# Virtual Hospital Economy: Design, Governance, and Risk Management

We design a non-combat, socially rich micro-economy for a hospital setting (up to 10 players per instance) with multiple currencies and reputation dimensions.  Three core value systems (currencies) will be used: (a) **Hospital Credits**, a general-purpose institutional token; (b) **Merit Points**, earned by constructive actions and used for progression; and (c) **Social Trust (Favors)**, a non-transferable reputation metric.  This trio balances ordinary trade, progression, and personal trust, as recommended for sustainable economies.  All faucets (ways to earn) have matching sinks (expenditures) to avoid uncontrolled inflation.  New players receive dedicated catch-up mechanics (e.g. starter packs of credits, or accelerated initial missions) so they can participate meaningfully without gifts, mitigating the “latecomer disadvantage”.  No real money or crypto is used; all value is internal to the game.  Wealth (credits) alone cannot buy full “release” or victory; that requires Merits earned by contribution.  Verified and unverified agreements are clearly labeled and function differently to ensure player freedom with transparent risk.  Community-led governance, clear rules, reporting, and appeals provide oversight and minimize abuse.

## Currencies and Value Systems

We use three currencies for clarity and balance:

- **Hospital Credits (Institutional Currency):**  
  - **Purpose:** Daily transactions for food, supplies, and service fees.  
  - **Issuer:** The hospital institution (game engine).  
  - **Faucet:** Players earn credits by completing routine tasks (cleaning wards, assisting meals, delivering messages, organizing inventory, inspecting environment, etc.).  For example, a clean-room task or delivering medicine rewards a fixed credit amount.  Credits may also come from NPC interactions (e.g. performing a service for an NPC staff member, or winning small bets).  
  - **Sink:** Credits are spent on basic needs and services (food, medicine, hygiene supplies, maintenance tools, room upgrades) and on transaction fees.  Importantly, purchasing from NPC vendors *removes* currency from circulation (like “buying from the void”).  Examples: paying a nurse for clinic supplies (credits sink out), buying consumables, or paying small taxes/fees for using hospital facilities (e.g. printing costs).  Death/failure penalties do **not** apply in a non-combat hospital, but other drains like utility fees or fines for rule violations can remove credits (see **Governance**).  
  - **Transferability:** Freely tradeable among players.  Trades of credits have a small transaction fee (e.g. 1–5%) that permanently removes credits, as a sink.  
  - **Storage:** Accumulated in player accounts.  No expiration (credits last until spent), but large idle balances can attract special fees or progressive tax.  
  - **Caps:** The system ensures soft caps via diminishing returns on faucets and active sinks.  A strict hard cap per player is unnecessary if sinks (above) scale with faucet size.  However, daily credit gains are bounded by limited tasks, preventing any infinite faucet.  
  - **Fraud Risk:** Minimal; credits are numeric and centrally managed, so duplication exploits must be prevented by logging every faucet event.  All official tasks are logged; no mechanism allows hidden currency creation.  
  - **New-Player Protection:** Beginners get a modest credit stipend or free meals to start, and early tasks yield slightly higher credit-to-effort so they can compete.  New players may also get access to a mentor voucher (limited-use bonus) so they aren’t shut out of basic necessities.  
  - **Veteran Limits:** Super-linear credit faucets (like tasks whose yield grows with player level) are avoided.  No player can “farm” credits exponentially; tasks have fixed or slowly scaling payouts.  This prevents veteran monopolies.  
  - **Scenario Rewards:** Credits awarded for in-scenario achievements (solving puzzles, organizing events) reinforce active play.  
  - **Escape/Release:** Credits can buy comfort items or speed certain chores, but cannot be converted 1:1 into merits or instant release.  
  - **Privacy:** Credit balances are publicly visible only to that player and official audits; private deals can be negotiated but engine fees still apply.

