Missing Roll-Call Reconciliation / 漏点名复核机制
Missing Roll-Call Reconciliation is the mechanism that prevents a prior movement, notice, payroll, caption, promise, or custody receipt from silently becoming universal proof that everyone is safely accounted for.
It binds 漏点名账本, 漏点名复核, and 漏点名默认.
Design promise
The mesh is now strong at creating receipts: egress receipts, capacity notices, caption witness records, protected witness payroll rows, private promise boundaries, route asset custody, and fan oxygen releases. The weakest surface is the second-order check: the receipt says the subject moved, but the future reader asks whether the same subject is present, identified, lawfully/publicly vouched, and safe enough to consume.
This mechanism makes roll-call a playable state pressure rather than an epilogue text box.
State-triggered entry
Open only when a concrete contradiction exists.
entry_state_required:
trigger_kind: state_pressure
prior_receipt_any:
- live_floor_egress
- capacity_notice_service
- caption_witness_custody
- protected_witness_payroll
- confidant_promise
- fan_oxygen
- route_asset_custody
- broadcast_reality
receipt_claims_presence_or_safety: true
later_reader_contradicts_receipt: true
expected_subject_visible: true
identity_or_seal_visible_or_explicit_absence: true
protection_scope_visible_or_explicit_absence: true
condition_visible_or_explicit_absence: true
future_reader_or_route_consumes_roll_call_state: true
player_response_available: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_missing_count_trigger: true
no_dashboard_or_lens_health_trigger: trueThe mechanism fails if entry comes from a fixed emergency phase, fixed turn number, day/week cadence, raw attendance count, raw missing count, chapter quota, dashboard state, or lens health.
Core object model
missing_roll_call_state:
trigger_kind: state_pressure
source_receipt:
source_surface: live_floor_egress | capacity_notice_service | caption_witness_custody | protected_witness_payroll | confidant_promise | fan_oxygen | route_asset_custody | broadcast_reality | equivalent
receipt_id_or_absence: <receipt id or explicit_absence>
receipt_claim: safe_exit | served_notice | payroll_checked_in | witness_delivered | source_anonymized | route_asset_escorted | oxygen_queue_released | performer_withdrawn | equivalent
receipt_holder: producer | safety_marshal | access_operator | archive | inspector | fan_delegate | handler | sponsor | editor | equivalent
expected_subject:
subject_kind: named_character | sealed_witness | performer_body | fan_delegate | access_caption_reader | child_voice_source | proof_bundle | route_asset | crew_member | equivalent
expected_identity_or_seal: <name seal alias or explicit_absence>
expected_location_or_state: ward_air_room | fan_oxygen_gate | archive_counter | caption_table | cutroom_blackbox | stage_threshold | public_table | protected_payroll | route_asset_slot | equivalent
protection_scope_or_absence: public_name_allowed | sealed_name_only | anonymous_public | lawful_only | private_only | handler_only | route_asset_only | explicit_absence | equivalent
conflict_reader:
reader: fan_public | access_caption_class | archive | inspector | sponsor | handler | protected_witness_payroll | route_asset_reader | broadcast_reality | lawful_table | equivalent
contradiction: receipt_says_present_reader_says_absent | receipt_says_safe_condition_unsafe | identity_alias_unrecognized | duplicate_presence | false_missing | substituted_body | custody_gap | protection_scope_conflict | equivalent
consequence_if_unreconciled: witness_exposed | fan_panic | access_class_escalation | archive_fraud | sponsor_capture | route_blocked | proof_contaminated | character_missed | recovery_only | equivalent
default_narrator: safety_marshal_log | archive_counter | fan_public_roll_call | sponsor_manifest | broadcast_reality_echo | handler_shortcut | route_asset_reader | crowd_memory | equivalent
future_reader_or_route: <future consumer>Transition rules
1. Presence is not identity
A subject may be physically present while the expected sealed identity is missing. A public body count, sponsor manifest, oxygen line, or safety log cannot substitute for a witness seal, private promise row, caption reader name, or route asset condition.
2. Identity is not custody
A named or sealed identity may be found without a valid future reader. If the archive, access class, fan public, payroll, route asset reader, or lawful table will consume the row later, the rite must produce a receipt-after or explicit absence.
3. Custody is not condition
A witness, performer, proof bundle, or route asset can arrive under custody while exposed, hostile, injured, substituted, contaminated, or recovery-only. The condition must be stored separately from the arrival receipt.
