Source Anonymity Escrow / 来源匿名托管线

Source Anonymity Escrow opens when a proof row, transcript line, counterreceipt, confidant promise, or witness route can help a future reader only if the source remains hidden from at least one other reader.

Existing pages already cover paying protected witnesses, preserving redacted transcript rows, shifting proof burden, and challenging excluded receipts. This storyline covers the missing management question between them: who can rely on an unnamed source, who is allowed to audit the shield, and what happens if the game treats anonymity as either free proof or automatic disclosure?

Primary playable question

When an anonymous source makes a route, proof claim, public receipt, lawful annex, sponsor defense, or broadcast correction possible, does the player seal the identity in escrow, disclose under lawful seal, publish an anonymous public proof, substitute another proof, pay and shield the source, split reader access, reject the source, accept sponsor exposure, or let forced disclosure harden?

A valid answer must name:

  • the source claim;
  • the protected source or explicit absence;
  • the reader requesting proof;
  • the reader from whom the source remains hidden;
  • the escrow holder, shield, substitute proof, or explicit absence;
  • the future route or reader that consumes the anonymity state.

State-triggered entry

Open this storyline only from live state pressure:

entry_state:
  trigger_kind: state_pressure
  source_claim_present: true
  anonymous_or_protected_source_visible_or_explicit_absence: true
  future_reader_demands_proof: true
  disclosure_target_or_hidden_reader_visible: true
  escrow_holder_or_shield_or_explicit_absence_visible: true
  substitute_proof_or_explicit_absence_visible: true
  future_route_consumes_anonymity_state: true
  player_can_escrow_disclose_publish_substitute_pay_split_reject_expose_or_default: true
  no_fixed_turn_trigger: true
  no_fixed_day_or_week_trigger: true
  no_raw_source_count_trigger: true
  no_dashboard_or_lens_health_trigger: true

The line fails if it opens from generic secrecy, a raw witness count, a fixed episode step, dashboard/lens health, or a clean “anonymous tip” scene with no future reader.

Bound content pack

  • 来源匿名托管机制 defines the visibility split between proof reader, hidden reader, escrow holder, shield, substitute proof, and forced disclosure.
  • 来源匿名托管案卷 records claim, protected source, proof reader, hidden reader, shield, substitute proof, and future consumer.
  • 来源匿名托管听证 assigns escrow, disclosure, publication, substitution, payment, split access, rejection, sponsor exposure, or default.
  • 来源披露默认 fires when an unnamed source becomes free proof or is exposed without holder, shield, substitute proof, or future route cost.

Storyline spine

Beat 1 - A source claim becomes useful

A transcript line, protected witness, confidant promise, counterreceipt, payroll row, caption proof, route log, or public receipt contains a source that cannot be safely named to every reader.

The source claim cannot be only atmosphere. It must be about to affect a route, proof burden, lawful annex, public correction, sponsor defense, archive custody, or broadcast reality state.

Beat 2 - Readers diverge

The proof reader may be lawful body, public table, archive, inspector, sponsor, route claimant, editor, fan oxygen queue, harmed artist, or broadcast reality.

The hidden reader may be sponsor, public table, archive, inspector, hostile claimant, editor, fan queue, pirate relay, management, route asset, or explicit absence.

Both must be recorded. Anonymous proof fails if no one is named as entitled to read it and no one is named as shielded from it.

Beat 3 - Escrow is assigned

Run 来源匿名托管听证 before the future route consumes the claim.

The hearing requires docket, source claim, proof reader, hidden reader, source protection state, escrow holder or shield, substitute proof or absence, and selected posture.

Beat 4 - Anonymity and proof diverge

A source can stay anonymous while lawful proof exists; public proof can stay anonymous but fail lawful admissibility; sponsor disclosure can solve one route while poisoning a witness; substitute proof can protect the source but weaken scope.

Beat 5 - Default forces disclosure or free proof

If the source claim is consumed with no escrow state, 来源披露默认 records whether the failure became forced disclosure, free anonymous proof, sponsor outing, public doxxing, lawful-only silencing, or recovery-only route.

