Revocation Window Readback Lens / 撤销窗口回读 Lens
This lens proves that a route asset, consent grant, or proxy proof can later face a revocation window that is playable and replay-bound rather than silently remaining clean forever.
Observable promise
When a future reader tries to rely on a route asset whose permission can be revoked, the game must surface a readback naming the route asset, original grant, revoking claimant or explicit absence, notice carrier, proof receipt or absence, window state, accepted cost, and future route effect.
The lens fails if revocation opens from a fixed turn count, if the revoking claimant is hidden, if the player can buy a universal clean waiver, or if ignoring the window has no durable future consequence.
Must pass
- Entry is state-pressure driven and explicitly rejects fixed turn/day/week/dashboard/lens-health triggers.
- The docket records route asset, original grant, revoking claimant or absence, affected future reader, notice carrier, proof receipt or absence, window state, and default risk.
- The hearing requires assignable slots for docket, route asset, original grant, revoking claimant, affected reader, notice carrier, proof receipt or absence, selected posture, accepted cost, and future route effect.
- At least seven branch families diverge by posture, notice/window state, cost, counter deltas, and future route effect.
- The default event records a false-clean reliance claim and mutates future play into recovery-only or costlier routing.
- Durable lens-scoped game-cli replay exports prove both an honored readback branch and a default hardening branch.
Replay evidence expectation
Required replay exports:
lens/replays/revocation-window-readback.honor.replay.jsonlens/replays/revocation-window-readback.default.replay.json
Both must come from sessions whose ids start with lens-storyteller-lens-revocation-window-readback-v1-.
Non-goals
This lens does not create a universal clean waiver, does not use storyteller-main, and does not depend on a fixed turn number.