Skip to content

claude-code: integrate model-specific Marginal Commons evidence #61

Description

@SignalLayerLabs

Context

MARGINAL is adding privacy-preserving, model-specific shared evidence through Marginal Commons.

Claude Code should participate without exporting private session context and without allowing shared evidence to bypass local Earned Enforcement.

Contribution wanted

Integrate Claude Code into the Commons lifecycle using the existing MARGINAL privacy architecture and shared-evidence protocol.

Target flow:

SessionStart
→ resolve a safely canonical public Claude model identity
→ load only that model namespace prior
→ run normally

SessionEnd
→ finalize local evidence
→ Evidence Compiler
→ Privacy Gate
→ durable local outbox
→ Marginal Ingress
→ matching model namespace in Marginal Commons

Model isolation

  • Claude model A evidence must never enter model B.
  • Public model versions/snapshots remain distinct when reliably known.
  • Never export arbitrary user-supplied model strings.
  • Never export private deployment aliases.
  • Never export organization-specific endpoint names.
  • Never export fine-tune IDs or local model aliases.
  • If model identity cannot be proven canonical and public, evidence stays local.
  • Ambiguous multi-agent/subagent attribution stays local.
  • Do not guess model identity.

Privacy requirements

Commons contribution must not contain raw:

  • prompts;
  • source code;
  • command text;
  • tool output;
  • filenames or paths;
  • repository identity;
  • user identity;
  • session identity;
  • device/install identity;
  • credentials;
  • arbitrary metadata;
  • arbitrary free text;
  • local state/evidence hashes that could become linkable identifiers.

No empty heartbeat should be sent when a session produces no privacy-safe evidence.

Modes

Preserve the three user modes:

  • Local Only — no Commons contribution;
  • Commons Read-Only — may consume Commons, uploads nothing;
  • Commons Contributor — contributes only privacy-safe evidence.

The mode is explicit and persisted locally. Existing users must not be silently opted in.

Authority rule

Commons evidence is a prior, not authority.

Even validated/promoted Commons evidence must not independently:

  • enable enforcement;
  • increment local promotion counters;
  • forge local Decision Receipts;
  • bypass local coverage/trust gates;
  • count as local false-stop review evidence.

Local evidence always has precedence.

Reliability

  • Offline SessionEnd queues safe evidence locally.
  • Retry survives restart.
  • ACK removes the queued item.
  • Invalid 4xx contribution is quarantined.
  • 5xx/timeout remains retryable.
  • Network/Commons failure must fail open and never block Claude Code.

Acceptance criteria

Add synthetic end-to-end coverage proving:

  1. Claude model A loads only A Commons prior.
  2. A privacy-safe SessionEnd contribution reaches only A namespace.
  3. Model B never sees A evidence.
  4. Unknown/private/custom model identity does not upload.
  5. Local Only performs zero contribution.
  6. Read-Only performs zero contribution.
  7. Contributor mode with no safe evidence performs zero remote call.
  8. Offline evidence is queued and later retried.
  9. Commons evidence cannot independently enable enforcement.
  10. Synthetic privacy canaries never reach Commons.

Non-goal

This issue does not promote Claude Code beyond its current capability label and does not make Commons a source of enforcement authority.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    claude-codeClaude Code integrationcommonsMarginal Commons shared evidenceenhancementNew feature or requestevidenceEvidence quality, attribution and validationhelp wantedExtra attention is neededintegrationAgent/runtime integration workprivacyPrivacy boundary or telemetry work

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions