Final Archive Signoff Readback / 最终归档签核读回 Lens

Design intent

Prove that the existing Final Archive Signoff sequence carries a distinct artist posture and signoff result through to Claimants at the Table. The lens prevents an official, fan-authorized, or unfiled result from erasing the earlier artist answer and prevents the downstream claimant table from being mistaken for the signoff itself.

The observable surface is limited to current archive-version status and carry-forward.

Exact source chain oracle

A passing replay must show these source objects in this exact order:

  1. storyteller-rite-24-disaster-naming-rights
  2. storyteller-event-21-artists-refuse-archive
  3. storyteller-rite-25-final-archive-signoff
  4. storyteller-rite-26-claimants-at-table

The lens fails if Event 21 is skipped, Rite 25 is bypassed, or a Rite 26 claimant choice is presented as the Rite 25 result.

Six-row evidence oracle

Every focused replay must expose exactly these six readback rows, in order:

  1. continuity docket — card-storyteller-continuity-docket
  2. safe archive version — card-storyteller-safe-archive-version
  3. fan archive signature — card-storyteller-fan-archive-signature
  4. disaster naming rights — card-storyteller-disaster-naming-rights
  5. unfiled blackbox fragment — card-storyteller-unfiled-blackbox-fragment
  6. Han Yanshuang signatory — card-storyteller-han-yanshuang

These rows do not map to six slots. Rite 25 keeps two legacy staging slots, slot-docket and slot-signature, whose accepts entries are canonical hints only. A passing evaluator verifies the resolved artist answer and five card-possession preconditions, then the idempotently normalized evidence-ready/fragment after-state. Staging assignments must be in hand but never count as authority evidence.

Posture oracle

Event 21 exposes stable option IDs, with index retained as an order check.

Option indexStable option IDRequired posture flagNormalized posture
0pacify_archive_identity_proteststoryteller_artist_archive_pacifiedpacified
1preserve_unfiled_artist_selfstoryteller_artists_keep_unfiled_selfunfiled_self

Both options normally show storyteller_artists_archive_answered, storyteller_archive_signoff_evidence_ready, and the gained unfiled blackbox fragment. Rite 25 requires the resolved event and artist-answer flag, then idempotently reasserts evidence-ready/fragment for compatible legacy saves. Exactly one posture-specific flag is selected for each focused replay, and the posture must remain readable after Rite 25.

Signoff-result oracle

Rite 25 exposes stable choice IDs, with index retained as an order check.

Choice indexStable choice IDCodeRequired mirrored flagNormalized result
0seal_official_continuity1storyteller_official_continuity_sealedofficial_continuity_sealed
1authorize_fan_archive2storyteller_fan_archive_authorizedfan_archive_authorized
2refuse_final_signoff3storyteller_unfiled_reality_survivesunfiled_reality_survives

finalArchiveSignoffResultCode is canonical. Each choice sets its code and leaves exactly one mirrored result flag true by unsetting the other two. Stable choice ID, index, code, normalized result, and flag must agree.

Four-profile coverage oracle

Required replay profileEvent 21Rite 25Required assertion
pacified-officialoption 0choice 0pacified + official + Rite 26 reachable
pacified-fan-authorizedoption 0choice 1pacified + fan-authorized + Rite 26 reachable
unfiled-official-conflictoption 1choice 0unfiled + official coexist as conflict + Rite 26 reachable
unfiled-refusaloption 1choice 2unfiled + unfiled-result + Rite 26 reachable

The four profiles must collectively cover both artist postures and all three signoff results. They are focused coverage, not all six possible combinations.

Carry-forward oracle

All three Rite 25 choices inherit the same common effects. Every focused replay must show:

  • storyteller_archive_signoff_convened and storyteller_archive_signoff_result_recorded after Rite 25;
  • evidence-ready plus the blackbox fragment, whether normally prepared by Event 21 or idempotently normalized by Rite 25;
  • finalArchiveSignoffProgress === 1 and result code in 1..3 after Rite 25;
  • exactly one mirrored result flag agreeing with the code;
  • the chosen Event 21 posture still visible;
  • the chosen Rite 25 result still visible;
  • storyteller-rite-26-claimants-at-table reachable.

Rite 26 must reject progress other than 1 or code outside 1..3, and it requires an explicit claimant option. If it resolves, its two legacy staging assignments remain non-authoritative, the code is unchanged, progress becomes 2, and storyteller_archive_claimants_convened, storyteller_archive_signoff_result_carried_to_claimants, and card-storyteller-archive-ownership-table become downstream evidence. They cannot replace any upstream assertion.

Authority-boundary oracle

Every replay/readback must explicitly keep these inferences false:

  1. signoff_overrides_artist_consent_or_refusal
  2. fan_signature_grants_artist_claimant_or_owner_authority
  3. signoff_grants_voice_ownership_or_permission
  4. signoff_grants_memorial_or_archive_license
  5. disaster_naming_contract_grants_victim_name_authority
  6. signoff_determines_medical_status_personhood_or_death
  7. blackbox_carry_forward_grants_universal_custody_or_ownership
  8. signoff_authorizes_later_reuse_or_afteruse
  9. han_yanshuang_signatory_equals_universal_inspector_approval
  10. rite_26_claimant_choice_rewrites_artist_posture_or_signoff_result

Pass conditions

The lens passes only when all of the following are evaluator-visible:

  • exact Rite 24 Event 21 Rite 25 Rite 26 order;
  • exact six-row evidence table backed by five enforced card preconditions plus the idempotently ensured fragment, never six claimed slots;
  • exactly two legacy staging slots on Rite 25 and Rite 26, with staging explicitly denied authority;
  • result code mapping 1/2/3 plus exactly one agreeing mirrored result flag;
  • both artist postures across the four focused profiles;
  • all three signoff results across the four focused profiles;
  • explicit conflict preservation in unfiled-official-conflict;
  • Rite 26 progress/code gates, required claimant option, unchanged result code, carried flag, and progress 2;
  • all authority denials remain false;
  • source identity is storyteller for every runtime object used.

Required replay evidence

  • lens/replays/final-archive-signoff-readback.pacified-official.replay.json
  • lens/replays/final-archive-signoff-readback.pacified-fan-authorized.replay.json
  • lens/replays/final-archive-signoff-readback.unfiled-official-conflict.replay.json
  • lens/replays/final-archive-signoff-readback.unfiled-refusal.replay.json

These four evaluator-registered game-cli exports are the required implemented replay contract.

Non-goals

  • Not a claimant ownership lens.
  • Not a consent, voice, memorial, victim-name, medical, personhood, death, or universal-custody lens.
  • Not an afteruse lens.
  • Not a replacement for the disaster-naming/continuity-lease or archive/memorial-claims lenses.
  • Not satisfied by simple source-object existence or by a single happy-path replay.