Missing Roll-Call Reconciliation Lens / 漏点名复核 Lens

This lens observes whether 漏点名复核线 and 漏点名复核机制 correctly turn post-egress accounting contradictions into playable pressure.

The current mesh can already create strong receipts: live-floor movement, capacity service, caption witness custody, protected witness payroll, private promise boundaries, fan oxygen release, and route asset custody. This lens targets the next weak seam: a receipt that says the subject moved is not the same thing as proving the same subject is present, identified, vouched, and safe enough for the next reader.

A passing implementation must prove prior receipt, expected subject, identity or seal, protection scope, later conflict reader, contradiction, support, receipt-after, branch deltas, future consumer, and default false-accounting consequences.

This lens observes:

It is observed through:

Observable promise

A passing run must show:

  • prior receipt source and holder;
  • receipt claim;
  • expected subject;
  • expected identity or seal;
  • protection scope or explicit absence;
  • expected location or state;
  • later conflict reader;
  • contradiction kind;
  • consequence if unreconciled;
  • selected posture;
  • handler or explicit absence;
  • support or explicit absence;
  • receipt-after or explicit absence;
  • presence state after;
  • identity state after;
  • custody state after;
  • condition after;
  • future reader or route effect.

The lens fails if the result is only safe, missing, all accounted for, someone died, crowd angry, reputation down, route asset moved, witness in custody, or broadcast says present.

Entry oracle

A valid implementation opens only from a live contradiction between prior receipt and later reader.

entry_state_required:
  trigger_kind: state_pressure
  prior_receipt_any:
    - live_floor_egress
    - capacity_notice_service
    - caption_witness_custody
    - protected_witness_payroll
    - confidant_promise
    - fan_oxygen
    - route_asset_custody
    - broadcast_reality
  receipt_claims_presence_or_safety: true
  later_reader_contradicts_receipt: true
  expected_subject_visible: true
  identity_or_seal_visible_or_explicit_absence: true
  protection_scope_visible_or_explicit_absence: true
  condition_visible_or_explicit_absence: true
  future_reader_or_route_consumes_roll_call_state: true
  player_response_available: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_missing_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

The lens must fail if entry comes from fixed turn number, day/week interval, chapter quota, raw crowd count, raw missing count, generic attendance, dashboard status, lens health, or a standalone death reveal.

Ledger oracle

漏点名账本 or equivalent must record the contradiction as separable rows.

ledger_required:
  source_receipt:
    source_surface: live_floor_egress | capacity_notice_service | caption_witness_custody | protected_witness_payroll | confidant_promise | fan_oxygen | route_asset_custody | broadcast_reality | equivalent
    receipt_id_or_absence: <receipt id or explicit_absence>
    receipt_claim: safe_exit | served_notice | payroll_checked_in | witness_delivered | source_anonymized | route_asset_escorted | oxygen_queue_released | performer_withdrawn | equivalent
    receipt_holder: producer | safety_marshal | access_operator | archive | inspector | fan_delegate | handler | sponsor | editor | equivalent
  expected_subject:
    subject_kind: named_character | sealed_witness | performer_body | fan_delegate | access_caption_reader | child_voice_source | proof_bundle | route_asset | crew_member | equivalent
    expected_identity_or_seal: <name seal alias or explicit_absence>
    expected_location_or_state: ward_air_room | fan_oxygen_gate | archive_counter | caption_table | cutroom_blackbox | stage_threshold | public_table | protected_payroll | route_asset_slot | equivalent
    protection_scope_or_absence: public_name_allowed | sealed_name_only | anonymous_public | lawful_only | private_only | handler_only | route_asset_only | explicit_absence | equivalent
  conflict_reader:
    reader: fan_public | access_caption_class | archive | inspector | sponsor | handler | protected_witness_payroll | route_asset_reader | broadcast_reality | lawful_table | equivalent
    contradiction: receipt_says_present_reader_says_absent | receipt_says_safe_condition_unsafe | identity_alias_unrecognized | duplicate_presence | false_missing | substituted_body | custody_gap | protection_scope_conflict | equivalent
    consequence_if_unreconciled: witness_exposed | fan_panic | access_class_escalation | archive_fraud | sponsor_capture | route_blocked | proof_contaminated | character_missed | recovery_only | equivalent
  reconciliation_state:
    selected_posture: physical_search | sealed_identity_match | public_roll_call | lawful_quiet_check | substitute_receipt | route_asset_quarantine | accept_absence_scar | false_all_clear_default | equivalent
    handler_or_absence: <handler or explicit_absence>
    support_or_absence: <support or explicit_absence>
    receipt_after_or_absence: <receipt or explicit_absence>
    condition_after: found_safe | found_exposed | sealed_present | public_present | lawful_only | substituted | hostile | blocked | missed | recovery_only | contradiction_pending | equivalent
    future_reader_or_route: <future consumer>

The lens fails if presence, identity, custody, condition, reader, and future consequence are collapsed into one all-clear flag.

