Emergency Power Priority / 应急供电优先机制

Emergency Power Priority is the mechanism that turns blackout risk from an abstract result into a finite physical resource problem.

Storyteller already has strong surfaces for broadcast capacity, facility access, route assets, call sheets, oxygen liability, and blackout scars. This mechanism fills the missing execution layer between them: when the Seventh Dome has only enough emergency power for some surfaces, the game must ask what stays powered, what is shed, who files that decision, and which future route reads the scar.

Its observed objects are 应急供电账本, 应急供电优先分配, and 供电削减默认.

Design promise

A black screen is not only a schedule failure. It may be caused by a board cut, a stage blackout, a relay trip, a door lock, a cold-chain freezer drawing reserve, a ward oxygen pump, a fan-gate crowd feed, or a sponsor-metered glamour load.

When more than one powered surface claims finite emergency power, the implementation must show:

  • a named power source;
  • a safe load threshold or equivalent load state;
  • at least two competing powered surfaces;
  • priority claimants and consequences for the losing surface;
  • a player assignment that can certify, shed, split, borrow, narrow, hold, overdraw, or default;
  • durable deltas and a future reader.

The mechanism fails if “power” becomes a generic cost, if sponsor money makes load infinite, if the losing surface is hidden, or if blackout is only a prose consequence.

Executable contract

The runtime implementation is one-shot and consumes exactly nine cards in this slot order: ledger, power_source, protected_surface, shed_surface, priority_claim, handler, support, future_reader, and default_risk. Each accepts its corresponding storyteller.card.emergency_power_* card, with ledger fixed to storyteller.card.emergency_power_ledger.v1; every assignment must be present in hand.

The allocation rite has exactly eight branch/state/future mappings:

branch_state_future:
  certify_priority: priority_certified -> power_priority_certificate_required
  load_shed: deliberate_load_shed -> shed_surface_recovery_required
  split_power: split_power_degraded -> degraded_power_reader_required
  borrow_generator: borrowed_power_claim_attached -> generator_claim_maturity_due
  narrow_slot: low_power_slot_narrowed -> slot_contract_reads_power_scope
  public_safety_hold: public_safety_hold_visible -> public_or_lawful_power_notice_required
  overdraw_anyway: overdraw_default_pending -> hidden_trip_recovery_pending
  default_selects: priority_default_pending -> default_actor_power_disposition_pending

Only choice indexes 6 and 7 set emergency_power.default_pending, event.power_shed_default.armed, future_route.power_shed_recovery_pending, and power_reality.false_clean_all_powered_claimed. The other six choices clear those flags. Skip or underfill leaves the mechanism unresolved; it does not auto-default.

The event has exactly eight terminal/state/future mappings: governor_trip -> governor_load_trip -> tripped_surface_recovery_only; sponsor_meter_capture -> sponsor_glamour_priority -> oxygen_or_public_power_restitution_required; security_grid_lock -> security_route_lock -> facility_access_recovery_required; ward_reserve_priority -> oxygen_preserved_slot_shed -> narrowed_broadcast_reader_required; archive_freezer_priority -> archive_cold_chain_preserved -> lost_live_surface_addendum_required; blackout_fold -> blackout_fold_recovery_only -> blackout_recovery_route_required; public_queue_priority -> public_feed_priority -> lawful_or_archive_delay_reader_required; and borrowed_source_claim -> lender_power_claim_attached -> generator_claim_maturity_reader_required.

Recovery consumes the terminal result downstream and never reopens the one-shot allocation rite.

State-triggered entry

Open this mechanism when all are true:

  1. a crisis depends on finite electricity, lighting, relay, oxygen support, archive cold storage, security doors, proof scanning, cutroom access, fan-gate feed, or equivalent powered surface;
  2. at least two powered surfaces cannot all remain cleanly powered from the same source;
  3. a player assignment can change which surface is protected and which surface becomes shed, degraded, delayed, public-only, lawful-only, sponsor-only, recovery-only, or blocked;
  4. a fully assigned rite can explicitly choose overdraw_anyway or default_selects, allowing the event to expose a default actor;
  5. at least one future route, slot, custody object, public receipt, proof route, or route asset reads the outcome;
  6. no trigger depends on fixed turn count, day interval, chapter quota, dashboard health, or raw page count.

