Confidant Promise Breach Lens / 私约违背 Lens

This lens observes whether 私约违背线 and 私约违背机制 correctly make named private promises into playable route pressure.

The current mesh is already strong at service scope, evidence carryover, mandate scarcity, handler burden, witness reprisal, protected witness payroll, and public contrition. This lens targets the next gap: a character trusting the producer with material is not automatic permission to spend that material.

A passing implementation must prove named confidant, protected material, requested use, permission scope, pressure actor, threat if unused, assigned hearing, branch divergence, and future character or route consumption. A generic relationship value, affection flag, or hidden trust penalty does not satisfy this lens.

This lens observes:

It is observed through:

Observable promise

When private material becomes useful, the game must show:

  • promise row or explicit absence;
  • named confidant or explicit absence;
  • promise holder;
  • protected material;
  • permission scope or explicit absence;
  • requested use;
  • pressure actor;
  • proof or explicit absence;
  • threat if unused;
  • handler or explicit absence;
  • shield, cost, or explicit absence;
  • selected posture;
  • promise state after;
  • character state after;
  • protected material state after;
  • future character or route effect.

The lens fails if the result is only trust +1, trust -1, character angry, character loyal, romance locked, proof accepted, route unlocked, handler assigned, or public knows.

Entry oracle

A valid implementation opens only from live state pressure:

entry_state_required:
  trigger_kind: state_pressure
  named_confidant_or_explicit_absence_visible: true
  private_promise_or_boundary_present: true
  protected_material_visible: true
  requested_use_present: true
  permission_scope_visible_or_explicit_absence: true
  pressure_actor_visible: true
  threat_if_unused_visible: true
  future_character_or_route_consumes_promise_state: true
  player_can_honor_renegotiate_anonymize_protect_trade_refuse_breach_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_promise_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

The lens must fail if entry comes from fixed turn number, fixed day/week interval, chapter quota, raw character count, raw promise count, relationship-point threshold, dashboard state, lens health, generic social scene, or generic proof import.

Ledger oracle

私约承诺账本 or equivalent must record three locks separately.

ledger_required:
  trust_lock:
    promise_id: <stable id>
    promise_holder: producer | handler | archive | editor | sponsor | public_witness | equivalent
    confidant_character: yu_lan | baiya | shen_luo | han_yanshuang | mu_ning | ai_sheng | li_xingtong | equivalent | explicit_absence
    promise_origin_surface: character_scene | witness_intake | edit_room | archive_copy | oxygen_queue | rehearsal | route_asset | lawful_hearing | equivalent
    private_boundary: private_only | named_hearing_only | anonymous_public | lawful_only | route_asset_only | emergency_only | disputed | explicit_absence
  material_lock:
    protected_material: confession | refusal | source_identity | route_secret | witness_name | checksum | unreleased_take | private_boundary | equivalent
    proof_or_absence: <receipt oath checksum statement memory note or explicit_absence>
    requested_use: proof_anchor | public_addendum | lawful_appeal | sponsor_countercopy | management_metric | route_unlock | handler_authority | witness_protection | equivalent
  consequence_lock:
    pressure_actor: sponsor | archive | inspector | fan_public | management | editor | route_claimant | producer | broadcast_reality | equivalent
    threat_if_unused: route_blocked | legal_exposure | public_distrust | witness_unprotected | proof_gap | handler_burden | sponsor_capture | equivalent
    shield_or_cost_or_absence: witness_payroll | anonymity_shell | lawful_seal | public_contrition | route_quarantine | substitute_proof | sponsor_release | handler_burden | explicit_absence | equivalent
    promise_state: pending | honored | renegotiated | anonymized | protected_disclosure | traded | refused | breached | hostile | missed | recovery_only
    future_character_or_route: <character route route asset rite ending scar or explicit_absence>

The lens fails if trust, material, requested use, scope, and future consequence are collapsed into one generic relationship row.

