Broadcast Warrant Trace Lens / 播出许可痕迹 Lens

This lens observes whether 播出许可痕迹线 turns the older 播出许可机制 rule into a visible authority, cost, and trace contract.

Observable promise

A passing implementation must show:

  • a major intervention;
  • warrant authority or explicit absence;
  • operator surface;
  • cut path;
  • cost surface;
  • selected warrant branch;
  • trace state after;
  • future reader or route effect;
  • durable default when authority, operator, cost, or trace is hidden.

The lens fails if a powerful action becomes broadcast reality only because it succeeded locally.

Entry oracle

entry_state_required:
  trigger_kind: state_pressure
  major_intervention_attempted: true
  warrant_authority_or_explicit_absence_visible: true
  operator_surface_visible: true
  cut_path_or_explicit_absence_visible: true
  cost_surface_or_explicit_absence_visible: true
  trace_can_mutate_future_reader: true
  future_reader_consumes_warrant_trace: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_authority_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

The lens must fail if entry comes from a fixed turn number, day/week interval, raw authority count, dashboard state, lens health, or generic permission pressure without a named intervention.

Exact runtime oracle

The rite must expose exactly eight required slots and accept only these real source: storyteller cards from hand:

SlotExact card ID
ledgerstoryteller.card.broadcast_warrant_ledger.v1
interventionstoryteller.card.broadcast_warrant_intervention.v1
authority_sourcestoryteller.card.broadcast_warrant_authority_source.v1
operator_surfacestoryteller.card.broadcast_warrant_operator_surface.v1
cut_pathstoryteller.card.broadcast_warrant_cut_path.v1
cost_surfacestoryteller.card.broadcast_warrant_cost_surface.v1
future_readerstoryteller.card.broadcast_warrant_future_reader.v1
default_riskstoryteller.card.broadcast_warrant_default_risk.v1

Virtual assignments, a selected-branch card, missing cards, broad accepts, or cards not in hand fail the lens.

Every selected rite option must leave exactly one branch/state/future triple:

Branch IDState flag suffixFuture flag suffix
sponsor_warrantsponsor_scoped_warrantsponsor_only_until_unwind
lawful_warrantlawful_authorized_tracelawful_only_with_public_addendum
archive_warrantarchive_scoped_warrantarchive_reader_must_name_source
oxygen_warrantoxygen_public_warrantfan_public_receipt_required
audit_warrantaudit_locked_warrantaudit_reader_required
unauthorized_witnessdirty_public_tracelawful_annex_or_recovery_required
black_box_cutblack_box_tracechecksum_required_before_reuse
refuse_broadcastbroadcast_refusednoncanon_intervention_preserved
unauthorized_trace_defaultunauthorized_default_pendingunauthorized_warrant_recovery_pending

The full flags are broadcast_warrant.branch.<branch>, broadcast_warrant.state.<state>, and future_route.<future>. A run fails if it leaves two branches, states, or futures true.

Ledger oracle

Broadcast Warrant Ledger must separate:

ledger_required:
  intervention_id: <stable intervention id>
  authority_source_or_absence: <authority or explicit_absence>
  operator_surface: <operator or explicit_absence>
  cut_path: <cut path or explicit_absence>
  cost_surface: <cost or explicit_absence>
  trace_state_after: <trace state>
  future_reader_or_route: <future consumer>
  unauthorized_default_risk: <risk>

The ledger fails if it stores only authorized, permission ok, succeeded, sponsor paid, legal approved, or edited clean.

Rite oracle

Broadcast Warrant Trace Review must expose divergent branch families:

  • sponsor_warrant
  • lawful_warrant
  • archive_warrant
  • oxygen_warrant
  • audit_warrant
  • unauthorized_witness
  • black_box_cut
  • refuse_broadcast
  • unauthorized_trace_default

Each branch must include relief, cost, trace state after, and future_effect_any.

For runtime, future_effect_any is not an open synonym set: it must equal the single exact future effect in the runtime table above. All nine choices must have effect-backed relief, cost, state, and future mutations; metadata-only counters or labels do not pass.

