Three-Key Custody Collision Lens / 三钥羁押撞锁 Lens

This lens observes whether 三钥羁押撞锁线 and 三钥羁押撞锁机制 correctly handle a single asset that sponsor, inspection, and cutroom authorities can all block, release, split, seize, or capture.

The lens exists because the current Storyteller mesh can already create sponsor insolvency, inspector audit, cutroom priority, narration priority, and route-asset pressure. A satisfying implementation must prove those powers collide over the same asset instead of resolving as isolated single-system wins.

This lens observes:

It is observed through:

Observable promise

A passing replay must show one named asset or target version with sponsor, inspection, and cutroom key states visible. It must name proof or explicit absence, missing/refused key, excluded holder, collateral at risk, selected release pattern, counter/state deltas, and future route effect.

The lens must fail if sponsor funding, inspection admissibility, or cutroom checksum silently grants universal custody.

Entry oracle

Valid entry is state-driven:

entry_state:
  shared_asset_visible: true
  shared_target_version_visible: true
  sponsor_key_visible: true
  inspection_key_visible: true
  cutroom_key_visible: true
  at_least_two_release_patterns_possible: true
  future_route_effect_possible: true
  no_fixed_turn_trigger: true

The lens fails if the surface opens from a fixed turn number, day interval, chapter quota, content-count target, generic upkeep phase, or lens-health state.

Required data surfaces

Docket card

三钥羁押案卷 or equivalent must expose each row with:

  • asset id;
  • asset kind;
  • shared target version;
  • sponsor key holder and key state;
  • inspection key holder and key state;
  • cutroom key holder and key state;
  • missing/refused key;
  • proposed release pattern;
  • excluded holder;
  • proof or explicit absence;
  • collateral at risk;
  • default if ignored;
  • future route effect.

The lens fails if the card stores only a binary approval, a winning faction, or a generic custody flag.

Hearing rite

三钥羁押听证 or equivalent must require:

  • selected row and asset;
  • all three key states;
  • selected release pattern;
  • proof or explicit absence;
  • collateral at risk;
  • excluded holder;
  • accepted finite cost;
  • resulting future route effect.

The lens fails if all three keys can be seated for free, if two-key release hides the excluded key, or if no future route state mutates.

Lockout event

三钥羁押锁死 or equivalent must fire or become default-ready when a missing/refused/counterfeit key is hidden, split terms are broken, or a default-ready row is ignored.

The event must mutate asset state and future route effect.

Required key states

A satisfying implementation must expose durable states equivalent to at least eight of:

  • key_unasked
  • key_offered
  • key_refused
  • key_seated
  • key_split
  • key_escrowed
  • key_counterfeit
  • key_hostile
  • key_seized
  • key_missing

Branch divergence oracle

At least four branch families must be playable and non-equivalent.

Branch A — All three keys with debt

Expected evidence:

selected_release_pattern: split_three_key
all_three_key_states_after: key_seated
relief_present: true
cost_present: true
future_route_effect_any: [protected, costlier, contradiction_pending]

Branch B — Sponsor + inspection release

Expected evidence:

selected_release_pattern: sponsor_inspection
excluded_key: cutroom
cutroom_state_after_any: [key_refused, key_hostile, key_missing]
future_route_effect_any: [lawful_only, contradiction_pending, recovery_only, hostile]

Branch C — Sponsor + cutroom release

Expected evidence:

selected_release_pattern: sponsor_cutroom
excluded_key: inspection
inspection_state_after_any: [key_refused, key_hostile, key_missing, key_counterfeit]
future_route_effect_any: [captured, public_only, costlier, recovery_only]

Branch D — Inspection + cutroom release

Expected evidence:

selected_release_pattern: inspection_cutroom
excluded_key: sponsor
sponsor_state_after_any: [key_refused, key_hostile, key_missing]
future_route_effect_any: [lawful_only, public_route_costlier, sponsor_retaliation, recovery_only]

Branch E — Split or escrow

Expected evidence:

selected_release_pattern_any: [split_three_key, escrow_and_delay]
key_state_after_any: [key_split, key_escrowed]
future_route_effect_any: [split_canon, contradiction_pending, costlier]

Branch F — Quarantine or blackout fold

Expected evidence:

selected_release_pattern_any: [quarantine, blackout_fold]
asset_state_after_any: [key_escrowed, key_seized, blackout_fold, recovery_only]
future_route_effect_any: [recovery_only, blackout_pressure_up, blocked]

Branch G — Lockout

Expected evidence:

selected_release_pattern: no_valid_release
event_seen: storyteller.event.three_key_custody_lockout.v1
asset_state_after_any: [sponsor_captured, inspection_seized, editor_withheld, counterfeit_exposed, blackout_fold, recovery_only]
future_route_effect_any: [captured, lawful_only, public_only, blocked, hostile, recovery_only]

Oracle assertions

A binding check should fail unless all assertions below are true.

