Branch Eligibility Receipts / 分支资格回执线

Branch Eligibility Receipts is the storyline for choices that matter precisely because they did not appear cleanly.

Storyteller already preserves selected outcomes, declined visible offers, route discontinuance, capacity notice service, counterreceipts, and management compression. This storyline binds the missing edge: a material branch can become locked, suppressed, downgraded, hidden by claimant pressure, or recovery-only before selection, and that absence must be a playable state when later readers can care.

This is not a tutorial layer or debug overlay. It is an in-world receipt trail for unavailable choices.

Gap this storyline fills

Without this pack, a branch can disappear for a good systemic reason—missing carrier, exhausted capacity, unserved notice, contested proof, sponsor veto, producer-license burden, route-asset custody, management compression, or broadcast-reality hardening—while the player and future replay only see generic absence.

That creates two regressions:

  1. the player cannot distinguish a meaningful lock from a clean non-option;
  2. later routes cannot price the absence because no in-world object preserved who benefited and who was harmed.

Branch Eligibility Receipts makes the lock itself material.

Primary playable question

When a meaningful branch is unavailable, what exact live state blocked it, who gains if that reason stays silent, who is harmed by the silence, and what scar-preserving recovery path remains?

Every answer must change future play. A branch may remain locked, downgrade, become eligible with cost, require a carrier, require a bond, become public-only, become lawful-only, become sponsor-only, or collapse into false-unavailable pressure.

State-triggered entry

Open this storyline only from live state pressure:

entry_state:
  trigger_kind: state_pressure
  source_option_set_present: true
  candidate_branch_present: true
  candidate_branch_material_to_future_play: true
  eligibility_state_any:
    - locked
    - suppressed
    - downgraded
    - hidden_by_claimant
    - recovery_only
    - explicit_absence
  blocking_surface_visible_or_explicit_absence: true
  missing_or_contested_requirement_visible_or_explicit_absence: true
  lock_beneficiary_visible_or_explicit_absence: true
  harmed_reader_if_silent_visible_or_explicit_absence: true
  future_reader_or_route_consumes_lock_state: true
  player_can_fulfill_assign_downgrade_bond_publish_accept_suppress_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_choice_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

Invalid entries include fixed turn number, day/week interval, chapter quota, raw missing-option count, tutorial prompt, dashboard state, lens-health state, or generic relationship availability.

Content pack

Mechanic

  • 分支资格回执机制 — defines unavailable branch states, concrete blocker requirements, beneficiary/harmed-reader fields, readback branches, and false-unavailable default.

Card

  • 分支资格回执 — records the candidate branch, lock reason, blocking row, harmed reader, beneficiary, proof bridge, recovery posture, and future route effect.

Rite

  • 分支资格回读 — lets the producer act on the lock reason by fulfilling a requirement, assigning a carrier, downgrading, paying a bond, publishing absence, accepting recovery-only, suppressing, or defaulting.

Event

  • 静默分支压下 — is armed only when default_silent receipts the fact that a material unavailable branch previously had no adequate receipt, only generic text, a hidden blocker/reader/beneficiary, the wrong blocker, or a false recovery-only posture.

Story beats

Beat 1 — The expected branch is tested

A source option set, rite, docket, route surface, or package exposes at least one candidate branch that was material to future play. The branch does not have to be visible to the player as selectable, but the system must know which branch family was tested.

Examples:

  • a public correction branch is missing because public notice was never served;
  • a lawful annex branch is downgraded because the proof carrier is captured;
  • a sponsor-safe rescue suppresses an artist-facing recovery branch;
  • a route-asset recruitment branch becomes recovery-only after custody hardens;
  • a management-compression branch hides a high-cost honesty option as inefficient;
  • broadcast reality treats a contradiction as already hardened because no absence receipt exists.

Beat 2 — The lock reason becomes a receipt

分支资格回执 enters play or is attached to the option set.

The receipt is valid only if it names:

  • candidate branch id or explicitly hidden identity;
  • eligibility state before readback;
  • blocking surface and row, or explicit absence;
  • missing, contested, or exhausted requirement;
  • lock beneficiary;
  • harmed reader if silent;
  • proof bridge, carrier, bond, or explicit absence;
  • future reader or route that consumes the lock.

