Counterparty Reliance Unwind / 相对方信赖撤回机制

Counterparty Reliance Unwind is the mechanism for the moment when a false-clean or overbroad authority has already induced action. A prior row may be narrowed, corrected, quarantined, or callback-bound, but the relying counterparty has already spent or moved something. This mechanism makes that reliance action visible, reversible only with cost, and consumable by future routes.

It composes with 播出合约回读线 and 回叫消费证明线 without duplicating them. Readback asks whether the old contract can be reused by the current reader. Callback consumption asks whether relief still carries an owed callback. This mechanism asks what happens after somebody acted on the false-clean presentation before the correction landed.

Core rule

A reliance action cannot become clean proof of the source authority.

A passing implementation must preserve all three facts at once:

  1. the source authority row still exists and keeps its own state;
  2. the counterparty’s reliance action already happened;
  3. future readers consume the cost, scope, hostility, escrow, or recovery state created by the reliance unwind.

First source-backed runtime producer

The general mechanism is currently instantiated by the Seat Map Annotation false-default chain:

first_runtime_producer:
  upstream_default: storyteller.event.false_seat_map_annotation_default.v1
  source_state: seat_map_annotation.state.false_clean_default
  source_future_effect: seat_map_annotation.future.recovery_only
  relying_counterparty: sponsor_recap_desk
  reliance_action_taken: scheduled_group_consent_recap
  sunk_surface: recap_slot_time
  harmed_or_displaced_reader: protected_caption_access_patron
  entry_event: storyteller.event.counterparty_reliance_discovered.v1
  ledger: storyteller.card.counterparty_reliance_ledger.v1
  rite: storyteller.rite.reliance_unwind_conference.v1
  default_event: storyteller.event.false_reliance_default.v1
  downstream_consumer: storyteller.card.recall_claim_priority_queue.v1

The sponsor desk’s schedule is evidence of reliance, never retroactive evidence of group consent. This producer exercises the reusable contract; it does not limit future producers to seat maps, sponsors, or recap slots.

Required state objects

Reliance ledger

相对方信赖账本 stores the row.

Minimum required fields:

counterparty_reliance_row_required:
  source_authority_row: <row id or explicit_absence>
  source_surface: audience_jury_seat_map_annotation_afteruse | broadcast_contract_readback | callback_consumption | sponsor_afteruse | recovery_indemnity | broadcast_signatory | asset_provenance | settlement_aftershock | equivalent
  clean_or_overbroad_claim: <claim>
  relying_counterparty: <counterparty>
  reliance_action_taken: <action already taken>
  sunk_surface: <money slot witness custody public trust worker claimant route asset license or equivalent>
  harmed_or_displaced_reader: <reader or explicit_absence>
  proof_bridge_or_absence: <proof bridge or explicit_absence>
  selected_unwind: honor_limited_reliance | reimburse_and_unwind | convert_to_scoped_license | escrow_reliance | clawback_with_notice | publish_reliance_debt | quarantine_reliance | false_reliance_default
  accepted_cost_surface_or_absence: <cost or explicit_absence>
  future_reader_effect: accepted_with_reliance_cost | public_only | lawful_only | sponsor_only | split_required | contradiction_pending | blocked | hostile | recovery_only | false_reliance_hardened | equivalent

The mechanism fails if the state object records reliance as only money, flavor anger, generic liability, or sponsor pressure.

Assignment rite

信赖撤回会 resolves the row through named assignments.

The rite must require:

  • source authority row;
  • clean or overbroad claim;
  • relying counterparty;
  • reliance action already taken;
  • sunk surface;
  • harmed or displaced reader;
  • handler or explicit absence;
  • proof bridge or explicit absence;
  • support or explicit absence;
  • selected unwind posture;
  • accepted cost surface;
  • future route or reader effect.

