Recovery Indemnity Shelf Lens / 复原追偿搁架 Lens
This lens observes whether 复原追偿搁架线 and 复原追偿搁架机制 correctly make future recourse playable after recovery inventory, sponsor proof, archive custody, or claimant receipt stabilizes a crisis.
The oracle is: a recovery/sponsor/archive success is not complete until Storyteller names who carries future recourse. A sponsor release, recovery allocation, archive copy, claimant receipt, or management closure cannot silently move liability onto a worker, claimant body, archive shelf, public trust, or producer license.
This lens intentionally sits after two recent surfaces. 复原库存分诊 Lens prevents double-spending finite recovery rows. 赞助后用引证 Lens prevents sponsor proof from becoming a clean universal key. This lens tests the next downstream seam: who can be called back when the row or proof fails later.
Primary observation link
This lens observes:
- 复原追偿搁架线;
- 复原追偿搁架机制;
- 复原追偿搁架;
- 复原追偿指派;
- 复原追偿默认;
- 复原库存分诊线;
- 赞助后用引证线;
- 认领人现场接待线;
- 经营压缩台;
- Route Assets and Custody;
- 交接链跑腿;
- 首接保全员.
It is observed through:
Observable promise
When a recovery, sponsor, archive, management, or claimant route leaves recourse behind, Storyteller must show:
- the source object and source scar, or explicit absence;
- proposed holder or explicit absence;
- holder state before and after;
- protected reader;
- burdened or excluded reader;
- future recall reader;
- assignment branch;
- shelf state after;
- cost and future route effect;
- default capture if no credible assignment exists.
The lens fails if liability is represented as abstract money, clean legal waiver, clean sponsor release, clean archive stamp, management KPI, or silent worker/claimant consent.
Entry oracle
A valid entry must come from state pressure:
entry_state_required:
trigger_kind: state_pressure
source_object_present: true
source_object_kind: recovery_inventory_row | sponsor_afteruse_citation | archive_custody_proof | claimant_floor_receipt | management_clean_report | equivalent
source_scar_present_or_explicit_absence: true
proposed_or_missing_indemnity_holder_visible: true
protected_reader_present: true
burdened_or_excluded_reader_present_or_explicit_absence: true
future_recall_reader_present: true
worker_or_claimant_liability_possible_or_explicit_absence: true
player_can_assign_split_escrow_refuse_quarantine_or_default: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_count_trigger: true
no_dashboard_or_lens_health_trigger: trueThe lens must fail if eligibility depends on fixed turn count, fixed day/week interval, chapter quota, raw crisis count, dashboard status, lens health, generic legal review, generic sponsor anger, or clean post-success bookkeeping.
Required observable content
Shelf card
复原追偿搁架 or equivalent must record:
shelf_card_required:
source_pressure: recovery_inventory_allocation | sponsor_afteruse_citation | archive_custody_proof | claimant_floor_intake | management_clean_report | equivalent
source_object:
object_id: <card row citation proof or explicit_absence>
original_scar: <shortfall injury omission false-clean claim default capture or explicit_absence>
state_before: allocated | split | reserved | borrowed_forward | quarantined | sponsor_only | public_only | lawful_only | false_available | recovery_only | equivalent
proposed_indemnity_holder:
holder: sponsor | producer_license | archive_escrow | ward_queue | public_fan_trust | worker_carrier | claimant_body | inspector_escrow | explicit_absence | equivalent
holder_asset_or_absence: lin_qiao_chain_runner | pei_zhan_first_custody_bailiff | recovery_worker | claimant_row | archive_copy | sponsor_release | producer_license | explicit_absence | equivalent
holder_state_before: protected | exposed | captured | hostile | absent | coerced | scoped | equivalent
protected_reader:
reader: <reader>
minimum_acceptance_surface: <surface>
burdened_or_excluded_reader:
reader: <reader or explicit_absence>
harm_or_burden: <harm>
future_recall_reader: sponsor | lawful_archive | public_fan | artist_boundary | worker_testimony | claimant_counterclaim | management_appeal | route_asset | equivalent
shelf_state_after: proposed | assigned | split | escrowed | refused | quarantined | default_captured | false_clean | recalled | recovery_only | equivalent
future_route_effect: sponsor_only | lawful_only | public_only | artist_boundary_only | worker_hostile | claimant_hostile | route_costlier | blocked | contradiction_pending | accepted_with_cost | equivalentThe lens fails if the card records only liability_resolved, waiver_signed, archive_safe, worker_signed, sponsor_paid, or claimant_released.
