Audience Grievance Merge Register / 观众申诉并案登记机制

Audience Grievance Merge Register is the mechanism for deciding when multiple audience-facing complaints are the same incident, when they must stay separate, and when a clean merge would erase a harmed cohort.

The current mesh already has intake, crisis ledger reconciliation, audience stability, fan token custody, public contrition, and counterreceipts. The missing operational seam is the merge action itself: the producer often wants to collapse many similar complaints into one manageable row. That merge is playable only if it records who is represented, who is harmed by representation, and which future reader consumes the merged state.

Exact executable contract

The runtime-backed v1 mechanic instantiates the broader design with one fixed crisis-ledger row: audience.merge.blackout.09 / blackout.incident.09. Its two cohorts are caption_access_row_09 (miscaption, caption_log_09, named_scope) and fan_oxygen_row_09 (oxygen_loss, oxygen_row_09, batch_scope). The clean merge benefits stability_table, harms caption_user, and is read by public_contrition; its normal future effect is public_addendum_required, and its fixed default risk is proof_carrier_contamination.

The abstract source/cohort/proof/reader alternatives elsewhere on this page are a design envelope, not a claim that the current runtime dynamically materializes every listed combination.

exact_runtime_assignments:
  register: storyteller.card.audience_grievance_merge_register.v1
  source_surface: storyteller.card.audience_grievance_source_surface.v1
  incident_key: storyteller.card.audience_grievance_incident_key.v1
  cohort_one: storyteller.card.audience_grievance_caption_cohort_row.v1
  cohort_two: storyteller.card.audience_grievance_oxygen_cohort_row.v1
  beneficiary: storyteller.card.audience_grievance_clean_merge_beneficiary.v1
  harmed_reader: storyteller.card.audience_grievance_harmed_reader.v1
  future_reader: storyteller.card.audience_grievance_future_reader.v1
  handler: storyteller.card.audience_grievance_merge_handler.v1
exact_required_slot_count: 9
all_slots_required: true
exact_accepts_required: true
assigned_cards_must_be_in_hand: true
selected_choice_required: true

The rite exposes exactly eight explicit choices, in stable order: merge_as_one_scoped (0), split_by_harm (1), split_by_reader (2), representative_lead (3), reject_duplicate_with_scar (4), publish_conflict (5), quarantine_proof (6), and default_clean_merge (7). Only index 7 arms the default event and its three pending flags. Missing, substituted, off-hand, choiceless, and repeated reviews fail without arming default.

After explicit choice 7, the event has exactly five exclusive scar-preserving terminals: false_duplicate_denial, universal_representative_closure, public_apology_overreach, proof_carrier_contamination, and broadcast_reality_false_closure. Every terminal clears pending state, records a distinct state/future effect, marks the default resolved, preserves an overmerge scar, and grants storyteller.card.overmerged_grievance_counterreceipt.v1.

The mechanic’s authority stops at grouping the named incident key and preserving its cohort/harm/proof rows. It does not perform claimant intake, convert ledger relief or debt, stabilize audience attention, audit proof lineage, grant or audit representative mandate, decide route-asset ownership, assign an answerability seat, or resolve a downstream counterreceipt challenge. It grants no universal merge, representation, proof equivalence, clean closure, consent, or universal route authority.

Mechanism promise

A grievance cluster can be merged only with a named scope. Similar claims do not automatically become the same route object.

The mechanism is valid when it forces all of the following into play:

  1. source surface;
  2. incident key or explicit absence;
  3. at least two grievance cohorts;
  4. harm type for each cohort or explicit absence;
  5. proof carrier for each cohort or explicit absence;
  6. proposed merge state;
  7. beneficiary of a clean merge;
  8. harmed cohort or reader if merged cleanly;
  9. selected posture;
  10. future reader or route consuming the merge state;
  11. branch with relief, cost, and future effect.

