Inspection Shadow Crew Custody Lens / 监察影子组羁押 Lens

This lens observes whether Inspection Shadow Crew Custody Storyline and 监察影子组羁押机制 turn field logistics into playable custody pressure.

A passing implementation proves that contested proof cannot be solved by high-rank authority alone. The replay must show a movable proof object, a carrier or explicit absence, contested factions, a branchy transfer decision, and durable consequences for both successful and negative carrier outcomes.

The file path is legacy-compatible. The canonical lens is state-triggered and fails if the package is offered because of a fixed turn number, day count, chapter quota, raw page count, or lens-health state.

This lens observes:

It is observed through:

Observable promise

A passing replay must show that a proof object has to cross a contested service-corridor chain and that the player must decide how that movement is carried, covered, bypassed, exposed, suppressed, or sacrificed.

The lens fails if the package behaves as a chapter milestone, a scheduled upkeep beat, a free card grant, or an authority-only button.

Must pass

1. Entry is state-driven

The offer appears only when a contested field-custody state exists.

Required entry evidence:

entry_state:
  trigger_kind: state_pressure
  movable_or_uncertain_proof_present: true
  affected_route_or_proof_present: true
  claimant_factions_count_min: 2
  carrier_or_explicit_absence_present: true
  unresolved_pressure_present: true
  no_fixed_turn_trigger: true

The lens fails if the offer appears from a fixed turn number, day interval, chapter quota, page-count target, lens-health state, or generic post-ruling label without contested proof movement.

2. Movable proof is named

The replay must name the proof object or packet being moved. Valid examples include:

  • fan oxygen receipt;
  • archive docket copy;
  • black-box fragment;
  • consent/refusal printout;
  • witness stub;
  • memorial air copy;
  • voice custody receipt;
  • route-asset packet;
  • returned evidence from Evidence Carryover Fork.

A vague phrase like evidence is insufficient unless it resolves to a stable in-world object id.

3. Claimant factions are present

At least two factions or claimant roles must be active, such as:

  • archive desk;
  • white-glove inspection;
  • sponsor stop-loss desk;
  • fan oxygen public;
  • unauthorized historian network;
  • black-box/editor authority;
  • artist or consent boundary;
  • pirate relay;
  • false owner claimant;
  • production desk.

The lens fails if the handoff has no live opposition or beneficiary.

4. Carrier or explicit absence is represented

The implementation must expose a carrier state for Cen Wei, 林乔, a fan delegate, archive clerk, editor source, public witness, or equivalent.

Valid states include:

  • crew_offer_ready
  • runner_authorized
  • lawful_chain_witness
  • public_receipt_carrier
  • editor_masked_carrier
  • neutral_route_asset
  • suppressed_carrier
  • hostile_leak_source
  • captured_carrier
  • sacrificed_permit
  • explicit_absent

The lens fails if high-rank actors erase the carrier slot rather than assigning, bypassing, suppressing, or explicitly missing it.

5. Transfer rite is fillable and branchy

Shadow Evidence Transfer or equivalent must expose at least five non-equivalent branches among:

  • lawful chain;
  • public receipt chain;
  • editor mask;
  • production-neutral route asset;
  • sponsor/manager cover;
  • suppression or managed bypass;
  • permit/carrier sacrifice;
  • leak, capture, or hostile carrier.

Each branch must record assigned slots or explicit absence:

assigned_slots:
  proof_object: <stable id>
  carrier: <carrier id or explicit_absent>
  permit_or_cover: <permit, oath, public receipt, editor mask, sponsor cover, or none>
  handler: <handler id or none>
  claimant_pressure: <active claimant>

6. Branches cannot collapse

Different branches must change different relief, cost, route state, and carrier state.

Expected non-equivalence:

  • lawful chain improves admissibility but raises inspection/bureau/lawful-only cost;
  • public receipt blocks private capture but raises sponsor/fan/public exposure cost;
  • editor mask protects identity or continuity but raises edit/archive/source ambiguity cost;
  • production-neutral route keeps carrier usable but raises handler/payroll/recovery cost;
  • sponsor cover saves immediate slot or money but increases contract capture and distrust;
  • suppression/bypass leaves carrier absent and future transfer costlier;
  • sacrifice protects stronger proof while losing carrier/permit and creating witness debt;
  • leak/capture/hostility creates durable failure, false owner, duplicate claim, or recovery-only route.

7. Success has a cost

Any successful carrier branch must include visible cost or scar.