Assignment rite
复原追偿指派 or equivalent must require:
assignment_required:
shelf: storyteller.card.recovery_indemnity_shelf.v1
source_object: <object or explicit_absence>
source_scar: <scar or explicit_absence>
proposed_holder: <holder>
holder_asset_or_absence: <asset or explicit_absence>
protected_reader: <reader>
burdened_or_excluded_reader: <reader or explicit_absence>
proof_or_support_or_absence: recovery_inventory_ledger | sponsor_afteruse_docket | archive_copy | fan_oxygen_receipt | first_custody_slip | public_receipt | inspector_stamp | explicit_absence | equivalent
recognition_surface: sponsor_retains | producer_underwrites | archive_escrow | public_fan_trust | worker_protected_refusal | split_recourse | quarantine_source | default_selects
accepted_cost_surface: <cost or explicit_absence>
future_recall_reader: <reader>
no_fixed_turn_trigger: trueThe lens fails if sponsor money, archive stamp, recovery inventory allocation, management authority, legal wording, or a famous handler resolves the shelf without naming the burdened reader and future recall reader.
Default event
复原追偿默认 or equivalent must fire or arm when:
- no recourse holder is recorded;
- sponsor proof is cited as resolving every future claim;
- archive custody receives a clean shelf without a burdened reader;
- worker or claimant is treated as silent holder;
- absent holder is treated as consent;
- split recourse is reported as universal acceptance;
- quarantined source is later used as clean proof;
- management files the shelf as closed while recall remains possible.
Required default payload:
default_event_required:
event: storyteller.event.recovery_indemnity_default.v1
default_actor: sponsor | management | archive_queue | ward_queue | inspector | handler_absence | producer_absence | equivalent
captured_holder: sponsor | producer_license | archive_shelf | public_fan_trust | worker_carrier | claimant_body | explicit_absence | equivalent
burdened_or_hidden_reader: <reader or explicit_absence>
protected_reader_claimed: <reader or explicit_absence>
false_clean_claim: recourse_resolved | sponsor_settled_all | worker_signed_all | archive_holds_all | recovery_safe | public_receipt_clean | metric_closed | claimant_body_released | equivalent
holder_state_after: coerced | absent | captured | hostile | false_owner | recovery_only | explicit_absence | equivalent
shelf_state_after: default_captured | false_clean | recalled | recovery_only | contradiction_pending | equivalent
future_route_effect: worker_hostile | claimant_hostile | sponsor_only | public_only | lawful_only | artist_boundary_only | route_costlier | blocked | recovery_only | contradiction_pending
counter_deltas_min: 3Branch divergence oracle
A satisfying implementation must prove at least six branch families, including one default/capture branch.
| Branch family | Required relief | Required cost | Required future effect |
|---|---|---|---|
| Sponsor retains | worker or claimant burden blocked | sponsor pressure, contract capture, or schedule pressure rises | sponsor recall, sponsor-only, or accepted-with-cost |
| Producer underwrites | named backer visible | license encumbrance, inspection heat, or management pressure rises | route costlier or accepted-with-cost |
| Archive escrow | source trace preserved | archive debt, public delay, or checksum pressure rises | lawful-only, checksum-required, or contradiction-pending |
| Public/fan trust | public memory or refund path visible | sponsor pressure, fan resentment, or inspection heat rises | public-only or refund audit |
| Worker protected refusal | worker not silent liability sink | handler burden, payroll leak, or inspection exposure rises | worker testimony or route-asset witness |
| Split recourse | immediate route partly unblocks | source ambiguity, archive debt, or hostile reader rises | split-required or contradiction-pending |
| Quarantine source | unsafe liability transfer blocked | current route blocks and pressure rises | blocked, recovery-only, or lawful-after-review |
| Default shelving | immediate metric or slot may close | hidden burden and false-clean claim harden | worker hostile, claimant hostile, sponsor-only, lawful-only, public-only, blocked, recovery-only |
No branch may create universal acceptance across sponsor, lawful/archive, public/fan, artist-boundary, worker, claimant, management, and route-asset readers.
Worker and claimant liability oracle
A pass requires at least one worker or claimant liability path to be observable. Valid evidence includes:
- 交接链跑腿 becomes
route_asset_indemnity_witness,coerced_indemnity_signer, orhostile_recourse_witness; - 首接保全员 becomes
archive_escrow_witness,sponsor_burdened_worker,indemnity_absent_signer, orhostile_recourse_witness; - a claimant row becomes
claimant_burdened_body,recovery_only_claimant, orclaimant_hostile; - a worker or claimant is protected by refusal or escrow and the cost moves to sponsor, producer license, archive, public/fan trust, inspection, handler burden, or route recovery.
The lens fails if worker or claimant liability is only implied, flavor text, or a hidden cost.
