Proof Wall Pinning Custody / 举证墙钉选羁押机制
Proof Wall Pinning Custody is the mechanism for the in-world surface where crisis proof becomes visible before it becomes accepted.
The current mesh already answers many adjacent questions:
- 举证负荷再分配线 decides who must keep proof alive.
- 裁定读者冲突线 decides which future readers can consume a source row.
- 读者反驳通知线 decides whether an affected party can answer before a cited row becomes authority.
- 路线装配兼容线 decides whether multiple route assets can be bundled.
- 复原追偿搁架线 decides who carries future recourse after stabilization.
The uncovered seam is visibility custody. A proof may be alive, scoped, rebuttable, compatible, and still become false when it is pinned to a reader-facing wall while another material proof is hidden. This mechanism makes the pin, owner, wall surface, omission, and future reader effect playable.
Primary design question
When a future reader is about to consume a proof surface, which proof is pinned, which proof is scoped or hidden, who owns the pin, and what future route state is created by that visibility?
Core objects
Proof wall
A proof wall is an in-world surface read by one or more readers. It can be:
- public wall;
- lawful wall;
- sponsor brief;
- archive pinboard;
- artist-boundary slate;
- route-loadout surface;
- management-closure surface;
- equivalent reader-facing proof surface.
It is not a task board, dashboard, or governance artifact.
Visible pin
The proof made visible for a named reader and scope. It carries proof kind, current state, pin owner, and scope claim.
Occluded proof
A relevant proof, receipt, counterline, boundary, recovery shelf, or explicit absence that is not visible on the wall but would change future acceptance if shown.
Pin owner
The actor, desk, route asset, public witness, archive, sponsor, editor, artist proxy, worker carrier, claimant, inspector, or explicit absence that controls the visible pin.
Future reader
The reader who consumes the wall state later: public/fan, lawful/archive, sponsor, artist-boundary, claimant, worker testimony, route asset, management, or equivalent.
Entry contract
Open this mechanism only through state pressure:
entry_state_required:
trigger_kind: state_pressure
wall_surface_present: true
future_reader_present: true
visible_pin_candidate_present_or_explicit_absence: true
occluded_or_absent_proof_present: true
pin_owner_or_explicit_absence_present: true
reader_specific_scope_or_conflict_visible: true
future_route_or_reader_consumes_wall_state: true
player_can_pin_scope_rotate_split_mark_quarantine_or_default: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_proof_count_trigger: true
no_dashboard_or_lens_health_trigger: trueA wall may contain many proof rows, but raw number is never the trigger. The trigger is that visibility or occlusion would change a future reader’s acceptance, hostility, route cost, custody, or recovery state.
Bound content
- 举证墙钉选案卷 records the visible pin, pin owner, omitted proof, harmed reader, wall state, and future effect.
- 举证墙钉选复核 lets the player pin public, lawful, sponsor, artist-boundary, split, marked-unread, quarantine, or default surfaces.
- 举证墙遮蔽默认 fires or arms when a reader consumes a false or underfilled wall.
State machine
| State | Meaning | Gameplay obligation |
|---|---|---|
unpinned | A proof wall exists but no reader-ready proof is pinned. | Offer review or arm default if a reader consumes it. |
pinned | A named proof is visible for a named reader. | Scope, owner, and omitted proof are recorded. |
scoped | Visible proof is limited to a declared use. | Other readers remain narrowed, hostile, or bridge-required. |
rotated | An older proof was moved behind a newer pin. | Old proof remains recallable and scarred. |
split_wall | Different readers receive different surfaces. | No universal clean proof exists. |
marked_unread | Proof is visible but not cleanly readable. | Future bridge, annex, checksum, callback, or counterline is required. |
quarantined | Proof is blocked from consumption. | False-front risk falls; route delay or recovery pressure rises. |
false_front | Wall appears clean while material proof is hidden. | Default event can fire or arm. |
default_occluded | Omitted proof is erased by play. | Hidden reader becomes hostile, captured, blocked, or recovery-only. |
When a future reader tries to cite the old proof after rotated, Proof Wall Rotation Receipt must open or explicitly be impossible. The initial pinning review does not by itself make the old pin current proof.
Branch families
Pin public proof
Use when the game needs public receipt, fan legitimacy, public counterline, historian proof, or anti-capture visibility.
Relief:
- private capture falls;
- public receipt legitimacy rises;
- occluded public harm becomes visible.
Cost:
- sponsor pressure, witness exposure, public contradiction, or inspection heat rises.
Future effects:
public_only;accepted_with_scope;bridge_required;contradiction_pending.
Pin lawful proof
Use when admissibility, archive chain, inspector stamp, or custody trace matters more than public readability.
Relief:
- archive signature legitimacy and custody clarity improve;
- false-front fraud drops.
Cost:
- public delay, bureau favor debt, lawful-only routing, or fan distrust rises.
Future effects:
lawful_only;checksum_required;accepted_with_scope;bridge_required.
Pin sponsor proof
Use when slot survival, stop-loss, makegood, or sponsor-safe brief must remain visible.
Relief:
- sponsor/slot pressure falls;
- immediate resource pressure may ease.
Cost:
- contract capture, public distrust, artist-boundary risk, or claimant hostility rises.
