Source Anonymity Escrow / 来源匿名托管机制
Source Anonymity Escrow prevents an unnamed source from becoming universal proof and prevents disclosure pressure from automatically destroying a protected source.
The mechanism is state-triggered. It opens only when an anonymous or protected source claim is about to be consumed by a future route, proof reader, lawful annex, public receipt, sponsor defense, or broadcast reality surface.
Mechanic promise
A passing implementation proves:
- the source claim is visible;
- the protected source or explicit absence is visible;
- proof reader and hidden reader are separate surfaces;
- escrow holder, shield, substitute proof, or explicit absence is recorded;
- future route consumption reads the anonymity state;
- forced disclosure or free anonymous proof creates durable scar;
- no fixed turn, day/week, raw count, dashboard, or lens-health trigger exists.
Entry model
entry_state:
trigger_kind: state_pressure
source_claim_present: true
anonymous_or_protected_source_visible_or_explicit_absence: true
future_reader_demands_proof: true
disclosure_target_or_hidden_reader_visible: true
escrow_holder_or_shield_or_explicit_absence_visible: true
substitute_proof_or_explicit_absence_visible: true
future_route_consumes_anonymity_state: true
player_can_escrow_disclose_publish_substitute_pay_split_reject_expose_or_default: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_source_count_trigger: true
no_dashboard_or_lens_health_trigger: trueState row
来源匿名托管案卷 records:
source_anonymity_row:
source_claim_id: <stable id>
source_surface: transcript_line | protected_witness | confidant_promise | counterreceipt | caption_log | route_log | public_receipt | checksum | equivalent
source_claim_text_or_code: <claim code>
source_identity_state: anonymous | sealed | protected | payroll_due | public_alias | lawful_only | sponsor_known | explicit_absence | equivalent
proof_reader: lawful_body | public_table | archive | inspector | sponsor | route_claimant | editor | fan_oxygen_queue | harmed_artist | broadcast_reality | equivalent
hidden_reader_or_absence: sponsor | public_table | archive | inspector | hostile_claimant | editor | fan_queue | pirate_relay | management | route_asset | explicit_absence
requested_use: route_unlock | proof_burden_shift | lawful_annex | public_correction | sponsor_defense | counterreceipt_support | broadcast_reality_patch | equivalent
escrow_holder_or_absence: han_yanshuang | yu_lan | baiya | shen_luo | ruan_chi | inspector | archive_clerk | public_delegate | explicit_absence
shield_or_support_or_absence: lawful_seal | anonymity_shell | payroll_token | checksum_mask | public_alias | substitute_proof | route_quarantine | explicit_absence
substitute_proof_or_absence: checksum | lawful_annex | public_receipt | transcript_excerpt | witness_oath | route_log | explicit_absence
future_reader_or_route: <reader route ending scar or explicit_absence>Resolution model
来源匿名托管听证 must select one posture:
escrow_sealed_source;lawful_sealed_disclosure;anonymous_public_proof;substitute_proof;pay_and_shield_source;split_reader_access;reject_anonymous_source;sponsor_exposure;forced_disclosure_default.
Each posture must write source state, proof reader state, hidden reader state, and future route effect.
Default model
来源披露默认 fires or arms when:
- anonymous source proof is accepted without holder, shield, substitute proof, or explicit absence;
- a protected source is exposed without route cost;
- sponsor disclosure is treated as public repair;
- public anonymous proof is treated as lawful admissibility;
- future route consumes source proof while the hidden reader is absent or implied.
The default produces forced_disclosure, free_anonymous_proof, sponsor_outing, public_doxxing, lawful_only_silence, source_harmed, proof_poisoned, appeal_required, route_blocked, or recovery_only.
Integration rules
- With 受保护证人薪册机制, this mechanism consumes payroll and protection state rather than paying the witness itself.
- With 听证笔录删改机制, this mechanism consumes transcript row and keeper state rather than deciding the transcript posture.
- With 举证负荷再分配机制, this mechanism decides whether anonymous proof can carry burden and under which reader scope.
- With Route Assets and Custody, future route assets may become escrow-required, lawful-only, public-only, split-reader, proof-burden-open, sponsor-only, blocked, or recovery-only.
Failure states
The mechanism fails if it allows:
- anonymous source proof to satisfy every reader;
- source disclosure with no shield, holder, or recovery scar;
- public anonymous proof to become lawful proof;
- sponsor exposure to count as public repair;
- source protection to exist without proof reader and hidden reader;
- route unlock without future consumption of anonymity state;
- fixed turn, fixed day/week, raw source count, dashboard, or lens-health trigger.