Hearing assignment oracle

私约承诺听证 or equivalent must require explicit assignment.

assignment_required:
  docket: storyteller.card.confidant_promise_ledger.v1
  selected_promise_row: <row id>
  confidant_character: <named character or explicit_absence>
  protected_material: <material>
  requested_use: <use>
  permission_scope_or_absence: <scope or explicit_absence>
  pressure_actor: <actor>
  threat_if_unused: <threat>
  handler_or_absence: producer | shen_luo | yu_lan | han_yanshuang | baiya | ai_sheng | fan_delegate | lawful_clerk | archive_clerk | explicit_absence | equivalent
  shield_or_cost_or_absence: <shield cost or explicit_absence>
  selected_posture: honor_privacy | renegotiate_consent | anonymize_source | protected_disclosure | trade_promise | refuse_use | public_breach | silent_breach_default
  future_character_or_route: <future consumer>

The lens fails if sponsor money, archive authority, lawful seal, public outrage, edit checksum, or famous handler can spend the private material without these slots.

Branch divergence oracle

A satisfying implementation must prove at least five constructive branch families plus default, or explicitly block missing families with state reasons.

Branch familyRequired reliefRequired costRequired future effect
Honor privacytrust or boundary preserved, source exposure downproof gap, route cost, sponsor/archive pressuresubstitute proof, route costlier, handler burden
Renegotiate consentscoped use becomes legitimate, proof gains scopeconsent debt, notice burden, recovery costscoped-use-only, further notice, character route costlier
Anonymize sourcematerial can be used without exposing charactersource ambiguity, archive debt, weaker proofcorroboration required, contradiction pending
Protected disclosurelawful/public hearing or witness path openswitness payroll, inspection heat, route delayshield required, witness route with cost
Trade promiseimmediate route pressure dropsfaction capture, private capture, public distrustfaction gate, character hostile or costlier
Refuse usebreach blocked, boundary preservedlegal exposure, public distrust, proof gapappeal, addendum, substitute proof required
Public breachpublic truth or route access opens nowtrust loss, exposure, recruitability damagehostile witness, public contrition, recovery-only risk
Silent breach defaultfastest desk consumes materialhidden breach hardenshostile, unavailable, missed, blocked, recovery-only

No branch may create universal acceptance across character, public, lawful, sponsor, archive, management, route asset, handler, and broadcast-reality readers.

Default oracle

私约违背默认 must fire or arm when:

  • protected material is used without a promise row;
  • permission scope is absent, hidden, or violated;
  • a private source identity becomes public proof without anonymization or shield;
  • a refusal becomes broadcast consent;
  • a checksum shared under edit boundary becomes sponsor-safe copy;
  • a lawful exception becomes universal route unlock;
  • a child-voice trace becomes public counterfeed without protection;
  • a future character or route consumes the material without reading promise state.

Required payload:

default_required:
  event: storyteller.event.confidant_breach_default.v1
  promise_row_or_absence: <row id or explicit_absence>
  confidant_character: <named character or explicit_absence>
  promise_origin_surface: <surface or explicit_absence>
  protected_material: <material or explicit_absence>
  requested_use: proof_anchor | public_addendum | lawful_appeal | sponsor_countercopy | management_metric | route_unlock | handler_authority | witness_protection | equivalent
  breach_actor: producer | sponsor | archive | inspector | fan_public | management | editor | route_claimant | broadcast_reality | equivalent
  missing_or_violated_inputs:
    permission_scope: present | hidden | absent | violated
    proof_anchor: present | hidden | absent
    character_notice: present | hidden | absent
    protection_or_shield: present | hidden | absent
    future_route_consumer: present | hidden | absent
  breach_state_after: promise_breached | source_exposed | private_capture | hostile_witness | handler_unavailable | recruit_missed | recovery_only | equivalent
  future_character_or_route_effect: hostile | unavailable | costlier | faction_bound | public_only | lawful_only | blocked | recovery_only | ending_scar | equivalent

The default fails if it changes only mood, money, generic reputation, or hidden affection.

Success cost oracle

Every non-default branch must include relief, cost, and future effect:

counter_deltas_required:
  relief: at_least_one
  cost: at_least_one
  future_character_or_route_effect: at_least_one

Accepted surfaces include confidant_trust, character_availability, recruitability, missability, witness_exposure, handler_burden, proof_legitimacy, source_ambiguity, public_receipt_distrust, sponsor_capture, archive_debt, producer_license_pressure, route_asset_access_cost, future_recovery_cost, and broadcast_reality_drift.