Rite oracle

漏点名复核 or equivalent must require explicit assignment.

assignment_required:
  ledger: storyteller.card.missing_roll_call_ledger.v1
  selected_row: <row id>
  source_receipt_or_absence: <receipt id or explicit_absence>
  expected_subject: <subject>
  expected_identity_or_seal: <name seal alias or explicit_absence>
  protection_scope_or_absence: <scope or explicit_absence>
  conflict_reader: <reader>
  contradiction: <contradiction>
  selected_posture: physical_search | sealed_identity_match | public_roll_call | lawful_quiet_check | substitute_receipt | route_asset_quarantine | accept_absence_scar | false_all_clear_default
  handler_or_absence: producer | shen_luo | yu_lan | han_yanshuang | baiya | ai_sheng | fan_delegate | safety_marshal | access_operator | archive_clerk | explicit_absence | equivalent
  support_or_absence: corridor_light | oxygen_reserve | caption_notice | payroll_token | checksum_bag | lawful_counter | anonymity_shell | witness_guard | explicit_absence | equivalent
  receipt_after_or_absence: public_receipt | lawful_receipt | sealed_identity_receipt | access_caption_receipt | payroll_token | archive_receipt | route_asset_quarantine_receipt | explicit_absence | equivalent
  future_reader_or_route: <future consumer>

The lens fails if sponsor manifest, lawful seal, public memory, handler confidence, egress log, or broadcast reality can clear the contradiction without these slots.

Branch divergence oracle

A satisfying implementation must prove at least five constructive branch families plus default, or explicitly block missing families with state reasons.

Branch familyRequired reliefRequired costRequired future effect
Physical searchsubject found or false missing cleareddelay, hazard, public anxietycondition receipt, route costlier, fan/access pressure
Sealed identity matchprotected subject counted without public namepublic distrust, lawful notice, handler burdensealed-present or lawful-only state
Public roll-callcrowd helps locate or clear absenceexposure, panic, sponsor/inspection heatpublic receipt, reprisal, promise breach risk
Lawful quiet checkarchive/inspector validates safelypublic distrust, access pressure, route delaylawful-only presence, appeal pressure
Substitute receiptearlier receipt stands in temporarilyproof ambiguity, future contradictioncontested receipt, contradiction pending
Route asset quarantinemismatch cannot contaminate canonroute blocked, sponsor pressure, archive burdenquarantined asset, recovery-only risk
Accept absence scarfalse all-clear blockedpanic, ending scar pressurerecovery-only or scarred ending eligibility
False all-clear defaultboard clears fasthidden harm hardensdefault false accounting mutates future play

No branch may make one prior receipt satisfy every public, lawful, sponsor, route, fan, access, witness, and broadcast reader cleanly.

Default oracle

漏点名默认 must fire or arm when:

  • a prior receipt claims safety or presence but no roll-call row exists;
  • the expected subject is hidden;
  • the identity or seal is absent, hidden, or violated;
  • a conflict reader is hidden;
  • a sponsor, public, lawful, handler, route asset, or broadcast narrator marks all-clear without cost;
  • condition is omitted;
  • receipt-after is omitted;
  • the branch claims universal all-clear.

Required payload:

default_required:
  event: storyteller.event.missing_roll_call_default.v1
  source_row_or_absence: <row id or explicit_absence>
  source_receipt_or_absence: <receipt id or explicit_absence>
  expected_subject_or_absence: <subject or explicit_absence>
  conflict_reader_or_absence: <reader or explicit_absence>
  default_narrator: safety_marshal_log | archive_counter | fan_public_roll_call | sponsor_manifest | broadcast_reality_echo | handler_shortcut | route_asset_reader | crowd_memory | equivalent
  default_accounting_rule: all_clear | lawful_only_presence | public_name_presence | sponsor_manifest_presence | aired_presence | handler_certified | asset_condition_presence | crowd_memory_presence | equivalent
  missing_inputs:
    source_receipt: present | absent | hidden
    expected_subject: present | absent | hidden
    identity_or_seal: present | absent | hidden | violated
    protection_scope: present | absent | hidden | violated
    support: present | absent | hidden
    conflict_reader: present | absent | hidden
    receipt_after: present | absent | hidden
  state_after: false_all_clear | false_missing | sealed_identity_exposed | lawful_only_presence | sponsor_accounted_only | aired_duplicate | route_asset_quarantined | hostile_witness | character_unavailable | recovery_only | equivalent
  future_reader_effect: access_class_escalation | fan_oxygen_review | witness_reprisal | promise_breach | archive_fraud_review | sponsor_capture | route_blocked | broadcast_reality_scar | ending_scar | equivalent
  counter_deltas_min: 3

