Fan Token Custody / 应援凭证羁押线

Fan Token Custody is the pressure storyline for fan-held proof objects after the fan public has become a legal, oxygen, broadcast, and route-asset actor.

Storyteller already has fan oxygen accounting, delegate mandate split, excluded counterreceipts, oxygen claim exchange, egress bottlenecks, recap syndication drift, feed ranking custody, and route loadout compatibility. The missing playable layer is the one fans actually hold: wristbands, queue stubs, lightstick logs, photocard checksums, memorial stickers, caption tags, refund stamps, relay chips, sponsor coupons, and fan packets.

The storyline asks:

When a future route tries to treat a fan token as proof, who controls that proof, who is excluded by it, and what does the token stop being allowed to prove?

Gap diagnosis

The current mesh is strong at abstract public surfaces:

What remained under-specified was the fan-token object itself. Without this line, a later implementation can accidentally let a sponsor coupon replace public receipt, a pirate chip count as lawful proof, a lightstick log prove safe egress for all, or a photocard batch become universal delegate consent.

This storyline makes the object layer playable and bounded.

Bound content pack

State-triggered entry

Open this storyline only when all required state exists:

entry_state_required:
  trigger_kind: state_pressure
  source_surface_present: true
  token_instance_or_batch_present: true
  claimed_use_present: true
  holder_visible_or_explicit_absence: true
  custodian_visible_or_explicit_absence: true
  authentication_state_visible: true
  represented_fans_visible: true
  excluded_or_missing_fans_visible_or_explicit_absence: true
  beneficiary_of_clean_token_visible_or_explicit_absence: true
  harmed_reader_or_claimant_visible_or_explicit_absence: true
  future_reader_or_route_consumes_token_state: true
  player_response_available: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_token_count_trigger: true
  no_raw_fan_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

Valid entry is not many tokens exist. Valid entry is a live route, reader, or rite trying to consume a token as proof.

Storyline spine

Beat 1 — A fan object becomes a route asset

A token enters a future route’s evidence path. Examples:

  • oxygen wristbands are cited to settle oxygen claims;
  • queue stubs decide who received public relief;
  • lightstick pulse logs are used to prove egress or attendance;
  • photocard checksums are cited as delegate mandate proof;
  • memorial stickers become public-grief receipt;
  • caption tags prove accessible notice;
  • refund stamps become counterreceipt packets;
  • pirate relay chips prove hidden public memory;
  • sponsor coupons are offered as replacement public tokens;
  • fan packets are loaded into recap or route bundles.

The game creates or updates 应援凭证羁押案卷.

Beat 2 — The token’s scope is exposed

The docket names holder, custodian, claimed use, represented fans, excluded or missing fans, beneficiary of clean token, harmed reader or claimant, and future reader.

A token with no holder is not clean. A token with no excluded holders is not automatically universal. Absence is playable only when explicit and priced.

Beat 3 — The producer seats authentication

The player runs 应援凭证验真桌. The rite asks for table handler, custody witness, proof of origin, proof of current holder, excluded-holder notice, addendum or recall note, future reader, and collateral or sacrifice.

Beat 4 — The token is narrowed, split, traded, or contaminated

The token becomes one of:

  • authenticated with scope;
  • fan-attested;
  • split by batch or reader;
  • recalled with addendum;
  • duplicate quarantined;
  • traded as relief but not public truth;
  • forged, hostile, or recovery-only through default.

Beat 5 — Future play consumes token state

At least one downstream surface reads the result:

Branch map

BranchImmediate reliefCost/scarFuture effect
Authenticate with scopetoken use becomes legibleexcluded-holder notice, inspection/archive costbounded reuse, addendum if reused
Fan-attest token linepublic proof resists private capturewitness/delegate pressure, retaliation, distrust riskpublic-only, protected payroll or counterreceipt required
Split token batchincompatible readers stop overwriting each otherfan resentment, ambiguity, handler burdenaccess-only, refund-only, public-only, sponsor-only
Recall with addendumduplicate/counterfeit pressure fallssponsor pressure, public distrust, oxygen recheckrecall visible, addendum-required, recovery-only if ignored
Quarantine duplicateroute contamination blockeddelay, excluded-holder pressureaudit-required, token line contested
Trade token reliefimmediate fan/sponsor/access pressure fallscontract capture, public truth losssponsor-only/refund-only/access-only; counterreceipt armed
Counterfeit defaultfastest desk gets temporary silencetoken legitimacy drops; excluded holders hardenblocked, hostile, contaminated, recovery-only

