Custody Proof Chain Receipt Storyline / 羁押证据链回执线

Custody Proof Chain Receipt is the storyline for the moment a proof object has to move from one holder to a future reader.

The existing vault already has archive enforcement, proof-board snapshots, counter-broadcast custody, route-asset handoff, and stabilization liability handoff. This packet covers the thinner missing seam between them: a proof object may be valid in its source scene and still become unsafe when the next desk tries to cite it without a transfer receipt.

This packet binds that seam into concrete content:

Playable question

When a later reader tries to use a transferred proof object, who can prove the transfer, what scope survived, and which gap becomes a scar?

The player can:

  • seal the chain for a narrow lawful or archive reader;
  • split custody between source holder and receiving reader;
  • publish a public counterstub that makes the handoff visible but not fully legal;
  • attach a lawful annex after a missing holder or witness appears;
  • rebuild the carrier path through a named runner or route asset;
  • quarantine the proof until a future receipt exists;
  • underfill the receipt and trigger a false-clean transfer default.

No branch may turn one proof receipt into universal safety for sponsor, public, lawful, archive, cutroom, route asset, and fan oxygen readers.

State-triggered entry

Open this storyline only from live transfer pressure:

entry_state_required:
  trigger_kind: state_pressure
  transfer_or_handoff_attempted: true
  source_proof_object_visible: true
  source_holder_or_explicit_absence: true
  carrier_or_explicit_absence: true
  receiving_reader_or_route_visible: true
  proof_gap_or_explicit_absence_visible: true
  future_reader_consumes_receipt_state: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_proof_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

Valid entry sources include a black-box fragment, archive shard, voice custody receipt, legal-body file, memorial license, fan oxygen proof, public testimony, enforcement docket, route-asset packet, or proof-board row that must be used by a different reader.

Storyline spine

Beat 1 - A source proof leaves its original scene

A proof object was created by another storyline or mechanism. It may be real, scoped, partial, contested, or explicitly absent. The important pressure is that another reader now wants to consume it: lawful reader, archive, public table, sponsor desk, cutroom, fan oxygen audit, route asset, memorial route, recovery reader, or management report.

Beat 2 - Docket opens

Create or refresh Custody Proof Receipt Docket.

custody_proof_receipt_docket:
  source_proof_object: <proof object or explicit_absence>
  source_holder_or_absence: <holder or explicit_absence>
  carrier_or_absence: <carrier or explicit_absence>
  attempted_claim_or_consumer: <reader route rite ending or explicit_absence>
  receiving_reader_or_route: <reader route or explicit_absence>
  transfer_scope: lawful_only | archive_only | public_only | sponsor_only | split | recovery_only | blocked | equivalent
  proof_gap_or_absence: missing_holder | missing_carrier | missing_signature | scope_mismatch | stale_copy | hostile_counterstub | explicit_absence
  receipt_state_after: unopened | sealed | split | public_counterstub | lawful_annex | rebuilt | quarantined | false_clean_default_ready | recovery_only
  future_reader_or_route_effect: <effect or explicit_absence>
  false_clean_transfer_default_risk: <risk or explicit_absence>

The docket fails if it stores only “proof exists”, “receipt filed”, or “handoff completed”.

Beat 3 - Chain review assigns custody

Run Custody Proof Chain Review.

The review must choose one posture:

BranchImmediate reliefCost/scarFuture state
seal_chainarchive or lawful citation improvesnarrow scope, public or sponsor reader delayedsealed but reader-scoped
split_receiptsource holder and reader both remain truedual-reader conflict, reconciliation requiredsplit custody or two-reader ruling
public_counterstubcrowd can see the transferinspection heat, lawful annex requiredpublic-only until annex
lawful_annexadmissibility improvesroute delay, excluded reader noticelawful-only or annex-required
carrier_rebuildcarrier path becomes playablerunner burden, route cost, witness exposurerebuilt but scarred
quarantine_prooffalse clean use is blockedroute delay, recovery costblocked, recovery-only, or future proof receipt needed
false_clean_transfer_defaultimmediate pressure falls temporarilyfalse-clean transfer and hidden gaphostile, blocked, lawful-only, or recovery-only

Beat 4 - Future reader consumes the receipt

The result must mutate later play. A sealed chain can be cited, but only by its scoped reader. A split receipt can keep public and archive accounts both true while requiring reconciliation. A public counterstub can stop capture but cannot grant lawful safety. A rebuilt carrier path can unlock a route while exposing the carrier. A quarantine blocks the proof until a later receipt exists.

Beat 5 - False-clean transfer hardens

If the player or implementation hides source holder, carrier, scope, gap, receiving reader, or future effect, False-Clean Proof Transfer Default fires or arms.

Counters and state keys

  • custody_receipt_state: unopened | sealed | split | public_counterstub | lawful_annex | rebuilt | quarantined | false_clean_default_ready | recovery_only
  • proof_chain_integrity
  • archive_signature_legitimacy
  • public_receipt_legitimacy
  • carrier_burden
  • inspection_heat
  • sponsor_copy_pressure
  • route_asset_acceptance
  • recovery_cost
  • hidden_gap_debt

Replay/session evidence requirements

Worker evidence should include:

  • source proof object and source storyline;
  • seed and session id;
  • holder, carrier, receiving reader, and explicit absences;
  • selected branch;
  • before/after counters;
  • emitted or armed default events;
  • future reader effect and any blocked reader;
  • named reason when a transfer is not clean.

Explicit non-goals

  • Not a generic evidence log.
  • Not proof-board snapshot custody; this packet observes the transfer receipt after a proof object leaves its board or source scene.
  • Not archive enforcement; this packet can feed enforcement, but does not serve an order.
  • Not stabilization liability handoff; this packet moves proof, not debt ownership.
  • Not facility access; a room handoff can be one carrier, but the proof receipt is the tracked object.