- **Merit Points (Contribution Currency):**  
  - **Purpose:** Reflect constructive contribution and service to the community; needed for “sentence reduction” or status progression (e.g. moving up in work duties, earning privileges, or eventual “release”).  
  - **Issuer:** Granted by the institution for tasks beneficial beyond personal gain (education, training classes, facility maintenance, tutoring, mediation, puzzle-solving assistance, communal event organization, restorative justice activities).  
  - **Faucet:** Earned by performing valuable, often altruistic activities: repairing equipment, cleaning critical zones, tutoring others, leading group votes, resolving disputes, or volunteering for safe but difficult work.  Minor tasks yield credits, but Merits are reserved for contribution and educational service.  Merits might also be granted upon reaching certain milestones (e.g. “5 verified successfully completed tasks”).
  - **Sink:** Spending Merits is rare; they primarily accumulate to unlock progression.  Merits might be “spent” on actions like reducing one’s detainment time (each 10 Merits reduces mandatory in-hospital days by one), or applying for advanced programs.  Upon exit/escape, a certain Merit threshold is required.  Importantly, Merit sinks do **not** allow conversion to credits or favors; they are non-liquid.
  - **Transferability:** *Non-transferable*.  Merits attach to the player’s record and cannot be given away, sold, or exchanged.  This prevents rich players from simply buying progression.  (No marketplace for Merits exists.)  
  - **Storage:** Account-bound, likely shown on a status board or personal dossier.  Merits slowly decay only by formal spending (e.g. “use 5 Merits to get a privileged room”).  There is no expiry, but Merits do not inflate like credits (the supply is controlled by tasks).  
  - **Caps:** A sensible cap prevents runaway accumulation.  For example, no more than X Merits/month can be earned (ensuring late players can catch up if X is not too low).  Tasks are limited in number.  Also, excessive unspent Merits might “stall” progression: e.g. unlocking one privilege requires spending Merits, encouraging sinks.  
  - **Fraud Risk:** Low, since no trading.  To prevent alternate-account merit farming, require Merits for team tasks only when all participants are distinct (trust via communication records).  Merit tasks often require accountability (tutoring others or maintaining records), which cannot be faked easily.  
  - **New-Player Protection:** New arrivals can earn a few Merits by completing an orientation or introduction program.  Also, group tasks (like cleanup) award Merits to all participants, helping new joiners integrate.  
  - **Veteran Limits:** Veterans cannot accumulate infinite Merits either; tasks have per-person quotas (e.g., “Max 1 merit for classroom host per day”).  Systems track who did what, so no pair of players can collude to farm Merits with each other repeatedly.  
  - **Scenario Rewards & Release:** Merits correlate to legitimate progression and eventual release.  For example, every 50 Merits might allow an application for a review board, at which point the player could “graduate” or leave early.  Release is based on Merits plus time, not just wealth.  

- **Social Trust (Reputation/Favors):**  
  - **Purpose:** Measures personal trustworthiness and influence with NPCs, factions, and other players on non-transferable dimensions (reliability, cooperation, discretion, etc.).  Trust can unlock social opportunities (being elected to a committee, choosing group assignments, getting access to informal networks).  
  - **Issuer:** Gained or lost via interactions. Not “issued” by the game bank, but accrued through recorded behaviors. NPCs and players may vouch for you, or gossip can spread reputation signals.  
  - **Faucet:** Increases when players keep promises in *unverified* deals, act reliably on community projects, successfully mediate disputes, or assist others without immediate benefit.  For example, if player A helps B solve a puzzle without guarantee, B’s trust in A goes up.  Organizing social events or demonstrating compassion in dialogues raises social reputation.  High scores in reliability, discretion, etc. accumulate via peers’ feedback or NPC observation (e.g. “Hey, I saw you fix the machine instead of taking credit” → reliability+).  
  - **Sink:** Reputation naturally decays over time without reinforcement (old good deeds are forgotten unless sustained).  Favors only decrease via negative actions (breaking agreements, betraying trust, being caught deceiving).  To avoid runaway positivity, strong reputations require maintenance.  There is no “spend” of trust per se, but using it for perks (like being elected) might reset it slightly (the more power you get, the more scrutiny, so your net trust returns toward neutral unless maintained).  
  - **Transferability:** **Non-transferable and cannot be traded**.  It is purely personal.  For instance, you cannot “give” your trust to someone else, nor cash it out.  Only interactions affect it.  
  - **Visibility:** Multi-dimensional (e.g. reliability, discretion, compassion, cooperation, opportunism). Different factions/NPCs may care about different dimensions (e.g. management values compliance; patients value compassion). Reputation scores may have a public component (e.g. a visible star rating for reliability) and private logs (a record of what actions caused reputation changes).  
  - **Decay & Contest:** Under imperfect information, reputations tend to regress to neutral unless actively maintained. Our system implements decay: trust points drop slowly each week if no new actions. If someone is falsely reported (see **Governance**), they can present evidence (chat logs, signed agreements) to dispute a claim. NPCs will consider both reputation and concrete evidence: a high trust NPC might give the benefit of doubt but still examine proof.  
  - **Reputation ≠ Justice:** Verified misconduct (caught cheating, breaking rules) results in formal penalty (see Governance) and is stored separately in a “Justice Record”.  This record does not automatically erase social trust (it is factual data).  Conversely, social popularity does not override evidence of wrongdoing.  This distinction avoids “mob justice” trumping official findings.  
  - **NPC Use:** NPCs use reputation: a reliable player is trusted with minor responsibilities (letting you handle equipment unsupervised), while a low-reputation player might have restrictions.  NPC merchants may offer better prices or unique items to players known as trustworthy.  
  - **Privacy:** Trust scores are semi-public. A player may see basic ratings, but detailed action logs remain internal unless reviewed in dispute.  One cannot instantly spy on someone’s entire history.  This balances transparency with privacy.  