Default oracle

Unauthorized Warrant Trace Default must record:

Only unauthorized_trace_default may arm the event. It must set all four flags, while the other eight branches clear them and cannot reach the event:

  • broadcast_warrant.unauthorized_default_pending
  • event.unauthorized_warrant_trace_default.armed
  • future_route.unauthorized_warrant_recovery_pending
  • broadcast_reality.false_clean_warrant_claimed

The event must expose exactly three terminal/state/future mappings:

Terminal IDExact state afterExact future effect
expose_authority_gapauthority_gap_exposedpublic_or_lawful_warrant_review_required
quarantine_false_warrantfalse_warrant_quarantinedintervention_blocked_until_warrant_served
accept_recovery_only_tracerecovery_only_tracewarrant_trace_recovery_only

Each terminal must clear all four pending flags and leave exactly one terminal state/future pair. The required contextual payload remains:

unauthorized_warrant_trace_default:
  source_ledger: storyteller.card.broadcast_warrant_ledger.v1 | explicit_absence
  attempted_intervention: <intervention id>
  missing_authority: <authority or explicit_absence>
  missing_operator_or_absence: <operator or explicit_absence>
  false_or_missing_cut_path: <cut path or explicit_absence>
  capturing_reader: sponsor | lawful_reader | archive | public_table | oxygen_queue | memorial_route | cutroom | producer_license | management_report | route_asset | blackout_system | equivalent
  trace_state_after: authority_gap_exposed | false_warrant_quarantined | recovery_only_trace
  future_reader_effect: public_or_lawful_warrant_review_required | intervention_blocked_until_warrant_served | warrant_trace_recovery_only

The default fails if it is only a warning, only an audit meter change, or a clean retcon.

Adjacency oracle

The lens observes per-intervention broadcastability and the trace created at review time.

If a test passes because one of those adjacent systems supplied its own result without the exact eight-card warrant review, this lens fails.

Local authority oracle

All card, rite, event, public-rollup, replay, and evaluator surfaces must preserve the exact local denial boundary:

authority_boundary:
  localAuthorityOnly: true
  recordsInterventionWarrantTraceOnly: true
  preservesNamedAuthorityOperatorCutAndCost: true
  preservesFutureReaderScope: true
  requiresVisibleTraceForBroadcastReality: true
  grantsConsent: false
  grantsLegalValidity: false
  grantsWaiver: false
  grantsSettlement: false
  grantsRouteClearance: false
  grantsArchiveRelease: false
  grantsProofTruth: false
  grantsSponsorWarranty: false
  grantsProducerLicenseRelease: false
  grantsSponsorAuthority: false
  grantsFanAuthority: false
  grantsInspectorAuthority: false
  grantsEditorAuthority: false
  grantsProducerLicense: false
  grantsFutureReuseAuthority: false
  grantsUniversalBroadcastAuthority: false

The packet may prove only that this intervention was reviewed through the named authority source, operator, cut, cost, future reader, and default-risk row.

Executable evidence oracle

The following surfaces are all required and must agree exactly:

  • game-content/storyteller/cards/broadcast-warrant-ledger.json5
  • game-content/storyteller/rites/broadcast-warrant-trace-review.json5
  • game-content/storyteller/events/unauthorized-warrant-trace-default.json5
  • lens/storyteller-broadcast-warrant-trace.runtime.test.ts
  • lens/replays/broadcast-warrant-trace.replay.json
  • scripts/evaluate_lenses.mjs
  • public/data/storytellerCards.json5
  • public/data/storytellerRite+nodes.json5
  • public/data/storytellerEvent+nodes.json5

The focused Jest test owns exhaustive coverage of all nine branch mappings and all three terminals from equivalent reset states. The deterministic replay owns one exact target path only: all eight cards assigned, rite choice index 8 (unauthorized_trace_default), all four pending flags visible, then event option index 0 (expose_authority_gap). A create action, end-turn action without the target rite, unrelated event, or source-object discovery cannot satisfy runtime progress.

Progress metric

  • 20%: storyline, mechanism, ledger, rite, event, and lens links exist.
  • 40%: entry is state-triggered and all eight exact assignment cards are real Storyteller cards required in hand.
  • 60%: all nine branch/state/future mappings are effect-backed and mutually exclusive.
  • 80%: only unauthorized_trace_default arms all four pending flags and all three event terminals resolve exclusively.
  • 100%: focused test, exact choice-8 to option-0 replay, evaluator checks, source objects, public rollups, adjacency, and local authority denials all agree.

Non-goals

  • Not a permission meter.
  • Not a producer-license encumbrance duplicate.
  • Not a sponsor copy warranty duplicate.
  • Not a legality conversion duplicate.
  • Not valid if authority, operator, cost, trace, and future reader collapse into one success flag.