Witness Recantation Ledger / 证词翻供账本

Witness Recantation Ledger is the visible card for a previously useful witness, operator, caption witness, or proof carrier whose testimony is no longer safe to reuse as clean proof.

The current mesh already proves how testimony is created and protected through 操作员证词合议线, 字幕证词羁押线, and 证人报复链. This card catches the next failure: a route continues to cite old testimony after the witness has narrowed, contradicted, withdrawn, been captured, gone hostile, or become unavailable.

A recantation row does not mean the old proof was fake. It means the old proof now has a reliability boundary that future readers must consume.

Required row fields

witness_recantation_row:
  recantation_id: <stable id>
  source_proof:
    source_proof_id: <caption witness ledger operator conclave row recap fragment callback carrier or equivalent>
    source_surface: operator_witness_conclave | caption_witness_custody | access_caption_reliance | recap_syndication | callback_carrier_collision | protected_witness_payroll | equivalent
    source_session_id_or_absence: <session id or explicit_absence>
    source_seed_or_absence: <seed or explicit_absence>
    accepted_by_reader: sponsor | public | lawful_reader | archive | fan_public | route_asset | broadcast_reality | split | equivalent
    accepted_state_before: accepted | accepted_with_scar | public_only | lawful_only | sponsor_only | caption_only | split_required | protected | quarantined | equivalent
  witness:
    witness_id: <person operator delegate caption witness or explicit_absence>
    witness_state_before: protected | recruited | retained | suppressed | captured | hostile | disappeared | public_shelter | audit_protected | masked_by_edit | explicit_absence | equivalent
    state_change_source: reprisal | counterproof | lawful_pressure | sponsor_capture | public_contradiction | edit_checksum | archive_order | route_asset_claim | equivalent
    new_statement_state: upheld | narrowed | corrected | retracted | contradicted | coerced_silence | unavailable | hostile_counterstatement | explicit_absence | equivalent
  reliance_boundary:
    reliance_reader: sponsor | public | lawful_reader | archive | fan_public | route_asset | broadcast_reality | equivalent
    omitted_or_harmed_reader: <reader or explicit_absence>
    proof_gap_or_absence: context_missing | caption_context_gap | service_gap | chain_gap | coercion_gap | source_scope_gap | explicit_absence
    future_reader_or_route: <reader route asset rite proof window or explicit_absence>
  resolution:
    selected_posture: corroborate | narrow_scope | publish_correction | protect_recantation | substitute_proof | quarantine_reliance | default_clean_reuse
    relief_gained: []
    cost_paid: []
    future_effect: upheld_with_scar | scope_narrowed | correction_required | witness_protection_required | proof_substitution_scar | quarantined | blocked | hostile | recovery_only | false_clean_reuse | equivalent

Creation rules

Create or update this card only from state pressure:

  • a previously accepted proof object, witness row, operator row, caption witness, recap fragment, callback carrier, or protected person exists;
  • a later state change makes the old testimony disputed, narrowed, contradicted, coerced, unavailable, or risky;
  • at least one future reader or route would otherwise reuse the old proof as clean;
  • the witness state and proof boundary are visible, or their absence is explicit;
  • the player can corroborate, narrow, correct, protect, substitute, quarantine, or default the reliance.

The card must not be created from fixed turn number, day/week interval, raw testimony count, relationship score, dashboard state, lens health, or generic late-game escalation.

What the card catches

  • an access-caption route citing a caption witness whose context was later withdrawn;
  • a recap fragment relying on an operator who has since been captured by sponsor wording;
  • a callback carrier collision solved through a witness who later refuses cross-reader service;
  • a protected witness staying useful after payroll leak without a reliability rehearing;
  • a route asset unlocking from operator proved it without reading that operator’s changed state.

Scar memory

Every resolution leaves at least one visible scar:

  • testimony_reliance.scope_narrowed
  • testimony_reliance.correction_required
  • testimony_reliance.counterproof_needed
  • testimony_reliance.witness_protection_required
  • testimony_reliance.source_ambiguity
  • testimony_reliance.route_costlier
  • testimony_reliance.false_clean_reuse_default

A recantation review can preserve a route, but it cannot retroactively make the old testimony universally clean.

Counter hooks

The card may mutate or expose:

  • testimony_reliability
  • source_ambiguity
  • witness_safety_debt
  • witness_retaliation_risk
  • public_receipt_distrust
  • access_caption_pressure
  • caption_context_debt
  • sponsor_stop_loss_pressure
  • contract_capture
  • lawful_annex_debt
  • archive_debt
  • route_asset_pressure
  • broadcast_reality_drift
  • future_route_cost
  • recovery_only_pressure

Non-goals

  • Not generic witness danger; 证人报复链 already handles retaliation.
  • Not first testimony creation; 操作员证词合议线 handles testimony formation.
  • Not a relationship or loyalty meter.
  • Not a clean appeal reset.
  • Not valid unless a future route or reader would consume the old proof state.