The current runtime enforces these as twelve exact in-hand slots: ledger, false-clean claim, relying counterparty, scheduled action, sunk recap slot, source floorplan, source seat-map docket, displaced patron row, Jao Min proof bridge, Jao Min handler, one branch posture bundle, and the Chapter Two future reader. The posture bundle itself carries the branch’s accepted cost and future-reader effect, so neither can be supplied by a mismatched generic card.

No famous handler, sponsor clause, archive stamp, lawful wording, edit checksum, public receipt, management urgency, or broadcast fact may replace those slots.

Default event

虚洁净信赖默认 fires or arms when the relying action is used to prove that the source authority was clean, or when the reliance action is hidden while future routes consume its benefit.

The default must name:

  • source authority;
  • relying counterparty;
  • reliance action;
  • sunk surface;
  • harmed or displaced reader;
  • false reliance claim;
  • default actor;
  • future effect.

State machine

state_machine:
  unopened:
    meaning: source authority has no reliance action yet or reliance action is not visible
  ledgered:
    meaning: source authority and relying action are both visible
  honored_limited:
    meaning: good-faith reliance is accepted only for named reader or surface
  reimbursed_unwound:
    meaning: reliance is reversed by spending named cost
  scoped_license:
    meaning: reliance becomes one-reader or one-route authority
  escrowed:
    meaning: reliance is preserved but cannot be cited as clean proof
  clawed_back_with_notice:
    meaning: reliance benefit is removed with notice or receipt
  debt_published:
    meaning: reliance cost is public, lawful, or archive-visible
  quarantined:
    meaning: reliance is too unsafe for current route use
  false_reliance_hardened:
    meaning: relying action became false proof of source authority
  hostile:
    meaning: counterparty or displaced reader contests future route
  recovery_only:
    meaning: source can be used only through scar-preserving recovery

Branch families

BranchReliefCostFuture effect
Honor limited reliancegood-faith counterparty does not instantly become enemyreader scope, public distrust, sponsor heat, archive debt, or route cost risesaccepted with cost, public-only, lawful-only, sponsor-only
Reimburse and unwindfalse-clean claim is lowered and custody/proof can recovermoney, license encumbrance, route delay, handler burdencostlier, accepted with cost, contradiction pending
Convert to scoped licensecurrent route can proceed with limited authoritysource ambiguity, correction pressure, reader splitpublic-only, lawful-only, sponsor-only, split-required
Escrow relianceunsafe clean reuse is blocked while trace is preservedroute delay, archive debt, inspection heatblocked, lawful-only, recovery-only
Clawback with noticeoverbroad benefit is removed visiblycounterparty hostility, sponsor pressure, public distrusthostile, contradiction-pending, recovery-only
Publish reliance debthidden cost becomes public/lawful/archive memorypublic confusion, sponsor pressure, inspection heataccepted with cost, split-required, contradiction-pending
Quarantine reliancefraud, worker exposure, or false route ownership is reducedcurrent route blocks, recovery cost, counterparty hostilityblocked, recovery-only
False reliance defaultimmediate pressure may dropfalse reliance hardens and displaced reader hostility risesfalse-reliance-hardened, hostile, blocked, recovery-only

No branch may produce universal clean authority across public, lawful, sponsor, archive, worker, claimant, route asset, management, and broadcast-reality readers.

Source integration

Seat Map Annotation false default

座位图批注后用回执线 is the first runtime producer. Its false default preserves the real jury floorplan and protected patron row while arming a later discovery: the sponsor recap desk has already scheduled a group-consent recap on the false-clean seat map. The recap slot is sunk; the caption-access patron reader is displaced; the seat-map error remains false.

Recall claim priority

召回认领优先级线 is the first named downstream consumer. Its queue already accepts storyteller.card.counterparty_reliance_ledger.v1 as a callable source. That handoff makes the unwind result determine which sponsor, protected-patron, public, or lawful claim can consume the constrained recap surface first.

Broadcast contract readback

When 播出合约回读线 narrows or blocks a prior contract row after a later party already scheduled, paid, aired, released, or accepted custody, this mechanism creates a reliance ledger. The source readback remains true; the reliance action becomes the new pressure.