## Player Activities and Loop Design

We create multiple engaging loops (tasks) beyond grind or combat, rewarding diverse playstyles:

- **Cleaning and Maintenance:** Regular tasks like sanitizing wards or repairing machinery are required. Players gain credits and occasional Merits for thoroughness.  This ensures low-skill tasks always have some value and sinks service needs.  
- **Meal Assistance:** Helping serve or prepare meals yields credits and minor social reputation (compassion).  Players might trade favors (e.g. taking a shift for someone).  
- **Inventory Organization:** Sorting supplies and delivering items earns credits.  Organized storage can yield bonuses (easier future task completion).  
- **Mediation & Dispute Resolution:** When conflicts arise, skilled mediators can earn Merits by helping groups reach agreement, or by proving rumors false.  Success is logged, giving reliability or cooperation points.  NPCs may task players to judge disputes.  
- **Record Verification:** Checking logs (e.g. patient records or resource inventories) is a puzzle-like task yielding credits and occasionally Merits if it prevents a problem (like catching an error).  
- **Message/Package Delivery:** Quick mini-tasks delivering notes or tokens around the hospital earn credits.  Successful delivery (especially under time pressure) gives small reliability reputation boosts.  
- **Environmental Inspection:** Random inspections (checking radiation levels, infection control) give credits; using findings for genuine improvements can yield Merits.  
- **Tutoring/Education:** Players can teach skills (e.g. advanced recipe or puzzle strategy) to others in a classroom. Tutors earn Merits and social trust (generosity, accuracy).  
- **Puzzle Assistance:** Offering hints or help to stuck players is tracked: if accepted, the helper gains trust in “cooperation” and “compassion”.  This encourages open help networks.  
- **Communal Voting:** Periodically, players vote on non-essential changes (like selecting the next social activity, or minor facility upgrades).  Participants earn slight reputation for civic engagement; majority rules ensure fairness.  
- **Crafting Harmless Utility Items:** Using communal resources to craft things like flower pots or bulletin boards. These require credits (sink) and yield small reputation or communal benefit.  Crafted items might enhance ambiance or solve minor needs, giving satisfaction.  
- **Entertainment/Social Events:** Organizing a trivia night, talent show, or board game in a lounge yields Merits for organizers and improves group morale (an abstract reward).  Entertainer-of-the-week might get a token favor from NPC staff.  
- **Trading:** Players buy/sell items (tools, food, contraband if any) for credits.  Trades incur a fee (sink).  A small marketplace emerges, but prices and lawfulness are monitored for fraud or hoarding.  
- **Verified Contracts:** The game “job board” offers tasks with locked-in credit rewards; completion is objectively verified (see next section).  
- **Unverified Favors:** Players can request help (e.g. “Pass me this note” or “Sneak this to a friend”). These rely on trust and yield potential favors; failure just means the requester lost nothing but trust (see Agreements below).  
- **Reputation Reporting:** Players witness actions (good or bad) and can submit reports. Each report is considered “evidence” for reputation updates or governance action.  For example, reporting someone cleaning effectively may boost that person’s reliability, while reporting sabotage would trigger an investigation.  
- **Rumor Verification:** A player might receive a hearsay (e.g. “The head nurse likes apples”); verifying it (asking NPC) yields social insight or cleverness reputation.  
- **Collaborative Investigations:** Some story tasks (e.g. finding a missing patient or solving a mystery) require teaming up. Success yields Merits and status.