Counter contract
Every resolved or defaulted branch must mutate at least three surfaces:
counter_deltas_required:
relief: at_least_one
cost: at_least_one
future_reader_or_route_effect: at_least_oneRelevant surfaces:
recovery_indemnity_pressureindemnity_holder_exposuresponsor_stop_loss_pressurecontract_captureproducer_license_encumbrancearchive_debtinspection_heatpublic_receipt_legitimacypublic_receipt_distrustfan_oxygen_resentmentworker_coercion_riskpayroll_leakhandler_burdenclaimant_body_burdensource_ambiguityfalse_clean_indemnityroute_recovery_cost
Downstream read requirement
A pass requires at least one downstream reader or route to consume the shelf state:
- 复原库存分诊线 consumes the shelf when a borrowed or reserved row is recalled;
- 赞助后用引证线 consumes the shelf when sponsor proof is reused;
- 认领人现场接待线 consumes the shelf when a claimant receipt or body is burdened;
- 经营压缩台 is blocked from clean closure;
- Route Assets and Custody consumes worker or route-asset holder state.
The lens fails if the shelf is resolved but never read by a later route, event, reader, worker state, claimant state, or recovery path.
Oracle assertions
A binding check should fail unless all assertions below are true.
- Primary links exist —
observesandobserved_througharrays contain concrete wiki pages. - Entry is state-triggered — entry comes from recovery, sponsor, archive, claimant, or management source scar, not fixed sequence timing or counts.
- Source scar is visible — the shelf names the source object and scar, or explicit absence.
- Holder is visible — proposed holder or missing holder is named with state before and after.
- Readers are visible — protected reader, burdened/excluded reader, and future recall reader are present.
- Card memory exists — shelf card records source, holder, readers, state, and future route effect.
- Rite assignment exists — rite requires holder, proof/support, recognition surface, cost, and future recall reader.
- Worker/claimant liability is not silent — worker or claimant burden either mutates state or is explicitly absent.
- Branches diverge — at least six branch families differ by holder state, reader state, cost, and future route effect.
- Success has cost — every non-default branch records relief, cost, and future effect.
- Default is durable — default event names actor, false-clean claim, burdened reader, holder state, shelf state, and future effect.
- Downstream consumption exists — a later route/reader consumes shelf state.
- No fixed trigger — no fixed turn/day/week/raw count/dashboard/lens-health trigger.
Replay evidence expectation
lens_id: storyteller.lens.recovery_indemnity_shelf.v1
session_id: lens-recovery-indemnity-shelf-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
trigger_kind: state_pressure
source_object_present: true
source_scar_present_or_explicit_absence: true
proposed_or_missing_indemnity_holder_visible: true
protected_reader_present: true
burdened_or_excluded_reader_present_or_explicit_absence: true
future_recall_reader_present: true
worker_or_claimant_liability_possible_or_explicit_absence: true
no_fixed_turn_trigger: true
offered:
card: storyteller.card.recovery_indemnity_shelf.v1
rite: storyteller.rite.recovery_indemnity_assignment.v1
branch_runs:
assignment_branch:
selected_branch: sponsor_retains | producer_underwrites | archive_escrow | public_fan_trust | worker_protected_refusal | split_recourse | quarantine_source
source_object: <object>
source_scar: <scar or explicit_absence>
proposed_holder: <holder>
protected_reader_state_after: <state>
burdened_reader_state_after: <different state>
holder_state_after: <state>
shelf_state_after: <state>
future_recall_reader: <reader>
future_route_effect: <effect>
counter_deltas:
relief: []
cost: []
future: []
default_branch:
event_seen_or_armed: storyteller.event.recovery_indemnity_default.v1
default_actor: <actor>
false_clean_claim: <claim>
captured_holder: <holder>
burdened_or_hidden_reader: <reader>
holder_state_after: <state>
shelf_state_after: <state>
future_route_effect: <effect>
assertions:
- primary_links_exist
- entry_is_state_triggered
- source_scar_visible
- holder_visible_or_absent
- protected_and_burdened_readers_visible
- future_recall_reader_visible
- worker_or_claimant_liability_not_silent
- readers_diverge
- success_has_relief_cost_and_future_effect
- default_names_actor_false_clean_claim_burdened_reader_and_future_effect
- downstream_reader_consumes_shelf
- no_fixed_turn_triggerNon-goals
- Not raw lens-count growth.
- Not a governance/checklist page.
- Not abstract insurance or clean legal waiver.
- Not a sponsor cleanup tool.
- Not a replacement for recovery inventory, sponsor afteruse, claimant intake, or route custody.
- Not valid unless future playable state changes.