Beat 3 — The producer reads back the lock

分支资格回读 offers scar-preserving postures.

A generic unlock, pay cost, show hint, or try later is insufficient. The readback must say what state changes and what future reader will remember.

Beat 4 — The branch changes shape

Possible outcomes:

PostureImmediate reliefVisible costFuture route effect
Fulfill requirementfull branch becomes selectableproof, capacity, notice, carrier, or handler cost is paidbranch_eligible_with_named_cost
Assign carrierbranch reason becomes carried by named actor/objectcarrier leverage, capture risk, or burden riseseligibility_carrier_required
Downgrade branchlesser route becomes playableclean branch is lost; harmed reader remains nameddowngraded_branch_only
Pay bondtemporary eligibility opensbond debt, sponsor pressure, or license burden riseseligibility_bond_required
Publish absencelock becomes public/lawful/archive/route evidenceconfusion, retaliation, or inspection heat risespublic_absence_receipt_required
Accept recovery-onlyfalse clean route is blockedroute narrows permanentlybranch_recovery_only
Suppress lockimmediate pressure dropsa named challenge is armedsuppressed_branch_challenge_armed
Default silentbranch disappears fastestharmed reader and blocker harden against playersilent_branch_suppression_pending

No branch may make the unavailable option irrelevant to every reader.

Beat 5 — A future reader consumes the lock

The storyline is incomplete until a later surface reads the receipt or default. Valid readers include route-asset custody, declined-offer afterbid, capacity notice service, route discontinuance, management compression, public receipt, lawful annex, sponsor unwind, archive seal, ending scar, or broadcast reality.

Branch boundaries with adjacent storylines

This storyline applies earlier: the branch cannot be treated as a clean non-option before those downstream systems can read it.

The hard adjacency is selection timing. A declined offer was visible in the source option set and the player did not select it. A branch-eligibility receipt is created before selection because a material candidate branch is unavailable, suppressed, downgraded, or recovery-only. A visible-but-unselected offer must never be relabelled as an eligibility failure, and an unavailable branch must never be fabricated as a declined offer.

Exact runtime readback

The runtime-backed packet binds one nine-card assignment surface. Every slot is required, accepts only its named card, and the assigned card must be in hand.

SlotExact runtime card
receiptstoryteller.card.branch_eligibility_receipt.v1
source_option_setstoryteller.card.branch_eligibility_source_option_set.v1
candidate_branchstoryteller.card.branch_eligibility_candidate_branch.v1
blocker_rowstoryteller.card.branch_eligibility_blocker_row.v1
missing_requirementstoryteller.card.branch_eligibility_missing_requirement.v1
lock_beneficiarystoryteller.card.branch_eligibility_lock_beneficiary.v1
harmed_readerstoryteller.card.branch_eligibility_harmed_reader.v1
proof_bridgestoryteller.card.branch_eligibility_proof_bridge.v1
future_readerstoryteller.card.branch_eligibility_future_reader.v1

storyteller.rite.branch_eligibility_readback.v1 exposes exactly eight stable branch IDs. Their state and future effects are not synonyms or prose-only labels:

Branch IDExact state afterExact future effect
fulfill_requirementeligibility_restored_with_costbranch_eligible_with_named_cost
assign_carriercarrier_assignedeligibility_carrier_required
downgrade_branchbranch_downgradeddowngraded_branch_only
pay_bondbond_postedeligibility_bond_required
publish_absenceabsence_publishedpublic_absence_receipt_required
accept_recovery_onlyrecovery_only_acceptedbranch_recovery_only
suppress_locklock_suppressedsuppressed_branch_challenge_armed
default_silentsilent_default_pendingsilent_branch_suppression_pending

The first seven outcomes remain local readback results. Only default_silent arms all four pending flags: branch_eligibility.silent_default_pending, event.silent_branch_suppression.armed, future_route.silent_branch_suppression_pending, and broadcast_reality.branch_falsely_absent. The default event then offers exactly three terminal repairs: reconstruct the eligibility receipt, publish the hidden beneficiary, or freeze the falsely unavailable route.

