Facility Access Lockdown Lens / 设施通行封控 Lens
Primary observation link
This lens observes 设施通行封控线, 设施通行图机制, 第七穹顶设施通行图, Spatial Model, 制作分诊台机制, and Route Assets and Custody.
It is observed through 设施通行图, 设施通行派线, and 房间封控撞锁.
Observable promise
Storyteller must prove that crisis work happens inside a contested facility, not in abstract menus. When a person, proof object, black-box edit, fan witness chain, oxygen room, archive copy, sponsor bridge, or route asset depends on a physical room or passage, the implementation must expose room state, passage state, claimant, access requirements, player assignment, and future availability consequences.
A pass requires a concrete place map, a visible card, an assignable routing rite, a collision/default event, branch divergence, and replay evidence that access choices change future route availability or room control.
Scope
This lens covers:
- rooms and thresholds: cutroom, archive counter, fan gate, white-glove checkpoint, sponsor bridge booth, service corridor, ward air room, stage threshold, or equivalent;
- passage edges between rooms and thresholds;
- access states: open, restricted, contested, sealed, rerouted, watched, burned, claimed;
- claimants: inspector, archive, sponsor, fan public, editor, security, route asset, blackout system, contradiction, or equivalent;
- access requirements: permit, handler, escort, proof, public cover, oxygen support, archive seal, sponsor language, explicit absence;
- branch results: certify, reroute, seal, break seal, or default;
- future effects on route availability, custody, proof value, person state, broadcast reality, public legitimacy, schedule pressure, and route strategy.
It does not cover purely abstract priority decisions where no room, passage, threshold, or physical access is at stake.
State-triggered entry oracle
A valid replay or state inspection must open the facility layer from spatial contention, not fixed chronology.
Minimum entry evidence:
- at least one crisis depends on a physical room node or passage edge;
- the node/edge is restricted, contested, sealed, watched, rerouted, burned, claimed, or missing a route;
- a player assignment could still change the access result;
- at least one handler/support source is available or explicitly absent;
- at least one claimant can benefit if room control defaults;
- the affected room/route can change future availability, custody, proof value, person state, broadcast reality, public legitimacy, schedule pressure, or route strategy.
Required observable content
Place map
第七穹顶设施通行图 or equivalent must define:
- room nodes;
- passage edges;
- access states;
- current claimants;
- required access inputs;
- default danger when unresolved.
At least one concrete node and one concrete edge must be visible in replay evidence when the lens is evaluated.
Visible card
设施通行图 or equivalent must record:
- active node/edge ids;
- node/edge states before assignment;
- current claimant;
- held assets or dependent crisis;
- access requirements;
- assignments or explicit absence;
- default actor and default state.
Routing rite
设施通行派线 or equivalent must require:
- map;
- origin node;
- target node;
- edge or explicit missing route;
- route state before assignment;
- handler or explicit absence;
- access support or explicit absence;
- claimant pressure.
The rite cannot pass with a generic action point or famous-handler shortcut. A route without node/edge state and access support is not a route.
Collision event
房间封控撞锁 or equivalent must fire, resolve, or be recorded when access is unresolved, broken illegally, underfilled, or defaulted.
The event must record:
- source map;
- source rite state;
- affected node/edge;
- missing inputs;
- claimant actor;
- branch family;
- room state after;
- preserved trace or none;
- counter/state deltas;
- blocked/costlier/recovery route effects.
Required durable states
A satisfying implementation must expose durable states equivalent to at least eight of:
facility_map_openroute_certifiedservice_corridor_rerouteroom_seal_activeseal_broken_on_cameraroom_claim_defaultedrunner_exposed_by_reroutestage_threshold_contestedarchive_counter_claimedcutroom_blackbox_lockedroom_locked_recovery_onlycheckpoint_certified_with_debtfan_gate_surgesponsor_private_lockeditor_auto_patch_from_locked_cutroom
Branch divergence oracle
Branch A — Certify the route
Expected evidence:
- restricted/watched/contested route receives credible handler plus access support;
- target room becomes reachable, certified, or escort-only;
- at least one cost rises: inspection heat, public debt, sponsor capture, oxygen debt, runner exposure, edit debt, or schedule scar;
- future availability of the target changes.
Branch B — Reroute through service access
Expected evidence:
- official path is blocked or dangerous;
- service corridor or equivalent alternate path is used;
- person/proof/route asset moves or avoids seizure;
- low-rank staff, runner, proof chain, or hidden passage takes durable risk.
Branch C — Seal for protection
Expected evidence:
- room/edge is sealed to protect a person, proof, crowd, edit, ward, or stage threshold;
- immediate harm or seizure risk drops;
- another route, rite, broadcast option, or schedule lane becomes blocked, delayed, or costlier;
- seal owner and release condition are recorded.
Branch D — Break the seal
Expected evidence:
- player violates inspection, archive, sponsor, security, medical, or crowd seal;
- access is gained, partially gained, or fails loudly;
- 房间封控撞锁 or equivalent records backlash;
- future legal/archive/sponsor/public/security access becomes harder.
Branch E — Let room control default
Expected evidence:
- access is not credibly routed, certified, sealed for protection, or delayed;
- current claimant controls the node/edge;
- room/edge becomes claimed, locked, burned, captured, hostile, scarred, black-screened, or recovery-only;
- at least three counters or durable states change.
