The control plane for your coding agents, however you run them.
An open-source control plane for coding agents. One checkout of rules, skills, roles and stances, projected into Claude Code and Codex with your own primitives, enforced with hooks, and measured with usage telemetry and cost controls. It layers under the rules libraries and orchestration you already use.
Preferences you can switch: autonomy, delegation, cost, testing, voice, commits, planning, licensing and build versus buy. Three of those bind to enforcement today: autonomy sets which shell-command grade stops and asks, delegation changes spawn routing, and cost resolves a model and budget table per role. The rest are prose that swaps cleanly. The usage report groups rule hits by the variant that was selected, so a switch can be checked rather than assumed.
Compatibility
- claude-code-cli-macos: qualified
- claude-code-vscode-macos: unqualified
- claude-code-cli-linux: qualified
- claude-code-plugin-marketplace: unqualified
- codex-cli-macos: unqualified
- codex-vscode-macos: unqualified
- codex-desktop-macos: unqualified
- codex-cli-linux: unqualified
- cursor: planned
- grok: planned
Qualification basis: native evidence recorded for this release.
Native restrictions remain authoritative. See the versioned compatibility catalog for evidence and gaps.
Compatibility policy
Stable interfaces, preview boundaries, deprecation, migration and failed-release recovery are defined in the versioned compatibility policy.
Migration
Upgrade from v0.14.1 to package the Claude Directory submission as a minimal regular-file plugin bundle, fix the sandbox skill's network and credential guidance, and publish matching plugin metadata at v0.14.2. The patch changes no configuration schema or defaults, and the architecture-viewer preview is inert until an external adapter is registered and selected.
- Run
citizen upgrade --dry-run, inspect the recorded plugin and checkout changes, then runcitizen upgrade. The plugin marketplace and plugin manifests now report v0.14.2. - Run
citizen sync --dry-run, resolve any unmanaged-file conflict it names, then runcitizen sync. Existing configuration and stance selections remain unchanged. - Run
citizen diffandcitizen doctor; both should report no projection drift.
Recovery
- Preserve every conflict or adopted backup reported by the dry run.
- To return to v0.14.1, check out v0.14.1, run
citizen sync --dry-run, thencitizen sync; no configuration migration needs reversing. - If the Claude Code plugin was upgraded, reinstall the v0.14.1 checkout as the
model-citizenmarketplace source before installing its plugin version again. - Use
citizen uninstallonly to remove the installation entirely; see docs/runtime-installation.md for ownership recovery.