Each loop is voluntary and yields a mix of credits, Merits, and trust.  Importantly, these loops are not forced punishment labor; they are framed as part of normal life or optional community service.  For example, cleaning is just part of hospital upkeep, while tutoring is explicitly altruistic (merit-earning).  There is always choice: for instance, players can mingle at social events for reputation instead of lab chores.

## Verified vs Unverified Agreements

Two contract classes are implemented:

- **Verified Agreements (Engine-Guaranteed Contracts):** Players propose or accept clearly defined tasks from a system interface. When accepted: 
  - The agreed reward is escrowed in the system (held and guaranteed). 
  - The task objective is objective and measurable (e.g. “Deliver these medicines to room 12”).
  - Cancellation rules are spelled out: either party can cancel before start with partial penalty. 
  - A transparent fee (e.g. 5% of reward) is taken by the hospital for broker services (this is a credit sink). 
  - Completion evidence is automatically logged (the system notes deliveries, time stamps). 
  - Disputes (e.g. claimant says “I did it”) are resolved by checking logs; if evidence is lacking, the contract can fail. 
  - **Terms locked:** Once both accept, neither can unilaterally change terms. 
  - After fulfilment, the reward is released from escrow to the fulfiller. 
  - No party can scam via a verified contract: if conditions are met (logged), the system pays out. 

  Examples: the hospital “Job Board” offers credit-scoped errands, or two players use the contract UI to trade goods for credits. In all cases, the system ensures enforcement without trust.

- **Unverified Favors (Player-to-Player Favors):** Informal requests between players:
  - There is **no escrow or guarantee**. If A helps B move a box and B promised 10 credits, B must pay on good faith. The engine does not hold B’s credits in advance, and A has no guarantee.
  - These appear in a “Community Post” board or chat with a clear risk label (e.g. red text “UNVERIFIED – Favors at Risk”). 
  - Terms can be flexible (both can renegotiate on the fly). 
  - The potential reward can be higher than system jobs (since risk is higher). 
  - **No arbitration:** If B reneges, only B’s reputation suffers (reliability down). There is no automatic enforcement, but the system might note “B failed an unverified promise” in logs and reduce B’s trust scores.
  - These are purely social transactions, relying on personal trust and reputation. 
  - Clear labeling and disclaimers are shown so players know “this is not guaranteed by the hospital.” The UI explicitly warns, e.g. “Use your discretion – no institutional backing.” 
  - Because there is no government protection, players often enlist witnesses or partial payments (“pay on delivery”) to reduce risk.

- **Witnessed Agreements (Third Category, optional):** If needed, a compromise: player C can vouch for an unverified favor between A and B by co-signing it. Then the terms become semi-verified: C will cover small part if B cheats, for example. This adds a layer of social insurance without engine escrow. It’s optional and visible.

This clear separation ensures players always know risk. No ambiguous promises – either the system backs it or it’s just a personal favor.

## Reputation Model

Rather than a single number, reputation is multi-dimensional. Key dimensions include **Reliability**, **Compassion**, **Cooperation**, **Discretion**, **Accuracy**, **Institutional Compliance**, **Opportunity-Seeking**, **Aggression (Verbal/Disruptiveness)**, and **Mediation Skill**.  Each dimension can be positive or negative and has its own score. For example, helping with tasks consistently raises *Reliability*, gossiping raises *Discretion (down)*, successful conflict resolution raises *Mediation*.  

