Crystal Dorm Witness Safehouse Lens / 水晶宿舍证人安全屋 Lens

This lens checks whether the existing Crystal Dorm slice of ST-SCALE-07 behaves as a post-build facility storyline rather than ten disconnected runtime objects. It observes exact entry from the ST-SCALE-01 success, exact staff compatibility, public/hidden posture divergence, repeatable operation pressure, inspection, acknowledged safehouse repurpose, fold failure, facility isolation, and narrow authority.

Source and count oracle

source_contract:
  source: storyteller
  scale_family: ST-SCALE-07
  facility_id: card-storyteller-st-scale-07-crystal-dorm-facility
  route_interaction: artist-safehouse
  exact_card_count: 3
  exact_rite_count: 5
  exact_event_count: 2
  total_bound_objects: 10
  public_rollup_parity_required: true

Exact runtime binding

KindExact objectRequired role
cardcard-storyteller-st-scale-07-crystal-dorm-facilityfacility
cardcard-storyteller-st-scale-07-crystal-dorm-medic-slotmedic role-capacity token
cardcard-storyteller-st-scale-07-crystal-dorm-witness-guard-slotwitness-guard role-capacity token
ritestoryteller-rite-st-scale-07-crystal-dorm-buildpost-success build handoff
ritestoryteller-rite-st-scale-07-crystal-dorm-staffexact role-capacity allocation
ritestoryteller-rite-st-scale-07-crystal-dorm-repeatable-userepeatable operation
ritestoryteller-rite-st-scale-07-crystal-dorm-inspectionstaffed inspection response
ritestoryteller-rite-st-scale-07-crystal-dorm-repurposeshowroom/safehouse branch
eventstoryteller-event-st-scale-07-crystal-dorm-inspectionsurprise inspection
eventstoryteller-event-st-scale-07-crystal-dorm-fold-accidentmissed-inspection fold

No other card, rite, or event is part of the bound count. The ST-SCALE-01 success rite is external predecessor evidence. The existing card-storyteller-st-scale-02-glass-dorm-scandal is downstream failure evidence. Neither changes the 3 + 5 + 2 binding.

Must pass

1. Entry comes from the exact existing success

The build surface is blocked until storyteller-st-scale-01-crystal-dorm-plan-success has written storyteller_st_scale_01_crystal-dorm-plan_success. The profile must prove the blocked-before and reachable-after states.

Holding the Crystal Dorm facility card without the predecessor flag is insufficient. Another contract’s success, another facility’s built flag, or an unbound placeholder permit cannot satisfy entry.

This is post-build evidence. Broadcast License: First Contract Gates Reality remains responsible for its own unauthorized-build, acceptance, premiere, and expiry fixture. The lens fails if it replays or claims that pre-build contract as the Crystal Dorm facility board.

2. Three exact cards keep separate roles

The facility card must expose public face, hidden use, all five exact rites, both exact compatible staff tags, both exact inspection/failure events, and routeInteraction: artist-safehouse.

The medic slot must expose staffTag: medic; the witness-guard slot must expose staffTag: witness-guard. They are exact role-capacity tokens. Possession alone may not set facility_crystal-dorm_staffed; only allocation through the staff rite does. Neither token identifies, assigns, recruits, protects, employs, or authorizes an actual person. A generic tag match, another facility’s role-capacity token, or one token duplicated twice fails the lens.

3. Five rites preserve a facility spine plus interrupt

exact ST-SCALE-01 success
  -> build / facility_crystal-dorm_built
       -> public build may open surprise inspection immediately
  -> allocate exact role-capacity token / facility_crystal-dorm_staffed
       -> repeatable operation pressure (zero or more runs)
       -> select surprise-inspection stance / facility_crystal-dorm_inspection_triggered
       -> staffed-capacity inspection response
            -> repurpose / public showroom retained OR hidden safehouse unlocked

Build is an eight-day long operation whose base output is only facility integrity plus the built flag; hidden-use state comes from selecting hidden_use. Role-capacity allocation and repeatable use are quick. Inspection and repurpose are same-day obligations. Repeatable use requires staffed-capacity state, but inspection does not require a repeatable-use completion. The inspection event needs only built plus risk. Its response rite additionally needs facility_crystal-dorm_inspection_triggered, staffed capacity, risk, the exact facility, and an exact medic or witness-guard role-capacity token; it cannot resolve before an event stance is selected. Repurpose follows the inspection record. A global facility flag or another facility’s progress is not equivalent.

