Missing Roll-Call Reconciliation / 漏点名复核机制

Missing Roll-Call Reconciliation is the mechanism that prevents a prior movement, notice, payroll, caption, promise, or custody receipt from silently becoming universal proof that everyone is safely accounted for.

It binds 漏点名账本, 漏点名复核, and 漏点名默认.

Design promise

The mesh is now strong at creating receipts: egress receipts, capacity notices, caption witness records, protected witness payroll rows, private promise boundaries, route asset custody, and fan oxygen releases. The weakest surface is the second-order check: the receipt says the subject moved, but the future reader asks whether the same subject is present, identified, lawfully/publicly vouched, and safe enough to consume.

This mechanism makes roll-call a playable state pressure rather than an epilogue text box.

State-triggered entry

Open only when a concrete contradiction exists.

entry_state_required:
  trigger_kind: state_pressure
  prior_receipt_any:
    - live_floor_egress
    - capacity_notice_service
    - caption_witness_custody
    - protected_witness_payroll
    - confidant_promise
    - fan_oxygen
    - route_asset_custody
    - broadcast_reality
  receipt_claims_presence_or_safety: true
  later_reader_contradicts_receipt: true
  expected_subject_visible: true
  identity_or_seal_visible_or_explicit_absence: true
  protection_scope_visible_or_explicit_absence: true
  condition_visible_or_explicit_absence: true
  future_reader_or_route_consumes_roll_call_state: true
  player_response_available: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_missing_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

The mechanism fails if entry comes from a fixed emergency phase, fixed turn number, day/week cadence, raw attendance count, raw missing count, chapter quota, dashboard state, or lens health.

Core object model

missing_roll_call_state:
  trigger_kind: state_pressure
  source_receipt:
    source_surface: live_floor_egress | capacity_notice_service | caption_witness_custody | protected_witness_payroll | confidant_promise | fan_oxygen | route_asset_custody | broadcast_reality | equivalent
    receipt_id_or_absence: <receipt id or explicit_absence>
    receipt_claim: safe_exit | served_notice | payroll_checked_in | witness_delivered | source_anonymized | route_asset_escorted | oxygen_queue_released | performer_withdrawn | equivalent
    receipt_holder: producer | safety_marshal | access_operator | archive | inspector | fan_delegate | handler | sponsor | editor | equivalent
  expected_subject:
    subject_kind: named_character | sealed_witness | performer_body | fan_delegate | access_caption_reader | child_voice_source | proof_bundle | route_asset | crew_member | equivalent
    expected_identity_or_seal: <name seal alias or explicit_absence>
    expected_location_or_state: ward_air_room | fan_oxygen_gate | archive_counter | caption_table | cutroom_blackbox | stage_threshold | public_table | protected_payroll | route_asset_slot | equivalent
    protection_scope_or_absence: public_name_allowed | sealed_name_only | anonymous_public | lawful_only | private_only | handler_only | route_asset_only | explicit_absence | equivalent
  conflict_reader:
    reader: fan_public | access_caption_class | archive | inspector | sponsor | handler | protected_witness_payroll | route_asset_reader | broadcast_reality | lawful_table | equivalent
    contradiction: receipt_says_present_reader_says_absent | receipt_says_safe_condition_unsafe | identity_alias_unrecognized | duplicate_presence | false_missing | substituted_body | custody_gap | protection_scope_conflict | equivalent
    consequence_if_unreconciled: witness_exposed | fan_panic | access_class_escalation | archive_fraud | sponsor_capture | route_blocked | proof_contaminated | character_missed | recovery_only | equivalent
  default_narrator: safety_marshal_log | archive_counter | fan_public_roll_call | sponsor_manifest | broadcast_reality_echo | handler_shortcut | route_asset_reader | crowd_memory | equivalent
  future_reader_or_route: <future consumer>

Transition rules

1. Presence is not identity

A subject may be physically present while the expected sealed identity is missing. A public body count, sponsor manifest, oxygen line, or safety log cannot substitute for a witness seal, private promise row, caption reader name, or route asset condition.

2. Identity is not custody

A named or sealed identity may be found without a valid future reader. If the archive, access class, fan public, payroll, route asset reader, or lawful table will consume the row later, the rite must produce a receipt-after or explicit absence.

3. Custody is not condition

A witness, performer, proof bundle, or route asset can arrive under custody while exposed, hostile, injured, substituted, contaminated, or recovery-only. The condition must be stored separately from the arrival receipt.

