Fan Token Custody Lens / 应援凭证羁押 Lens
This lens observes whether 应援凭证羁押线 and 应援凭证羁押机制 correctly make fan-held tokens into bounded route assets rather than clean proof shortcuts.
The oracle is:
A fan token can prove something only for a named source, holder, scope, and future reader. It cannot become universal clean proof.
This lens exists because the surrounding mesh already handles fan delegates, excluded counterreceipts, oxygen claims, live-floor egress, recap fragments, and route loadouts. The remaining risk is object laundering: a wristband, queue stub, lightstick log, photocard checksum, memorial sticker, caption tag, refund stamp, relay chip, sponsor coupon, or fan packet is used as clean proof without holder/custody/scope.
Primary observation link
This lens observes:
- 应援凭证羁押线;
- 应援凭证羁押机制;
- Fan Oxygen;
- Route Assets and Custody;
- Broadcast Reality;
- 粉丝委任分裂线;
- 被排除者反回执挑战线;
- Oxygen Claim Exchange Storyline;
- 直播现场通行瓶颈线;
- 回顾分发漂移线;
- 路线装配兼容线.
It is observed through:
Must pass
1. Entry is state-triggered by token consumption
Required evidence:
entry_state:
trigger_kind: state_pressure
source_surface_present: true
token_instance_or_batch_present: true
claimed_use_present: true
future_reader_or_route_consumes_token_state: true
player_response_available: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_token_count_trigger: true
no_raw_fan_count_trigger: true
no_dashboard_or_lens_health_trigger: trueThe lens fails if entry comes from fixed turn number, day/week interval, chapter quota, raw token count, raw fan count, dashboard state, lens health, or collectible rarity.
2. Token identity and custody are visible
应援凭证羁押案卷 must show:
token_identity:
token_kind: oxygen_wristband | queue_stub | lightstick_log | memorial_sticker | photocard_checksum | access_caption_tag | refund_stamp | pirate_relay_chip | sponsor_coupon | fan_packet | equivalent
token_instance_or_batch: <id or explicit_absence>
holder: <actor or explicit_absence>
custodian_or_absence: <actor or explicit_absence>
authentication_state_before: unverified | authenticated | batch_scoped | duplicate_seen | sponsor_issued | fan_made | forged | recalled | quarantined | recovery_only | equivalentThe lens fails if the token is described only as fan sentiment, merch, proof flavor, or generic inventory.
3. Claimed use, scopes, and excluded holders are visible
The docket must show:
scope_and_use:
claimed_use: access | oxygen_claim | refund | public_receipt | delegate_mandate | recap_proof | route_asset | sponsor_makegood | mirror_or_feed_ranking | equivalent
represented_fans: <scope>
excluded_or_missing_fans: <scope or explicit_absence>
beneficiary_of_clean_token: <actor/faction or explicit_absence>
harmed_reader_or_claimant: <reader/claimant or explicit_absence>
future_reader_or_route: <reader/route/rite/system>The lens fails if absence of excluded holders is assumed from silence rather than recorded as explicit absence.
4. Authentication table is assignable
应援凭证验真桌 must require assignment or explicit absence for:
assignment_slots:
table_handler: <actor or explicit_absence>
custody_witness: <actor/proof or explicit_absence>
proof_of_token_origin: <proof or explicit_absence>
proof_of_current_holder: <proof or explicit_absence>
excluded_holder_notice: <notice or explicit_absence>
addendum_or_recall_note: <note or explicit_absence>
future_reader: <reader>
collateral_or_sacrifice: <asset/cost or explicit_absence>The lens fails if sponsor money, public popularity, a famous handler, or an inspector seal authenticates the token without filling these slots.
5. Branches diverge by token state and future effect
At least five branch families must be playable or explicitly blocked by state:
- authenticate with scope;
- fan-attest token line;
- split token batch;
- recall with addendum;
- quarantine duplicate;
- trade token relief;
- accept counterfeit default.
Passing evidence must show different token states and future route effects.
6. No universal clean token
No branch may make a fan token clean proof for all fan oxygen, delegate mandate, public receipt, sponsor makegood, access proof, recap proof, feed/mirror ranking, and route loadout uses.
Required evidence:
no_universal_clean_token:
token_state_after_not_clean_universal: true
represented_scope_named: true
excluded_scope_visible_or_explicit_absence: true
at_least_one_future_reuse_is_bounded_or_costed: trueThe lens fails if clean_universal, all_fans_represented_by_absence, or equivalent appears as a successful state.
