Proof Wall Pinning Custody / 举证墙钉选羁押机制

Proof Wall Pinning Custody is the mechanism for the in-world surface where crisis proof becomes visible before it becomes accepted.

The current mesh already answers many adjacent questions:

The uncovered seam is visibility custody. A proof may be alive, scoped, rebuttable, compatible, and still become false when it is pinned to a reader-facing wall while another material proof is hidden. This mechanism makes the pin, owner, wall surface, omission, and future reader effect playable.

Primary design question

When a future reader is about to consume a proof surface, which proof is pinned, which proof is scoped or hidden, who owns the pin, and what future route state is created by that visibility?

Core objects

Proof wall

A proof wall is an in-world surface read by one or more readers. It can be:

  • public wall;
  • lawful wall;
  • sponsor brief;
  • archive pinboard;
  • artist-boundary slate;
  • route-loadout surface;
  • management-closure surface;
  • equivalent reader-facing proof surface.

It is not a task board, dashboard, or governance artifact.

Visible pin

The proof made visible for a named reader and scope. It carries proof kind, current state, pin owner, and scope claim.

Occluded proof

A relevant proof, receipt, counterline, boundary, recovery shelf, or explicit absence that is not visible on the wall but would change future acceptance if shown.

Pin owner

The actor, desk, route asset, public witness, archive, sponsor, editor, artist proxy, worker carrier, claimant, inspector, or explicit absence that controls the visible pin.

Future reader

The reader who consumes the wall state later: public/fan, lawful/archive, sponsor, artist-boundary, claimant, worker testimony, route asset, management, or equivalent.

Entry contract

Open this mechanism only through state pressure:

entry_state_required:
  trigger_kind: state_pressure
  wall_surface_present: true
  future_reader_present: true
  visible_pin_candidate_present_or_explicit_absence: true
  occluded_or_absent_proof_present: true
  pin_owner_or_explicit_absence_present: true
  reader_specific_scope_or_conflict_visible: true
  future_route_or_reader_consumes_wall_state: true
  player_can_pin_scope_rotate_split_mark_quarantine_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_proof_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

A wall may contain many proof rows, but raw number is never the trigger. The trigger is that visibility or occlusion would change a future reader’s acceptance, hostility, route cost, custody, or recovery state.

Bound content

  • 举证墙钉选案卷 records the visible pin, pin owner, omitted proof, harmed reader, wall state, and future effect.
  • 举证墙钉选复核 lets the player pin public, lawful, sponsor, artist-boundary, split, marked-unread, quarantine, or default surfaces.
  • 举证墙遮蔽默认 fires or arms when a reader consumes a false or underfilled wall.

State machine

StateMeaningGameplay obligation
unpinnedA proof wall exists but no reader-ready proof is pinned.Offer review or arm default if a reader consumes it.
pinnedA named proof is visible for a named reader.Scope, owner, and omitted proof are recorded.
scopedVisible proof is limited to a declared use.Other readers remain narrowed, hostile, or bridge-required.
rotatedAn older proof was moved behind a newer pin.Old proof remains recallable and scarred.
split_wallDifferent readers receive different surfaces.No universal clean proof exists.
marked_unreadProof is visible but not cleanly readable.Future bridge, annex, checksum, callback, or counterline is required.
quarantinedProof is blocked from consumption.False-front risk falls; route delay or recovery pressure rises.
false_frontWall appears clean while material proof is hidden.Default event can fire or arm.
default_occludedOmitted proof is erased by play.Hidden reader becomes hostile, captured, blocked, or recovery-only.

When a future reader tries to cite the old proof after rotated, Proof Wall Rotation Receipt must open or explicitly be impossible. The initial pinning review does not by itself make the old pin current proof.

Branch families

Pin public proof

Use when the game needs public receipt, fan legitimacy, public counterline, historian proof, or anti-capture visibility.

Relief:

  • private capture falls;
  • public receipt legitimacy rises;
  • occluded public harm becomes visible.

Cost:

  • sponsor pressure, witness exposure, public contradiction, or inspection heat rises.

Future effects:

  • public_only;
  • accepted_with_scope;
  • bridge_required;
  • contradiction_pending.

Pin lawful proof

Use when admissibility, archive chain, inspector stamp, or custody trace matters more than public readability.

Relief:

  • archive signature legitimacy and custody clarity improve;
  • false-front fraud drops.

Cost:

  • public delay, bureau favor debt, lawful-only routing, or fan distrust rises.

Future effects:

  • lawful_only;
  • checksum_required;
  • accepted_with_scope;
  • bridge_required.

Pin sponsor proof

Use when slot survival, stop-loss, makegood, or sponsor-safe brief must remain visible.

Relief:

  • sponsor/slot pressure falls;
  • immediate resource pressure may ease.

Cost:

  • contract capture, public distrust, artist-boundary risk, or claimant hostility rises.

Future effects:

  • sponsor_only;
  • captured;
  • accepted_with_scope;
  • unwind_required.

Pin artist-boundary proof

Use when refusal, voice/body boundary, proxy limit, or safety marker must control the wall.

Relief:

  • artist refusal is respected;
  • voice integrity or coercion risk improves.

Cost:

  • sponsor promise, fan expectation, management pressure, or route unlock worsens.

