Unauthorized Recipient Service Default / 无权限受领送达默认
Unauthorized Recipient Service Default fires or arms when a notice, callback, counterreceipt, addendum, remedy, or route packet is treated as served because someone received it, even though that recipient did not have current authority for the intended reader.
This event is the service-side mirror of 未送达容量告知 and 沉默代表默认. It does not erase the delivery attempt. It records that delivery and authority diverged.
Default triggers
Fire or arm this event when any of these are true:
- a stale class representative receives notice for a cohort whose mandate has drifted;
- an access operator receives notice for readers who are outside the operator’s current scope;
- a sponsor, lawful, archive, public, or fan-only recipient is filed as universal service;
- a discharged witness carrier or substitute carrier accepts a service row without renewed authority;
- a proxy runner receipt is treated as reader consent;
- a withdrawn, bought-off, captured, absent, or hostile recipient is used as proof of service;
- future play consumes the service row without checking current recipient authority.
Required payload
unauthorized_recipient_service_default_required:
event: storyteller.event.unauthorized_recipient_service_default.v1
source_service_row:
source_row_id: <row id or explicit_absence>
source_surface: <surface or explicit_absence>
service_purpose: <purpose or explicit_absence>
intended_reader: <reader or explicit_absence>
affected_cohorts: []
recipient:
selected_recipient: <actor desk carrier delegate proxy or explicit_absence>
recipient_class: <class or explicit_absence>
authority_source_row_or_absence: <row or explicit_absence>
authority_scope: <scope or explicit_absence>
authority_state_at_service: stale | limited | refused | absent | proxy_only | disputed | hidden | equivalent
false_service:
false_service_claim: old_representative_served_all | operator_signed_for_all | sponsor_notice_as_public | lawful_annex_as_public | public_notice_as_lawful | witness_receipt_as_current | proxy_receipt_as_consent | absence_as_service | equivalent
default_narrator: sponsor | management_table | archive | lawful_reader | public_table | route_claimant | access_operator | proxy_runner | broadcast_reality | equivalent
omitted_or_deferred_readers: []
hidden_authority_gap: <gap or explicit_absence>
aftermath:
service_state_after: false_served | reservice_required | split_required | public_only | lawful_only | sponsor_only | blocked | hostile | recovery_only | contradiction_pending | equivalent
recipient_state_after: false_authority | hostile | captured | exposed | absent | quarantined | recovery_only | equivalent
future_reader_or_route_effect: callback_required | addendum_required | reservice_required | audit_required | route_delay | blocked | hostile | costlier | recovery_only | contradiction_pending | equivalent
counter_deltas_min: 3The event fails if it changes only money, mood, generic complaint pressure, or reputation.
Future scar
A valid default must be consumed later by at least one reader or route. Accepted effects include reservice_required, split_required, blocked, hostile, audit_required, route_delay, recovery_only, or contradiction_pending.
Non-goals
- Not punishment for choosing a slow branch.
- Not a generic missed notice.
- Not valid when the intended reader and the recipient’s current authority are both explicit and aligned.