Revocation Window Readback

A route asset that once looked safe can be consumed by a future reader after its consent, proxy, or custody authority has become revocable. The player must not be allowed to treat the old grant as permanent unless the revocation window is read back.

Playable pressure

The pressure appears when a future route attempts to rely on a prior grant and the repo can name all of these fields:

  • route_asset
  • original_grant
  • revoking_claimant_or_absence
  • affected_future_reader
  • notice_carrier
  • proof_receipt_or_absence
  • window_state
  • accepted_cost
  • future_route_effect

The trigger is trigger_kind: state_pressure; it is not a turn timer, not a day/week timer, and not a dashboard/lens-health event.

Branch families

  1. honor_revocation_readback — publish the notice and carry a bond into the future route.
  2. lawful_window_annex — preserve use only with lawful annex and inspection heat.
  3. public_counter_notice — let public readers challenge the old grant with receipts.
  4. sponsor_holdback — pay sponsor holdback while making future reliance narrower.
  5. editor_checksum_reissue — reissue a corrected asset with edit debt.
  6. split_revocation_escrow — split future use between claimant and archive custody.
  7. default_false_clean_reliance — ignore the window and harden the route into recovery-only.

No branch is a universal clean waiver; each branch names a claimant/reader state, cost, and future route effect.