The default fails if it changes only mood, money, reputation, generic attendance, or generic safety.

Success cost oracle

Every non-default branch must include at least one relief, one cost, and one future mutation.

branch_result_required:
  presence_state_after: present | absent | false_missing_cleared | false_all_clear_blocked | unresolved | equivalent
  identity_state_after: named | sealed_present | public_exposed | lawful_only | alias_contested | duplicate | substituted | equivalent
  custody_state_after: public_receipt | lawful_receipt | archive_receipt | payroll_receipt | sponsor_manifest_only | route_asset_quarantined | no_receipt | equivalent
  condition_after: found_safe | found_exposed | injured | hostile | blocked | missed | recovery_only | contradiction_pending | equivalent
  counter_deltas:
    relief: at_least_one
    cost: at_least_one
    future: at_least_one

Replay/session evidence shape

lens_id: storyteller.lens.missing_roll_call_reconciliation.v1
session_id: lens-missing-roll-call-reconciliation-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  prior_receipt_claims_presence_or_safety: true
  later_reader_contradicts_receipt: true
  expected_subject_visible: true
  identity_or_seal_visible_or_explicit_absence: true
  protection_scope_visible_or_explicit_absence: true
  future_reader_or_route_consumes_roll_call_state: true
  no_fixed_turn_trigger: true
offered:
  card: storyteller.card.missing_roll_call_ledger.v1
  rite: storyteller.rite.missing_roll_call_reconciliation.v1
branch_runs:
  physical_search_or_equivalent:
    selected_posture: physical_search
    support_or_absence: <support>
    receipt_after_or_absence: <receipt>
    future_reader_effect: <effect>
    counter_deltas: { relief: [], cost: [], future: [] }
  sealed_or_lawful_or_equivalent:
    selected_posture: sealed_identity_match | lawful_quiet_check
    identity_state_after: sealed_present | lawful_only
    future_reader_effect: <effect>
    counter_deltas: { relief: [], cost: [], future: [] }
  public_or_substitute_or_equivalent:
    selected_posture: public_roll_call | substitute_receipt
    condition_after: <condition>
    future_reader_effect: <effect>
    counter_deltas: { relief: [], cost: [], future: [] }
  quarantine_or_absence_or_equivalent:
    selected_posture: route_asset_quarantine | accept_absence_scar
    future_reader_effect: recovery_only | route_asset_quarantined | equivalent
    counter_deltas: { relief: [], cost: [], future: [] }
  default_branch:
    event_seen_or_armed: storyteller.event.missing_roll_call_default.v1
    default_narrator: <narrator>
    default_accounting_rule: <rule>
assertions:
  - primary_links_exist
  - entry_is_state_triggered_by_prior_receipt_later_reader_contradiction
  - prior_receipt_expected_subject_identity_scope_conflict_reader_condition_and_future_consumer_are_visible
  - presence_identity_custody_and_condition_are_separate
  - selected_posture_has_handler_support_receipt_after_and_future_reader
  - branch_outcomes_diverge_by_relief_cost_future_state
  - every_non_default_branch_has_relief_cost_and_future_mutation
  - false_all_clear_default_names_default_narrator_accounting_rule_and_future_scar
  - earlier_receipt_never_becomes_universal_all_clear
  - no_generic_attendance_or_death_counter
  - no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_trigger

Non-goals

  • Not a generic attendance scene.
  • Not a death counter.
  • Not a safety governance page.
  • Not raw count satisfaction.
  • Not a replacement for live-floor egress, capacity service, caption custody, protected witness payroll, private promise, fan oxygen, or route asset custody.
  • Not valid unless the contradiction changes proof economy, route state, character availability, witness protection, fan/access pressure, or broadcast reality.