Source Anonymity Escrow Docket / 来源匿名托管案卷

Source Anonymity Escrow Docket is the board card for a source claim that needs to be useful to one future reader while remaining hidden, sealed, substituted, or explicitly absent for another reader.

It exists because anonymity and proof are different truths. A source can be protected while proof remains scoped, or named while public repair remains broken.

Required fields

card_id: storyteller.card.source_anonymity_escrow_docket.v1
row_id: <stable id>
trigger_kind: state_pressure
source:
  source_claim_id: <stable id>
  source_surface: transcript_line | protected_witness | confidant_promise | counterreceipt | caption_log | route_log | public_receipt | checksum | equivalent
  source_claim_text_or_code: <claim code>
  source_identity_state: anonymous | sealed | protected | payroll_due | public_alias | lawful_only | sponsor_known | explicit_absence | equivalent
readers:
  proof_reader: lawful_body | public_table | archive | inspector | sponsor | route_claimant | editor | fan_oxygen_queue | harmed_artist | broadcast_reality | equivalent
  hidden_reader_or_absence: sponsor | public_table | archive | inspector | hostile_claimant | editor | fan_queue | pirate_relay | management | route_asset | explicit_absence
use:
  requested_use: route_unlock | proof_burden_shift | lawful_annex | public_correction | sponsor_defense | counterreceipt_support | broadcast_reality_patch | equivalent
  future_reader_or_route: <reader route ending scar or explicit_absence>
protection:
  escrow_holder_or_absence: han_yanshuang | yu_lan | baiya | shen_luo | ruan_chi | inspector | archive_clerk | public_delegate | explicit_absence
  shield_or_support_or_absence: lawful_seal | anonymity_shell | payroll_token | checksum_mask | public_alias | substitute_proof | route_quarantine | explicit_absence
  substitute_proof_or_absence: checksum | lawful_annex | public_receipt | transcript_excerpt | witness_oath | route_log | explicit_absence
  first_action_choices:
    - escrow_sealed_source
    - lawful_sealed_disclosure
    - anonymous_public_proof
    - substitute_proof
    - pay_and_shield_source
    - split_reader_access
    - reject_anonymous_source
    - sponsor_exposure
    - forced_disclosure_default

Valid states after allocation

  • escrow_required - proof can travel only with sealed holder receipt.
  • lawful_only_source - admissibility improves while public proof remains limited.
  • anonymous_public_only - public repair improves but lawful reader still needs annex.
  • substitute_bridge_required - source stays hidden while substitute proof carries weaker route.
  • protected_source_route - source remains usable through shield/payroll.
  • split_reader_source - readers receive scoped versions rather than one universal proof.
  • proof_burden_open - anonymous source is rejected and the burden remains unresolved.
  • sponsor_only_exposure - sponsor pressure resolves while public/source harm remains.
  • forced_disclosure_default - 来源披露默认 hardens.

Failure cases

This card fails if:

  • it records a source claim but not proof reader and hidden reader;
  • it records a shield but not future consumer;
  • it hides source absence instead of recording explicit absence;
  • it lets public anonymous proof satisfy lawful readers;
  • it lets sponsor exposure repair public trust;
  • it opens from fixed turn, fixed day/week, raw source count, dashboard, or lens health.