State-triggered entry

Open this mechanism only from state pressure:

entry_state_required:
  trigger_kind: state_pressure
  source_surface_present: true
  grievance_cohorts_min: 2
  incident_key_or_explicit_absence_present: true
  harm_types_visible_or_explicit_absence: true
  proof_carrier_visible_or_explicit_absence_for_each_cohort: true
  proposed_merge_would_change_future_play: true
  clean_merge_beneficiary_visible_or_explicit_absence: true
  harmed_if_merged_cleanly_visible_or_explicit_absence: true
  future_reader_or_route_consumes_merge_state: true
  player_can_merge_split_lead_reject_publish_quarantine_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_complaint_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

Valid source surfaces include crisis ledger rows, claimant floor intake rows, fan oxygen rows, blackout residue claims, fan token lines, public contrition rows, audience stability rows, receipt counterclaims, caption/access evidence, and route-asset custody rows.

Invalid entries include fixed turn number, chapter quota, raw complaint count, dashboard alert, sentiment score alone, or lens health.

Core objects

Merge state machine

merge_states:
  intake:
    - unreviewed_cluster
    - incident_key_shared
    - incident_key_disputed
    - harm_type_divergent
    - proof_carrier_divergent
    - representative_claimed
    - duplicate_alleged
    - merge_contaminates_proof
  after_resolution:
    - merge_as_one_scoped
    - split_by_harm
    - split_by_reader
    - representative_lead_scoped
    - rejected_duplicate_with_counterreceipt_risk
    - conflict_published
    - quarantined_for_proof_recheck
    - default_overmerged
    - recovery_only_for_merged_out_cohort
invalid_states:
  - clean_universal_merge
  - all_harms_satisfied_by_same_apology_without_scope
  - representative_lead_as_universal_consent
  - duplicate_rejection_without_future_effect
  - proof_carrier_closes_unlike_harms_for_free

Branch families

1. Merge as one with scope

Use when cohorts share incident key, proof carrier, and acceptable future reader.

Relief: queue pressure, stability pressure, or management pressure falls. Cost: excluded-cohort, public distrust, or counterreceipt risk rises. Future: apology, correction, oxygen recheck, or access row carries a scoped incident key.

2. Split by harm

Use when the same incident produced unlike injuries.

Relief: erasure risk falls and public legitimacy can rise. Cost: handler burden, remedy cost, sponsor stop-loss, or schedule pressure rises. Future: at least two remedies or routes remain visible and one becomes costlier.

3. Split by reader

Use when archive, lawful, public, fan, caption, access, sponsor, or stability readers cannot consume the same merge.

Relief: future reader ambiguity falls. Cost: route complexity, archive debt, public addendum pressure, or lawful annex pressure rises. Future: route becomes lawful-only, public-only, fan-only, archive-contested, sponsor-only, or split-required.

4. Representative lead with notice

Use when one cohort speaks first but cannot close all cohorts.

Relief: hearing can proceed and claimant-floor pressure falls. Cost: mandate pressure, notice pressure, and excluded reader pressure rise. Future: counterreceipt rights remain armed for cohorts not represented.

5. Reject duplicate with scar

Use when a cohort appears already represented.

Relief: queue pressure falls. Cost: false duplicate risk and hostile cohort pressure rise. Future: counterreceipt, public challenge, hostile route, or recovery-only state is armed.

6. Publish conflict

Use when the merge conflict itself must become public, lawful, or archive-readable.

Relief: public receipt or archive legibility rises. Cost: sponsor pressure, audience churn, and stability debt rise. Future: apology/correction cannot claim clean closure without conflict note.

7. Quarantine merge

Use when merging would contaminate proof carriers.

Relief: route asset and proof integrity are protected. Cost: route delay, fan oxygen resentment, caption/access pressure, and recovery cost rise. Future: recheck, addendum, or recovery-only posture is required.

8. Default overmerge

In the executable v1 packet, use only when the complete nine-card review explicitly selects choice 7, default_clean_merge. Skipped, hidden, underfilled, substituted, off-hand, choiceless, and repeated attempts are rejected and do not arm the event. Automatic omission/expiry defaulting remains outside this runtime.

Relief: fastest row, apology, or stability table reads clean. Cost: overmerged grievance default is armed. Future: the false clean incident key is consumed by counterreceipt, apology instability, route hostility, recovery-only branch, or broadcast reality contradiction.