4. Public face and hidden use diverge on all five rites

Each rite exposes both stable IDs:

  • public_face, adding spectacle yield and inspection risk;
  • hidden_use, adding artist trust and hidden-use state plus audit heat.

The selected option remains replay-visible per rite. For repeatable use, durable replay/turn history preserves the full posture order while state exposes the run count, ever-posture flags, and mutually exclusive last-posture flags. The lens fails if an option is absent, the effects are identical, one posture silently clears the other’s pressure, or either posture becomes a claim of consent or ownership.

5. Repeatable use accumulates operational pressure

The repeatable-use rite is unavailable before role capacity has been allocated through the staff rite and requires the exact facility plus an exact medic or witness-guard role-capacity token. Each completed operation applies its base facility-integrity, inspection-risk, and spectacle-yield deltas, increments crystal_dorm_operation_runs, preserves the corresponding ever-posture flag, clears the opposite last-posture flag, and sets the selected last-posture flag.

Focused evidence must execute the rite at least twice and compare sequential post-run snapshots. After public then hidden operation, both facility_crystal-dorm_use_public_face and facility_crystal-dorm_use_hidden_use remain true, facility_crystal-dorm_last_operation_public_face is cleared, facility_crystal-dorm_last_operation_hidden_use is true, and the run counter is two. The durable replay/turn log, not aggregate final counters alone, preserves the full order. The lens fails if repeatability farms benefit without inspection risk or audit heat, erases prior pressure or an ever flag, miscounts runs, or leaves both last-posture flags true.

6. Inspection event and staffed response are both reachable

With the exact facility built and inspection risk at least one, the inspection event must trigger. Every selected response writes facility_crystal-dorm_inspection_triggered, while its option-specific effects remain exact and distinct:

  • show_public_face adds spectacle yield +1 and inspection risk +1;
  • route_inspector_to_hidden_use adds public accountability, artist trust, and audit heat +1 each while leaving inspection risk unchanged;
  • seal_room_for_sponsor adds sponsor control +2, artist trust -1, inspection risk +1, and facility integrity -3.

A public-face build can create the event state before role-capacity allocation and without repeatable use. Selecting the sponsor seal after that build leaves a triggered, unrecorded inspection and drives the build’s two integrity to -1, making the fold event endogenously reachable. The response IDs remain exactly show_public_face, route_inspector_to_hidden_use, and seal_room_for_sponsor.

The inspection rite separately requires the triggered flag, built and staffed-capacity state, inspection risk, exact facility input, and an exact compatible role-capacity token. It must be blocked before an event stance is selected. Resolution reduces risk, adds public accountability, and writes facility_crystal-dorm_inspection_recorded. Triggering the event alone is not a recorded inspection; resolving the rite must not erase the event’s pressure or certify the public account as complete truth.

7. Safehouse repurpose follows the inspection record

Only facility_crystal-dorm_inspection_recorded opens the repurpose rite. Its base result records that the choice occurred. public_face retains the public showroom, adds spectacle and inspection risk, and does not unlock the safehouse. Only hidden_use adds artist trust, reduces sponsor control, adds hidden-use and audit pressure, and writes facility_crystal-dorm_artist-safehouse_unlocked.

The safehouse flag is a facility-route capability. It does not recruit any named character, satisfy Mu Ning’s route, or make all artists, witnesses, patients, or staff protected.

8. Fold accident remains a real failure branch

Focused evidence must make the fold event reachable when facility_crystal-dorm_inspection_triggered is true, facility_crystal-dorm_inspection_recorded is false, and facility_integrity <= 0. Those concrete conditions back missed:storyteller-rite-st-scale-07-crystal-dorm-inspection; the profile must not invent a relative-day timeout. Every selected response records facility_crystal-dorm_fold_accident_triggered, then exposes one of three branch-specific outcomes rather than applying one common consequence payload:

  • fold_to_black_screen adds death pressure and grants the exact existing downstream card-storyteller-st-scale-02-glass-dorm-scandal, without adding public accountability;
  • convert_to_public_accountability adds public accountability +2 without granting the black-screen card/death package for free;
  • bury_as_sponsor_maintenance writes sponsor burial/capture pressure instead of either public outcome.

