Custody Proof Chain Receipt Storyline / 羁押证据链回执线
Custody Proof Chain Receipt is the storyline for the moment a proof object has to move from one holder to a future reader.
The existing vault already has archive enforcement, proof-board snapshots, counter-broadcast custody, route-asset handoff, and stabilization liability handoff. This packet covers the thinner missing seam between them: a proof object may be valid in its source scene and still become unsafe when the next desk tries to cite it without a transfer receipt.
This packet binds that seam into concrete content:
Playable question
When a later reader tries to use a transferred proof object, who can prove the transfer, what scope survived, and which gap becomes a scar?
The player can:
- seal the chain for a narrow lawful or archive reader;
- split custody between source holder and receiving reader;
- publish a public counterstub that makes the handoff visible but not fully legal;
- attach a lawful annex after a missing holder or witness appears;
- rebuild the carrier path through a named runner or route asset;
- quarantine the proof until a future receipt exists;
- underfill the receipt and trigger a false-clean transfer default.
No branch may turn one proof receipt into universal safety for sponsor, public, lawful, archive, cutroom, route asset, and fan oxygen readers.
State-triggered entry
Open this storyline only from live transfer pressure:
entry_state_required:
trigger_kind: state_pressure
transfer_or_handoff_attempted: true
source_proof_object_visible: true
source_holder_or_explicit_absence: true
carrier_or_explicit_absence: true
receiving_reader_or_route_visible: true
proof_gap_or_explicit_absence_visible: true
future_reader_consumes_receipt_state: true
no_fixed_turn_trigger: true
no_fixed_day_or_week_trigger: true
no_raw_proof_count_trigger: true
no_dashboard_or_lens_health_trigger: trueValid entry sources include a black-box fragment, archive shard, voice custody receipt, legal-body file, memorial license, fan oxygen proof, public testimony, enforcement docket, route-asset packet, or proof-board row that must be used by a different reader.
Storyline spine
Beat 1 - A source proof leaves its original scene
A proof object was created by another storyline or mechanism. It may be real, scoped, partial, contested, or explicitly absent. The important pressure is that another reader now wants to consume it: lawful reader, archive, public table, sponsor desk, cutroom, fan oxygen audit, route asset, memorial route, recovery reader, or management report.
Beat 2 - Docket opens
Create or refresh Custody Proof Receipt Docket.
custody_proof_receipt_docket:
source_proof_object: <proof object or explicit_absence>
source_holder_or_absence: <holder or explicit_absence>
carrier_or_absence: <carrier or explicit_absence>
attempted_claim_or_consumer: <reader route rite ending or explicit_absence>
receiving_reader_or_route: <reader route or explicit_absence>
transfer_scope: lawful_only | archive_only | public_only | sponsor_only | split | recovery_only | blocked | equivalent
proof_gap_or_absence: missing_holder | missing_carrier | missing_signature | scope_mismatch | stale_copy | hostile_counterstub | explicit_absence
receipt_state_after: unopened | sealed | split | public_counterstub | lawful_annex | rebuilt | quarantined | false_clean_default_ready | recovery_only
future_reader_or_route_effect: <effect or explicit_absence>
false_clean_transfer_default_risk: <risk or explicit_absence>The docket fails if it stores only “proof exists”, “receipt filed”, or “handoff completed”.
Beat 3 - Chain review assigns custody
Run Custody Proof Chain Review.
The review must choose one posture:
| Branch | Immediate relief | Cost/scar | Future state |
|---|---|---|---|
seal_chain | archive or lawful citation improves | narrow scope, public or sponsor reader delayed | sealed but reader-scoped |
split_receipt | source holder and reader both remain true | dual-reader conflict, reconciliation required | split custody or two-reader ruling |
public_counterstub | crowd can see the transfer | inspection heat, lawful annex required | public-only until annex |
lawful_annex | admissibility improves | route delay, excluded reader notice | lawful-only or annex-required |
carrier_rebuild | carrier path becomes playable | runner burden, route cost, witness exposure | rebuilt but scarred |
quarantine_proof | false clean use is blocked | route delay, recovery cost | blocked, recovery-only, or future proof receipt needed |
false_clean_transfer_default | immediate pressure falls temporarily | false-clean transfer and hidden gap | hostile, blocked, lawful-only, or recovery-only |
Beat 4 - Future reader consumes the receipt
The result must mutate later play. A sealed chain can be cited, but only by its scoped reader. A split receipt can keep public and archive accounts both true while requiring reconciliation. A public counterstub can stop capture but cannot grant lawful safety. A rebuilt carrier path can unlock a route while exposing the carrier. A quarantine blocks the proof until a later receipt exists.
Beat 5 - False-clean transfer hardens
If the player or implementation hides source holder, carrier, scope, gap, receiving reader, or future effect, False-Clean Proof Transfer Default fires or arms.
Counters and state keys
custody_receipt_state:unopened | sealed | split | public_counterstub | lawful_annex | rebuilt | quarantined | false_clean_default_ready | recovery_onlyproof_chain_integrityarchive_signature_legitimacypublic_receipt_legitimacycarrier_burdeninspection_heatsponsor_copy_pressureroute_asset_acceptancerecovery_costhidden_gap_debt
Replay/session evidence requirements
Worker evidence should include:
- source proof object and source storyline;
- seed and session id;
- holder, carrier, receiving reader, and explicit absences;
- selected branch;
- before/after counters;
- emitted or armed default events;
- future reader effect and any blocked reader;
- named reason when a transfer is not clean.
Explicit non-goals
- Not a generic evidence log.
- Not proof-board snapshot custody; this packet observes the transfer receipt after a proof object leaves its board or source scene.
- Not archive enforcement; this packet can feed enforcement, but does not serve an order.
- Not stabilization liability handoff; this packet moves proof, not debt ownership.
- Not facility access; a room handoff can be one carrier, but the proof receipt is the tracked object.