4. Sealed identity has a cost

Protecting a sealed witness, child-voice source, private confidant, or route secret can clear roll-call only by accepting public distrust, lawful-only presence, notice burden, handler burden, or future route cost. It cannot also satisfy every public and sponsor reader cleanly.

5. Public roll-call is powerful but dangerous

Public names can clear false missing states or locate bodies, but public roll-call can breach private promise, expose protected witnesses, trigger reprisal, or make broadcast reality harden the wrong identity.

6. Route assets cannot swallow people

If a route asset arrives but its human carrier, source, performer body, or sealed witness does not reconcile, the asset must become quarantined, contested, costlier, or recovery-only. Asset custody cannot erase human roll-call.

7. Default accounting mutates future play

If the player hides the contradiction, the default narrator marks someone present or absent by shortcut. That shortcut must create false all-clear, false missing, exposed identity, lawful-only presence, sponsor-only accounting, aired duplicate, route quarantine, hostile witness, character unavailable, or recovery-only state.

Playable operations

漏点名复核 exposes these operations:

OperationImmediate reliefRequired scar
Physical searchverifies presence and conditiondelay, hazard, public anxiety, or broadcast pressure
Sealed identity matchpreserves protected identity while counting the subjectlawful-only/public distrust/handler burden
Public roll-callclears false missing or locates a bodyexposure, panic, reprisal, promise breach
Lawful quiet checkvalidates without public namingpublic distrust, access pressure, lawful heat
Substitute receiptlets earlier receipt stand in temporarilyambiguity and contradiction pending
Route asset quarantineblocks contaminated consumptionroute blocked, sponsor pressure, archive burden
Accept absence scarrefuses false all-clearpanic, ending scar, recovery-only path
False all-clear defaultfastest narrator accounts everyonehidden harm hardens through default event

Counter and state contract

Every constructive branch must produce relief, cost, and future mutation.

Primary counters:

  • roll_call_conflict_pressure
  • search_delay
  • witness_exposure_risk
  • fan_oxygen_resentment
  • access_caption_pressure
  • archive_fraud_risk
  • sponsor_stop_loss_pressure
  • handler_burden
  • route_asset_pressure
  • broadcast_reality_scar
  • public_safety_legitimacy

Primary durable states:

  • missing_roll_call_open
  • false_missing_cleared
  • false_all_clear_blocked
  • sealed_identity_present
  • lawful_only_presence
  • public_roll_call_receipt_required
  • substitute_receipt_contested
  • route_asset_quarantined
  • identity_alias_contested
  • witness_hostile
  • character_unavailable
  • recovery_only

Replay evidence shape

mechanic_id: storyteller.mechanic.missing_roll_call_reconciliation.v1
session_id: lens-missing-roll-call-reconciliation-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  prior_receipt_claims_presence_or_safety: true
  later_reader_contradicts_receipt: true
  expected_subject_visible: true
  identity_or_seal_visible_or_explicit_absence: true
  protection_scope_visible_or_explicit_absence: true
  future_reader_or_route_consumes_roll_call_state: true
  no_fixed_turn_trigger: true
objects:
  card: storyteller.card.missing_roll_call_ledger.v1
  rite: storyteller.rite.missing_roll_call_reconciliation.v1
branch_runs:
  resolved_branch:
    selected_posture: physical_search | sealed_identity_match | public_roll_call | lawful_quiet_check | substitute_receipt | route_asset_quarantine | accept_absence_scar
    expected_subject: <subject>
    conflict_reader: <reader>
    support_or_absence: <support>
    receipt_after_or_absence: <receipt or explicit_absence>
    condition_after: <condition>
    future_reader_effect: <effect>
    counter_deltas:
      relief: []
      cost: []
      future: []
  default_branch:
    event_seen_or_armed: storyteller.event.missing_roll_call_default.v1
    default_narrator: <narrator>
    default_accounting_rule: <rule>
assertions:
  - entry_is_state_triggered
  - prior_receipt_and_later_reader_visible
  - expected_subject_identity_scope_and_condition_are_separate
  - selected_posture_has_support_receipt_and_future_reader
  - no_universal_all_clear
  - default_mutates_future_play
  - no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_trigger

Non-goals

  • Not a generic attendance check.
  • Not a death counter.
  • Not a hidden safety audit.
  • Not a replacement for egress, access captions, witness payroll, private promise, fan oxygen, or route asset custody.
  • Not valid unless the earlier receipt, challenged subject, conflict reader, selected posture, relief/cost/future deltas, and future consumer are all observable.