The three option effect sets must be materially different and mutually exclusive: only black-screen receives death pressure and the folded card; public conversion receives accountability, trust, and risk relief without that black-screen package; sponsor burial receives sponsor control, audit heat, and risk relief without either death/card or public-accountability effects. Low integrity alone, an unrecorded response without the inspection-triggered state, a recorded inspection, another facility’s accident, or a generic black-screen event does not satisfy this branch.

9. Sibling facilities cannot substitute

The Blackbox Editing Room, Fan Interaction Hall, and Whitebox Evidence Vault are excluded. Their facility cards, staff slots, route interactions, counters, built/staffed flags, inspections, repurpose flags, and fold accidents must not advance this lens.

The lens also fails if a generic clinic, dorm, safehouse, inspection, or facility object substitutes for one of the ten exact bindings.

10. Authority remains narrow

authority_oracle:
  proves_exact_facility_operation: true
  proves_exact_role_capacity_allocation: true
  proves_person_identity_or_authorization: false
  proves_public_or_hidden_posture: true
  proves_local_inspection_record: true
  proves_safehouse_route_capability: true
  grants_resident_or_witness_ownership: false
  grants_blanket_surveillance_consent: false
  grants_treatment_or_diagnosis_consent: false
  grants_body_or_voice_capture_consent: false
  grants_personhood_or_death_finding: false
  grants_archive_or_memorial_custody: false
  grants_naming_likeness_or_merchandising_rights: false
  grants_universal_facility_access: false
  grants_blanket_broadcast_authority: false

No facility card, staff tag, public presentation, hidden-use acknowledgement, inspection record, safehouse flag, fold accident, counter threshold, or selected response may bypass this boundary.

Completion oracle

passing_result:
  exact_predecessor_success_required: true
  exact_bound_cards: 3
  exact_bound_rites: 5
  exact_bound_events: 2
  public_rollup_parity: true
  exact_staff_tags: [medic, witness-guard]
  role_capacity_tokens_are_not_people: true
  possession_without_staff_rite_is_not_allocation: true
  public_face_option_count: 5
  hidden_use_option_count: 5
  repeatable_pressure_preserved: true
  repeatable_run_counter_and_last_posture_visible: true
  repeatable_full_order_preserved_in_replay_log: true
  inspection_event_and_rite_distinct: true
  inspection_rite_requires_triggered_event_stance: true
  inspection_interrupt_reachable_before_repeatable_use: true
  sponsor_seal_endogenous_fold_path: true
  repurpose_public_showroom_without_safehouse: true
  repurpose_hidden_safehouse_only: true
  fold_options_have_distinct_effects: true
  every_selected_fold_branch_records_common_fold_flag: true
  fold_requires_triggered_unrecorded_inspection_and_nonpositive_integrity: true
  fold_relative_day_timer_required: false
  sibling_facility_substitutions: 0
  named_character_auto_resolutions: 0
  forbidden_authority_mutations: 0

Failure conditions

The lens fails if any of the ten exact objects is absent; build opens without the exact ST-SCALE-01 success; build adds hidden-use state without selecting that branch; a role-capacity token is generic or substituted, possession counts as allocation, or a token is treated as a person; repeatable use opens before the staff rite, miscounts runs, erases an ever flag, or leaves both last-posture flags true; inspection incorrectly waits for repeatable use or its rite resolves before an event stance; the event and staffed-capacity response rite are conflated; any event branch has the wrong risk, integrity, trust, accountability, or sponsor delta; public and hidden postures collapse; repeatable operation loses its pressure; public repurpose unlocks the safehouse; hidden repurpose omits its trust/sponsor cost; the fold event cannot be reached through sponsor sealing, accepts only one prerequisite, gives public conversion less than +2 accountability, or collapses its three option effects; another facility advances the state; a named character route is silently resolved; or any result grants authority beyond the exact facility operation and local record.

Runtime evidence target

The executable sibling registers the object and check contract. Focused runtime tests, evaluator assertions, and game-CLI replay profiles should provide blocked-entry, role-capacity allocation, sequential repeatable-operation snapshots, event-stance gating, lawful repurpose, and sponsor-seal fold evidence without broadening the bound object count.