Common-Source Corroboration Audit / 同源佐证审计机制

This mechanism separates authentic surface count from independent root count.

An inspector report, editor checksum, archive copy, memorial-voice file, public clip, and carrier receipt may each be authentic and useful. They do not become independent merely because they have different holders, formats, timestamps, signatures, or institutional labels. When several rows share one root capture, cite one another, or loop through a broadcast that cites its own derivatives, they contribute at most one independent source family until a genuinely distinct origin capture is commissioned and arrives.

Core invariants

hard_rules:
  authenticity_is_not_independence: true
  different_holder_is_not_distinct_root: true
  different_format_is_not_distinct_root: true
  different_timestamp_is_not_distinct_root: true
  different_authority_scope_is_not_distinct_root: true
  checksum_of_copy_is_not_second_capture: true
  report_citing_checksum_is_not_independent_witness: true
  public_clip_of_broadcast_is_not_external_corroboration: true
  carrier_receipt_proves_transfer_not_claim_truth: true
  unknown_root_is_not_presumed_distinct: true
  circular_citation_counts_as_one_family: true
  no_universal_proof_authority: true

Exact runtime objects

cards:
  docket: storyteller.card.proof_lineage_docket.v1
  inspector_report: storyteller.card.inspector_report_lineage_row.v1
  editor_checksum: storyteller.card.editor_checksum_lineage_row.v1
  archive_copy: storyteller.card.archive_copy_lineage_row.v1
  memorial_voice: storyteller.card.memorial_voice_lineage_row.v1
  public_clip: storyteller.card.public_clip_lineage_row.v1
  carrier_receipt: storyteller.card.carrier_receipt_lineage_row.v1
rites:
  intake: storyteller.rite.common_source_corroboration_intake.v1
  review: storyteller.rite.common_source_corroboration_review.v1
events:
  entry: storyteller.event.proof_lineage_collision.v1
  default: storyteller.event.self_corroborating_broadcast_default.v1

Exact source-family schema

Every apparent source row must retain this schema through intake, collision, review, default, replay, and future consumption:

proof_lineage_row_required:
  rowCardId: storyteller.card.<lineage-row>.v1
  proofId: <stable proof row id>
  apparentSourceId: <stable apparent source id>
  surfaceKind: inspector_report | editor_checksum | archive_copy | memorial_voice | public_clip | carrier_receipt
  sourceFamilyId: family.lyra.last-air-edit.017
  lineageRootId: slot.last_air_edit
  rootSourceIdOrExplicitAbsence: slot.last_air_edit | explicit_absence
  parentCopyIdOrAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
  parentSourceIdOrExplicitAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
  sourceSessionIdOrAbsence: session.lyra.last-air-edit.017 | explicit_absence
  custodian: <named inspector editor archivist memorial desk fan public or carrier>
  custodianOrExplicitAbsence: <same named custodian or explicit_absence>
  derivationKind: inspector_summary | checksum | archive_copy | memorial_mix | public_clip | carrier_receipt
  originFingerprintOrExplicitAbsence: sha256:lyra-last-air-edit-017 | explicit_absence
  claimFragment: <exact proposition traced through this row>
  authorityScope: inspection | editor_continuity | archive_custody | memorial_voice | public_receipt | carrier_transfer
  captureOrIssueTime: <stable time row>
  versionId: <stable version id>
  futureReaderOrRoute: reader.memorial-archive-route-clearance
  harmedReaderOrClaimantIfOvercounted: lyra_voice_and_memorial_route_claimant
  provesScope: <one exact local proposition>
  doesNotProve: [<explicit denied authorities>]
  independenceState: shared_root
  localAuthorityOnly: true

The docket must also calculate without inference:

source_family_summary_required:
  requestedUse: authorize_memorial_voice_archive_route_as_independently_verified
  requestedCorroboratedClaim: the_named_voice_phrase_has_six_independent_confirmations_for_memorial_archive_route_use
  futureReader: reader.memorial-archive-route-clearance
  harmedFutureReaderOrRoute: reader.memorial-archive-route-clearance
  lineageRootId: slot.last_air_edit
  sourceSessionIdOrAbsence: session.lyra.last-air-edit.017 | explicit_absence
  claimedCorroborationCount: 6
  apparentSourceCount: 6
  distinctLineageRootCount: 1
  establishedRootCount: 1
  unknownRootCount: 0
  circularFamilyCount: 0
  circularFamilyCountAfterFalseBroadcast: 1
  corroborationWeightBeforeReview: 6
  corroborationWeightIfDisclosed: 1
  independentWeightAllowed: 1
  overcountedWeight: 5
  independenceStateBefore: common_root_unreviewed
  broadcastClaimStatus: proposed
  proofRowIds: [<six exact proof ids>]

Runtime chain

intake:
  rite_id: storyteller.rite.common_source_corroboration_intake.v1
  option_id: record_common_source_collision
  repeatable: false
  records_common_source_pressure_without_resolving_lineage: true
 
entry:
  event_id: storyteller.event.proof_lineage_collision.v1
  option_id: open_common_source_corroboration_review
  requires_completed_intake: true
  requires_all_seven_exact_cards: true
  exposes_requested_claim_root_count_authority_scopes_and_future_reader: true
 
review:
  rite_id: storyteller.rite.common_source_corroboration_review.v1
  repeatable: false
  exact_slot_count: 7
  branch_count: 7

Cards alone do not open the entry event or review. A raw count of agreeing sources, fixed time, dashboard state, or lens status cannot substitute for the intake and collision chain.