4. Sealed identity has a cost
Protecting a sealed witness, child-voice source, private confidant, or route secret can clear roll-call only by accepting public distrust, lawful-only presence, notice burden, handler burden, or future route cost. It cannot also satisfy every public and sponsor reader cleanly.
5. Public roll-call is powerful but dangerous
Public names can clear false missing states or locate bodies, but public roll-call can breach private promise, expose protected witnesses, trigger reprisal, or make broadcast reality harden the wrong identity.
6. Route assets cannot swallow people
If a route asset arrives but its human carrier, source, performer body, or sealed witness does not reconcile, the asset must become quarantined, contested, costlier, or recovery-only. Asset custody cannot erase human roll-call.
7. Default accounting mutates future play
If the player hides the contradiction, the default narrator marks someone present or absent by shortcut. That shortcut must create false all-clear, false missing, exposed identity, lawful-only presence, sponsor-only accounting, aired duplicate, route quarantine, hostile witness, character unavailable, or recovery-only state.
Playable operations
漏点名复核 exposes these operations:
| Operation | Immediate relief | Required scar |
|---|---|---|
| Physical search | verifies presence and condition | delay, hazard, public anxiety, or broadcast pressure |
| Sealed identity match | preserves protected identity while counting the subject | lawful-only/public distrust/handler burden |
| Public roll-call | clears false missing or locates a body | exposure, panic, reprisal, promise breach |
| Lawful quiet check | validates without public naming | public distrust, access pressure, lawful heat |
| Substitute receipt | lets earlier receipt stand in temporarily | ambiguity and contradiction pending |
| Route asset quarantine | blocks contaminated consumption | route blocked, sponsor pressure, archive burden |
| Accept absence scar | refuses false all-clear | panic, ending scar, recovery-only path |
| False all-clear default | fastest narrator accounts everyone | hidden harm hardens through default event |
Counter and state contract
Every constructive branch must produce relief, cost, and future mutation.
Primary counters:
roll_call_conflict_pressuresearch_delaywitness_exposure_riskfan_oxygen_resentmentaccess_caption_pressurearchive_fraud_risksponsor_stop_loss_pressurehandler_burdenroute_asset_pressurebroadcast_reality_scarpublic_safety_legitimacy
Primary durable states:
missing_roll_call_openfalse_missing_clearedfalse_all_clear_blockedsealed_identity_presentlawful_only_presencepublic_roll_call_receipt_requiredsubstitute_receipt_contestedroute_asset_quarantinedidentity_alias_contestedwitness_hostilecharacter_unavailablerecovery_only
Replay evidence shape
mechanic_id: storyteller.mechanic.missing_roll_call_reconciliation.v1
session_id: lens-missing-roll-call-reconciliation-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
trigger_kind: state_pressure
prior_receipt_claims_presence_or_safety: true
later_reader_contradicts_receipt: true
expected_subject_visible: true
identity_or_seal_visible_or_explicit_absence: true
protection_scope_visible_or_explicit_absence: true
future_reader_or_route_consumes_roll_call_state: true
no_fixed_turn_trigger: true
objects:
card: storyteller.card.missing_roll_call_ledger.v1
rite: storyteller.rite.missing_roll_call_reconciliation.v1
branch_runs:
resolved_branch:
selected_posture: physical_search | sealed_identity_match | public_roll_call | lawful_quiet_check | substitute_receipt | route_asset_quarantine | accept_absence_scar
expected_subject: <subject>
conflict_reader: <reader>
support_or_absence: <support>
receipt_after_or_absence: <receipt or explicit_absence>
condition_after: <condition>
future_reader_effect: <effect>
counter_deltas:
relief: []
cost: []
future: []
default_branch:
event_seen_or_armed: storyteller.event.missing_roll_call_default.v1
default_narrator: <narrator>
default_accounting_rule: <rule>
assertions:
- entry_is_state_triggered
- prior_receipt_and_later_reader_visible
- expected_subject_identity_scope_and_condition_are_separate
- selected_posture_has_support_receipt_and_future_reader
- no_universal_all_clear
- default_mutates_future_play
- no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_triggerNon-goals
- Not a generic attendance check.
- Not a death counter.
- Not a hidden safety audit.
- Not a replacement for egress, access captions, witness payroll, private promise, fan oxygen, or route asset custody.
- Not valid unless the earlier receipt, challenged subject, conflict reader, selected posture, relief/cost/future deltas, and future consumer are all observable.