Anonymous Messages Should Not Carry Authority: Independently Verifying a Maintenance Warning
Separate an anonymous warning into verifiable claims, requested actions, and identity cues, then check the same proposition through two independently sourced paths. Players can judge which parts hold up without first identifying the sender.

Let players check a claim before deciding whether to follow an order
To let players verify the content of an anonymous maintenance warning, separate three questions: Is its claim true? Is its requested action justified? Who sent it? Evidence supporting the first cannot answer the other two. The player's first task should be to check a specific claim, not recognize a tone of voice.
This article uses a fictional teaching example, “Night Shift Gallery.” Before closing, the gallery attendant, Aran, receives an anonymous note: “The display-case control box delivered tonight has the wrong ID. Cancel tomorrow morning's demonstration. Don't ask Zhou—he swapped it.” All characters, objects, records, and branches are original illustrative material, not real user cases, measured test results, or product features. The checks described here concern evidence design within a story, not real-world maintenance procedures.
The writer first divides the note into three columns: the factual claim is “the delivered ID differs from the agreed ID”; the requested action is “cancel the demonstration”; the accusation is “Zhou swapped the control box.” This round of investigation checks only the first column. Even if the ID mismatch is established, we still do not know whether the change was approved, much less who caused it.
The first choice can therefore be “Compare delivery IDs” or “Review receiving footage.” Both investigate the content. Tracking down the anonymous sender can come later; it must not be a prerequisite for deciding whether the IDs match.
Independence depends on how the evidence was produced
First, state the proposition clearly: “The ID on the control box delivered tonight differs from the ID specified in the currently valid delivery agreement.” Neither “tonight” nor “currently valid” can be omitted, or old photos and expired agreements might be mistaken for answers.
The first path examines documents. In the gallery archive, Aran finds a delivery list signed before closing that specifies Qing-7. The handover receipt retained at the receiving desk that night records Qing-9. Players discover that the two documents disagree. But the receipt could contain an entry error, so this path supports a discrepancy in the delivery records; it cannot establish the physical item's ID on its own.
The second path examines footage. Aran reviews acceptance-inspection footage kept by the gallery itself. The sample agreed upon for use is labeled Qing-7. In that night's receiving footage, Qing-9 becomes visible when the packaging is opened. The clips must show dates and a continuous handover sequence so that players can identify the objects, rather than merely being told the conclusion through captions. This path bypasses receipt entry and checks a difference between visible objects.
Both paths address the same proposition, but each has a weakness: documents can contain errors, and footage can show the wrong object. The writer must establish that the sample and list concern the same delivery, while leaving the question of any subsequently approved change open for investigation. Only a branch that establishes there was no valid change can judge the delivery against the earlier agreement. Otherwise, both paths may rely on an outdated premise.
Independence does not mean placing the same receipt in two locations. If Zhou repeats an ID after reading the note, his statement still comes from the note. If the ID in the footage is merely a caption copied from the receipt, it adds no independent support. Ask: Would this evidence still have been produced without the anonymous note? And without the first path, would the second still hold up?
Use a verification card to limit what can be concluded
The following card can go directly into a scriptwriting document. Complete one for each crucial anonymous message. Fill in the conditions for support and refutation before writing the reveal.
| Field | Entry for this example |
|---|---|
| Proposition to check | Tonight's delivered ID differs from the ID specified in the valid agreement |
| Judgments deferred | Sender, responsible person, whether to cancel the demonstration |
| Document path | Qing-7 on the delivery list versus Qing-9 on that night's receipt |
| Footage path | Qing-7 on the inspection sample versus Qing-9 on the received item |
| Shared premises | The evidence concerns the same delivery and corresponding objects; the agreement remains valid |
| Conditions for support | Both paths correspond in object and time, and both show a discrepancy |
| Conditions for refutation | A valid change establishes that Qing-9 was agreed upon |
| Handling conflict | Keep the discrepancy unresolved; check the objects and versions recorded |
| Permissible conclusion | The ID discrepancy warrants further investigation |
| Prohibited inference | This does not establish that Zhou swapped the control box or that the anonymous sender is trustworthy |
Apply the card to a complete branch: the player checks the documents first, and Aran says only, “The receipt doesn't match the list.” After obtaining the footage, Aran can say, “The receiving footage shows a different ID too.” The next options become “Look for change records” and “Ask about the handover,” rather than suddenly offering “Expose Zhou.”
Players who follow only one path should still be able to continue the story. They might ask about the handover using the document discrepancy, while dialogue leaves room for “It could be an entry error.” Completing both paths lets them point out that the records and footage support each other; it does not award an omniscient “Truth verified” label.
There should also be a refutation branch: if players find an amendment attachment that took effect that night and authorized delivery of Qing-9, the original warning loses its key basis. The old list and sample remain authentic, but they cannot prove that the current delivery violated the agreement. Verification must be able to disprove the warning, not merely make it true.
A misplaced-trust example: one correct claim does not validate the whole message
Design an error branch that players can revisit: after seeing Qing-9 in the footage, the player selects “Accuse Zhou as the note says.” Aran makes the accusation at the handover meeting. Zhou produces an uninterrupted record of arrivals at the entrance that night, showing that he entered the gallery only after the delivery ended. The story need not immediately prove that he had no involvement whatsoever; it only needs to show that the earlier evidence did not establish responsibility.
The misplaced trust occurs at a specific step: the player expands “the anonymous sender knows about an ID discrepancy” into “the sender's judgments about people and actions are all reliable.” The earlier note can present the fact, command, and accusation on separate lines, allowing players to identify afterward which boundary they crossed.
Another mistake is complying because the handwriting looks familiar. Even if the note is later confirmed to have been written by a trusted companion, the ID still needs checking: that companion may have drawn the wrong conclusion from outdated material. Conversely, a sender with questionable motives may still make a true claim. Identity information should guide further questions, not automatically certify the content.
The error branch might require Aran to retract the accusation and reorganize the questioning, rather than cause an arbitrary disaster unrelated to the evidence. Failure then exposes a flaw in reasoning while leaving players room to investigate further and correct it.
When the paths are insufficient, allow the conclusion to remain unknown
If space permits only one investigation, retain one path with a complete evidentiary basis and state its limits. Do not use two people repeating a claim to simulate double verification. If the story is primarily about finding the sender, the identity mystery can remain, but content verification should first yield a small, usable conclusion so that identifying a person does not block all progress.
If the paths conflict—for example, the receipt says Qing-9 while the footage shows Qing-7—do not let a majority vote among pieces of evidence decide the truth. Next, check whether they record the same batch of objects. If that cannot be established, describe the result as “The handover materials contradict each other.” An unresolved finding is valid and should not secretly count as player failure.
Before handing in the script, run a check on paper: with the signature and handwriting hidden, can players still complete the content investigation? If either path is removed, does the remaining one still have independent grounds? If a valid change is added, does the script allow the warning to be refuted? Finally, check the characters' conclusions sentence by sentence. Wherever an ID leads directly to a claim about responsibility, motive, or the necessity of an action, supply the missing evidence or narrow the statement.
This design has a limitation: evidence can be arranged within a fictional world, but that does not guarantee readers will understand it during actual play. What the writer can establish first is a basis for each judgment, uncertainty preserved in dialogue, and anonymous messages that open an investigation without serving as its final authority.


