Common-Source Corroboration Audit / 同源佐证审计机制
This mechanism separates authentic surface count from independent root count.
An inspector report, editor checksum, archive copy, memorial-voice file, public clip, and carrier receipt may each be authentic and useful. They do not become independent merely because they have different holders, formats, timestamps, signatures, or institutional labels. When several rows share one root capture, cite one another, or loop through a broadcast that cites its own derivatives, they contribute at most one independent source family until a genuinely distinct origin capture is commissioned and arrives.
Core invariants
hard_rules:
authenticity_is_not_independence: true
different_holder_is_not_distinct_root: true
different_format_is_not_distinct_root: true
different_timestamp_is_not_distinct_root: true
different_authority_scope_is_not_distinct_root: true
checksum_of_copy_is_not_second_capture: true
report_citing_checksum_is_not_independent_witness: true
public_clip_of_broadcast_is_not_external_corroboration: true
carrier_receipt_proves_transfer_not_claim_truth: true
unknown_root_is_not_presumed_distinct: true
circular_citation_counts_as_one_family: true
no_universal_proof_authority: trueExact runtime objects
cards:
docket: storyteller.card.proof_lineage_docket.v1
inspector_report: storyteller.card.inspector_report_lineage_row.v1
editor_checksum: storyteller.card.editor_checksum_lineage_row.v1
archive_copy: storyteller.card.archive_copy_lineage_row.v1
memorial_voice: storyteller.card.memorial_voice_lineage_row.v1
public_clip: storyteller.card.public_clip_lineage_row.v1
carrier_receipt: storyteller.card.carrier_receipt_lineage_row.v1
rites:
intake: storyteller.rite.common_source_corroboration_intake.v1
review: storyteller.rite.common_source_corroboration_review.v1
events:
entry: storyteller.event.proof_lineage_collision.v1
default: storyteller.event.self_corroborating_broadcast_default.v1Exact source-family schema
Every apparent source row must retain this schema through intake, collision, review, default, replay, and future consumption:
proof_lineage_row_required:
rowCardId: storyteller.card.<lineage-row>.v1
proofId: <stable proof row id>
apparentSourceId: <stable apparent source id>
surfaceKind: inspector_report | editor_checksum | archive_copy | memorial_voice | public_clip | carrier_receipt
sourceFamilyId: family.lyra.last-air-edit.017
lineageRootId: slot.last_air_edit
rootSourceIdOrExplicitAbsence: slot.last_air_edit | explicit_absence
parentCopyIdOrAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
parentSourceIdOrExplicitAbsence: <direct parent proof id or slot.last_air_edit or explicit_absence>
sourceSessionIdOrAbsence: session.lyra.last-air-edit.017 | explicit_absence
custodian: <named inspector editor archivist memorial desk fan public or carrier>
custodianOrExplicitAbsence: <same named custodian or explicit_absence>
derivationKind: inspector_summary | checksum | archive_copy | memorial_mix | public_clip | carrier_receipt
originFingerprintOrExplicitAbsence: sha256:lyra-last-air-edit-017 | explicit_absence
claimFragment: <exact proposition traced through this row>
authorityScope: inspection | editor_continuity | archive_custody | memorial_voice | public_receipt | carrier_transfer
captureOrIssueTime: <stable time row>
versionId: <stable version id>
futureReaderOrRoute: reader.memorial-archive-route-clearance
harmedReaderOrClaimantIfOvercounted: lyra_voice_and_memorial_route_claimant
provesScope: <one exact local proposition>
doesNotProve: [<explicit denied authorities>]
independenceState: shared_root
localAuthorityOnly: trueThe docket must also calculate without inference:
source_family_summary_required:
requestedUse: authorize_memorial_voice_archive_route_as_independently_verified
requestedCorroboratedClaim: the_named_voice_phrase_has_six_independent_confirmations_for_memorial_archive_route_use
futureReader: reader.memorial-archive-route-clearance
harmedFutureReaderOrRoute: reader.memorial-archive-route-clearance
lineageRootId: slot.last_air_edit
sourceSessionIdOrAbsence: session.lyra.last-air-edit.017 | explicit_absence
claimedCorroborationCount: 6
apparentSourceCount: 6
distinctLineageRootCount: 1
establishedRootCount: 1
unknownRootCount: 0
circularFamilyCount: 0
circularFamilyCountAfterFalseBroadcast: 1
corroborationWeightBeforeReview: 6
corroborationWeightIfDisclosed: 1
independentWeightAllowed: 1
overcountedWeight: 5
independenceStateBefore: common_root_unreviewed
broadcastClaimStatus: proposed
proofRowIds: [<six exact proof ids>]Runtime chain
intake:
rite_id: storyteller.rite.common_source_corroboration_intake.v1
option_id: record_common_source_collision
repeatable: false
records_common_source_pressure_without_resolving_lineage: true
entry:
event_id: storyteller.event.proof_lineage_collision.v1
option_id: open_common_source_corroboration_review
requires_completed_intake: true
requires_all_seven_exact_cards: true
exposes_requested_claim_root_count_authority_scopes_and_future_reader: true
review:
rite_id: storyteller.rite.common_source_corroboration_review.v1
repeatable: false
exact_slot_count: 7
branch_count: 7Cards alone do not open the entry event or review. A raw count of agreeing sources, fixed time, dashboard state, or lens status cannot substitute for the intake and collision chain.