Callback consumption proof

When 回叫消费证明线 reveals that a relief row still owed a callback after a future counterparty consumed it, this mechanism records the spend or custody move caused by the clean relief presentation. The owed callback is not erased by reimbursement or license conversion.

Recovery indemnity shelf

When 复原追偿搁架线 assigns or refuses a future recourse holder after a counterparty relied on clean shelter, this mechanism decides whether the reliance is honored, unwound, scoped, escrowed, clawed back, published, quarantined, or defaulted.

Ruling reader collision

When 裁定读者冲突线 proves that readers are incompatible, this mechanism handles the party that already acted before the incompatibility was recognized. Reader collision decides recognition; reliance unwind decides sunk reliance.

False-service claimant escalation

When 误服裁定认领升级线 creates a concrete claimant row, this mechanism can make sponsor, management, archive, or public reliance on the false service into a debt that the claimant consumes.

Counter contract

Every resolution or default must mutate at least three surfaces:

counter_deltas_required:
  relief: at_least_one
  cost: at_least_one
  future_reader_or_route_effect: at_least_one

Primary surfaces:

  • counterparty_reliance_pressure
  • false_reliance_hardened
  • reliance_legibility
  • counterparty_hostility
  • sunk_reliance_cost
  • displaced_reader_hostility
  • reader_scope_narrowing
  • source_ambiguity
  • public_receipt_distrust
  • sponsor_stop_loss_pressure
  • archive_debt
  • inspection_heat
  • producer_license_encumbrance
  • route_delay
  • route_asset_false_owner
  • worker_exposure
  • claimant_burden
  • broadcast_reality_drift
  • future_route_acceptance

Replay evidence shape

The first runtime pair is expected at:

  • lens/replays/counterparty-reliance-unwind.reimburse.replay.json;
  • lens/replays/counterparty-reliance-unwind.false-default.replay.json.
mechanic: storyteller.mechanic.counterparty_reliance_unwind.v1
session_id: lens-counterparty-reliance-unwind-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  source_authority_row_present: true
  clean_or_overbroad_claim_present: true
  relying_counterparty_present: true
  reliance_action_already_taken: true
  sunk_surface_visible: true
  no_fixed_turn_trigger: true
offered:
  card: storyteller.card.counterparty_reliance_ledger.v1
  rite: storyteller.rite.reliance_unwind_conference.v1
branch_runs:
  constructive_branch:
    selected_unwind: honor_limited_reliance | reimburse_and_unwind | convert_to_scoped_license | escrow_reliance | clawback_with_notice | publish_reliance_debt | quarantine_reliance
    ledger_state_after: <state>
    relying_counterparty_state_after: <state>
    displaced_reader_state_after: <state>
    future_reader_effect: <effect>
    counter_deltas: {}
  default_branch:
    selected_unwind: false_reliance_default
    event_seen_or_armed: storyteller.event.false_reliance_default.v1
    false_reliance_claim: <claim>
    future_reader_effect: <effect>
    counter_deltas: {}
downstream_read:
  reader: public | lawful_reader | sponsor | archive | claimant | worker | route_asset | management | broadcast_reality | equivalent
  consumed_state: <ledger state>
  route_effect_after_read: <effect>
assertions:
  - entry_is_state_triggered
  - source_authority_preserved
  - reliance_action_already_taken_visible
  - sunk_surface_visible
  - displaced_reader_visible_or_explicit_absence
  - branches_diverge
  - every_success_has_cost
  - false_reliance_default_names_actor_and_claim
  - downstream_reader_consumes_reliance_state
  - no_universal_clean_authority
  - no_fixed_turn_trigger

Non-goals

  • Not a new verdict.
  • Not a generic indemnity or settlement system.
  • Not a substitute for readback, callback, reader collision, or claimant intake.
  • Not a timer.
  • Not valid if the reliance action has not already changed state.
  • Not valid if the future route does not read the resulting reliance state.