Broadcast Warrant Trace Lens / 播出许可痕迹 Lens
This lens observes whether 播出许可痕迹线 turns the older 播出许可机制 rule into a visible authority, cost, and trace contract.
Observable promise
A passing implementation must show:
- a major intervention;
- warrant authority or explicit absence;
- operator surface;
- cut path;
- cost surface;
- selected warrant branch;
- trace state after;
- future reader or route effect;
- durable default when authority, operator, cost, or trace is hidden.
The lens fails if a powerful action becomes broadcast reality only because it succeeded locally.
Entry oracle
entry_state_required:
trigger_kind: state_pressure
major_intervention_attempted: true
warrant_authority_or_explicit_absence_visible: true
operator_surface_visible: true
cut_path_or_explicit_absence_visible: true
cost_surface_or_explicit_absence_visible: true
trace_can_mutate_future_reader: true
future_reader_consumes_warrant_trace: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_authority_count_trigger: true
no_dashboard_or_lens_health_trigger: trueThe lens must fail if entry comes from a fixed turn number, day/week interval, raw authority count, dashboard state, lens health, or generic permission pressure without a named intervention.
Exact runtime oracle
The rite must expose exactly eight required slots and accept only these real source: storyteller cards from hand:
| Slot | Exact card ID |
|---|---|
ledger | storyteller.card.broadcast_warrant_ledger.v1 |
intervention | storyteller.card.broadcast_warrant_intervention.v1 |
authority_source | storyteller.card.broadcast_warrant_authority_source.v1 |
operator_surface | storyteller.card.broadcast_warrant_operator_surface.v1 |
cut_path | storyteller.card.broadcast_warrant_cut_path.v1 |
cost_surface | storyteller.card.broadcast_warrant_cost_surface.v1 |
future_reader | storyteller.card.broadcast_warrant_future_reader.v1 |
default_risk | storyteller.card.broadcast_warrant_default_risk.v1 |
Virtual assignments, a selected-branch card, missing cards, broad accepts, or cards not in hand fail the lens.
Every selected rite option must leave exactly one branch/state/future triple:
| Branch ID | State flag suffix | Future flag suffix |
|---|---|---|
sponsor_warrant | sponsor_scoped_warrant | sponsor_only_until_unwind |
lawful_warrant | lawful_authorized_trace | lawful_only_with_public_addendum |
archive_warrant | archive_scoped_warrant | archive_reader_must_name_source |
oxygen_warrant | oxygen_public_warrant | fan_public_receipt_required |
audit_warrant | audit_locked_warrant | audit_reader_required |
unauthorized_witness | dirty_public_trace | lawful_annex_or_recovery_required |
black_box_cut | black_box_trace | checksum_required_before_reuse |
refuse_broadcast | broadcast_refused | noncanon_intervention_preserved |
unauthorized_trace_default | unauthorized_default_pending | unauthorized_warrant_recovery_pending |
The full flags are broadcast_warrant.branch.<branch>, broadcast_warrant.state.<state>, and future_route.<future>. A run fails if it leaves two branches, states, or futures true.
Ledger oracle
Broadcast Warrant Ledger must separate:
ledger_required:
intervention_id: <stable intervention id>
authority_source_or_absence: <authority or explicit_absence>
operator_surface: <operator or explicit_absence>
cut_path: <cut path or explicit_absence>
cost_surface: <cost or explicit_absence>
trace_state_after: <trace state>
future_reader_or_route: <future consumer>
unauthorized_default_risk: <risk>The ledger fails if it stores only authorized, permission ok, succeeded, sponsor paid, legal approved, or edited clean.
Rite oracle
Broadcast Warrant Trace Review must expose divergent branch families:
sponsor_warrantlawful_warrantarchive_warrantoxygen_warrantaudit_warrantunauthorized_witnessblack_box_cutrefuse_broadcastunauthorized_trace_default
Each branch must include relief, cost, trace state after, and future_effect_any.
For runtime, future_effect_any is not an open synonym set: it must equal the single exact future effect in the runtime table above. All nine choices must have effect-backed relief, cost, state, and future mutations; metadata-only counters or labels do not pass.
