Source Anonymity Escrow / 来源匿名托管机制

Source Anonymity Escrow prevents an unnamed source from becoming universal proof and prevents disclosure pressure from automatically destroying a protected source.

The mechanism is state-triggered. It opens only when an anonymous or protected source claim is about to be consumed by a future route, proof reader, lawful annex, public receipt, sponsor defense, or broadcast reality surface.

Mechanic promise

A passing implementation proves:

  • the source claim is visible;
  • the protected source or explicit absence is visible;
  • proof reader and hidden reader are separate surfaces;
  • escrow holder, shield, substitute proof, or explicit absence is recorded;
  • future route consumption reads the anonymity state;
  • forced disclosure or free anonymous proof creates durable scar;
  • no fixed turn, day/week, raw count, dashboard, or lens-health trigger exists.

Entry model

entry_state:
  trigger_kind: state_pressure
  source_claim_present: true
  anonymous_or_protected_source_visible_or_explicit_absence: true
  future_reader_demands_proof: true
  disclosure_target_or_hidden_reader_visible: true
  escrow_holder_or_shield_or_explicit_absence_visible: true
  substitute_proof_or_explicit_absence_visible: true
  future_route_consumes_anonymity_state: true
  player_can_escrow_disclose_publish_substitute_pay_split_reject_expose_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_source_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

State row

来源匿名托管案卷 records:

source_anonymity_row:
  source_claim_id: <stable id>
  source_surface: transcript_line | protected_witness | confidant_promise | counterreceipt | caption_log | route_log | public_receipt | checksum | equivalent
  source_claim_text_or_code: <claim code>
  source_identity_state: anonymous | sealed | protected | payroll_due | public_alias | lawful_only | sponsor_known | explicit_absence | equivalent
  proof_reader: lawful_body | public_table | archive | inspector | sponsor | route_claimant | editor | fan_oxygen_queue | harmed_artist | broadcast_reality | equivalent
  hidden_reader_or_absence: sponsor | public_table | archive | inspector | hostile_claimant | editor | fan_queue | pirate_relay | management | route_asset | explicit_absence
  requested_use: route_unlock | proof_burden_shift | lawful_annex | public_correction | sponsor_defense | counterreceipt_support | broadcast_reality_patch | equivalent
  escrow_holder_or_absence: han_yanshuang | yu_lan | baiya | shen_luo | ruan_chi | inspector | archive_clerk | public_delegate | explicit_absence
  shield_or_support_or_absence: lawful_seal | anonymity_shell | payroll_token | checksum_mask | public_alias | substitute_proof | route_quarantine | explicit_absence
  substitute_proof_or_absence: checksum | lawful_annex | public_receipt | transcript_excerpt | witness_oath | route_log | explicit_absence
  future_reader_or_route: <reader route ending scar or explicit_absence>

Resolution model

来源匿名托管听证 must select one posture:

  • escrow_sealed_source;
  • lawful_sealed_disclosure;
  • anonymous_public_proof;
  • substitute_proof;
  • pay_and_shield_source;
  • split_reader_access;
  • reject_anonymous_source;
  • sponsor_exposure;
  • forced_disclosure_default.

Each posture must write source state, proof reader state, hidden reader state, and future route effect.

Default model

来源披露默认 fires or arms when:

  • anonymous source proof is accepted without holder, shield, substitute proof, or explicit absence;
  • a protected source is exposed without route cost;
  • sponsor disclosure is treated as public repair;
  • public anonymous proof is treated as lawful admissibility;
  • future route consumes source proof while the hidden reader is absent or implied.

The default produces forced_disclosure, free_anonymous_proof, sponsor_outing, public_doxxing, lawful_only_silence, source_harmed, proof_poisoned, appeal_required, route_blocked, or recovery_only.

Integration rules

  • With 受保护证人薪册机制, this mechanism consumes payroll and protection state rather than paying the witness itself.
  • With 听证笔录删改机制, this mechanism consumes transcript row and keeper state rather than deciding the transcript posture.
  • With 举证负荷再分配机制, this mechanism decides whether anonymous proof can carry burden and under which reader scope.
  • With Route Assets and Custody, future route assets may become escrow-required, lawful-only, public-only, split-reader, proof-burden-open, sponsor-only, blocked, or recovery-only.

Failure states

The mechanism fails if it allows:

  • anonymous source proof to satisfy every reader;
  • source disclosure with no shield, holder, or recovery scar;
  • public anonymous proof to become lawful proof;
  • sponsor exposure to count as public repair;
  • source protection to exist without proof reader and hidden reader;
  • route unlock without future consumption of anonymity state;
  • fixed turn, fixed day/week, raw source count, dashboard, or lens-health trigger.