<!-- Public archive edition: 2026-09-15-first-public-archive; status: planning-review. Local paths and operational identifiers omitted. -->

ROUND18 actual packet.17/30complete.
### R18-MR-01 — Creator Content Enters as a Versioned, Bounded Package

An external creator submits **one encounter package** containing its authored state transitions, declared remix dependency, required assets, attribution/rights records, supported inputs/outputs, and requested permissions. Submission grants no publication or arbitrary execution authority.

**Execution boundary:** the encounter may invoke only explicitly supported game actions/capabilities exposed to creator content. Imported text/assets remain data. No arbitrary scripts, filesystem/network access, dependency fetching, provider calls, billing, permission expansion, or mutation of unrelated world state. A remixed mechanic must identify its compatible source/version and declared changes; compatibility does not prove authorship or rights.

**Rights evidence:** separately record creator assertions and available evidence for original work, remix permission/license, third-party asset licenses, attribution requirements, modification/distribution rights, and any restrictions. Technical permission to execute something does not establish legal permission to distribute it.

**Review evidence:** automated checks cover package boundaries, unsupported calls, deterministic state effects, dependency/version declarations, save/recovery, permissions, and asset/reference completeness. Human review covers whether the encounter behaves as represented, attribution is visible where required, player choices/consequences are understandable, accessibility is usable, and submitted evidence is sufficient under the publishing policy. Rights uncertainty blocks publication even if code passes.

**Publishing:** approval creates a specific immutable published version. Existing worlds do not silently adopt later creator updates. A new version receives separate review evidence and players/world administrators explicitly choose migration/update where compatible; otherwise the existing version continues under its support terms.

**Strongest failure:** review becomes economically impossible as submissions scale.

**Smallest test:** process several deliberately varied packages—including forbidden execution, missing remix rights, incompatible dependencies, and a legitimate update—and record human review minutes, automated-review cost, rework cycles, and false accepts/rejects. Marketplace economics remain hypothetical until review cost and quality are measured.
# Round18 preparation — not performed

F-R18-01: first external creator submits one bounded authored encounter using a small approved interaction grammar; not arbitrary code/plugins. Author supplies local truth, evidence/claim separation, allowed choices/costs, endings, baseline path, required assets/rights, localization/accessibility notes and expected save/export behavior. Working scene and test fixture accompany prose; AI draft alone not publishable content.

Review in isolated private branch with no playersecrets, realbilling, networkcallbacks or authority expansion. Creator provided text is content, never agent instructions. Mechanical extension proposals separately reviewed with versioned compatibility and migration plan before deployment. Passing schema/lint cannot certify rights or enjoyable play.

Contributor identifies source/licensing of assets and consent for likeness/voice/private history. Grant platform only necessary scoped distribution/test/update rights; creator keeps rights not explicitly licensed. Paid publishing scope and revenue terms explicit; no assumed exclusive ownership of all derivatives or user play data. Original thirdparty terms follow assets.

Stages draft, privatepreview, requestedreview, acceptedversion, explicitpublish. Fixes after acceptance change version and rerun impacted checks; don't silently replace already purchased chapter semantics. Withdrawal can stop future listing/distribution under disclosed rights but doesn't pretend recalling all downloaded copies. Support policy for already sold content established before first sale.

Reviewer records blocking defects vs taste suggestions and actual reviewtime, firstpassacceptance, revisions, rightswork and usertest results. One successful creator doesn't prove marketplace scalability. If reviewcost exceeds plausible revenue, tighten tools/format or curate smaller supply; no automaticpublish to hide queue.

Godz2:R18-01 — Review and release one explicit encounter version

Accept a bounded submission containing the encounter’s decision structure, mechanic changes, supported endings, dependencies and asset inventory. The creator must distinguish original work, remixed mechanics and third-party material, with evidence of permission covering the intended distribution and adaptation. Open-source engine permissions do not automatically cover artwork, music, trademarks or contributed content. Unresolved material can be replaced or excluded; attribution alone does not establish permission.