Local authority boundary

The receipt may establish only that this option set tested a named candidate branch against a named blocker, missing requirement, beneficiary, harmed reader, proof bridge, and future reader. It does not establish that the candidate branch was legally or factually correct, does not satisfy the missing requirement, and grants no consent, waiver, settlement, route clearance, archive release, proof truth, sponsor authority, fan authority, inspector authority, editor authority, or universal broadcast authority.

Counter contract

Every resolved readback or silent default must mutate at least three durable surfaces:

counter_contract:
  relief_min: 1
  cost_min: 1
  future_reader_or_route_effect_min: 1

Expected values:

  • branch_eligibility_state
  • false_unavailable_pressure
  • lock_beneficiary_pressure
  • harmed_reader_state
  • proof_bridge_integrity
  • carrier_burden
  • notice_service_pressure
  • capacity_pressure
  • sponsor_stop_loss_pressure
  • producer_license_pressure
  • public_receipt_legitimacy
  • public_receipt_distrust
  • lawful_access_integrity
  • archive_debt
  • route_asset_pressure
  • management_pressure
  • broadcast_reality_contradiction
  • future_route_cost
  • recovery_only_window

Replay evidence shape

The required durable artifact is lens/replays/branch-eligibility-receipts.replay.json. It must execute the target rite with all nine real assignments, select default_silent, verify all four pending flags, and resolve reconstruct_eligibility_receipt. The focused runtime test proves all eight branch mappings and all three default-event terminals from resettable eligible states. Generic create, end_turn, source-object discovery, or a UI lock label is not target-rite evidence.

storyline: storyteller.storyline.branch_eligibility_receipts.v1
session_id: lens-branch-eligibility-receipts-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  source_option_set_present: true
  candidate_branch_present: true
  candidate_branch_material_to_future_play: true
  eligibility_state_before: locked | suppressed | downgraded | hidden_by_claimant | recovery_only | explicit_absence
  blocking_surface_visible_or_explicit_absence: true
  lock_beneficiary_visible_or_explicit_absence: true
  harmed_reader_if_silent_visible_or_explicit_absence: true
  future_reader_or_route_consumes_lock_state: true
  no_fixed_turn_trigger: true
offered:
  card: storyteller.card.branch_eligibility_receipt.v1
  rite: storyteller.rite.branch_eligibility_readback.v1
receipt:
  candidate_branch_id: <id_or_hidden>
  blocking_surface: <surface_or_explicit_absence>
  missing_requirement_or_absence: <requirement_or_absence>
  lock_beneficiary: <actor_or_reader>
  harmed_reader_if_silent: <actor_or_reader>
readback_runs:
  constructive_branch:
    selected_posture: fulfill_requirement | assign_carrier | downgrade_branch | pay_bond | publish_absence | accept_recovery_only
    eligibility_state_after: <state>
    future_route_effect: <effect>
    counter_deltas:
      relief: []
      cost: []
      future: []
  default_branch:
    selected_posture: suppress_lock | default_silent
    event_seen_or_armed: storyteller.event.silent_branch_suppression.v1
    false_unavailable_claim: <claim>
    future_route_effect: <effect>
assertions:
  - branch_absence_is_receipted_or_defaulted
  - blocker_is_concrete_or_explicit_absence
  - harmed_reader_and_beneficiary_visible_or_explicit_absence
  - readback_branches_diverge
  - future_reader_consumes_lock_state
  - no_clean_silent_branch_disappearance
  - no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_trigger

Missability and recovery

The storyline is missable when a branch is never receipted and a later system hardens its absence. Recovery is allowed only through scar-preserving work: late readback, published absence, carrier assignment, bond payment, proof bridge restoration, lawful addendum, public correction, route-asset recovery, or recovery-only branch.

Recovery must not erase that the branch was once silently suppressed.

Non-goals

  • Not a tutorial, hint overlay, UI debug panel, analytics dashboard, or governance page.
  • Not a branch-count requirement.
  • Not a fixed unlock schedule.
  • Not a duplicate of declined offers, route discontinuance, capacity notice service, counterreceipts, or management compression.
  • Not valid unless unavailable branch state changes future play.