Broadcast Warrant Trace / 播出许可痕迹线

Broadcast Warrant Trace is the storyline for the moment a forceful intervention wants to become broadcast reality.

The older 播出许可机制 rule says that private force is not canon just because a character attempts it. This storyline turns that rule into a visible content pack: every major intervention must name the authority, operator, cut path, cost, trace, and future reader that will inherit the result.

Playable question

When a crisis response clears a room, edits a contradiction, legalizes a shortcut, oxygenates a crowd, memorializes a loss, or sponsors a new public version, what makes that intervention broadcastable?

The player can:

  • use sponsor authority and accept capture;
  • use lawful authority and accept audit or lawful-only routing;
  • use archive authority and accept archive debt;
  • use oxygen or memorial authority and accept public grief cost;
  • use audit authority and accept inspection heat;
  • preserve an unauthorized witness and accept dirty trace;
  • cut through black-box edit and accept source ambiguity;
  • refuse broadcast and preserve the intervention as non-canon;
  • allow an unauthorized trace default.

No branch may make the same intervention clean for sponsor, lawful reader, archive, public, oxygen, memorial, audit, cutroom, and route asset readers at once.

State-triggered entry

Open this storyline only from live state pressure:

entry_state_required:
  trigger_kind: state_pressure
  major_intervention_attempted: true
  warrant_authority_or_explicit_absence_visible: true
  operator_surface_visible: true
  cut_path_or_explicit_absence_visible: true
  cost_surface_or_explicit_absence_visible: true
  trace_can_mutate_future_reader: true
  future_reader_consumes_warrant_trace: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_authority_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

Valid entry sources include security clearance, facility access, sponsor copy, broadcast stability, legality conversion, public recap, production triage, archive enforcement, fan oxygen, or a route asset trying to use a prior intervention as proof.

Bound content pack

Exact runtime contract

The runtime-backed packet uses one eight-card assignment surface. Every slot is required, accepts only the named card, and the assigned card must be present in hand.

SlotExact runtime card
ledgerstoryteller.card.broadcast_warrant_ledger.v1
interventionstoryteller.card.broadcast_warrant_intervention.v1
authority_sourcestoryteller.card.broadcast_warrant_authority_source.v1
operator_surfacestoryteller.card.broadcast_warrant_operator_surface.v1
cut_pathstoryteller.card.broadcast_warrant_cut_path.v1
cost_surfacestoryteller.card.broadcast_warrant_cost_surface.v1
future_readerstoryteller.card.broadcast_warrant_future_reader.v1
default_riskstoryteller.card.broadcast_warrant_default_risk.v1

storyteller.rite.broadcast_warrant_trace_review.v1 exposes exactly nine stable branch IDs. Each branch produces exactly one branch flag, one state flag, and one future-route flag:

Branch IDExact state afterExact future effect
sponsor_warrantsponsor_scoped_warrantsponsor_only_until_unwind
lawful_warrantlawful_authorized_tracelawful_only_with_public_addendum
archive_warrantarchive_scoped_warrantarchive_reader_must_name_source
oxygen_warrantoxygen_public_warrantfan_public_receipt_required
audit_warrantaudit_locked_warrantaudit_reader_required
unauthorized_witnessdirty_public_tracelawful_annex_or_recovery_required
black_box_cutblack_box_tracechecksum_required_before_reuse
refuse_broadcastbroadcast_refusednoncanon_intervention_preserved
unauthorized_trace_defaultunauthorized_default_pendingunauthorized_warrant_recovery_pending

Only unauthorized_trace_default arms all four pending flags:

  • broadcast_warrant.unauthorized_default_pending
  • event.unauthorized_warrant_trace_default.armed
  • future_route.unauthorized_warrant_recovery_pending
  • broadcast_reality.false_clean_warrant_claimed

The other eight branches clear those flags and cannot reach the default event. The event then exposes exactly three terminal repairs:

Terminal IDExact state afterExact future effect
expose_authority_gapauthority_gap_exposedpublic_or_lawful_warrant_review_required
quarantine_false_warrantfalse_warrant_quarantinedintervention_blocked_until_warrant_served
accept_recovery_only_tracerecovery_only_tracewarrant_trace_recovery_only

Storyline spine

Beat 1 - Intervention is attempted

A character, route asset, sponsor desk, edit desk, archive reader, public witness, oxygen queue, legal seal, or producer surface attempts to make a crisis response real.

The attempt is not enough. The implementation must show what authority makes it actionable or why authority is explicitly absent.