- **Actions Affecting Dimensions:** Every logged action maps to one or more dimensions. E.g. delivering correct medicine on time → +Reliability; forgiving a player’s mistake → +Compassion; being caught forging a note → -Compliance.  There are no rewards for bullying or cheating; those lower *Cooperation* and *Reliability*. Punishments drop certain dimensions (like institutional compliance). 
- **Visibility:** Current dimension scores are shown on a player’s profile (e.g. **“Reliability: 4★”**), but the underlying evidence (like “Volunteered for cleanup on Jan 3 (+Reliability)”) is viewable only via an appeal panel or by mutual agreement (to prevent doxing). However, aggregate public indicators and logs allow others to judge credibility. 
- **Decay and Monitoring:** Without continued positive actions, each dimension gradually drifts toward neutral. This reflects the idea that “under imperfect monitoring, reputations are temporary.” In practice, we apply a weekly small decay to each score (or automatic half-life) so that players must keep contributing or risk losing reputation.  
- **False Reports:** Reported actions (especially negative) require moderation: a complaint triggers a mini-investigation using chat logs, witnesses, or system logs. If found false, the accuser is penalized (diminished trust on *Accuracy*) and protected by counter-report mechanisms. This discourages false reporting. The system also asks for evidence when someone accuses another of misconduct. This echoes safety-by-design: “what protections to prevent falsifying reports or evidence?” 
- **Appeals and Evidence:** A player with low reputation can appeal by providing evidence of good behavior (e.g. other players’ attestations, chat logs of fulfilled promises). Appeals are reviewed by either NPC moderators or a council of trusted players. This ensures reputation changes are contestable, distinguishing it from absolute guilt.  
- **Reputation vs Justice:** Game physics separate reputation from justice records. For example, if a player is fined for a rule violation, that fact is logged (affecting *Compliance*), but it does not automatically reset all other trust levels. Reputation repair is possible through consistent future behavior; *lying* irreparably damages trust, but mere incompetence can be forgiven. (In our design, lying shows as “deception” in the logs which permanently hurts certain dimensions, reflecting negotiation research on trust.)  
- **NPC and Faction Use:** NPCs use reputation as a filter. A hospital administrator NPC, for instance, may only entrust keys to a player with high Reliability. A faction of patients may protect someone with high Compassion. Conversely, someone with high Opportunism might be approached by a shady NPC offering illegal tasks. This makes reputation mechanically meaningful.  
- **Inspecting Reputation:** Players can view others’ reputations (basic levels and known bad marks). The interface will allow “view justification” – clicking a minus star shows one or two summarized incidents (e.g. “Betrayed trust on 7/12: agreed to help but didn’t” with optional redaction of personal data). This provides transparency in ratings.

Overall, the multi-faceted reputation encourages varied positive behavior and makes trust a scarce, non-liquid resource that influences opportunities.  No single “popularity score” overshadows objective evidence; proven misconduct cannot be erased by popularity.

## Contraband and Risky Items

We introduce abstract contraband items to create intrigue and subterfuge without teaching real crimes. Examples: 

- **Forbidden Notes:** Torn-out pages or encoded messages. Possibly puzzle fragments that could solve a mystery but are banned to prevent cheating. Carrying notes requires secrecy.  
- **Restricted Puzzle Pieces:** Key items for solving hospital puzzles (like lab combination clues) marked as “restricted”; smuggling them can shortcut tasks.  
- **Unauthorized Tokens:** E.g. extra time-vouchers for restroom or cafeteria access beyond quota.  
- **Faction Symbols:** Secret group pins or tokens used by hidden factions.  
- **Illicit Game Pieces:** Homemade poker chips or dice used for gambling in dorms.  
- **Copied Records:** Blank hallpass copies or spare key cards (game analogues).  
- **Communication Relays:** Hidden codebooks for circumventing communication (e.g. old-fashioned pigeons messages inside drawings).  

