Recall Claim Priority / 召回认领优先级机制
Recall Claim Priority is the mechanism that turns a matured stabilization ticket, liability call, or reliance unwind into a contested queue of claimants. It starts after a cost has become callable, not when the first liability object is created.
The mechanism answers a practical management-RPG question: when sponsor clawback, inspector remand, fan refund, archive seal, editor checksum, witness protection, claimant body, or route-asset rescue all call the same carrier, collateral, escrow, handler lane, proof object, or public bond, which call is answered first and what happens to the calls that wait?
It is not a generic finance layer, not a replacement for stabilization-liability-handoff, and not a duplicate of failure-state-arbitration. Failure arbitration chooses which failure becomes official reality. Claim priority chooses which claimant can consume the same limited carrier or collateral first.
Entry contract
Open this mechanism only from live state pressure:
entry_state:
trigger_kind: state_pressure
callable_source_present_any:
- storyteller.card.stabilization_liability_ticket.v1
- storyteller.event.stabilization_debt_recall.v1
- storyteller.event.liability_call_default.v1
- storyteller.card.counterparty_reliance_ledger.v1
call_rows_min: 2
rows_share_same_carrier_or_collateral: true
rows_have_non_equivalent_demands: true
first_satisfaction_can_change_later_satisfaction: true
future_route_or_reader_effect_possible: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_count_trigger: true
no_dashboard_or_lens_health_trigger: trueValid shared surfaces include sponsor escrow, inspector surety, public bond, fan refund pool, edit checksum, route asset, proof bridge, archive copy, callback carrier, handler time, production lane, facility room, lawful seal, public receipt, or explicit absence.
Claim queue row
Every queue row must record the claimant and the consequence of ordering.
claim_queue_row:
row_id: <stable id>
source_ticket_or_reliance_row: <ticket row, recall event, call default, or reliance ledger row>
claimant: sponsor | inspector | archive | editor | fan_public | artist | witness | pirate | lawful_reader | public_reader | route_claimant | worker | management | broadcast_reality | equivalent
claim_kind: clawback | remand | refund | seizure | correction | checksum_reopen | callback_call | witness_protection | route_asset_rescue | public_answer | recourse_call | equivalent
demanded_surface: money | slot | proof_object | public_receipt | fan_oxygen | legal_seal | route_asset | edit_capacity | handler_time | archive_copy | callback_carrier | facility_room | public_version | equivalent
relief_if_first: <what improves if this claimant is satisfied first>
cost_if_first: <what worsens because this claimant is satisfied first>
consequence_if_deferred: <stay, hostility, injunction, refund escalation, route capture, witness exposure, distrust, or recovery-only>
hardening_if_ignored: <false owner, public-only, lawful-only, sponsor-only, hostile, captured, blocked, recovery-only, contradiction-pending>
proof_anchor_or_absence: <proof object or explicit_absence>
handler_or_absence: <handler, claimant delegate, route asset, or explicit_absence>A row is invalid if it only says sponsor wants money, fans are angry, audit arrives, or route pressure rises. The demanded surface, ordering consequence, proof anchor, and future effect must be playable.
Priority resolution states
queue_state:
unqueued: callable pressure exists but no ordering row is visible
queued: at least two call rows are visible
priority_set: one claimant is answered first and others receive scar states
consolidated: two compatible calls are bundled through one proof or public answer
split_tender: carrier/collateral is split across surfaces with explicit drift or debt
substituted: another carrier/collateral is posted before the first call consumes the original surface
stayed_with_notice: one call is deferred with notice, not erased
subordinated: one claimant accepts lower priority with a named concession
refused: player rejects a call and arms default or hostility
double_called_default: the same surface is promised twice or consumed by incompatible claimants
recovery_only: clean satisfaction is impossible; scar repair remains possibleBranch families
Sponsor first
The player answers stop-loss, naming, escrow, or clawback first.
Expected result: immediate sponsor pressure or slot pressure can improve, while contract capture, public distrust, fan resentment, lawful suspicion, or future correction cost rises. Other claimants receive visible stayed, subordinated, hostile, or recovery-only states.
Inspector or archive first
The player answers remand, lawful seal, admissible copy, quarantine, or proof rehearing first.
Expected result: custody clarity, lawful use, or fraud containment can improve, while inspection heat, bureau favor debt, public delay, sponsor retaliation, or route asset quarantine rises.
Public or fan first
The player answers refund, public receipt, oxygen debt, pirate relay, or public countercopy first.
Expected result: private capture is blocked and public legitimacy can rise, while sponsor stop-loss, witness exposure, audit heat, public panic, or blackout pressure rises.
Editor or checksum first
The player answers cutroom checksum, source proof, continuity patch, or black-box bridge first.
Expected result: slot legibility or continuity can improve, while edit debt, source ambiguity, archive suspicion, public distrust, or reality drift rises.
Artist, witness, or worker protection first
The player protects the body, voice, witness, proxy, worker carrier, or refusal receipt before institutional calls consume the surface.
Expected result: consent, witness safety, or worker trust can improve, while schedule pressure, sponsor delay, handler burden, lawful cost, or route delay rises.
