About this project

Model Citizen is a control plane for coding agents, designed to sit underneath whatever rules library or orchestration layer you use. It lets you define rules, skills, roles, and stances once, then projects them into Claude Code and Codex, enforcing them with hooks and keeping a ledger of what each session did and spent. Key features include: - **Guardrails with judgment**: Hooks handle deterministic checks like grading shell commands (read-only to irreversible), stopping turns when your repo's gate is red, reviewing fresh context, catching secrets, neutralizing untrusted tool output, and sandboxing. - **Reversible settings**: Sync has a dry run, diff shows drift, an ownership journal records changes, and uninstall restores what it adopted. Shared primitives live in one place and sync into each runtime's native settings. - **Cost and usage visibility**: Cost postures (frugal, balanced, max) set model, effort, and soft budgets per role. Model tiering assigns roles to capability classes (frontier, strong, standard, light) rather than specific models. A usage feed reports turn and subagent costs, and a decision log records hook decisions. - **Readable output**: Voice stances (concise, answer-card, scannable) shape output. Review Card plans open with a one-screen card and stop at a build gate. Subagent returns are bounded with findings and word caps. - **Measurable rules**: Every rule names a deterministic detector over the transcript or explains why it can't be decided. Lint fails commits otherwise. Usage reports show how often each rule fired. - **Preference switches**: Nine stance dimensions (autonomy, delegation, testing, cost, voice, commits, planning, licensing, build vs. buy) each with named variants. Set defaults, override per repo or session, and write your own stance dimensions as Markdown folders. It supports Claude Code CLI (macOS, Linux) as qualified, with Codex CLI and other clients unqualified or planned. The harness is not an LLM API gateway or model provider; Claude Code and Codex remain responsible for model access and native permissions. Installation is via a one-line script or manual clone. Sync, doctor, and uninstall commands manage configuration and ownership. The project is MIT-licensed and welcomes contributions.