Methodology note · v0.1
Evidence standards
What a Civic Shield record contains and why, how a judgement is separated from a certainty, and the points at which a person must decide. Published as a draft so that it can be argued with before it is used.
1 · Definitional basis
The reference point is the IHRA working definition of antisemitism, which is non-legally binding [1]. It is used as a reference for categorisation, never as a legal test and never as a verdict about a person.
It is applied with one protection stated explicitly and treated as a first-class outcome rather than an exception: criticism of a government, a state, an army, a policy, a party or a leader — including Israel’s — is not antisemitism. An item assessed as protected criticism is recorded as such, with reasons, and is retained as a training example rather than discarded.
Where a platform rule or a legal provision is engaged, it is cited to the specific clause and to the version of that clause in force on the date of capture [2].
2 · The unit of work is a record, not an alert
A record is the object Civic Shield produces. Its fields, and the reason each one exists, are set out with an annotated example on how it works. In summary: the address and the moment of capture; how the page was rendered and what was retained; the readable text including text inside images; a translation attached rather than substituted; a digest over the preserved bundle; the specific rule engaged with its effective date; the two scores; and an append-only custody log.
The digest is the part that does the work. It does not protect content — it establishes that the content has not changed since the moment it was sealed. That is why the example record recomputes it in the reader’s browser rather than asserting it.
3 · Severity and confidence are different claims
Severity describes how serious the content would be if the reading is correct. Confidence describes how likely the reading is to be correct. Merging them into a single number destroys the information that matters most, because a severe item read with low confidence and a mild item read with high confidence require opposite handling.
Model confidence and reviewer confidence are recorded separately for the same reason. A reviewer who agrees with a model is a different piece of evidence from a reviewer who was shown the model’s answer first, and the record keeps track of which happened.
4 · Where a human must decide
Automation is permitted for reading, extraction, translation drafting, preservation and first-pass categorisation. It is not permitted for any decision that leaves the organisation.
- Every escalation is reviewed and released by a person.
- Borderline cases — satire, quotation, condemnation, historical discussion, political criticism — go to review by definition and are never resolved by threshold.
- No public labelling of any person or body, at any confidence, by any process. This one is not a threshold; it does not exist as an available action.
- No legal filing, and no automatic notice of any kind.
5 · What this note does not yet contain
- The full taxonomy, with its category definitions and worked boundary cases.
- The inter-rater agreement protocol, and the target agreement level.
- Retention periods by record class, which depend on the impact assessment.
- The evaluation results — precision, recall, and false-positive behaviour on protected criticism — because no evaluation has been run.
- The legal basis for collection as applied to this organisation, which is described as a framework on principles and awaits a written opinion [3].
Changelog
-
v0.1 — 3 August 2026
First publication. Draft. No operating practice described.
References