Observe actions and decisions without changing caller behavior.
Codex
Runtime governance for Codex.Shadow first.
A native Codex plugin that observes repeated work, records evidence locally and only earns narrow enforcement after proof.
- Open source
- Local first
- Shadow first
- Fails open on ambiguity
Codex integration
Install once. Start powerless.
MARGINAL ships a native Codex plugin. A new installation begins in Shadow Mode: it observes lifecycle signals and records governance evidence without assuming that installation grants authority to block.
codex plugin marketplace add SignalLayerLabs/Marginal --ref main
codex plugin add marginal@marginalThe Codex adapter is currently labeled Tool Enforcement, not Full Compute Enforcement. Its authority is deliberately narrow and repository-local: only supported tool actions can become denyable after representative evidence and explicit promotion.
What Earned Enforcement means
Promotion is evidence-bound rather than global. Integrity drift, changed evidence or safety failures can demote the repository back toward observation. Generic shell, tests, search, writes, network and unsupported paths remain outside broad enforcement claims.
Trust boundary
Capability claims stay adapter-specific.
Supported Codex tool actions can be intercepted under the exact proven condition.
MARGINAL does not describe Codex integration as Full Compute Enforcement.
Best first test
Install the plugin, use Codex normally, then inspect MARGINAL status/diagnostics and the Decision Ledger. The first useful outcome is evidence about your workload—not a universal savings percentage.
FAQ
Fast answers.
Does MARGINAL block Codex immediately after install?
No. It starts in Shadow Mode. Narrow repository-local Tool Enforcement must be earned from local evidence and explicit promotion.
Does MARGINAL control every Codex action?
No. The public capability is Tool Enforcement, not Full Compute Enforcement, and unsupported or ambiguous paths remain outside the blocking boundary.
Can I remove the Codex plugin?
Yes. The project documents a clean removal path using codex plugin remove marginal@marginal.
Try it
Observe first. Prove waste. Earn enforcement.
Install MARGINAL in Shadow Mode, inspect what your agent actually repeats, and contribute traces that make the governor harder to fool.
Why enforcement starts powerless
Shadow Mode and Earned Enforcement are not marketing labels: they are a trust model that separates installation from authority.