Core object model

emergency_power_priority_state:
  trigger_kind: state_pressure
  source_incident_id: <blackout_capacity_facility_or_slot_id>
  power_source:
    id: <generator_battery_grid_bridge_route_asset_or_absence>
    state: stable | strained | seized | sponsor_metered | public_only | lawful_only | borrowed | failing | hidden | explicit_absence
    safe_load_units: <number_or_named_threshold>
    overdraw_consequence: blackout_fold | oxygen_drop | door_lock | archive_freeze | board_misair | crew_hazard | equivalent
  powered_surfaces:
    - surface: live_board | stage_lights | relay | oxygen_pumps | ward_air | archive_cabinet | security_doors | fan_gate | cutroom | corridor_lights | proof_scanner | equivalent
      claimant: producer | sponsor | fan_public | inspector | archive | security | crew | route_asset | claimant | explicit_absence
      load_units: <number_or_named_weight>
      priority_claim: contract | safety | public_receipt | lawful_proof | sponsor_clause | route_escape | archive_seal | explicit_absence
      consequence_if_shed: <route_effect_or_state>
  default_actor: generator_governor | sponsor_meter | security_grid | ward_reserve | archive_freezer | blackout_system | public_queue | borrowed_source_claimant | equivalent
  future_reader_or_route: <reader route slot custody object public receipt or route asset>

Transition rules

1. A powered surface cannot be silently shed

If a surface loses power, the ledger must name it and record its future state. Accepted losing states include delayed, degraded, recovery_only, public_only, lawful_only, sponsor_only, blocked, blackout_folded, or equivalent.

2. A protected surface must carry priority evidence

A protected surface must have a claim: safety, lawful proof, public notice, archive integrity, route escape, sponsor clause, contract row, oxygen support, or explicit emergency discretion. If the implementation cannot name the claim, the rite remains unavailable or unresolved; the runtime does not silently arm a default.

3. Borrowed power attaches a claimant

Borrowing a generator, battery, sponsor meter, security backup, ward reserve, fan relay, pirate relay, or route-asset power is allowed only if a claimant, price, maturity, release condition, or future reader is recorded.

4. Narrowing a slot is a valid power solution, not a clean airing

The player may lower power draw by rewriting the slot: audio-only, low-light, no live cutroom, no gate feed, no stage glamour, no proof scanner, or equivalent. The narrowed slot must be read by schedule, sponsor, public, lawful, or route-asset surfaces later.

5. Overdraw is a branch, not a success state

The player can choose to overdraw to preserve immediate spectacle or timing. That branch must arm hidden trip, oxygen drop, archive freeze, crew hazard, door lock, board misair, or blackout fold. It cannot resolve as clean all powered.

6. Capacity liability and facility access consume the power state

The resulting power state must be readable by at least one existing surface: 播出容量责任级联机制, 设施通行图机制, 直播现场班组负荷机制, 路线资产维护分诊机制, or equivalent.

Playable operations

应急供电优先分配 exposes these operations:

OperationImmediate reliefRequired scar
Certify priorityProtected surface stays poweredLosing surface named and future reader scoped
Load shedOverdraw and blackout risk fallShed surface delayed, degraded, or recovery-only
Split powerMultiple routes remain openReliability, clarity, safety, or legality worsens
Borrow generatorImmediate route poweredClaimant, price, maturity, capture, or wear attaches
Narrow slotSlot airs with lower drawSponsor, audience, schedule, or proof scar recorded
Public safety holdUnsafe loads held openlySponsor/schedule pressure and inspection heat rise
Overdraw anywayImmediate timing or glamour preservedHidden trip/default/recovery-only state armed
Default selectsPlayer explicitly accepts choice index 7 after full assignmentDefault actor disposition becomes pending

Default rule

供电削减默认 is reachable only after all nine exact cards resolve through choice index 6 or 7 and all four common pending flags are present. Missing assignments, hidden inputs, or a skipped review cannot reach it.