Oracle assertions
A binding check should fail unless all assertions below are true.
- Primary links exist — lens has populated
observesandobserved_througharrays pointing to concrete Storyteller pages. - Entry is state-triggered — the facility layer opens from access contention, not from a fixed turn count.
- Concrete place exists — at least one room node and one passage edge are visible in card or replay state.
- Access state exists — node/edge state is not prose-only; it is open, restricted, contested, sealed, rerouted, watched, burned, claimed, or equivalent.
- Claimant exists — unresolved access names who benefits from room control.
- Requirement exists — route requires permit, handler, escort, proof, public cover, oxygen support, archive seal, sponsor language, or explicit absence.
- Routing rite assigns real slots — origin, target, route, handler, support, claimant, and branch are recorded.
- Success has cost — certifying or rerouting access must raise some debt, heat, exposure, scar, or capture pressure.
- Seal choices change future play — sealing or breaking a seal changes future route availability, difficulty, proof value, or person state.
- Default mutates state — unresolved room control cannot disappear; it must emit collision/default state and future route effect.
- No teleporting assets — route assets, proof objects, and people cannot change room without route state or explicit offscreen/default consequence.
- Replay provenance exists — passing evidence includes seed/session id, source crisis, node/edge state, offered card/rite, assignment or absence, outcome, event emission if any, future route effects, and counter deltas.
Progress metric
facilityAccessLockdownProgress = 0..10:
0: no concrete facility access state.1: at least one relevant room node exists.2: at least one passage edge connects the node to another playable threshold.3: node/edge exposes access state and claimant.4: 设施通行图 or equivalent enters play with access requirements and default actor.5: 设施通行派线 or equivalent offers origin, target, route, handler, support, and branch.6: certify or reroute branch changes room/edge state and pays cost.7: seal or break-seal branch changes future availability, difficulty, or route risk.8: 房间封控撞锁 or equivalent records unresolved/broken/default room control.9: at least one route asset, proof, person, public queue, edit, or broadcast option has future availability changed by access state.10: at least two divergent replay branches prove access success with cost and unresolved/broken/default collision with durable future effect.
Evidence shape
lens_id: storyteller.lens.facility_access_lockdown.v1
session_id: lens-facility-access-lockdown-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
source_crisis:
id: <crisis_ticket_or_route_asset_or_proof_id>
family: archive | oxygen | sponsor | inspector | witness | claimant | settlement | reality_drift | clean_ending | route_asset | schedule | equivalent
depends_on_access: true
active_node:
id: cutroom_blackbox | archive_counter_seven | fan_oxygen_gate | white_glove_checkpoint | sponsor_bridge_booth | service_corridor_chain | ward_air_room | stage_threshold | equivalent
state: restricted | contested | sealed | watched | burned | claimed
claimant: inspector | archive | sponsor | fan_public | editor | security | route_asset | blackout_system | contradiction
held_assets: []
active_edge:
id: <edge_id>
from: <node_id>
to: <node_id>
state: open | restricted | contested | sealed | rerouted | watched | burned | claimed
requirements:
- permit | handler | escort | proof | public_cover | oxygen_support | archive_seal | sponsor_language | explicit_absence
offered:
card: storyteller.card.facility_access_map.v1
rite: storyteller.rite.facility_access_routing.v1
branch_runs:
certify_or_reroute:
branch: certify | reroute
origin_node: <node_id>
target_node: <node_id>
edge_or_route: <edge_id>
handler: <handler_or_route_asset>
support: <permit_or_proof_or_resource>
outcome:
route_state_after: open | certified | escort_only_open | rerouted
target_room_effect: reachable | protected
cost_state: <inspection_heat_or_runner_risk_or_contract_capture_or_equivalent>
counter_deltas: {}
seal_or_break:
branch: seal | break_seal
outcome:
room_state_after: sealed | burned | scarred | recovery_only
relief_state: <protected_or_access_gained>
cost_state: <blocked_route_or_heat_or_debt>
counter_deltas: {}
default_collision:
branch: default
event: storyteller.event.room_seal_collision.v1
claimant_actor: inspector | archive | sponsor | fan_public | editor | security | route_asset | blackout_system | contradiction
missing_inputs:
handler: <handler_or_absent>
support: <support_or_absent>
route: <edge_or_absent>
outcome:
room_state_after: locked | claimed | captured | hostile | scarred | recovery_only
future_route_effect: blocked | costlier | hostile | captured | terminal | recovery_only
counter_deltas: {}
assertions:
- state_triggered_from_facility_access_contention
- concrete_room_node_and_passage_edge_visible
- claimant_and_required_access_recorded
- routing_rite_assigns_origin_target_route_handler_and_support
- success_has_visible_cost
- unresolved_or_broken_seal_emits_room_collision
- future_route_or_room_availability_changes
- no_fixed_turn_triggerNon-goals
- Not bulk content or raw scale satisfaction.
- Not a fixed-turn escalation.
- Not a governance dashboard.
- Not a decorative map.
- Not a universal movement minigame.
- Not a generic action-point cost.
- Not a free cleanup layer for archive, oxygen, sponsor, inspector, witness, clean-ending, claimant, route-asset, production-triage, or reality-drift content.
- Not satisfied by page existence alone; proof must come from room/edge state, card, routing rite, claimant/default, collision event, and replay/session deltas.