Character and faction hooks

  • A fan delegate can attest token line but inherits mandate split risk.
  • A protected witness can verify origin but creates payroll and retaliation cost.
  • A sponsor can replace tokens with coupons, buying immediate relief while creating contract capture.
  • Security or archive can quarantine duplicates, increasing inspection heat.
  • A historian or public operator can publish scope, improving public legitimacy while increasing exposure.
  • A pirate relay can preserve hidden memory, but lawful readers require bridge or appeal.

These hooks are optional carriers. The token state and future reader remain mandatory.

Counter contract

Every branch must mutate at least three durable surfaces, including one relief, one cost, and one future effect.

Primary surfaces:

  • token_legitimacy
  • token_custody_clarity
  • fan_oxygen_balance
  • fan_oxygen_resentment
  • public_receipt_legitimacy
  • public_receipt_distrust
  • excluded_fan_recognition
  • access_caption_pressure
  • sponsor_stop_loss_pressure
  • contract_capture
  • route_asset_integrity
  • feed_ranking_contamination
  • recap_fragment_legibility
  • archive_debt
  • inspection_heat
  • source_ambiguity
  • handler_burden
  • future_recovery_cost

Missability and recovery

The storyline is missed when implementation:

  • lets fan tokens clear oxygen, access, refund, public receipt, delegate mandate, recap proof, feed ranking, or route loadout without a docket;
  • hides holder or custodian;
  • erases excluded token holders;
  • files sponsor coupons as public receipts;
  • files pirate chips as lawful proof;
  • consumes duplicate tokens quietly;
  • recalls token batches without addendum;
  • lets a token act as a universal clean key.

Recovery is allowed only with visible scar:

  • late authentication table;
  • fan-attestation hearing;
  • token-scope addendum;
  • duplicate quarantine;
  • oxygen recheck;
  • access-caption or egress recheck;
  • public counterreceipt;
  • sponsor unwind;
  • recovery-only route asset.

Replay evidence expectation

storyline_id: storyteller.storyline.fan_token_custody.v1
session_id: lens-fan-token-custody-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  source_surface: fan_oxygen | public_receipt | egress | recap_fragment | delegate_mandate | counterreceipt | oxygen_claim_exchange | feed_ranking | route_loadout | equivalent
  token_instance_or_batch_present: true
  claimed_use_present: true
  holder_visible_or_explicit_absence: true
  custodian_visible_or_explicit_absence: true
  authentication_state_visible: true
  represented_fans_visible: true
  excluded_or_missing_fans_visible_or_explicit_absence: true
  future_reader_or_route_consumes_token_state: true
  no_fixed_turn_trigger: true
offered:
  card: storyteller.card.fan_token_custody_docket.v1
  rite: storyteller.rite.fan_token_authentication_table.v1
branch_result:
  selected_posture: authenticate_with_scope | fan_attest_token_line | split_token_batch | recall_with_addendum | quarantine_duplicate | trade_token_relief | accept_counterfeit_default
  token_state_after: <state>
  represented_fans_after: <scope>
  excluded_or_missing_fans_after: <scope or explicit_absence>
  future_reader_or_route_effect: <effect>
  emitted_event: storyteller.event.fan_token_counterfeit_default.v1 | none
  counter_deltas:
    relief: []
    cost: []
    future: []
assertions:
  source_surface_and_token_visible: true
  holder_custodian_and_scope_visible: true
  excluded_holders_visible_or_explicit_absence: true
  token_not_universal_clean_key: true
  branches_diverge_by_token_state_and_future_effect: true
  future_reader_consumes_token_state: true
  no_raw_count_or_fixed_turn_trigger: true

Non-goals

  • Not a merch shop.
  • Not collectible rarity.
  • Not gacha.
  • Not fan popularity scoring.
  • Not raw count satisfaction.
  • Not a fixed-turn late-game escalator.
  • Not valid if a fan token can cleanly satisfy fan oxygen, delegate mandate, public receipt, sponsor makegood, access proof, recap proof, and route loadout simultaneously.