7. Success has relief, cost, and future reader effect
Every non-default branch must mutate at least three durable surfaces:
counter_deltas_required:
relief: at_least_one
cost: at_least_one
future_reader_or_route_effect: at_least_oneAccepted surfaces include token legitimacy, custody clarity, fan oxygen balance, fan oxygen resentment, public receipt legitimacy, public receipt distrust, excluded fan recognition, access-caption pressure, sponsor stop-loss pressure, contract capture, route asset integrity, feed-ranking contamination, recap-fragment legibility, archive debt, inspection heat, source ambiguity, handler burden, and future recovery cost.
8. Counterfeit default mutates future play
应援凭证伪造默认 must fire or be armed when a token is consumed as clean proof without scope.
Required default evidence:
default_event:
event: storyteller.event.fan_token_counterfeit_default.v1
default_cause: <cause>
token_instance_or_batch: <id or explicit_absence>
beneficiary_of_clean_token: <actor/faction or explicit_absence>
harmed_reader_or_claimant: <reader/claimant or explicit_absence>
default_narrator: sponsor | archive | inspector | security | fan_public | pirate_relay | feed_algorithm | route_claimant | editor | equivalent
future_reader_or_route_effect: token_addendum_required | fan_attestation_required | oxygen_recheck_required | access_caption_recheck_required | public_counterreceipt_armed | route_loadout_blocked | feed_ranking_contaminated | recap_fragment_disputed | sponsor_only_relief | hostile_token_holders | recovery_only_token_line | equivalentThe lens fails if the default is only money loss, generic distrust, mood damage, or a cosmetic counterfeit scene.
Replay evidence shape
lens: storyteller.lens.fan_token_custody.v1
session_id: lens-fan-token-custody-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
trigger_kind: state_pressure
source_surface: fan_oxygen | public_receipt | egress | recap_fragment | delegate_mandate | counterreceipt | oxygen_claim_exchange | feed_ranking | route_loadout | equivalent
token_instance_or_batch_present: true
claimed_use_present: true
future_reader_or_route_consumes_token_state: true
no_fixed_turn_trigger: true
docket:
card: storyteller.card.fan_token_custody_docket.v1
token_kind: <kind>
token_instance_or_batch: <id or explicit_absence>
holder: <actor or explicit_absence>
custodian_or_absence: <actor or explicit_absence>
authentication_state_before: <state>
represented_fans: <scope>
excluded_or_missing_fans: <scope or explicit_absence>
beneficiary_of_clean_token: <actor/faction or explicit_absence>
harmed_reader_or_claimant: <reader/claimant or explicit_absence>
offered:
rite: storyteller.rite.fan_token_authentication_table.v1
branch_result:
selected_posture: authenticate_with_scope | fan_attest_token_line | split_token_batch | recall_with_addendum | quarantine_duplicate | trade_token_relief | accept_counterfeit_default
token_state_after: <state>
represented_fans_after: <scope>
excluded_or_missing_fans_after: <scope or explicit_absence>
future_reader_or_route_effect: <effect>
emitted_event: storyteller.event.fan_token_counterfeit_default.v1 | none
counter_deltas:
relief: []
cost: []
future: []
assertions:
entry_is_state_triggered_by_token_consumption: true
token_holder_custodian_and_scope_visible: true
excluded_holders_visible_or_explicit_absence: true
claimed_use_and_future_reader_visible: true
branch_results_diverge: true
token_not_universal_clean_key: true
counterfeit_default_mutates_future_play: true
no_raw_count_or_fixed_turn_trigger: trueProgress metric
fanTokenCustodyProgress = 0..8:
0: no token route consumption exists.1: source surface, token kind, token instance/batch, and claimed use are visible.2: holder, custodian, and authentication state are visible or explicitly absent.3: represented fans, excluded/missing fans, beneficiary, harmed reader, and future reader are visible.4: 应援凭证羁押案卷 enters play.5: 应援凭证验真桌 offers explicit assignment slots.6: at least two constructive branches produce distinct token states and future effects.7: counterfeit/default branch mutates future route or reader state.8: replay evidence proves source surface, token scope, selected branch, deltas, future reader consumption, and no fixed-turn/raw-count trigger.
Failure cases
The lens must fail if any of these are true:
- entry is fixed-turn, fixed-day/week, chapter quota, raw token count, raw fan count, dashboard state, or lens-health state;
- no concrete token instance or batch exists;
- no claimed use exists;
- holder or custodian is hidden rather than explicit;
- represented and excluded fan scopes are omitted;
- sponsor coupon is filed as public receipt without addendum;
- pirate chip is filed as lawful proof without bridge;
- duplicate token is consumed quietly;
- token recall erases old proof without addendum;
- a fan token becomes universal clean proof;
- counterfeit default does not mutate future route, reader, oxygen, access, recap, feed, or loadout state.
Non-goals
- Not a merch shop.
- Not collectible rarity.
- Not gacha.
- Not fan popularity scoring.
- Not raw count satisfaction.
- Not a fixed-turn late-game escalator.
- Not valid unless a fan token’s proof scope changes future play.