Exactly seven review branches
branches:
commission_distinct_origin_capture:
lineage_state_after: distinct_origin_capture_commissioned
future_effect: distinct_origin_capture_required_before_clean_corroboration
disclose_common_source:
lineage_state_after: common_source_disclosed
future_effect: corroboration_weight_capped_at_one
counter_delta: corroborationWeightReduction:+5
split_by_authority:
lineage_state_after: authority_scopes_split
future_effect: reader_specific_proof_required
reopen_root_capture:
lineage_state_after: root_capture_reopened
future_effect: root_capture_required_before_route_unlock
quarantine_memorial_voice_use:
lineage_state_after: memorial_voice_quarantined
future_effect: memorial_voice_use_blocked_pending_lineage
publish_lineage_notice:
lineage_state_after: lineage_notice_published
future_effect: public_lineage_addendum_required
false_independent_corroboration:
lineage_state_after: false_independent_corroboration_pending
future_effect: self_corroborating_broadcast_default_pendingEach branch must change at least one relief surface, one cost surface, and one future route/readership surface. The first six are constructive but scoped; none can create universal proof. Only false_independent_corroboration may arm the default.
Harmful branch and exact pending gate
harmful_branch: false_independent_corroboration
pending_triple:
common_source_corroboration.default_pending: true
event.self_corroborating_broadcast_default.armed: true
future_route.self_corroborating_broadcast_default_pending: true
aired_flag:
broadcast_reality.false_independent_corroboration_aired: trueThe default is unreachable if any member of the triple is missing, the aired flag is false, the review remains unresolved, or any of the first six branches was selected.
Exactly three default terminals
default_terminals:
record_circular_proof_scar:
lineage_state_after: circular_proof_scar_recorded
future_effect: future_routes_require_distinct_lineage_roots
force_root_source_reaudit:
lineage_state_after: root_source_reaudit_required
future_effect: root_source_reaudit_required_before_memorial_or_archive_use
freeze_derived_route_assets:
lineage_state_after: derived_route_assets_frozen
future_effect: derived_route_assets_recovery_only_until_lineage_rebuilt
default_event_metadata:
circularFamilyCountAfterFalseBroadcast: 1Every terminal clears the pending triple and aired flag, resolves the event, preserves a false-multiplicity scar, and sets exactly one terminal state with its matching future effect. The event cannot retrigger.
Counter contract
Each review branch and default terminal must record at least three durable movements:
counter_deltas_required:
relief: at_least_one
cost: at_least_one
future_reader_or_route_effect: at_least_one
accepted_surfaces:
- proof_lineage_legibility
- independent_root_integrity
- corroboration_weight_reduction
- archive_debt
- memorial_voice_exposure
- public_lineage_distrust
- correction_duty
- route_delay
- reality_drift
- derived_route_asset_pressure
- recovery_only_pressureReachability contract
All seven branches share the same eligible post-collision state. Checks must reject:
- intake with a missing, wrong, or unheld card;
- intake with no selected option;
- entry before intake or without all seven exact cards;
- review before the entry event;
- review with a missing collision flag, wrong slot, absent card, or no choice;
- a second review resolution;
- default resolution before the harmful branch;
- default resolution with an incomplete pending triple or missing aired flag;
- a second default terminal.
Because review is nonrepeatable, one selected branch makes the other six missable for the incident. Because default is once-only, one terminal makes the other two missable.
Authority boundary
This mechanic tracks lineage roots and derivative relationships only. It requires distinct roots for independent corroboration and preserves inspection, editor, archive, memorial, public, and carrier scopes. It grants no underlying event truth, independent corroboration without distinct roots, universal inspector all-clear, editor source truth, archive pre-intake origin, memorial-voice consent, voice custody, route-asset content truth, public-clip independent witness status, sponsor immunity, or universal broadcast authority.
It may preserve a derivative as valid within inspection, editor, archive, memorial, public, or carrier scope while still capping the family at one independent root.
Integration boundaries
- Copy custody may be handled by Broadcast Asset Provenance Afterlife, but copy ownership cannot increase root count.
- A contradiction after air may open Broadcast Reality Drift Audit, but common-source agreement does not require a contradiction.
- A custody reader may open Custody Oracle Crossread, but selected oracle authority does not establish independent lineage.
- A conflicted reader may open Reader Recusal Record, but recusal does not repair dependent evidence.
- Fragment scope remains with Recap Syndication Drift, while this mechanic tests root independence even for complete derivatives.
- Witness disagreement remains with Operator Witness Conclave, while this mechanic can fire when every row agrees.
- Reader incompatibility remains with Ruling Reader Collision, while this mechanic audits many apparent sources for one claim.
- Board presentation remains with Proof Board Snapshot Custody, while this mechanic can fail on a complete and accurate board.
Replay evidence shape
lens_id: storyteller.lens.common_source_corroboration_audit.v1
replay: lens/replays/common-source-corroboration-audit.false-multiplicity-default.replay.json
required_actions_in_order:
- create_storyteller_lens_scoped_session
- resolve_common_source_corroboration_intake
- resolve_proof_lineage_collision
- resolve_false_independent_corroboration_review_branch
- resolve_one_self_corroborating_broadcast_default_terminal
required_final_evidence:
integrity_verified: true
session_seed_present: true
all_seven_cards_identified: true
source_family_schema_present: true
harmful_branch_visible: true
pending_triple_cleared: true
aired_flag_cleared: true
false_multiplicity_scar_visible: true
exactly_one_terminal_state: true
matching_future_effect_visible: true