Future effects:

  • artist_boundary_only;
  • blocked;
  • route_costlier;
  • recovery_only.

Split wall

Use when two or more readers cannot accept the same visible proof surface.

Relief:

  • incompatible readers remain playable;
  • private capture drops.

Cost:

  • source ambiguity, handler burden, public contradiction, and archive debt rise.

Future effects:

  • split_wall;
  • bridge_required;
  • contradiction_pending;
  • route_costlier.

Mark unread or partial

Use when a proof can be shown but cannot become authority yet.

Relief:

  • false-front pressure drops;
  • occluded proof is not erased.

Cost:

  • route delay, inspection heat, public distrust, or handler burden rises.

Future effects:

  • checksum_required;
  • lawful_annex_required;
  • public_counterline_required;
  • callback_required;
  • recovery_only_marker.

Quarantine pin

Use when a visible proof would create false public reality, fraud, artist-boundary violation, sponsor laundering, or route corruption.

Relief:

  • broadcast-reality drift, archive fraud, or false-front risk falls.

Cost:

  • current route blocks, sponsor pressure rises, fan resentment rises, or recovery cost grows.

Future effects:

  • blocked;
  • audit_required;
  • recovery_only.

Default occlusion

Occurs when a proof wall is consumed without a complete pin/occlusion contract.

Required result:

  • 举证墙遮蔽默认 fires or arms;
  • at least one reader becomes captured, hostile, blocked, contradiction-pending, costlier, or recovery-only.

Integration contracts

With proof burden

This mechanism does not assign the continuing proof holder. It can reveal that an assigned holder’s proof was pinned to the wrong wall or that a live proof burden was omitted from the visible surface.

With reader collision

A reader collision may decide which reader gets recognized. This mechanism decides what proof surface that reader actually saw and whether hidden proof makes the recognition false-front or scoped.

With rebuttal notice

A rebuttal can be valid but hidden. If a future reader consumes a wall without the rebuttal pin or explicit absence, proof-wall occlusion default is armed.

With route loadout

A loadout may be compatible but still false if its proof surface hides an omitted proof or marks a recovery-only proof as fresh.

With recovery indemnity

A recovery shelf may be pinned as proof only if the wall names who can later recall the shelf and who is excluded from that visibility.

Counter contract

Every branch must mutate at least three surfaces: one relief, one cost, and one future reader or route effect.

Core surfaces:

  • proof_wall_integrity
  • pin_owner_exposure
  • occluded_proof_pressure
  • future_reader_acceptance
  • public_receipt_legitimacy
  • public_receipt_distrust
  • archive_signature_legitimacy
  • archive_debt
  • sponsor_stop_loss_pressure
  • contract_capture
  • artist_refusal_respected
  • artist_refusal_violation
  • voice_integrity_risk
  • claimant_hostility
  • worker_testimony_safety
  • handler_burden
  • inspection_heat
  • broadcast_reality_drift
  • route_asset_pressure
  • future_recovery_cost

Replay evidence expectation

mechanic_id: storyteller.mechanic.proof_wall_pinning_custody.v1
session_id: lens-proof-wall-pinning-custody-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  wall_surface_present: true
  future_reader_present: true
  visible_pin_candidate_present_or_explicit_absence: true
  occluded_or_absent_proof_present: true
  pin_owner_or_explicit_absence_present: true
  reader_specific_scope_or_conflict_visible: true
  future_route_or_reader_consumes_wall_state: true
  no_fixed_turn_trigger: true
offered:
  card: storyteller.card.proof_wall_pinning_docket.v1
  rite: storyteller.rite.proof_wall_pinning_review.v1
branch_result:
  selected_posture: pin_public_proof | pin_lawful_proof | pin_sponsor_proof | pin_artist_boundary_proof | split_wall | mark_unread_or_partial | quarantine_pin | allow_default_occlusion
  wall_state_after: pinned | scoped | rotated | split_wall | marked_unread | quarantined | false_front | default_occluded
  visible_pin: <proof or explicit_absence>
  pin_owner: <owner or explicit_absence>
  occluded_or_absent_proof: <proof or explicit_absence>
  harmed_or_excluded_reader: <reader or explicit_absence>
  future_route_effect: <effect>
  event_seen_or_armed: storyteller.event.proof_wall_occlusion_default.v1 | explicit_absence
  counter_deltas:
    relief: []
    cost: []
    future: []
assertions:
  - entry_is_state_triggered
  - wall_surface_visible
  - pin_owner_visible_or_explicit_absence
  - occluded_proof_visible_or_explicit_absence
  - reader_scope_visible
  - branch_outcomes_diverge
  - success_has_cost
  - default_is_durable
  - future_reader_consumes_wall_state
  - no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_trigger

Failure cases

This mechanism fails if:

  • it treats the proof wall as a UI checklist or dashboard;
  • it triggers from fixed turn count, raw proof count, or lens health;
  • it records no omitted proof or explicit absence;
  • it hides pin owner exposure;
  • public, lawful, sponsor, artist-boundary, route, and management readers all accept the same clean pin;
  • a pinned proof has no future route effect;
  • default occlusion does not create a durable scar;
  • a recovery-only or quarantined proof is pinned as fresh proof.