Ledger Custodian / 账簿保管员

The Ledger Custodian is the living beneficiary-ledger witness for rite.public_oxygen_audit. They remember which relief unit was promised to which district and refuse to let sponsor receipts replace the source ledger.

Recruitment window

rite.expose_fan_oxygen_audit_pressure first places the gala broadcast, oxygen reserve, Community Archive, and named future reader on one table. That relevant prelude records fan_oxygen_debt = 2 and ledger_custodian.fan_oxygen_audit_pressure_visible; the notice cannot appear merely because its starter rows exist.

event.oxygen_audit_notice preselects one of three audit tuples for the same rite:

PreselectionLedgerPressure actorRights posture
Living witnessnpc.ledger_custodianfaction.city_inspectoratestoryteller.card.oxygen_audit_no_rights_transfer_receipt.v1
Documentary substitutecard.evidence.fan_oxygen_ledgerfaction.corporate_sponsorscard.rights.temporary_voice_release
Explicit absencestoryteller.card.ledger_custodian_explicit_absence.v1storyteller.card.oxygen_audit_pressure_absence.v1storyteller.card.oxygen_audit_rights_absence.v1

The event opens the window; the exact seven-slot rite records the disposition. Runtime requires an explicit rite choice and rejects any option whose branch flag or seven assigned cards do not match the event preselection. Only public_custody_pass may set ledger_custodian.recruited and route_asset.ledger_custodian_audit_witness. It retains living testimony, public Community Archive custody, and a recurring-audit future.

Both sponsor_custody_compromise and failure_blackout_audit set ledger_custodian.missed_for_current_audit. The substitute keeps documentary proof and temporary rights but cannot imply living testimony. The blackout keeps the archive contested, records unverified relief, and must not decrease fan-oxygen debt. All three terminal branches set ledger_custodian.audit_disposition_recorded; the same resolved audit cannot recruit the custodian afterward.

card.evidence.fan_oxygen_ledger is an audit evidence row that cites card-storyteller-fan-oxygen-ledger. Its runtime boundary is grantsSourceCard: false; it is not a parallel source ledger.