Branch map

BranchReliefCostFuture route effect
Escrow sealed sourceproof remains usable for scoped readerholder burden, audit heatescrow receipt required
Lawful sealed disclosureadmissibility improvespublic distrust, bureau debtlawful-only or appeal path
Anonymous public proofpublic repair improveslawful risk, source exposurepublic-only proof; audit later
Substitute proofsource stays hiddenweaker proof, route delaysubstitute bridge required
Pay and shield sourcewitness survivespayroll, capacity, sponsor heatprotected witness route remains
Split reader accessreaders get different truthscontradiction pressuredual-reader table required
Reject anonymous sourcefalse proof blockedroute may stallproof burden remains open
Sponsor exposuresponsor pressure falls nowhostile source, public scarsponsor-only or recovery route
Forced disclosure defaultimmediate burden may fallsource harm, proof poisonappeal, correction, or recovery-only

Counter contract

Every constructive branch must mutate at least one relief surface, one cost surface, and one future reader surface.

counter_surfaces:
  relief:
    - source_safety
    - proof_admissibility
    - public_receipt_legitimacy
    - route_unlock_pressure
    - witness_continuity
  cost:
    - escrow_holder_burden
    - inspection_heat
    - public_distrust
    - payroll_cost
    - sponsor_retaliation
    - contradiction_pressure
    - source_exposure_risk
  future:
    - escrow_receipt_required
    - lawful_only
    - public_only
    - substitute_bridge_required
    - protected_witness_route_open
    - dual_reader_table_required
    - proof_burden_open
    - sponsor_only
    - recovery_only

Character and faction hooks

  • 郁蓝 can publish anonymous public proof, but public repair is not lawful admissibility.
  • 韩砚霜 can hold lawful sealed disclosure, but bureau debt and lawful-only routing rise.
  • Baiya can provide substitute checksum proof or masked continuity, but source ambiguity and edit debt rise.
  • Shen Luo can negotiate sponsor exposure or quiet money, but witness loyalty and future blackmail worsen.
  • Redaction Stenographer can preserve a transcript source row, but needs shield, payroll, or explicit absence.

Missability and recovery

This storyline is missed when implementation:

  • lets an unnamed source satisfy all readers as clean proof;
  • forces source disclosure without holder, shield, or route cost;
  • records protected witness state but not proof reader and hidden reader;
  • records redaction but not anonymity consumer;
  • lets sponsor exposure count as public repair;
  • lets public anonymous proof count as lawful admissibility;
  • triggers from fixed turn, fixed day/week, raw source count, dashboard state, or lens health.

Recovery is allowed only through visible scar: late escrow receipt, lawful annex, public correction, substitute proof bridge, witness payroll reopen, sponsor exposure unwind, source apology, appeal, route quarantine, or recovery-only proof.

Replay evidence expectation

storyline_id: storyteller.storyline.source_anonymity_escrow.v1
session_id: lens-source-anonymity-escrow-v1-<timestamp>
seed: <deterministic-seed>
entry_state:
  trigger_kind: state_pressure
  source_claim_present: true
  anonymous_or_protected_source_visible_or_explicit_absence: true
  future_reader_demands_proof: true
  disclosure_target_or_hidden_reader_visible: true
  future_route_consumes_anonymity_state: true
  no_fixed_turn_trigger: true
offered:
  card: storyteller.card.source_anonymity_escrow_docket.v1
  rite: storyteller.rite.source_anonymity_escrow_hearing.v1
branch_result:
  selected_posture: escrow_sealed_source | lawful_sealed_disclosure | anonymous_public_proof | substitute_proof | pay_and_shield_source | split_reader_access | reject_anonymous_source | sponsor_exposure | forced_disclosure_default
  source_state_after: <state>
  proof_reader_state_after: <state>
  hidden_reader_state_after: <state>
  future_route_effect: <effect>
default_branch:
  event_seen_or_armed: storyteller.event.source_disclosure_default.v1
  disclosure_failure_kind: <kind>
assertions:
  - entry_is_state_triggered
  - proof_reader_and_hidden_reader_are_visible
  - holder_shield_or_substitute_proof_is_visible_or_explicit_absence
  - anonymity_and_proof_can_diverge
  - default_forced_disclosure_is_durable
  - no_fixed_turn_day_week_raw_count_dashboard_or_lens_health_trigger

Non-goals

  • Not another generic secret tip.
  • Not a replacement for witness payroll, transcript redaction, or proof burden reassignment.
  • Not a stealth-only branch; every result must change future reader state.