Recovery Counterstub Provenance / 复原副签来源线

Recovery Counterstub Provenance is the system-facing wrapper above the Cen Kou character route. It begins when a scarce recovery row is being cited, released, archived, or reallocated and the only visible authority is a low-rank counterstub.

The character page answers what happens to Cen Kou. This storyline answers what happens to the row: which reader may rely on the counterstub, which reader is excluded or blamed, and which future route inherits the worker-liability scar.

Why this wrapper exists

The current corpus already has:

The missing observable surface was the system readback between those layers. A worker signature can still be laundered as if it closed sponsor, archive, ward, fan oxygen, public, lawful, management, schedule, and route-asset readers at once. This storyline forces the counterstub row to remain scoped after the character state changes.

State-triggered entry

Open this storyline only when all conditions are present or explicitly absent:

entry_state_required:
  trigger_kind: state_pressure
  finite_recovery_row_present_or_explicit_absence: true
  counterstub_state_visible: true
  afteruse_archive_or_reallocation_claim_present: true
  competing_claims_min: 2
  desired_reader_present: true
  excluded_or_blamed_reader_present_or_explicit_absence: true
  counterstub_holder_or_explicit_absence_visible: true
  future_route_effect_pending: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

Invalid entries include generic sponsor pressure, generic archive review, raw low inventory, fixed calendar timing, dashboard state, or a clean character-recruitment event with no contested recovery row.

Storyline spine

Beat 1 - The counterstub becomes the proof surface

A recovery row is no longer just inventory. A sponsor, archive clerk, ward queue, fan oxygen reader, schedule desk, lawful reader, public reader, management report, or route asset wants to treat the row as proof.

The game creates or updates Recovery Counterstub Docket with:

counterstub_story_row:
  recovery_row:
    inventory_id: <stable row id or explicit_absence>
    inventory_kind: <kind>
    quantity_state_before: <state>
  counterstub:
    counterstub_id: <stable id or explicit_absence>
    counterstub_state: <state>
    named_holder_or_absence: cen_kou | unnamed_worker | handler_absence | explicit_absence | equivalent
    signature_pressure: voluntary | protected | coerced | bribed | blamed | absent | unknown | equivalent
  readers:
    desired_reader: <reader>
    excluded_or_blamed_reader: <reader or worker or explicit_absence>
    minimum_surface_for_desired_reader: <surface>
    minimum_surface_for_excluded_reader: <surface or explicit_absence>
  liability:
    blamed_actor_or_absence: <actor or explicit_absence>
    scapegoat_risk: none | low | rising | active | locked
  future_route_effect: <effect>

Beat 2 - The holder state and row scope split

The player may protect Cen Kou, recruit them, miss them, coerce them, or record explicit absence. That state matters, but it does not decide the row by itself.

The storyline must still answer whether the counterstub is accepted with cost, split, archive-locked, sponsor-only, lawful-only, public-only, recovery-only, blocked, or defaulted.

Beat 3 - Counterstub hearing assigns reader scope

Offer Recovery Counterstub Hearing once the docket is concrete. The rite assigns holder, row, reader, proof bridge, handler, excluded reader, and selected mode.

Valid modes:

  • protect_holder;
  • split_counterstub;
  • archive_lock;
  • sponsor_release;
  • recovery_reallocate;
  • refuse_false_stub;
  • scapegoat_default.

Beat 4 - Readers diverge

Every branch must leave at least two readers in different states. A valid branch can improve sponsor pressure while making public readers hostile, improve archive confidence while blocking sponsor afteruse, return a row to recovery while making management reports costlier, or protect a worker while forcing a schedule reader to wait.

A branch fails if sponsor, archive, public, ward, fan oxygen, lawful, management, schedule, and route-asset readers all accept the same counterstub as clean proof.

Beat 5 - Scapegoat default remains armed

If the player consumes the row without naming holder, signature pressure, desired reader, excluded reader, and future scar, Recovery Counterstub Scapegoat Default fires or arms.

The default must not be just a worker morale penalty. It must change future route recovery cost, archive counterstub debt, public or fan distrust, inspection heat, or a reader collision state.

Branch matrix

BranchImmediate reliefCost / scarFuture state
Protect holdercounterstub integrity rises; false clean claim weakenshandler burden, inspection heat, or sponsor pressure risesworker protected, accepted-with-counterstub, recruit window
Split counterstubone reader is unblocked without erasing anothersource ambiguity, archive debt, or public distrust risessplit-required, sponsor-only, archive-only, lawful-only, or public-only
Archive lockoriginal trace and lawful confidence improvesponsor, schedule, ward, or fan delay risesarchive-only, checksum-required, recovery-only until release
Sponsor releasestop-loss or commercial route pressure fallscontract capture, public distrust, worker risk risessponsor-only, unwind-required, hostile public/lawful reader
Recovery reallocateward, fan oxygen, or recovery route improvessponsor, archive, or management pressure risesrecovery-only, sponsor afteruse blocked, proof bridge required
Refuse false stubblamed worker is protected and false proof blockedimmediate schedule, sponsor, archive, or handler pressure risesblocked, costlier, contradiction-pending
Scapegoat defaultcapturing desk gets short-term reliefworker scapegoat risk and counterstub debt risesponsor-only, archive-only, recovery-only, hostile worker, blocked, or costlier

Lens contract

Recovery Counterstub Provenance Lens should pass only when the implementation proves:

  • this system storyline exists alongside the Cen Kou character storyline;
  • entry comes from recovery-row/counterstub state pressure, not fixed chronology;
  • the docket records row, holder or absence, signature pressure, desired reader, excluded reader, liability state, and future route effect;
  • the hearing exposes divergent branch families rather than universal acceptance;
  • the default records a false-clean claim, blamed holder or absence, hidden reader, and durable future scar.

Non-goals