Beat 2 - Warrant ledger opens

Create or refresh Broadcast Warrant Ledger. It must not be a permission flag. It must name the intervention, authority source, operator surface, cut path, cost surface, trace state after, and future reader.

broadcast_warrant_row:
  intervention_id: <stable intervention id>
  intervention_kind: clearance | edit | legalize | archive | sponsor | oxygen | memorial | audit | public_witness | route_asset_use | equivalent
  authority_source_or_absence: sponsor_asset | legal_asset | archive_asset | memorial_asset | oxygen_asset | audit_asset | public_witness | black_box_edit | producer_license | explicit_absence
  operator_surface: character_card | rite | route_asset | sponsor_copy | archive_order | public_receipt | oxygen_ledger | editor_checksum | explicit_absence
  cut_path: saintly_pacification | legal_folding | black_box_edit | unauthorized_witness | white_glove_audit | sponsor_package | oxygen_bridge | memorialization | refusal
  cost_surface: sponsor_capture | inspection_heat | archive_debt | oxygen_debt | memorial_debt | unauthorized_trace | edit_debt | public_distrust | explicit_absence
  trace_state_after: sponsor_scoped_warrant | lawful_authorized_trace | archive_scoped_warrant | oxygen_public_warrant | audit_locked_warrant | dirty_public_trace | black_box_trace | broadcast_refused | unauthorized_default_pending
  future_reader_or_route: <reader route rite ending or explicit_absence>
  unauthorized_default_risk: missing_authority | missing_operator | missing_cost | missing_trace | wrong_reader | false_clean_warrant | explicit_absence

Beat 3 - Review assigns the trace

Run Broadcast Warrant Trace Review. The review must assign a warrant branch, handler or explicit absence, proof or explicit absence, cost surface, and future reader effect.

Beat 4 - Trace changes future play

The result must mutate a later route, reader, event, or counter. A sponsor warrant can keep a broadcast moving but captures future use. A lawful warrant can make the result citeable but narrow public use. An archive warrant can preserve proof while raising archive debt. An unauthorized witness can block false canon while making future lawful use costlier.

Beat 5 - Default hardens

After all eight required cards are assigned, the player may explicitly choose unauthorized_trace_default: the named authority, operator, cut, cost, reader, and risk are visible, but the intervention is still allowed to harden without a valid warrant trace. Only that choice arms Unauthorized Warrant Trace Default; skipping or underfilling the review does not create an executable default path.

Branch map

BranchImmediate reliefCost/scarExact future state
Sponsor warrantslot or budget pressure fallscontract capture, public distrustsponsor_only_until_unwind
Lawful warrantlegal acceptance improvesinspection heat, lawful-only scopelawful_only_with_public_addendum
Archive warrantproof chain improvesarchive debt, delayed accessarchive_reader_must_name_source
Oxygen warrantpublic breathing or fan relief stabilizesoxygen debt, fan resentmentfan_public_receipt_required
Audit warrantfalse-clean risk dropsaudit pressure, handler exposureaudit_reader_required
Unauthorized witnessfalse canon is blockedunauthorized trace, future lawful costlawful_annex_or_recovery_required
Black-box cutcontinuity improvesedit debt, source ambiguitychecksum_required_before_reuse
Refuse broadcastclean falsehood is avoidedroute delay, sponsor pressurenoncanon_intervention_preserved
Unauthorized defaultimmediate pressure may fallfalse-clean warrant hardensunauthorized_warrant_recovery_pending

Missability and recovery

The review is reachable only with all eight exact cards in hand. Until then, the storyline remains unresolved: it neither invents missing evidence nor silently defaults. Once the one-shot review resolves, it cannot be reopened; recovery proceeds from a visible terminal scar into public/lawful review, sponsor unwind, archive addendum, oxygen restitution, memorial correction, audit review, checksum disclosure, or a recovery-only route asset.

The player can therefore miss a clean warrant by deliberately taking choice 8, but cannot miss the observable trace: all three event terminals preserve the scar and its future-reader restriction.

Follow-On Afteruse

Warrant Trace Afteruse Receipt handles the later seam: a scoped, dirty, black-box, sponsor-only, lawful-only, public-only, archive-only, refused, or recovery-only trace can be cited by a future reader only when the afteruse receipt names scope, harmed reader, proof bridge or absence, after-state, and future effect.

Adjacency boundary

This storyline answers one per-intervention question: what makes this attempted intervention broadcastable now, and what trace does that decision leave?

  • Broadcast Legality Conversion determines whether an already-described route can be converted into a lawful, public, sponsor, archive, or recovery posture. It does not replace the warrant row.
  • Producer License Encumbrance prices authority already pledged against the producer license. It does not prove the intervention’s operator, cut, or trace.
  • Sponsor Copy Warranty warranties a sponsor-facing copy. It does not authorize every intervention represented by that copy.
  • Warrant Trace Afteruse Receipt governs later consumption of an existing trace. This packet creates the source trace and must finish first.

