Phantom Coverage Crosscheck / 幻覆盖交叉核验线

Phantom Coverage Crosscheck is a pressure-system storyline for the moment when an official call sheet, lane ledger, proxy seat, or roll-call receipt says a live route is covered, but a later reader discovers that the named body is absent, double-counted, proxied, or already consumed by another obligation.

杜眠通告单长线 proves that a live floor lane needs real coverage. 阮停空席引座员线 preserves an empty answerability seat. 漏点名复核线 checks whether a later reader can find the expected subject. This storyline binds the seam between them:

Can a covered lane be trusted when the person who covers it is missing from roll-call, sitting as a proxy, or being counted for a different future reader?

Why this fills a gap

The current corpus already prevents several clean lies:

  • a call sheet cannot make exhausted floor labor safe;
  • an empty chair cannot become answerability for every future reader;
  • a movement or service receipt cannot become universal roll-call proof.

The remaining gap is cross-desk laundering. A route can still cite coverage exists even when the coverage came from:

  • a worker who was absent from the floor;
  • a proxy who was seated for answerability, not lane work;
  • a protected witness or route asset double-counted as floor support;
  • a sponsor or management summary that translated absence into coverage;
  • a lawful-only roll-call receipt reused as public safety proof;
  • an explicit absence that was recorded in one desk but hidden from another.

This storyline makes the false coverage itself playable. The player must decide whether to verify the body, convert coverage into a limited proxy receipt, split the lane and seat, publish the absent coverage, quarantine the route, accept a limited scar, or let phantom coverage harden.

Bound content pack

  • 幻覆盖交叉核验机制 defines how call-sheet coverage, roll-call presence, answerability seating, and future route use are compared.
  • 幻覆盖案卷 records the alleged coverage row, challenged subject, absence or proxy state, harmed reader, beneficiary, selected posture, and future effect.
  • 幻覆盖交叉核验 resolves the row through verification, proxy conversion, split, publication, quarantine, limited use, or hardening.
  • 幻覆盖默认 fires or arms when a covered lane is consumed without reconciling the missing or double-counted body.

State-triggered entry

Open this storyline only from a live contradiction:

entry_state_required:
  trigger_kind: state_pressure
  official_coverage_claim_visible: true
  coverage_source_row_visible: true
  challenged_subject_visible_or_explicit_absence: true
  roll_call_or_answerability_conflict_visible: true
  harmed_reader_if_coverage_is_false_visible_or_explicit_absence: true
  beneficiary_of_false_coverage_visible_or_explicit_absence: true
  future_reader_or_route_consumes_coverage: true
  player_can_verify_convert_split_publish_quarantine_accept_or_harden: true
  non_neutral_default_exists: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_phase_trigger: true
  no_raw_staff_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

Valid coverage source rows include call-sheet load ledger, missing roll-call ledger, answerability seat docket, live-floor crew load row, crew refusal default payload, route-asset maintenance row, public safety receipt, lawful quiet check, sponsor schedule summary, or equivalent.

Storyline spine

Beat 1 - Coverage has already been cited

A schedule board, sponsor report, management metric, route asset reader, public recap, lawful table, archive release, or broadcast reality reader has already treated a lane as covered.

The coverage may claim staffed, proxy seated, roll-call satisfied, public safety certified, lawful body present, route asset escorted, or equivalent.

Beat 2 - A later reader finds the body missing or double-used

A second surface challenges the coverage:

  • Du Mian’s call sheet shows the lane was thin, coerced, absent, or wrong-team;
  • Ruan Ting’s empty-seat row shows the named body was sitting as proxy or absent;
  • missing roll-call cannot find the named worker, witness, route asset, or proof carrier;
  • a sponsor or management summary counts a protected person as floor labor;
  • a lawful-only presence receipt is being reused as public safety proof.

Beat 3 - The docket compares four locks

Phantom Coverage Docket must keep these locks separate:

phantom_coverage_row:
  coverage_lock:
    source_row: <row id>
    official_coverage_claim: staffed | proxy_covered | lawful_presence | public_safety_certified | route_asset_escorted | sponsor_summary | management_metric | equivalent
    covered_lane_or_obligation: <lane_or_obligation>
  subject_lock:
    challenged_subject: <person route asset proof carrier or explicit_absence>
    subject_state_elsewhere: present | absent | proxy_seated | protected | captured | double_counted | lawful_only | public_only | recovery_only | explicit_absence | equivalent
  reader_lock:
    harmed_reader_if_false: crew_lane | public_safety | lawful_reader | sponsor_reader | route_asset_reader | archive_reader | broadcast_reality | equivalent | explicit_absence
    beneficiary_of_false_coverage: producer | sponsor | management | archive | public_table | route_claimant | broadcast_reality | equivalent | explicit_absence
  future_lock:
    future_reader_or_route: <future consumer>
    route_effect_if_unresolved: blocked | costlier | public_only | lawful_only | sponsor_only | recovery_only | ending_scar | equivalent

Beat 4 - The player chooses the crosscheck posture

Run 幻覆盖交叉核验. The player may verify a named worker, convert coverage to a limited proxy receipt, split lane coverage from answerability, publish absent coverage, quarantine the route, accept limited coverage with scar, or harden the phantom coverage default.

