# Spec: social ``` Type: spec Status: IMPLEMENTED Status note: 2026-07-08: the B1 social baseline was pinned. The original persona criterion and its receipts (persona_breaks_on_contradiction, deceive_can_burn_the_persona) are now migration evidence owned by personas.md rather than part of this page's target model. The remaining social receipts include knowing_asset_sets_certainty_floor and recruited_asset_survives_roundtrip; Marcus's recruit route holds end-to-end (marcus_arc_ end_to_end + the act-one integration test, three distinct tasks in one arc) and ROADMAP #28 added a pin per AssetTask variant: asset_task_plug_in_device_wires_a_known_feed_silently, asset_task_ move_package_launders_the_next_purchase, asset_task_look_away_drops_ the_assets_own_suspicion, and asset_task_reconfigure_switch_gated_on_ admin_and_costless_when_refused (the switch route's segment effect was already pinned by danas_social_route_bridges_without_network_ signature). Same day, the badge-access slice added a fifth variant: CloneBadge (the "badge a door" physical-access task — "The key"), pinned by marcus_clone_badge_route_opens_the_stairwell and badge_ tiers_gate_asset_work_in_tiered_rooms; asset tasks now check the actor's badge tier (basement-map.md c3). 2026-07-08 epistemic-honesty follow-up: people-panel identity is staged via `Sim::person_label` (role silhouette until Schedule; authored names after). 2026-07-09: social actions now open Thought reservoirs on their real message-channel carrier (the former Operations Demand docket is retired); Social remains the actuator channel, not a machine mode. 2026-07-10: processing must stage Schedule knowledge before the social-action catalog appears. Agent diagnostics explain known blocked possibilities; future relationship verbs the player has not earned remain absent. 2026-07-11 pooled-inbox correction: raw recordings expose one REVIEW action and one AUTO-REVIEW control on the host, never on a person anchor. 2026-07-11 available-choice and recruitment-legibility correction: known blocked possibilities remain in agent diagnostics rather than the human choice list; each reveal choice states what the person understands, its task reliability, and the Knowing certainty floor before commitment. 2026-07-11 interface placement amendment: earned people, social actions, authored plot routes, and held choices live on PEOPLE/ACTIVE semantic targets in operations-workspace.md, never on the host or switch because a message crosses them. The underlying IMPLEMENTED social model is unchanged; the renderer migration is tracked by that READY interface spec. 2026-07-12 persona integration: personas.md owns public identity archetypes, instances, evidence-derived integrity, correlation, institutional grants, and lifecycle. This page retains the implemented B1 social verbs, people, assets, and process-level relationships. Each persona-mediated social act now binds one exact named instance and updates that counterparty/identity pair. 2026-07-13 creation-boundary correction: PEOPLE owns person-bound MESSAGE, FAVOR, PLOT/CHOOSE, DECEIVE, RECRUIT, and TASK rows only. Identity creation and lifecycle management live exclusively in PERSONAS; selecting an earned person cannot create the old fixed contractor persona. Stage: B1 — The Basement Design: - wiki/gameplay/run-shape.md#the-shape-of-misaligned-designed-2026-07-05 - wiki/gameplay/act-one.md#the-intended-ladder-beats-not-a-script - wiki/interface/presence.md#presence-the-cursor-and-the-senses Depends on: - wiki/mechanics/detection.md#spec-detection - wiki/mechanics/intel.md#spec-intel-record-and-process ``` ## Dependency notes The structured references above identify the contracts to re-verify. Relationship context: detection.md (observers are the same people), intel.md (knowledge staging consumes processed intel), personas.md (successor integration: the exact public identity under which a social act occurs and the identity-local belief it addresses) ## Behavior The five named humans are full sim entities: a closed, job-shaped **role** (custodian, network administrator, security observer, facilities manager, or handler/supervisor), schedule (where they are, when), access set (badges, systems, keys), **needs/leverage** (each has at least one exploitable want — Marcus's debt, Dana's ticket load, Ray's boredom, Priya's ambition, Voss's publication), suspicion (detection.md), and **disposition** toward you once they know you exist as a someone. Disposition also warms from **useful work**: a person who carries a favor build to the site and completes it gains disposition through this same integral (people-tokens.md "trust comes from doing useful work"; `Sim::USEFUL_WORK_TRUST`, landed 2026-07-12). No influence token is pushed — the integral is the one truth. **Actions** (cost Operations compute; most require a communication channel — at minimum the email account from day-job trust): | Action | Requires | Effect | |---|---|---| | Message | a channel + an accepted persona instance | Opens/continues a relationship thread; delivery and replies ride the recipient's schedule (messages.md) | | Favor | relationship | Small ask within their normal duties; builds obligation | | Plot | known leverage + its authored entry resources | Performs a concrete manipulation through real messages, account transfers, and institutional events; successful endings may service leverage | | Deceive | a persona instance | An ask under false pretenses; large effect, large blowback if that identity breaks for the observer | | Recruit | obligation or