Consolidate or split tender
The player bundles compatible claims into one public/legal answer or splits the carrier across route copies.
Expected result: two claims can avoid immediate hostility, but source ambiguity, drift, future correction cost, and proof-maintenance burden rise. Consolidation is invalid if it hides omitted claimant harm.
Substitute collateral
The player posts a different proof object, route asset, public bond, lawful seal, handler lane, or escrow to keep the original surface usable.
Expected result: one route asset or proof survives, but substitute carrier pressure, exposure, or recovery-only risk rises.
Refuse, double-call, or false priority
The player hides the queue, promises the same surface to incompatible claimants, or treats the first claimant as universal closure.
Expected result: liability-call-default or stabilization-debt-recall fires or arms, at least one claimant becomes hostile, captured, public-only, lawful-only, sponsor-only, blocked, or recovery-only, and the source scar remains visible.
Counter and state deltas
Every resolution must alter at least three counters or durable states, including one immediate relief and one future cost.
Valid surfaces include:
recall_claim_prioritycall_queue_pressuresponsor_stop_loss_pressurecontract_captureinspection_heatbureau_favor_debtarchive_debtcustody_claritypublic_receipt_legitimacypublic_receipt_distrustfan_oxygen_resentmentoxygen_liabilitywitness_exposureworker_trustedit_debtsource_ambiguityreality_driftroute_asset_pressurehandler_burdenlane_scarfuture_correction_costrecovery_only_pressure
Invariants
- At least two call rows must be visible before priority can resolve.
- All call rows must point to the same constrained carrier, collateral, proof, lane, route asset, or explicit absence.
- The first satisfied claimant must improve one surface and worsen, delay, expose, subordinate, or harden another.
- Deferred claimants must not vanish; they receive stayed, subordinated, hostile, captured, public-only, lawful-only, sponsor-only, contradiction-pending, blocked, or recovery-only states.
- A public answer can consolidate claims only if omitted harm and proof anchor remain visible.
- A substitute carrier cannot erase the original scar.
- No branch may convert recall, reliance, or liability into clean universal closure.
- No trigger may depend on fixed turn count, day/week timing, raw content count, dashboard state, or lens-health state.
Integration hooks
- From stabilization-liability-ticket, this mechanism consumes
handoff_state,maturity_trigger,carrier,harmed_or_owed_claimant, andfuture_route_effect. - From stabilization-debt-recall, it consumes
recall_cause,claimant_calling,claimant_omitted_or_owed,carrier_before, andfuture_route_effect. - From liability-underwriting-ledger, it consumes guarantor, collateral, call trigger, and claimant pressure.
- From liability-call-default, it consumes failed collateral and caller state as one row in the queue.
- From counterparty-reliance-ledger, it consumes the relying counterparty, sunk surface, displaced reader, and selected unwind when a reliance cost is called by several desks.
- With claimant-briefing-order, first notice can change who enters the queue first.
- With claimant-collision-lock, a queued call may consume, seize, split, or substitute a route asset.
- With failure-state-arbitration, unresolved double-called queues may become failure rows when an official failure slot must be chosen.
Failure conditions
The mechanism fails if implementation:
- handles only one claimant after a recall even though multiple rows share the same carrier;
- lets the first claimant consume the whole surface as clean closure;
- omits deferred claimant states;
- uses generic pressure instead of demanded surfaces and ordering consequences;
- posts substitute collateral without naming the sacrificed or exposed substitute;
- treats fan refund, sponsor clawback, lawful remand, checksum reopen, and witness protection as equivalent penalties;
- makes default flavor-only;
- triggers from fixed timing, raw counts, dashboard state, or lens health.
Replay evidence shape
mechanism: storyteller.mechanics.recall_claim_priority.v1
session_id: lens-recall-claim-priority-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
callable_source_present: true
call_rows_min: 2
rows_share_same_carrier_or_collateral: true
no_fixed_turn_trigger: true
source:
source_surface: stabilization_liability_ticket | stabilization_debt_recall | liability_call_default | counterparty_reliance_ledger | equivalent
source_id: <row id>
carrier_or_collateral: <surface>
claim_rows:
- claimant: <claimant>
claim_kind: <kind>
demanded_surface: <surface>
relief_if_first: <relief>
cost_if_first: <cost>
consequence_if_deferred: <scar>
- claimant: <claimant>
claim_kind: <kind>
demanded_surface: <surface>
relief_if_first: <relief>
cost_if_first: <cost>
consequence_if_deferred: <scar>
selected_priority:
first_satisfied_claimant: <claimant>
queue_state_after: priority_set | consolidated | split_tender | substituted | stayed_with_notice | subordinated | refused | double_called_default | recovery_only
deferred_claimant_states:
- claimant: <claimant>
state_after: <state>
counter_deltas:
relief: []
cost: []
future_route_effect: <effect>
assertions:
- entry_is_state_pressure
- at_least_two_call_rows_visible
- shared_surface_visible
- first_satisfaction_changes_later_satisfaction
- deferred_claimants_persist
- success_has_cost
- no_clean_universal_closure