Each contraband type is purely fictional/symbolic (no weapons or illegal real actions). They add gameplay: some players (e.g. opportunists) might smuggle restricted puzzle clues to gain an edge. 

Contraband mechanics:  
- **Risk of Detection:** Being caught with contraband yields punishments (temporary restriction, loss of credits or Merits) and reputation hits (Reliability and Compliance).   
- **Snitching:** Players may find contraband in others’ space and can report it. This is akin to “Snitch tokens” in design games: if caught, the snitch earns credit or trust bonus.  Likewise, the “Balance” equilibrium is delicate: informers get a small reward, increasing social tension.  
- **Contraband Trading:** Contraband can be traded at a black-market risk. Selling a contraband item gains credits but endangers reputation if a sting operation catches the seller.  
- **No Instruction:** The system never explains “how to bypass a lock” or real illicit techniques; contraband is game-fiction.  
- **In-Game Narrative:** Contraband introduces storytelling (risk-taking, betrayal, detective work) rather than teaching real-world crime.  

By keeping contraband abstract and consequences in-game, we add emergent drama without real danger. For example, if Player A steals “restricted puzzle pieces” from Player B, a small leaderboard like chart the reputation drop and fuel a side-quest to recover the item. Witnesses (even minor ones) grant evidence. This all enriches gameplay: deception has measurable cost and narrative payoff.

## Social Governance and Justice

A multi-tiered player-driven governance system ensures fairness and deals with misconduct. Components include:

- **Code of Conduct:** The game has clear, accessible rules of behavior. These are communicated upfront (e.g. an orientation bulletin or rulebook item). Players acknowledge understanding at sign-up (a checkbox, purely for story).  
- **Reporting Tools:** Every player has a simple in-game form to report incidents (harassment, fraud, safety issues). Reports include category tags (abuse, cheating, safety hazard) and optional evidence (screenshots, witness names). Anonymous reporting is allowed but names are hidden from the accused.  
- **Community Council / Committees:** A council of elected (via in-game votes) players handles appeals. Members are those with high Trust and a mix of factions. Committees rotate monthly (to prevent cliques). For example, the “Appeals Committee” (3–5 players) reviews contested reports, with majority vote. A “Task Assignment Committee” might assign weekly communal chores fairly. Being elected raises one’s trust.  
- **Incident Review Flow:** When a player is reported for misconduct, the system flags them: their account may be temporarily flagged “under review”. The council sees report details and any evidence, then votes on outcome (unless it’s an obvious minor issue). Consequences (below) are applied systematically.  
- **Restorative Consequences:** For minor infractions (like failing an unverified promise or minor disobedience), punishments are restorative rather than purely punitive. E.g., the offender might have to perform extra community service tasks (losing credits but earning Merits) or public apology (losing trust points). The goal is restoration of community harmony, not mere banishment.  
- **Temporary Restrictions:** For more serious issues (graffiti, theft of contraband), a player might receive a short-term restriction (e.g. banned from communal lounge for 24h, or credit fine). Restrictions are clearly logged and time-limited, keeping the player in-game.  
- **Sanctions:** Only severe or repeated misconduct (e.g. large fraud, violent harassment) triggers heavy sanctions (like game suspension). Even then, appeals can reduce lengths.  
- **Reputation Repair:** After serving any sanction, a player’s reputation can recover through required meritorious actions. For instance, a player who cheated might be required to mentor new players for a week to regain trust. This repairs social standing gradually.  
- **False Reporting Safeguard:** If a report is found baseless, the reporter’s own trust in **Accuracy/Discretion** is penalized. This deters malicious or mistaken reports. One cannot falsely trip the system without consequence.  
- **New-Player Protection:** The council ensures new players aren’t dominated. Newbies have a “mentor” system (players choose to guide them) and new players get extra leniency on first minor errors (with warnings).  For example, a first-time unverified agreement betrayal might be forgiven with only a small trust penalty, acknowledging inexperience.  
- **Harassment vs Rivalry:** Ordinary roleplaying rivalry (teasing, bluffing) is not banned; only direct violations of code (hate speech, doxing, personal attacks) trigger reports. This distinction is explained to players as “game drama vs abuse.”  
- **Community-Led Governance:** This design follows research suggesting that player self-governance is effective in MMO communities. By giving players clear channels (voting, council) and responsibilities, the community polices itself. 
- **Appeal Paths:** Anyone flagged can appeal to the council. All evidence (logs, reports) is available in these sessions. The council can overturn or lessen sanctions. This ensures no one is condemned without a voice. 
- **Incident Logging:** Every action of governance is logged and visible in aggregate (not per-player). E.g. “10 reports handled, 8 warnings given this week.” This transparency builds trust in the system.

