific shared evidence through Marginal Commons.
Claude Code should participate without exporting private session context and without allowing shared evidence to bypass local Earned Enforcement.
Contribution wanted
Integrate Claude Code into the Commons lifecycle using the existing MARGINAL privacy architecture and shared-evidence protocol.
Target flow:
Model isolation
Privacy requirements
Commons contribution must not contain raw:
No empty heartbeat should be sent when a session produces no privacy-safe evidence.
Modes
Preserve the three user modes:
The mode is explicit and persisted locally. Existing users must not be silently opted in.
Authority rule
Commons evidence is a prior, not authority.
Even validated/promoted Commons evidence must not independently:
Local evidence always has precedence.
Reliability
Acceptance criteria
Add synthetic end-to-end coverage proving:
Non-goal
This issue does not promote Claude Code beyond its current capability label and does not make Commons a source of enforcement authority.