Counter contract

Every resolved branch must mutate at least three durable surfaces:

counter_contract:
  relief_min: 1
  cost_min: 1
  future_reader_or_route_effect_min: 1

Candidate counters:

  • grievance_queue_pressure
  • merge_legibility
  • audience_stability
  • public_receipt_legitimacy
  • public_receipt_distrust
  • excluded_cohort_pressure
  • false_duplicate_risk
  • counterreceipt_risk
  • fan_oxygen_balance
  • fan_oxygen_resentment
  • caption_access_pressure
  • claimant_floor_pressure
  • handler_burden
  • notice_service_pressure
  • mandate_pressure
  • sponsor_stop_loss_pressure
  • archive_debt
  • lawful_annex_pressure
  • route_asset_integrity
  • broadcast_reality_contradiction
  • future_recovery_cost

Missability and recovery

The mechanism is missed when implementation:

  • merges grievances as clean duplicates;
  • treats one representative as universal closure;
  • lets one apology close unlike harms;
  • lets one proof carrier satisfy oxygen, access, caption, witness, and public receipt claims for free;
  • hides the clean-merge beneficiary;
  • hides the harmed cohort;
  • rejects duplicates without future route effect;
  • drives entry from raw complaint count, fixed turn, dashboard state, or lens health.

In the broader design envelope, recovery must preserve scar. The fixed v1 rite is non-repeatable, so its event emits a counterreceipt and future-recovery flag rather than reopening the same rite:

  • a later compatible review that preserves the original scar;
  • split by harm or reader;
  • representative mandate correction;
  • published conflict note;
  • oxygen/access/caption recheck;
  • public contrition restatement;
  • counterreceipt acceptance;
  • recovery-only marking for merged-out route.

Replay evidence shape

mechanic_id: storyteller.mechanic.audience_grievance_merge_register.v1
session_id: lens-storyteller-lens-audience-grievance-merge-register-v1-<run-id>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  source_surface: <surface>
  grievance_cohorts_min: 2
  incident_key_or_explicit_absence_present: true
  future_reader_or_route_consumes_merge_state: true
  no_fixed_turn_trigger: true
register:
  card: storyteller.card.audience_grievance_merge_register.v1
  cohorts:
    - cohort_id: <id>
      harm_type: <harm or explicit_absence>
      proof_carrier_or_absence: <proof or explicit_absence>
    - cohort_id: <id>
      harm_type: <harm or explicit_absence>
      proof_carrier_or_absence: <proof or explicit_absence>
resolution:
  rite: storyteller.rite.audience_grievance_merge_review.v1
  selected_posture: merge_as_one | split_by_harm | split_by_reader | representative_lead | reject_duplicate | publish_conflict | quarantine | default_clean_merge
  merge_state_after: <state>
  clean_merge_beneficiary: <actor or explicit_absence>
  harmed_if_merged_cleanly: <cohort reader or explicit_absence>
  future_reader_or_route_effect: <effect>
  emitted_event: storyteller.event.overmerged_grievance_default.v1 | none
  counter_deltas:
    relief: []
    cost: []
    future: []
assertions:
  - entry_is_state_triggered
  - cohorts_and_harm_types_visible
  - proof_carriers_visible_or_explicit_absence
  - beneficiary_and_harmed_cohort_visible_or_explicit_absence
  - branch_results_diverge
  - future_reader_consumes_merge_state
  - default_overmerge_is_durable
  - no_fixed_turn_or_raw_count_trigger

Runtime and replay evidence

Runtime source is split across game-content/storyteller/cards/audience-grievance-merge-register-runtime.json5, game-content/storyteller/rites/audience-grievance-merge-review.json5, and game-content/storyteller/events/overmerged-grievance-default.json5. lens/storyteller-audience-grievance-merge-register.runtime.test.ts exhaustively checks the nine-slot gate, eight branch mappings, choice-7-only arming, five terminals, public rollups, and replay re-execution.

lens/replays/audience-grievance-merge-register.split-by-harm.replay.json proves the exact choice-1 constructive path. lens/replays/audience-grievance-merge-register.overmerged-default.replay.json proves choice 7 followed by event option 3, proof_carrier_contamination. They are two fixed runtime proofs inside the broader mechanism envelope.

Non-goals

  • Not a support-ticket deduplication system.
  • Not a sentiment dashboard.
  • Not raw complaint-count pressure.
  • Not a generic governance or QA workflow.
  • Not a replacement for claimant intake, crisis ledger reconciliation, fan token custody, public contrition, or counterreceipts.
  • Not valid unless merge state changes future play.