The default must mutate at least three surfaces: one relief/capture surface, one cost surface, and one future route or reader surface.

Counter and state contract

Every resolved branch must mutate at least three counters or durable states.

Primary counters:

  • power_reserve
  • power_overdraw_risk
  • blackout_risk
  • broadcast_reliability
  • oxygen_liability
  • schedule_pressure
  • sponsor_stop_loss_pressure
  • inspection_heat
  • crew_hazard
  • route_narrowness
  • archive_integrity
  • public_safety_legitimacy
  • future_claim_cost

Primary durable states:

  • emergency_power_warning_open
  • power_priority_certified
  • power_load_shed
  • power_split_degraded
  • borrowed_generator_claim
  • sponsor_meter_capture
  • ward_reserve_priority
  • archive_cold_chain_priority
  • stage_lights_narrowed
  • door_power_lock
  • proof_scanner_unpowered
  • power_overdraw_armed
  • blackout_fold_recovery_only

Replay evidence shape

mechanic_id: storyteller.mechanic.emergency_power_priority.v1
session_id: lens-emergency-power-priority-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  source_incident_id: <blackout_capacity_facility_or_slot_id>
  finite_power_source_present: true
  competing_powered_surfaces_min: 2
  future_reader_present: true
  no_fixed_turn_trigger: true
objects:
  ledger: storyteller.card.emergency_power_ledger.v1
  rite: storyteller.rite.emergency_power_priority_allocation.v1
branch_runs:
  resolved_branch:
    selected_branch: certify_priority | load_shed | split_power | borrow_generator | narrow_slot | public_safety_hold | overdraw_anyway | default_selects
    power_source: <source>
    protected_surface: <surface>
    shed_or_degraded_surface: <surface>
    priority_claim: <claim>
    future_route_effect: <effect>
    counter_deltas:
      relief: []
      cost: []
      future: []
  default_branch:
    event_seen_or_armed: storyteller.event.power_shed_default.v1
    selected_choice_index: 6 | 7
    terminal: governor_trip | sponsor_meter_capture | security_grid_lock | ward_reserve_priority | archive_freezer_priority | blackout_fold | public_queue_priority | borrowed_source_claim
    future_route_effect: <exact terminal future effect>
assertions:
  - finite_power_source_visible
  - competing_surfaces_visible
  - losing_surface_named
  - branch_has_priority_claim_handler_support_and_future_reader
  - borrowed_power_attaches_claimant_or_maturity
  - overdraw_is_not_clean_success
  - default_requires_four_pending_flags_and_exposes_eight_exact_terminals
  - no_fixed_turn_trigger

Failure cases

The mechanism fails if power is a generic budget number, if a generator has infinite load, if all surfaces remain cleanly powered, if a surface loses power without future consequence, if sponsor/security/archive/ward priority happens invisibly, if overdraw is not allowed to create later harm, or if no future route consumes the power state.

Local authority boundary

Every runtime and public object is source: storyteller, localAuthorityOnly: true, and may set only recordsFinitePowerPriorityOnly, preservesNamedSourceProtectedAndShedSurface, preservesDefaultActorAndFutureReader, and requiresVisibleLosingSurface true. It must keep grantsConsent, grantsLegalValidity, grantsWaiver, grantsSettlement, grantsRouteClearance, grantsArchiveRelease, grantsProofTruth, grantsSponsorAuthority, grantsFanAuthority, grantsInspectorAuthority, grantsEditorAuthority, grantsProducerLicense, grantsGeneratorOwnership, grantsInfinitePower, grantsCleanAllPoweredState, grantsFutureReuseAuthority, and grantsUniversalBroadcastAuthority false.

Non-goals