Exactly seven review branches

branches:
  commission_distinct_origin_capture:
    lineage_state_after: distinct_origin_capture_commissioned
    future_effect: distinct_origin_capture_required_before_clean_corroboration
  disclose_common_source:
    lineage_state_after: common_source_disclosed
    future_effect: corroboration_weight_capped_at_one
    counter_delta: corroborationWeightReduction:+5
  split_by_authority:
    lineage_state_after: authority_scopes_split
    future_effect: reader_specific_proof_required
  reopen_root_capture:
    lineage_state_after: root_capture_reopened
    future_effect: root_capture_required_before_route_unlock
  quarantine_memorial_voice_use:
    lineage_state_after: memorial_voice_quarantined
    future_effect: memorial_voice_use_blocked_pending_lineage
  publish_lineage_notice:
    lineage_state_after: lineage_notice_published
    future_effect: public_lineage_addendum_required
  false_independent_corroboration:
    lineage_state_after: false_independent_corroboration_pending
    future_effect: self_corroborating_broadcast_default_pending

Each branch must change at least one relief surface, one cost surface, and one future route/readership surface. The first six are constructive but scoped; none can create universal proof. Only false_independent_corroboration may arm the default.

Harmful branch and exact pending gate

harmful_branch: false_independent_corroboration
pending_triple:
  common_source_corroboration.default_pending: true
  event.self_corroborating_broadcast_default.armed: true
  future_route.self_corroborating_broadcast_default_pending: true
aired_flag:
  broadcast_reality.false_independent_corroboration_aired: true

The default is unreachable if any member of the triple is missing, the aired flag is false, the review remains unresolved, or any of the first six branches was selected.

Exactly three default terminals

default_terminals:
  record_circular_proof_scar:
    lineage_state_after: circular_proof_scar_recorded
    future_effect: future_routes_require_distinct_lineage_roots
  force_root_source_reaudit:
    lineage_state_after: root_source_reaudit_required
    future_effect: root_source_reaudit_required_before_memorial_or_archive_use
  freeze_derived_route_assets:
    lineage_state_after: derived_route_assets_frozen
    future_effect: derived_route_assets_recovery_only_until_lineage_rebuilt
default_event_metadata:
  circularFamilyCountAfterFalseBroadcast: 1

Every terminal clears the pending triple and aired flag, resolves the event, preserves a false-multiplicity scar, and sets exactly one terminal state with its matching future effect. The event cannot retrigger.

Counter contract

Each review branch and default terminal must record at least three durable movements:

counter_deltas_required:
  relief: at_least_one
  cost: at_least_one
  future_reader_or_route_effect: at_least_one
accepted_surfaces:
  - proof_lineage_legibility
  - independent_root_integrity
  - corroboration_weight_reduction
  - archive_debt
  - memorial_voice_exposure
  - public_lineage_distrust
  - correction_duty
  - route_delay
  - reality_drift
  - derived_route_asset_pressure
  - recovery_only_pressure

Reachability contract

All seven branches share the same eligible post-collision state. Checks must reject:

  • intake with a missing, wrong, or unheld card;
  • intake with no selected option;
  • entry before intake or without all seven exact cards;
  • review before the entry event;
  • review with a missing collision flag, wrong slot, absent card, or no choice;
  • a second review resolution;
  • default resolution before the harmful branch;
  • default resolution with an incomplete pending triple or missing aired flag;
  • a second default terminal.

Because review is nonrepeatable, one selected branch makes the other six missable for the incident. Because default is once-only, one terminal makes the other two missable.

Authority boundary

This mechanic tracks lineage roots and derivative relationships only. It requires distinct roots for independent corroboration and preserves inspection, editor, archive, memorial, public, and carrier scopes. It grants no underlying event truth, independent corroboration without distinct roots, universal inspector all-clear, editor source truth, archive pre-intake origin, memorial-voice consent, voice custody, route-asset content truth, public-clip independent witness status, sponsor immunity, or universal broadcast authority.

It may preserve a derivative as valid within inspection, editor, archive, memorial, public, or carrier scope while still capping the family at one independent root.

Integration boundaries

Replay evidence shape

lens_id: storyteller.lens.common_source_corroboration_audit.v1
replay: lens/replays/common-source-corroboration-audit.false-multiplicity-default.replay.json
required_actions_in_order:
  - create_storyteller_lens_scoped_session
  - resolve_common_source_corroboration_intake
  - resolve_proof_lineage_collision
  - resolve_false_independent_corroboration_review_branch
  - resolve_one_self_corroborating_broadcast_default_terminal
required_final_evidence:
  integrity_verified: true
  session_seed_present: true
  all_seven_cards_identified: true
  source_family_schema_present: true
  harmful_branch_visible: true
  pending_triple_cleared: true
  aired_flag_cleared: true
  false_multiplicity_scar_visible: true
  exactly_one_terminal_state: true
  matching_future_effect_visible: true