Default oracle
Unauthorized Warrant Trace Default must record:
Only unauthorized_trace_default may arm the event. It must set all four flags, while the other eight branches clear them and cannot reach the event:
broadcast_warrant.unauthorized_default_pendingevent.unauthorized_warrant_trace_default.armedfuture_route.unauthorized_warrant_recovery_pendingbroadcast_reality.false_clean_warrant_claimed
The event must expose exactly three terminal/state/future mappings:
| Terminal ID | Exact state after | Exact future effect |
|---|---|---|
expose_authority_gap | authority_gap_exposed | public_or_lawful_warrant_review_required |
quarantine_false_warrant | false_warrant_quarantined | intervention_blocked_until_warrant_served |
accept_recovery_only_trace | recovery_only_trace | warrant_trace_recovery_only |
Each terminal must clear all four pending flags and leave exactly one terminal state/future pair. The required contextual payload remains:
unauthorized_warrant_trace_default:
source_ledger: storyteller.card.broadcast_warrant_ledger.v1 | explicit_absence
attempted_intervention: <intervention id>
missing_authority: <authority or explicit_absence>
missing_operator_or_absence: <operator or explicit_absence>
false_or_missing_cut_path: <cut path or explicit_absence>
capturing_reader: sponsor | lawful_reader | archive | public_table | oxygen_queue | memorial_route | cutroom | producer_license | management_report | route_asset | blackout_system | equivalent
trace_state_after: authority_gap_exposed | false_warrant_quarantined | recovery_only_trace
future_reader_effect: public_or_lawful_warrant_review_required | intervention_blocked_until_warrant_served | warrant_trace_recovery_onlyThe default fails if it is only a warning, only an audit meter change, or a clean retcon.
Adjacency oracle
The lens observes per-intervention broadcastability and the trace created at review time.
- It does not perform Broadcast Legality Conversion.
- It does not price or release Producer License Encumbrance.
- It does not warranty Sponsor Copy Warranty.
- It does not consume an existing trace through Warrant Trace Afteruse Receipt.
If a test passes because one of those adjacent systems supplied its own result without the exact eight-card warrant review, this lens fails.
Local authority oracle
All card, rite, event, public-rollup, replay, and evaluator surfaces must preserve the exact local denial boundary:
authority_boundary:
localAuthorityOnly: true
recordsInterventionWarrantTraceOnly: true
preservesNamedAuthorityOperatorCutAndCost: true
preservesFutureReaderScope: true
requiresVisibleTraceForBroadcastReality: true
grantsConsent: false
grantsLegalValidity: false
grantsWaiver: false
grantsSettlement: false
grantsRouteClearance: false
grantsArchiveRelease: false
grantsProofTruth: false
grantsSponsorWarranty: false
grantsProducerLicenseRelease: false
grantsSponsorAuthority: false
grantsFanAuthority: false
grantsInspectorAuthority: false
grantsEditorAuthority: false
grantsProducerLicense: false
grantsFutureReuseAuthority: false
grantsUniversalBroadcastAuthority: falseThe packet may prove only that this intervention was reviewed through the named authority source, operator, cut, cost, future reader, and default-risk row.
Executable evidence oracle
The following surfaces are all required and must agree exactly:
game-content/storyteller/cards/broadcast-warrant-ledger.json5game-content/storyteller/rites/broadcast-warrant-trace-review.json5game-content/storyteller/events/unauthorized-warrant-trace-default.json5lens/storyteller-broadcast-warrant-trace.runtime.test.tslens/replays/broadcast-warrant-trace.replay.jsonscripts/evaluate_lenses.mjspublic/data/storytellerCards.json5public/data/storytellerRite+nodes.json5public/data/storytellerEvent+nodes.json5
The focused Jest test owns exhaustive coverage of all nine branch mappings and all three terminals from equivalent reset states. The deterministic replay owns one exact target path only: all eight cards assigned, rite choice index 8 (unauthorized_trace_default), all four pending flags visible, then event option index 0 (expose_authority_gap). A create action, end-turn action without the target rite, unrelated event, or source-object discovery cannot satisfy runtime progress.
Progress metric
- 20%: storyline, mechanism, ledger, rite, event, and lens links exist.
- 40%: entry is state-triggered and all eight exact assignment cards are real Storyteller cards required in hand.
- 60%: all nine branch/state/future mappings are effect-backed and mutually exclusive.
- 80%: only
unauthorized_trace_defaultarms all four pending flags and all three event terminals resolve exclusively. - 100%: focused test, exact choice-
8to option-0replay, evaluator checks, source objects, public rollups, adjacency, and local authority denials all agree.
Non-goals
- Not a permission meter.
- Not a producer-license encumbrance duplicate.
- Not a sponsor copy warranty duplicate.
- Not a legality conversion duplicate.
- Not valid if authority, operator, cost, trace, and future reader collapse into one success flag.