  1. Primary links existobserves and observed_through arrays point to concrete Storyteller pages.
  2. Entry is state-driven — no turn-count, day-count, chapter-quota, content-count, or lens-health trigger.
  3. Shared asset exists — one asset or target version is named and used by at least two source systems.
  4. Three keys are visible — sponsor, inspection, and cutroom key states are all visible or explicitly absent/refused.
  5. Missing/refused key is visible — no release hides the harmed key.
  6. Excluded holder is visible — every two-key or failed release names who is harmed.
  7. Proof/absence is named — proof object, checksum, legal seal, sponsor collateral, or explicit absence is recorded.
  8. Branch outcomes diverge — all-three, two-key release, split/escrow, quarantine/blackout, and lockout cannot collapse into one result.
  9. Lockout is durable — invalid release, counterfeit key, broken split, or ignored row mutates asset state and future route effect.
  10. At least three deltas exist — every resolved branch mutates at least three counters or durable states, including relief and cost.
  11. Future route mutates — result changes later route access, difficulty, custody, copy state, seizure risk, contradiction, ending eligibility, blackout pressure, or recovery-only state.
  12. No safe universal approval — the implementation does not let sponsor, inspection, or cutroom approval automatically satisfy every other holder.

Progress metric

threeKeyCustodyCollisionProgress = 0..8:

  • 0: no three-key custody state.
  • 1: at least one shared asset enters 三钥羁押案卷.
  • 2: sponsor, inspection, and cutroom key holders/states are visible or explicitly absent/refused.
  • 3: missing/refused key, excluded holder, proof/absence, and collateral are visible.
  • 4: 三钥羁押听证 or equivalent offers at least three release patterns.
  • 5: selected branch mutates at least three counters/states with relief and cost.
  • 6: at least three branch families produce non-equivalent future route states.
  • 7: 三钥羁押锁死 or equivalent fires/defaults on missing, refused, counterfeit, hidden, broken-split, or ignored key.
  • 8: at least four branch families are proven with replay/session evidence, including one two-key release, one split/escrow or quarantine branch, and one lockout branch.

Evidence shape

lens_id: storyteller.lens.three_key_custody_collision.v1
session_id: lens-three-key-custody-collision-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  asset_id: <asset>
  asset_kind: <kind>
  shared_target_version: <version>
  sponsor_key:
    holder: <holder or explicit_absence>
    state: <state>
  inspection_key:
    holder: <holder or explicit_absence>
    state: <state>
  cutroom_key:
    holder: <holder or explicit_absence>
    state: <state>
  source_surfaces:
    - <source surface>
  no_fixed_turn_trigger: true
offered_choices:
  - card.three_key_custody_docket
  - rite.three_key_custody_hearing
  - all_three_with_debt
  - sponsor_inspection
  - sponsor_cutroom
  - inspection_cutroom
  - split_or_escrow
  - quarantine_or_blackout
  - no_valid_release
branch_runs:
  all_three_with_debt:
    future_route_effect: <effect>
    counter_deltas: {}
  sponsor_inspection:
    excluded_key: cutroom
    future_route_effect: <effect>
    counter_deltas: {}
  sponsor_cutroom:
    excluded_key: inspection
    future_route_effect: <effect>
    counter_deltas: {}
  inspection_cutroom:
    excluded_key: sponsor
    future_route_effect: <effect>
    counter_deltas: {}
  split_or_escrow:
    key_state_after: <state>
    future_route_effect: <effect>
    counter_deltas: {}
  lockout:
    event: storyteller.event.three_key_custody_lockout.v1
    asset_state_after: <state>
    future_route_effect: <effect>
    counter_deltas: {}
assertions:
  - primary_links_exist
  - state_triggered_entry
  - shared_asset_visible
  - three_keys_visible
  - missing_or_refused_key_visible
  - excluded_holder_visible
  - proof_or_absence_named
  - branch_outcomes_diverge
  - lockout_durable
  - future_route_effect_mutates

Non-goals

  • Not a governance checklist.
  • Not a dashboard-only evidence spec.
  • Not a turn-count or day-count escalation.
  • Not a generic committee approval system.
  • Not a legal minigame.
  • Not a raw content-count expansion.
  • Not satisfied by page existence; proof must come from shared asset state, three visible keys, assignable hearing choice, branch divergence, durable lockout/default, counter deltas, and future route mutation.