Post-Credit Proxy Alias Readback
This mechanism prevents a future reader from treating canonical post-credit proxy evidence and runtime proxy receipt evidence as cleanly identical, cleanly separate, or silently migrated without preserving the alias basis.
It activates only when both sides are visible enough to be consumed by play:
- the canonical proxy docket or default;
- the runtime proxy receipt docket or false-proxy default;
- the future reader trying to cite one or both rows;
- the proxy actor and proxied subject, estate, or route asset;
- the harmed reader or explicit absence;
- the alias basis or explicit absence.
State Model
proxy_alias_state:
unseen: alias pair has not reached future play
candidate_alias: canonical and runtime rows may describe the same authority
candidate_divergence: rows may describe different readers, scopes, or sessions
bound_with_provenance: rows are linked by source receipt and future scope
split_required: readers must consume separate scoped rows
canonical_only: runtime alias is retired for future play
migrated_with_receipt: runtime row survives through explicit migration receipt
quarantined: no future reader may spend either row as clean alias proof
scarred_dual_record: both rows remain usable with visible scar and counterclaim
false_clean_alias: alias is spent clean without basis, split, scar, or migrationRequired Inputs
post_credit_proxy_alias_inputs:
canonical_proxy_docket: required
runtime_proxy_receipt_docket: required
canonical_default_event: required_or_explicit_absence
runtime_default_event: required_or_explicit_absence
alias_basis_or_absence: required
proxy_actor_or_absence: required
proxied_subject_or_estate: required
future_reader: required
harmed_or_excluded_reader: required
requested_alias_use: requiredResolution Branches
bind_alias_with_provenance: link canonical and runtime rows through source session, source docket, proxy actor, proxied subject, and future scope.split_alias_by_reader: keep both rows but require reader-specific citation rules.retire_runtime_alias: future readers must cite the canonical docket, and old runtime evidence needs migration proof.attach_migration_receipt: preserve runtime evidence with migration receipt, source session, and reader scope.quarantine_proxy_alias: block future use until provenance or split scope exists.accept_scarred_dual_record: allow both rows with visible scar, counterclaim, and reader-specific burden.false_clean_alias_default: spend the alias as clean equivalence or clean double authority without proof.
Counter Surfaces
Every review mutates at least three surfaces:
- relief:
reader_unblocked,archive_continuity,route_asset_continuity,migration_allowed, or equivalent; - cost:
alias_debt,provenance_heat,reader_hostility,migration_debt,route_asset_scar, or equivalent; - future effect:
provenance_required,reader_split_required,migration_required,route_asset_scar_required,blocked,hostile, orrecovery_only.
The mechanism fails if it only renames one object or writes dashboard text without changing future reader consumption.