Future effects:
sponsor_only;captured;accepted_with_scope;unwind_required.
Pin artist-boundary proof
Use when refusal, voice/body boundary, proxy limit, or safety marker must control the wall.
Relief:
- artist refusal is respected;
- voice integrity or coercion risk improves.
Cost:
- sponsor promise, fan expectation, management pressure, or route unlock worsens.
Future effects:
artist_boundary_only;blocked;route_costlier;recovery_only.
Split wall
Use when two or more readers cannot accept the same visible proof surface.
Relief:
- incompatible readers remain playable;
- private capture drops.
Cost:
- source ambiguity, handler burden, public contradiction, and archive debt rise.
Future effects:
split_wall;bridge_required;contradiction_pending;route_costlier.
Mark unread or partial
Use when a proof can be shown but cannot become authority yet.
Relief:
- false-front pressure drops;
- occluded proof is not erased.
Cost:
- route delay, inspection heat, public distrust, or handler burden rises.
Future effects:
checksum_required;lawful_annex_required;public_counterline_required;callback_required;recovery_only_marker.
Quarantine pin
Use when a visible proof would create false public reality, fraud, artist-boundary violation, sponsor laundering, or route corruption.
Relief:
- broadcast-reality drift, archive fraud, or false-front risk falls.
Cost:
- current route blocks, sponsor pressure rises, fan resentment rises, or recovery cost grows.
Future effects:
blocked;audit_required;recovery_only.
Default occlusion
Occurs when a proof wall is consumed without a complete pin/occlusion contract.
Required result:
- 举证墙遮蔽默认 fires or arms;
- at least one reader becomes captured, hostile, blocked, contradiction-pending, costlier, or recovery-only.
Integration contracts
With proof burden
This mechanism does not assign the continuing proof holder. It can reveal that an assigned holder’s proof was pinned to the wrong wall or that a live proof burden was omitted from the visible surface.
With reader collision
A reader collision may decide which reader gets recognized. This mechanism decides what proof surface that reader actually saw and whether hidden proof makes the recognition false-front or scoped.
With rebuttal notice
A rebuttal can be valid but hidden. If a future reader consumes a wall without the rebuttal pin or explicit absence, proof-wall occlusion default is armed.
With route loadout
A loadout may be compatible but still false if its proof surface hides an omitted proof or marks a recovery-only proof as fresh.
With recovery indemnity
A recovery shelf may be pinned as proof only if the wall names who can later recall the shelf and who is excluded from that visibility.
Counter contract
Every branch must mutate at least three surfaces: one relief, one cost, and one future reader or route effect.
Core surfaces:
proof_wall_integritypin_owner_exposureoccluded_proof_pressurefuture_reader_acceptancepublic_receipt_legitimacypublic_receipt_distrustarchive_signature_legitimacyarchive_debtsponsor_stop_loss_pressurecontract_captureartist_refusal_respectedartist_refusal_violationvoice_integrity_riskclaimant_hostilityworker_testimony_safetyhandler_burdeninspection_heatbroadcast_reality_driftroute_asset_pressurefuture_recovery_cost
Replay evidence expectation
mechanic_id: storyteller.mechanic.proof_wall_pinning_custody.v1
session_id: lens-proof-wall-pinning-custody-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
trigger_kind: state_pressure
wall_surface_present: true
future_reader_present: true
visible_pin_candidate_present_or_explicit_absence: true
occluded_or_absent_proof_present: true
pin_owner_or_explicit_absence_present: true
reader_specific_scope_or_conflict_visible: true
future_route_or_reader_consumes_wall_state: true
no_fixed_turn_trigger: true
offered:
card: storyteller.card.proof_wall_pinning_docket.v1
rite: storyteller.rite.proof_wall_pinning_review.v1
branch_result:
selected_posture: pin_public_proof | pin_lawful_proof | pin_sponsor_proof | pin_artist_boundary_proof | split_wall | mark_unread_or_partial | quarantine_pin | allow_default_occlusion
wall_state_after: pinned | scoped | rotated | split_wall | marked_unread | quarantined | false_front | default_occluded
visible_pin: <proof or explicit_absence>
pin_owner: <owner or explicit_absence>
occluded_or_absent_proof: <proof or explicit_absence>
harmed_or_excluded_reader: <reader or explicit_absence>
future_route_effect: <effect>
event_seen_or_armed: storyteller.event.proof_wall_occlusion_default.v1 | explicit_absence
counter_deltas:
relief: []
cost: []
future: []
assertions:
- entry_is_state_triggered
- wall_surface_visible
- pin_owner_visible_or_explicit_absence
- occluded_proof_visible_or_explicit_absence
- reader_scope_visible
- branch_outcomes_diverge
- success_has_cost
- default_is_durable
- future_reader_consumes_wall_state
- no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_triggerFailure cases
This mechanism fails if:
- it treats the proof wall as a UI checklist or dashboard;
- it triggers from fixed turn count, raw proof count, or lens health;
- it records no omitted proof or explicit absence;
- it hides pin owner exposure;
- public, lawful, sponsor, artist-boundary, route, and management readers all accept the same clean pin;
- a pinned proof has no future route effect;
- default occlusion does not create a durable scar;
- a recovery-only or quarantined proof is pinned as fresh proof.