{
  "code": "LOG-01",
  "slug": "courier-and-handoff-state-machine",
  "title": "Courier and Handoff State Machine",
  "category": "Tasking & Logistics",
  "status": "Current",
  "version": "2.0.4-wip",
  "summary": "Physical or digital operational handoffs use deterministic states, accessible destinations, tamper evidence, timeouts, and reviewable settlement.",
  "keywords": [
    "courier",
    "handoff",
    "escrow",
    "state machine",
    "collateral",
    "delivery",
    "drop box"
  ],
  "mission_phases": [
    "Plan",
    "Deliver",
    "Extract"
  ],
  "canonical": "https://iarpg.com/standard/courier-and-handoff-state-machine",
  "json": "https://iarpg.com/records/courier-and-handoff-state-machine.json",
  "requirements": [
    {
      "level": "MUST",
      "text": "Use Created, Accepted, In Transit, Delivered, Breached, Expired, and Canceled states with atomic settlement."
    },
    {
      "level": "MUST",
      "text": "Verify destination accessibility before posting and protect accepted couriers from later access revocation or obstruction."
    },
    {
      "level": "MUST",
      "text": "Keep reward, collateral, cargo ownership, and fees distinct in the economic ledger."
    },
    {
      "level": "SHOULD",
      "text": "Physicalized cargo communicate burden and tamper state without exposing protected contents by default."
    },
    {
      "level": "MAY",
      "text": "Support remote perimeter deposit when post-acceptance obstruction would otherwise make delivery impossible."
    }
  ],
  "research": [
    {
      "label": "Finite state machine architecture",
      "href": "/docs/report/systemic-architecture-for-trustless-escrow-and-courier-contracts-in-a-virtual-reality-mmorpg#2-1-finite-state-machine-fsm-architecture",
      "note": "Deterministic contract lifecycle."
    },
    {
      "label": "Universal perimeter receptacle",
      "href": "/docs/report/systemic-architecture-for-trustless-escrow-and-courier-contracts-in-a-virtual-reality-mmorpg#5-0-systemic-resolutions-the-universal-perimeter-receptacle-upr",
      "note": "Delivery access separated from private structure permissions."
    }
  ],
  "related": [
    "verified-and-unverified-tasking",
    "communications-and-compartmentation",
    "operational-economy-and-resource-pressure"
  ],
  "release": "IARPG-OPS-2",
  "revised_utc": "2026-07-20T12:04:07Z",
  "purpose": "Define trusted and untrusted tasking, deterministic handoffs, operational resources, jurisdiction, and support systems.",
  "rationale": "Operational logistics must expose risk, settlement, custody, and failure states before a player commits time or collateral.",
  "game_interaction": [
    "Accept tasking",
    "Lock escrow",
    "Carry package",
    "Complete handoff",
    "Review warrant reason"
  ],
  "inputs": [
    "Task contract",
    "Cargo or intelligence packet",
    "Jurisdiction state"
  ],
  "outputs": [
    "Settlement event",
    "Handoff record",
    "Warrant or clearance event"
  ],
  "state_transitions": [
    {
      "from": "not-applicable",
      "event": "record requirement evaluated",
      "to": "conforming-or-documented-exception"
    }
  ],
  "evidence_and_provenance": [
    "The implementation records the source, UTC event time, mission identifier, responsible role, and reason code for consequential state changes.",
    "Generated dialogue and player interpretation are not stored as authoritative facts without a separate verification event."
  ],
  "ui_requirements": [
    "Show the record code and requirement level at the point of use.",
    "Expose the reason for blocked, failed, escalated, or irreversible actions.",
    "Provide a direct link to the canonical standard and machine-readable record."
  ],
  "accessibility_requirements": [
    "Essential information is available without reliance on color, audio, motion, or a VR-only gesture.",
    "Keyboard, screen-reader, reduced-motion, seated-play, and high-contrast equivalents are documented where the interaction applies."
  ],
  "telemetry_events": [
    {
      "name": "standard.courier-and-handoff-state-machine.evaluated",
      "required_fields": [
        "event_id",
        "timestamp_utc",
        "mission_id",
        "record_code",
        "result",
        "reason_code"
      ]
    }
  ],
  "abuse_and_exploit_cases": [
    "A participant attempts to omit required context so another role accepts a misleading task.",
    "A generated or user-authored statement is presented as server-authoritative without verification.",
    "A consequential state transition occurs without a durable reason code."
  ],
  "failure_behavior": "Fail closed for irreversible or settlement-bearing actions. Preserve the current state, show the missing requirement, and allow correction or documented exception review.",
  "recovery_behavior": "Restore from the last authoritative event, retain the rejected transition in the audit log, and require a new validated event before continuing.",
  "example_implementation": "A mission interface evaluates LOG-01 before advancing the relevant state and writes the result to the local event log with a UTC timestamp and reason code.",
  "roles": [
    "Operative",
    "Handler",
    "Intelligence Analyst"
  ],
  "authority_types": [
    "Civil administration",
    "Military command",
    "Commercial intelligence service",
    "International verification body",
    "Scientific consortium",
    "Independent investigative network"
  ],
  "collection_disciplines": [],
  "interaction_types": [
    "Accept tasking",
    "Lock escrow",
    "Carry package"
  ],
  "evidence_requirement": "Reviewable provenance required",
  "conformance_level": "Level B — Playable",
  "implementation_maturity": "Published WIP",
  "related_examples": [
    "port-access-anomaly-investigation"
  ],
  "revision_history": [
    {
      "version": "1.0.0",
      "date_utc": "2026-07-19",
      "note": "Initial IARPG-OPS-1 publication."
    },
    {
      "version": "2.0.1-wip",
      "date_utc": "2026-07-19",
      "note": "Expanded for IARPG-OPS-2 workbench, simulation, evidence, accessibility, telemetry, and machine-readable publication."
    },
    {
      "version": "2.0.2-wip",
      "date_utc": "2026-07-19T16:42:07Z",
      "change": "Reviewed for operation-package lifecycle compatibility and local tool integration."
    },
    {
      "version": "2.0.3-wip",
      "date_utc": "2026-07-19T18:45:50Z",
      "note": "Reviewed for integrity-aware package verification, merge, multi-role replay, custody comparison, batch review, backup, publication preview, and release-promotion workflows."
    },
    {
      "version": "2.0.4-wip",
      "date_utc": "2026-07-20T12:04:07Z",
      "note": "Reviewed for canonicalization, round-trip portability, recovery, provenance, compatibility, accessibility, hosting evidence, and stable-promotion gates."
    }
  ]
}