Beat 5 - Coverage becomes future state, not cleanup text

Every branch must change the coverage state, subject state, and future route effect. A successful crosscheck may save one route, but it cannot make the original coverage universally safe.

Branch map

BranchImmediate reliefCost/scarFuture effect
Verify named workerreal body or explicit absence becomes visibledelay, exposure, overtime, or inspection heat risesverified coverage works only for named scope
Convert to proxy receiptfalse coverage stops claiming physical presencepublic distrust, lawful burden, sponsor pressure, or answerability cost risesproxy-only or lawful-only use
Split lane and seatfloor work and answerability stop sharing one bodyroute delay, split debt, management pressure risessplit-reader requirement before reuse
Publish absent coveragepublic reader sees the missing body or false safety claimsponsor stop-loss, public anxiety, worker exposure risepublic-only repair or contradiction addendum required
Quarantine covered routecontaminated coverage cannot enter clean route stateschedule pressure, route recovery cost, archive burden riseroute blocked or recovery-only until proof bridge
Accept limited coverageone reader may consume the claim with named scarharmed reader remains hostile or delayedlimited-use receipt, no cross-reader reuse
Harden phantom defaultfastest clean coverage remains officialfalse safety, hostile worker, empty seat, or roll-call debt hardensblocked, costlier, sponsor-only, lawful-only, recovery-only, or ending scar

No branch may let one covered lane satisfy every live-floor, roll-call, answerability, sponsor, lawful, public, route-asset, archive, and broadcast-reality reader.

Counter contract

Every constructive branch must mutate:

counter_deltas_required:
  relief: at_least_one
  cost: at_least_one
  future_route_or_reader_effect: at_least_one

Accepted surfaces include coverage_truth, phantom_coverage_pressure, crew_trust, public_safety_legitimacy, public_receipt_distrust, answerability_clarity, empty_seat_risk, roll_call_legibility, worker_exposure, protected_witness_payroll_due, sponsor_stop_loss_pressure, management_compression_pressure, inspection_heat, route_asset_integrity, schedule_pressure, split_reader_debt, and recovery_only_pressure.

Missability and recovery

This storyline is missed when a future route consumes covered-lane state while the challenged subject, proxy seat, explicit absence, harmed reader, or false-coverage beneficiary is hidden.

Missed or defaulted states include:

  • phantom_coverage_clean;
  • absent_body_counted;
  • proxy_counted_as_presence;
  • lawful_only_presence_reused_publicly;
  • protected_person_double_counted;
  • empty_seat_hidden_by_coverage;
  • roll_call_gap_hidden;
  • route_recovery_only.

Recovery is allowed only with scar: late body verification, public contradiction addendum, lawful-only narrowing, proxy unwinding, worker protection, route quarantine, call-sheet correction, empty-seat reopening, or recovery-only route use.

Replay evidence expectation

storyline_id: storyteller.storyline.phantom_coverage_crosscheck.v1
session_id: lens-phantom-coverage-crosscheck-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  official_coverage_claim_visible: true
  coverage_source_row_visible: true
  challenged_subject_visible_or_explicit_absence: true
  roll_call_or_answerability_conflict_visible: true
  future_reader_or_route_consumes_coverage: true
  no_fixed_turn_trigger: true
offered:
  card: storyteller.card.phantom_coverage_docket.v1
  rite: storyteller.rite.phantom_coverage_crosscheck.v1
branch_result:
  selected_posture: verify_named_worker | convert_to_proxy_receipt | split_lane_and_seat | publish_absent_coverage | quarantine_covered_route | accept_limited_coverage | harden_phantom_default
  coverage_state_after: <state>
  challenged_subject_state_after: <state or explicit_absence>
  harmed_reader_state_after: <state or explicit_absence>
  future_reader_or_route_effect: <effect>
  counter_deltas:
    relief: []
    cost: []
    future: []
default_branch:
  event_seen_or_armed: storyteller.event.phantom_coverage_default.v1
assertions:
  - entry_is_state_triggered_by_coverage_contradiction
  - coverage_subject_reader_and_future_locks_are_separate
  - branch_outcomes_diverge_by_crosscheck_posture
  - every_constructive_branch_has_relief_cost_and_future_effect
  - hardening_mutates_future_play
  - no_universal_clean_coverage
  - no_fixed_turn_day_phase_raw_staff_count_dashboard_or_lens_health_trigger

Non-goals

  • Not a duplicate of live-floor staffing.
  • Not a generic attendance check.
  • Not a replacement for answerability seating.
  • Not a way to make proxy coverage clean.
  • Not a fixed-turn aftercare scene.
  • Not valid unless the false coverage changes future route play.