Valid costs include:

  • runner_risk;
  • payroll_leak;
  • handler_burden;
  • inspection_heat;
  • bureau_favor_debt;
  • archive_debt;
  • sponsor_stop_loss_pressure;
  • fan_oxygen_liability;
  • fan_oxygen_resentment;
  • public_exposure;
  • contract_capture;
  • edit_debt;
  • source_ambiguity;
  • future_recovery_cost;
  • lawful-only or public-only routing.

The lens fails if a carrier success creates clean proof movement with no cost.

8. Negative branch is durable

A missed, suppressed, sacrificed, captured, or hostile carrier branch must change future play.

Required negative mutation:

  • carrier state becomes suppressed_carrier, hostile_leak_source, captured_carrier, sacrificed_permit, or explicit_absent;
  • at least one future rite, route, proof burden, public receipt, custody claim, or recovery branch becomes harder, costlier, unavailable, or recovery-only;
  • at least one adverse counter changes.

Shadow Crew Custody Leak or equivalent must be seen or armed when the negative branch creates leak pressure.

9. Carrier and route state both mutate

A resolved branch must mutate both:

  1. carrier/absence state; and
  2. route/proof/custody state.

The lens fails if only counters move while the route asset and carrier remain unchanged.

10. At least three deltas exist

Every resolved branch must mutate at least three counters or durable states. At least one must be relief and at least one must be cost.

Primary expected surfaces:

  • custody_clarity
  • custody_gap
  • proof_legibility
  • proof_burden
  • route_asset_pressure
  • runner_risk
  • payroll_leak
  • handler_burden
  • inspection_heat
  • bureau_favor_debt
  • archive_signature_legitimacy
  • archive_debt
  • public_receipt_legitimacy
  • public_receipt_distrust
  • fan_oxygen_liability
  • fan_oxygen_resentment
  • sponsor_stop_loss_pressure
  • contract_capture
  • edit_debt
  • source_ambiguity
  • continuity_hazard
  • false_owner_pressure
  • future_recovery_cost

11. Replay provenance is not trigger logic

Replay evidence may record turn ranges for debugging, but those fields cannot be used as eligibility. The in-world trigger must remain contested state: movable proof, claimants, carrier/absence, and mutable route/counter pressure.

The lens fails if a debug replay id or turn range replaces proof object, carrier, claimant, branch choice, or route state.

Branch assertions

Lawful chain assertion

selected_branch: lawful_chain
carrier_state_after_any:
  - lawful_chain_witness
  - neutral_route_asset
route_or_proof_after_any:
  - protected
  - lawful_only
  - costlier
relief_any:
  - custody_clarity_up
  - archive_signature_legitimacy_up
  - proof_legibility_up
  - false_owner_pressure_down
cost_any:
  - inspection_heat_up
  - bureau_favor_debt_up
  - runner_risk_up
  - route_lawful_only

Public receipt assertion

selected_branch: public_receipt_chain
carrier_state_after: public_receipt_carrier
route_or_proof_after_any:
  - protected
  - public_only
  - costlier
relief_any:
  - public_receipt_legitimacy_up
  - private_capture_blocked
cost_any:
  - sponsor_stop_loss_pressure_up
  - fan_oxygen_liability_up
  - public_exposure_up
  - inspection_heat_up

Editor mask assertion

selected_branch: editor_mask
carrier_state_after: editor_masked_carrier
route_or_proof_after_any:
  - split_canon
  - contradiction_pending
  - costlier
relief_any:
  - witness_retaliation_risk_down
  - continuity_hazard_down
cost_any:
  - edit_debt_up
  - archive_debt_up
  - source_ambiguity_up
  - public_receipt_distrust_up

Production-neutral assertion

selected_branch: production_neutral_route
carrier_state_after: neutral_route_asset
route_or_proof_after_any:
  - protected
  - costlier
  - route_asset
relief_any:
  - future_transfer_option_unlocked
  - faction_capture_delayed
cost_any:
  - handler_burden_up
  - payroll_leak_up
  - future_recovery_cost_up
selected_branch_any:
  - sponsor_cover
  - managed_bypass_or_suppress
carrier_state_after_any:
  - suppressed_carrier
  - explicit_absent
  - captured_carrier
route_or_proof_after_any:
  - captured
  - recovery_only
  - costlier
  - contradiction_pending
relief_any:
  - immediate_slot_pressure_down
  - sponsor_pressure_paused
cost_any:
  - contract_capture_up
  - public_receipt_distrust_up
  - future_recovery_cost_up
  - proof_burden_up