No branch in this packet grants route legality, clears producer-license debt, warranties sponsor copy, or authorizes later afteruse.

Local authority boundary

The packet may establish only that one named intervention was reviewed against one named authority source, operator, cut path, cost surface, default risk, and future reader. It grants no consent, waiver, settlement, route clearance, archive release, proof truth, sponsor warranty, producer-license release, fan authority, inspector authority, editor authority, future-reuse authority, or universal broadcast authority. Every runtime and public object must remain source: storyteller, localAuthorityOnly: true, and preserve those denials.

authority_boundary:
  localAuthorityOnly: true
  recordsInterventionWarrantTraceOnly: true
  preservesNamedAuthorityOperatorCutAndCost: true
  preservesFutureReaderScope: true
  requiresVisibleTraceForBroadcastReality: true
  grantsConsent: false
  grantsLegalValidity: false
  grantsWaiver: false
  grantsSettlement: false
  grantsRouteClearance: false
  grantsArchiveRelease: false
  grantsProofTruth: false
  grantsSponsorWarranty: false
  grantsProducerLicenseRelease: false
  grantsSponsorAuthority: false
  grantsFanAuthority: false
  grantsInspectorAuthority: false
  grantsEditorAuthority: false
  grantsProducerLicense: false
  grantsFutureReuseAuthority: false
  grantsUniversalBroadcastAuthority: false

Runtime, replay, and rollup evidence

The required durable artifact is lens/replays/broadcast-warrant-trace.replay.json. It must be a lens-scoped gameplay export that assigns all eight real cards, resolves storyteller.rite.broadcast_warrant_trace_review.v1 with choice index 8 (unauthorized_trace_default), proves all four pending flags, and resolves event option index 0 (expose_authority_gap). Creating a session, merely ending a turn, or surfacing the event ID is not target-rite evidence.

The focused test lens/storyteller-broadcast-warrant-trace.runtime.test.ts owns exhaustive coverage of all nine branch/state/future mappings and all three event terminals. The durable replay proves only the exact default-to-first-terminal target path. Runtime objects, the focused test, the replay, the evaluator in scripts/evaluate_lenses.mjs, and the three Storyteller public rollups must agree:

  • public/data/storytellerCards.json5
  • public/data/storytellerRite+nodes.json5
  • public/data/storytellerEvent+nodes.json5
storyline_id: storyteller.storyline.broadcast_warrant_trace.v1
session_id: lens-storyteller-lens-broadcast-warrant-trace-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  major_intervention_attempted: true
  warrant_authority_or_explicit_absence_visible: true
  operator_surface_visible: true
  future_reader_consumes_warrant_trace: true
offered:
  cards:
    ledger: storyteller.card.broadcast_warrant_ledger.v1
    intervention: storyteller.card.broadcast_warrant_intervention.v1
    authority_source: storyteller.card.broadcast_warrant_authority_source.v1
    operator_surface: storyteller.card.broadcast_warrant_operator_surface.v1
    cut_path: storyteller.card.broadcast_warrant_cut_path.v1
    cost_surface: storyteller.card.broadcast_warrant_cost_surface.v1
    future_reader: storyteller.card.broadcast_warrant_future_reader.v1
    default_risk: storyteller.card.broadcast_warrant_default_risk.v1
  rite: storyteller.rite.broadcast_warrant_trace_review.v1
branch_result:
  choice_index: 8
  selected_warrant_branch: unauthorized_trace_default
  trace_state_after: unauthorized_default_pending
  future_reader_effect: unauthorized_warrant_recovery_pending
  pending_flags:
    - broadcast_warrant.unauthorized_default_pending
    - event.unauthorized_warrant_trace_default.armed
    - future_route.unauthorized_warrant_recovery_pending
    - broadcast_reality.false_clean_warrant_claimed
event_result:
  event: storyteller.event.unauthorized_warrant_trace_default.v1
  option_index: 0
  selected_terminal: expose_authority_gap
  trace_state_after: authority_gap_exposed
  future_reader_effect: public_or_lawful_warrant_review_required
  counter_deltas:
    relief: []
    cost: []
    future: []
assertions:
  - all_eight_exact_cards_are_assigned_from_hand
  - exact_default_choice_and_terminal_are_executed
  - only_default_arms_all_four_pending_flags
  - focused_test_covers_all_nine_branches_and_three_terminals
  - evaluator_requires_target_rite_replay_and_public_rollup_parity
  - local_authority_denials_survive_runtime_replay_and_rollups

Non-goals

  • Not a generic permission meter.
  • Not a producer-license duplicate.
  • Not a sponsor copy warranty duplicate.
  • Not a legality conversion duplicate.
  • Not a fixed-turn security clearance.
  • Not satisfied by an action succeeding without authority, operator, cost, trace, and future-reader mutation.