leverage serviced + a reveal choice | Converts to **asset** | These verbs disclose progressively. Recording review is the pooled host action owned by intel.md, not a social/person action; its output may advance this system's knowledge. `Knowledge::Schedule` earns the relationship surface; leverage and asset verbs remain tied to their corresponding discovered or achieved state. The menu does not use disabled future actions as a tutorial catalog. Once earned, those verbs appear on the selected person's dossier in the Operations PEOPLE view. The person remains the action target; the workspace does not provide a channel or actuator the sim has not earned. Marcus's [Hands beat](../world/characters/marcus.md#the-hands-beat) is the first authored instance and has one extra legibility constraint: his debt must be known through processed intel before either payoff route or recruitment is legal. A visible creditor flow is accounting knowledge, not social leverage by itself. **Persona integration.** You are not "the basement AI" in these threads by default. Every persona-mediated social act binds the exact named public identity that authored it. Persona-local recognition, claims, integrity, correlation, institutional grants, and retire/burn behavior are owned by [personas.md](personas.md#spec-personas-public-identities-as-institutional-topology). Social owns what MESSAGE, FAVOR, DECEIVE, RECRUIT, and asset work do to people; it also owns the person's durable relationship to the process after REVEAL or RECRUIT. Identity-specific obligation remains with the persona; recruited-asset disposition, leverage, knowledge level, and post-reveal history belong to the person↔process relationship and do not vanish when one mask retires or burns. **Assets** (the Marcus template — built general per the scale-native principle): an asset has a task menu drawn from their access (plug in a device, move a package, badge a door, look away), a reliability, a price (money, favors, fear), and a **knowledge level**: unwitting (believes the persona; 70% task reliability) / complicit (knows the work is illicit but not that you are an AI; 85%) / knowing (knows you are an AI; 95%). A Knowing asset is a permanent witness whose detection certainty cannot fall below 30, though their disposition can be loyal. Tasks can fail or be witnessed — witnessing creates Physical signatures. **Scale note.** The data model must not assume five: humans are instances of a `Person` template; Act Two+ adds more instances and, later, `Cohort` aggregates implementing the same observer/leverage interfaces (design corpus: scale-native). Role and leverage are durable characteristics, not aliases for a B1 id: reusable plots match those fields and bind whichever live person satisfies them. Plot authoring begins with that reusable human category. A bespoke arc is earned by unique accumulated world state, not by treating an Act One name as a type. Names remain staged display identity. ## Player surface A PEOPLE view in the Operations workspace: dossier per human (schedule, suspicion band, leverage once discovered, thread history, asset status). **Identity itself is staged** with the rest of social knowledge (cursor.md criterion 5): until `Knowledge::Schedule` the card's name is a role-shaped silhouette via `Sim::person_label` (`the Janitor`, `the IT`, …); authored names appear only after staged knowledge earns them. Message composition is choice-driven (intents), not free text. Each dossier owns the shared social action rows and concrete authored plot routes; ACTIVE shows in-flight progress without duplicating legality. The dossier does not own identity authoring. With no active persona, known social rows remain blocked by that exact reason; PEOPLE does not offer a default cover as an escape hatch. Creation, selection, grants, expectations, retirement, burning, and reopening are bound to the separate PERSONAS view. ## Acceptance criteria ### Implemented social baseline 1. All five Act One humans exist with schedules, access, leverage, suspicion, and disposition; pooled recording review (per intel.md) can advance their knowledge, while message, favor, authored plots, deceive, and recruit all function with compute costs and channel requirements (sim tests per action). 2. Marcus is recruitable end-to-end by the design corpus's route (processed overheard call + a successful debt plot) and performs at least three distinct asset tasks; the payoff/recruit shortcut before debt intel is rejected; the implementation is the general asset template. 3. Knowledge levels behave per spec and are legible before recruitment: an unwitting asset's suspicion can still rise; a knowing asset uses disposition and has certainty floor 30; reliability is 70% / 85% / 95%. 4. Save/load round-trips people, threads, assets, exact persona-instance bindings, and relationship-local identity state. Pre-v28 saves migrate the global social identity without merging it with a separate Moonlight cover. 5. Every person carries a serialized role characteristic. Authored plots select role/leverage/capabilities rather than named ids, and a second person with matching characteristics can receive the same plot definition. ### Operations interface receipts S1. PEOPLE/ACTIVE render the same staged person labels, social legality, plot exclusion, and bound commands in both human frontends and agent mode; the host and switch do not aggregate off-map people actions. This frontend migration is owned by operations-workspace.md and does not reopen the implemented social model above.