Signal Escrow Readback / 信号托管回读
Signal Escrow Readback is the storyline for resolving a live broadcast signal whose custody is disputed while the broadcast is still reality-bearing.
A broadcast outage can be stabilized by placing the live signal in escrow, but the act cannot be invisible. The player must read back who holds the signal, who may still receive it, who is cut out, what proof bridges the claim, and what future route becomes narrower, costlier, quarantined, or recovery-only.
The pressure is not a fixed turn. It appears when a live signal is being patched through conflicting sponsor, public, inspector, archive, editor, or fan relay custody claims.
Playable question
When a live signal can be repaired only by putting it under custody, does the player split the feed, warehouse it with a sponsor, quarantine it with an inspector, delay it for an editor checksum, return it to a fan relay with liability, or refuse the escrow and let a false-clean seizure default fire?
The answer must name:
- the signal row and affected broadcast or route asset;
- holder before and holder after;
- authorized reader;
- excluded reader;
- proof bridge or explicit absence;
- selected custody posture;
- relief, cost, and at least three counter deltas;
- future route effect.
Gap diagnosis
The existing corpus already has custody proof, route asset, lawful annex, and broadcast-reality lanes. The missing seam is the live signal itself: once a signal outage is patched, later play can treat the feed as repaired unless the custody readback makes holder, reader scope, excluded reader, and future effect durable.
Without this storyline, implementation can:
- treat a sponsor-only feed as a public repair;
- quarantine a live feed without naming the reader who lost access;
- let an editor checksum delay erase fan relay or lawful reader claims;
- cite a patched signal as clean proof even when the bridge was absent;
- convert refusal into generic outage recovery instead of a named recovery-only state.
State-triggered entry
Open this storyline only when a live signal is about to be consumed as broadcast reality, route proof, lawful annex, public receipt, sponsor asset, archive material, editor continuity, or fan relay evidence:
entry_state_required:
trigger_kind: state_pressure
live_signal_visible: true
custody_claim_visible: true
holder_before_visible: true
authorized_reader_visible: true
excluded_reader_visible_or_explicit_absence: true
proof_bridge_visible_or_explicit_absence: true
future_route_or_reader_consumes_signal_state: true
player_can_split_warehouse_quarantine_checksum_return_refuse_or_default: true
no_fixed_turn_trigger: true
no_fixed_day_trigger: true
no_raw_pool_trigger: true
no_dashboard_or_lens_health_trigger: trueBound content pack
- 信号托管回读机制 defines the escrow row, state machine, branch contract, and false-clean default.
- 信号托管回读案卷 records signal id, holder before/after, authorized reader, excluded reader, proof bridge or absence, future route effect, and counter deltas.
- 信号托管回读 resolves split feed, sponsor warehouse, inspector quarantine, editor checksum, fan relay liability, or refusal/default.
- 信号托管伪清洁默认 records missing readback, hidden excluded reader, seized signal state, recovery-only future, and counter deltas.
- Signal Escrow Readback Lens observes the implementation contract.
Storyline spine
Beat 1 - The signal becomes a contested object
A live feed, delayed feed, archive feed, sponsor feed, or fan relay cannot be patched cleanly. Create or refresh Signal Escrow Readback Docket before the signal is consumed by a later route.
Beat 2 - Reader scope becomes visible
The docket names the current holder, proposed holder, authorized reader, excluded reader, and proof bridge. Explicit absence is allowed, but implied access is not.
Beat 3 - Custody posture prices the repair
Run Signal Escrow Readback. Every posture must change holder state and leave relief, cost, counters, and a future route effect.
Beat 4 - Future play inherits the signal state
Later route, archive, lawful, public, sponsor, editor, fan relay, or broadcast-reality surfaces consume future_route_effect, not a generic signal_fixed flag.
Beat 5 - Refusal creates false-clean seizure
If the readback is refused or skipped, Signal Escrow False-Clean Default records the hidden excluded reader and pushes later play into recovery-only or named readback repair.
Branch map
| Branch | Immediate relief | Cost/scar | Future state |
|---|---|---|---|
| Split public/lawful feed | public receipt and lawful archive both survive | sponsor route narrows | split_feed_required |
| Sponsor warehouse rider | capacity stabilizes | public/lawful routes become costlier | sponsor_only_costlier |
| Inspector quarantine hold | false-clean fraud drops | appeal or audit debt rises | quarantine_appeal_required |
| Editor checksum delay | continuity improves | audience churn and edit debt rise | checksum_delay_required |
| Fan relay liability scar | public trust rises | sponsor retaliation and recovery cost rise | fan_relay_liability_scar |
| Refuse escrow default | none | hidden excluded reader and seizure harden | recovery_only |
No branch may create a universal clean signal fixed result.
Missability and recovery
This storyline is missed when implementation:
- patches a signal without holder before and after;
- records authorized reader but hides the excluded reader;
- accepts a proof bridge without source row or explicit absence;
- treats sponsor, public, lawful, archive, editor, inspector, and fan readers as one audience;
- resolves from fixed turn, day, raw pool size, dashboard state, or lens health;
- mutates only a stability counter without future route effect.
Recovery requires reopening the docket, narrowing reader scope, adding a checksum, splitting the feed, placing the signal under lawful or inspector hold, attaching a liability scar, or routing the signal to recovery-only play.