Sacrifice/leak/capture assertion

selected_branch_any:
  - sacrifice_carrier_or_permit
  - leak_capture_or_hostile
carrier_state_after_any:
  - sacrificed_permit
  - hostile_leak_source
  - captured_carrier
route_or_proof_after_any:
  - false_owner_pressure
  - recovery_only
  - blocked
  - costlier
emitted_or_armed_event: storyteller.event.shadow_crew_custody_leak
cost_any:
  - custody_gap_up
  - archive_debt_up
  - sponsor_stop_loss_pressure_up
  - future_recovery_cost_up

Failure cases

The lens must fail if any of these are true:

  • entry is triggered by fixed turn number, day count, chapter quota, page-count target, or lens-health state;
  • movable proof object is not named;
  • fewer than two claimant factions are active;
  • no carrier, permit, witness, runner, clerk, source, or explicit absence is represented;
  • high-rank actor assignment alone satisfies the package;
  • the transfer rite has fewer than five non-equivalent branches;
  • success has no cost;
  • negative carrier outcome does not change future route availability, difficulty, proof burden, or claimant pressure;
  • Shadow Crew Custody Leak is only flavor and does not mutate state;
  • only counters move while carrier and route/proof states remain unchanged;
  • replay evidence uses debug turn range as a substitute for in-world state.

Progress metric

inspectionShadowCrewCustodyProgress = 0..8:

  • 0: no field-custody package exists.
  • 1: movable contested proof and at least two claimants are visible.
  • 2: carrier or explicit absence is represented.
  • 3: Inspection Shadow Crew Permit or equivalent cover can be assigned or explicitly absent.
  • 4: Shadow Evidence Transfer offers at least five non-equivalent branches.
  • 5: a successful branch mutates carrier and route/proof state with cost.
  • 6: a negative branch creates durable missed/suppressed/hostile/captured/sacrificed state.
  • 7: Shadow Crew Custody Leak or equivalent mutates future play when armed/fired.
  • 8: success and negative branches are replay-proven with seed/session id, assigned slots, states before/after, counter deltas, and no_fixed_turn_trigger: true.

Replay/session evidence shape

lens_id: storyteller.lens.inspection_shadow_crew_custody.v2
legacy_lens_id: storyteller.turn54_inspection_shadow_crew_package.v1
session_id: lens-storyteller-inspection-shadow-crew-custody-v2-<timestamp>
seed: <deterministic seed>
provenance_turn_range: <optional debug field only>
entry_state:
  trigger_kind: state_pressure
  movable_or_uncertain_proof_present: true
  affected_route_or_proof_present: true
  claimant_factions:
    - <claimant one>
    - <claimant two>
  carrier_or_explicit_absence_present: true
  unresolved_pressure_present: true
  no_fixed_turn_trigger: true
offered_choices:
  - lawful_chain
  - public_receipt_chain
  - editor_mask
  - production_neutral_route
  - sponsor_cover
  - managed_bypass_or_suppress
  - sacrifice_carrier_or_permit
  - leak_capture_or_hostile
assigned_slots:
  proof_object: <stable object id>
  carrier: cen_wei | lin_qiao | fan_delegate | archive_clerk | editor_source | explicit_absent | equivalent
  permit_or_cover: inspection_shadow_crew_permit | audit_oath | public_receipt | editor_mask | sponsor_cover | none
  handler: han_yanshuang | yu_lan | baiya | shen_luo | sponsor | production | none
branches:
  success_branch:
    selected_branch: lawful_chain | public_receipt_chain | editor_mask | production_neutral_route
    carrier_state_before: <state>
    carrier_state_after: <state>
    route_or_proof_state_after: <state>
    counter_deltas:
      relief:
        - <relief counter/state>
      cost:
        - <cost counter/state>
  negative_branch:
    selected_branch: managed_bypass_or_suppress | sacrifice_carrier_or_permit | leak_capture_or_hostile
    carrier_state_before: <state>
    carrier_state_after: <state>
    route_or_proof_state_after: <state>
    event_seen_or_armed: storyteller.event.shadow_crew_custody_leak
    counter_deltas:
      relief:
        - <possible short relief>
      cost:
        - <cost counter/state>
assertions:
  - entry is state-triggered
  - high-rank actor alone is insufficient
  - carrier and route/proof states both mutate
  - success has nonzero cost
  - negative branch changes future availability or difficulty

Non-goals

  • Not a turn-count package.
  • Not a bulk crew expansion.
  • Not a raw content-count target.
  • Not a governance or dashboard page.
  • Not a free repair for archive, proof, consent, sponsor, fan, editor, or inspection pressure.
  • Not satisfied by prose; evidence must be replay-derived.