Future consumption oracle

At least one later surface must consume the promise state:

  • character recruitability changes;
  • character missability changes;
  • handler becomes available, unavailable, hostile, or costlier;
  • route asset becomes protected, costlier, hostile, blocked, faction-bound, public-only, lawful-only, or recovery-only;
  • proof requires anonymized corroboration, lawful rehearing, public contrition, substitute proof, or protection;
  • witness reprisal or protected witness payroll opens;
  • producer license pressure reads the breach, shield, or public contrition scar;
  • broadcast reality hardens a public, lawful, sponsor, or recovery-only version of the promise use.

If the outcome remains local to one conversation scene, the lens is incomplete.

Progress metric

confidantPromiseBreachProgress = 0..9:

  • 0: no private promise pressure.
  • 1: named confidant or explicit absence plus protected material is visible.
  • 2: requested use and permission scope are visible or explicitly absent.
  • 3: pressure actor and concrete threat if unused are visible.
  • 4: 私约承诺账本 or equivalent records trust, material, and consequence locks separately.
  • 5: 私约承诺听证 exposes handler, shield/cost, selected posture, and future consumer.
  • 6: at least three constructive branch families are available and non-equivalent.
  • 7: selected branch mutates relief, cost, and future character or route effect.
  • 8: 私约违背默认 fires or arms with durable character or route mutation.
  • 9: replay proves constructive branch and breach/default branch, with future consumption by character availability, recruitability, missability, route asset, proof, producer license, or broadcast reality.

Replay/session evidence shape

lens_id: storyteller.lens.confidant_promise_breach.v1
session_id: lens-confidant-promise-breach-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  named_confidant_or_explicit_absence_visible: true
  private_promise_or_boundary_present: true
  protected_material_visible: true
  requested_use_present: true
  permission_scope_visible_or_explicit_absence: true
  pressure_actor_visible: true
  threat_if_unused_visible: true
  future_character_or_route_consumes_promise_state: true
  no_fixed_turn_trigger: true
ledger:
  card: storyteller.card.confidant_promise_ledger.v1
  promise_id: <stable id>
  confidant_character: <character or explicit_absence>
  protected_material: <material>
  permission_scope: <scope or explicit_absence>
  requested_use: <use>
  pressure_actor: <actor>
  threat_if_unused: <threat>
hearing:
  rite: storyteller.rite.confidant_promise_hearing.v1
  selected_posture: honor_privacy | renegotiate_consent | anonymize_source | protected_disclosure | trade_promise | refuse_use | public_breach | silent_breach_default
  handler_or_absence: <handler or explicit_absence>
  shield_or_cost_or_absence: <shield cost or explicit_absence>
outcome:
  promise_state_after: <state>
  character_state_after: <state>
  protected_material_state_after: <state>
  future_character_or_route_effect: <effect>
  counter_deltas:
    relief: []
    cost: []
    future: []
default:
  event_seen_or_armed: storyteller.event.confidant_breach_default.v1 | explicit_absence
assertions:
  - primary_links_exist
  - entry_is_state_triggered_by_private_promise_pressure
  - named_confidant_private_material_requested_use_permission_scope_pressure_actor_and_future_consumer_are_visible
  - promise_ledger_records_trust_material_and_consequence_locks_separately
  - hearing_assignment_slots_are_explicit
  - branches_diverge_by_promise_state_proof_state_character_state_cost_and_future_route_effect
  - every_success_has_relief_cost_and_future_character_or_route_effect
  - silent_breach_default_mutates_character_availability_recruitability_missability_or_route_state
  - private_promise_never_becomes_universal_permission
  - no_generic_affinity_meter
  - no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_trigger

Anti-regression notes

  • Do not satisfy this lens with affection points, friendship tiers, or romance flags.
  • Do not satisfy it with a generic character mood change.
  • Do not satisfy it with proof import unless the in-world promise row, requested use, permission scope, and future consumer are visible.
  • Do not let private trust become universal consent.
  • Do not trigger from fixed turn count, fixed day/week interval, raw count, dashboard state, or lens-health state.