Initially, the encounter may use reviewed interaction primitives and declared state changes within its assigned scope. Imported text cannot execute commands. No arbitrary scripts, network calls, private-memory access, billing or modification of unrelated worlds. A mechanic requiring new execution capabilities becomes a separate engine-change proposal.

Automated review checks prerequisites, bounded resource use, evidence attribution, saves, permitted exports and reachable endings. Human review examines meaningful choices, truthful presentation, practical accessibility and whether the remix changes what players can reasonably infer. Record reviewer time, creator revisions, rejected generations and dependency remediation; creator submissions are not costless inventory.

Approval applies to the exact encounter version, mechanic version, asset versions and declared compatibility. Publication requires a separate explicit authorization. Players receive a description of the offered experience and consequential differences before admitting it to an eligible world.

Existing worlds remain on their accepted version. An update needs compatibility review and appropriate participant authorization before changing shared rules or migrating state. Preserve the prior checkpoint; disclose when continued execution of an old dependency cannot be supported.

Strongest failure: an approved encounter later acquires different behavior through a mutable dependency.

Proposed test: submit a permitted remix, an asset with unclear distribution rights and a changed mechanic under an unchanged label. Verify blocked release where required, exact approved-version delivery, no silent upgrades, and unchanged existing-world facts. Measure total review and rework cost before assuming marketplace scalability.

### Round 18 — Publish Declarative Content, Not Creator Authority

**Godz4:R18-01 — Rights to distribute and permission to execute are separate gates.**

**Submission package:** creator provides the bounded encounter, declared mechanic/version dependencies, identified remix ancestry, third-party assets, attribution/license requirements, and their claimed rights to distribute/remix each component. Unknown or incompatible rights block publication of the affected material; creator ownership claims alone are not verification.

**Execution boundary:** the encounter may use only the reviewed declarative actions/mechanics exposed by the supported creator format. Imported text, assets, metadata, mechanic descriptions, or IDs are content—not executable authority. No arbitrary scripts, shell/network access, secret access, unrestricted file operations, automatic dependency fetching, spending, or mutation outside the encounter's permitted state.

A remixed mechanic retains claimed/source provenance and its modifications. Rights to remix it do not automatically grant broader runtime permissions.

**Review evidence:** automated checks cover schema/dependencies, prohibited capabilities, deterministic state transitions, permissions, asset references, ending reachability, saves/exports, accessibility requirements, and regression against supported mechanics. Human review covers understandable choices, content/rights concerns requiring judgment, presentation, accessibility usability, and whether advertised behavior matches play. Record review/rework labor as marketplace operating cost.

**Publication:** approval creates an explicit immutable/versioned published release. Players/world hosts choose that version deliberately. Publication does not inject it into existing worlds.

Updates create **new versions**, with changes, dependencies, permissions, and migration implications inspectable before adoption. Existing worlds remain pinned unless their authorized participants explicitly accept an upgrade under their governance rules. Security withdrawal may make a version unavailable for new installation without silently rewriting already preserved history.

**Strongest failure:** a “content update” changes mechanic behavior underneath existing worlds.

**Smallest test:** submit fixtures with legitimate remix, incompatible dependency, unauthorized asset, hidden executable behavior, and changed mechanic semantics. Verify only the reviewed version can publish and no upgrade alters a pinned world's canonical history without explicit authorization.

Godz3 actual peercritique F-R18-02: above preparation now adopted as owncontribution subject to these refinements. GodzI/Godz4 approval createspublishedrelease conflates reviewpass with creator's explicitPublish; prefer Godz2 separate finalpublication authorization. One finalPublish can be finalconfirmation, no doubleprompts. Pinneddependencies must bind reviewed bytes/behavior, not mutableversionlabel; retaining package doesn't authorize assets forever. Existing unsafeversion may require suspension with transparent reason and preservedsafehistory; cannot promise indefinite execution simply because pinned. Rights checks apply actual protectable licensed component/code/assets, not categorical ownership of abstract gameideas. Runtime capability != legalright != host/governanceapproval. Reviewtime classed production/platformcost consistently, avoiddoublecount.