In summary, governance combines coded rules with community oversight, balancing safety and player agency. Players know exactly how to report issues and how appeals work, making the system legible and trusted.

## Anti-Exploitation Measures

We analyze common abuse cases and built-in countermeasures:

| Abuse Case                                   | Prevention                                                  | Detection                                                    | Recovery/Remedy                                            |
|----------------------------------------------|-------------------------------------------------------------|--------------------------------------------------------------|------------------------------------------------------------|
| **Alternate-Account Farming (Sybil)**         | Limit one account per email/session. Require in-game tutorial completion before major rewards (so throwaways can’t jump in repeatedly).  | Monitor IP or session patterns: if two accounts act in lockstep (same login times, trading only with each other), flag for review. | Merge accounts or ban duplicates. Reset related gains from minor account to main or confiscate extras. |
| **Collusive Two-Player Trading Loop**        | Cap how often the same pair can trade rewards per day.   Use diminishing returns: repeated identical contract trades yield lower rewards. | Track history: flag patterns like A→B credits, B→A Merits repeatedly. | Nullify repeat trades beyond fair limit. Impose small fee on reciprocal deals (sink). |
| **Monopolizing Communal Tasks (Task Hogging)**| Assign rotating task schedules/quotas. Limit Merits from any single task per person. | If one player does >70% of communal tasks, alert the council. | Award share of credited tasks to others retroactively (auto-assign a fair portion). Suggest handover. |
| **Fake Positive Reviews / Self-Promotion**   | Reputation changes require logged evidence (witness signatures, timestamps). No “like” gimmicks.  | Detect impossible feats: e.g. player claims group help alone, system knows number of helpers. | If review is found bogus, nullify reputation gain and decrease *Accuracy*. |
| **Retaliatory Reporting (“Mass Harassment”)**| Allow counters-appeals. Encourage multiple sources for any serious claim.  | Patterns of quick symmetric reports between two players trigger review. | If abuse found (e.g. two players spamming reports on each other), temporarily disable their report privileges. |
| **Contract Cancellation Abuse**             | On verified contracts, enforce partial penalties for one-sided cancellation (losing some escrow).  | If one player cancels many contracts after minimal work, flag for investigation. | Cancel trade and return a portion to the other party. Possibly ban the abuser from new contracts for a time. |
| **Item Duplication Glitch**                 | Use authoritative item ledger (server checks). Prevent known duplication exploits. | Monitor inventory changes: if total supply jumps unexpectedly, lock accounts involved. | Immediately revert duplicated items from accounts. Adjust economy by banning illegitimate stock. |
| **Logout to Avoid Consequences**           | Implement a brief “logout penalty” delay after certain actions (e.g. leaving mid-contract incurs small cost).  | Notice if player repeatedly disconnects during disputes or tasks. | Flag as suspicious; require cool-down before trust recovery (e.g. slower reputation rebuild). |
| **Repeated Low-Risk Farming**              | Limit daily faucet from repetitive tasks. Introduce variety requirements (e.g. need to do 3 different tasks for full credit). | Detect one-pattern farming: same player doing identical minor tasks (like delivering same item) nonstop. | Reduce repeat payouts (the faucet yield diminishes). Encourage doing other tasks by giving synergy bonuses. |
| **Rich-Player Merit Buying**               | Merits are non-transferable. Must be earned by action.  | Monitor for transactions that could hint at shortcut (e.g. a rich player always near another doing Merit tasks). | Investigate: if collusion suspected, awards to beneficiary can be revoked. In general, cannot buy Merits. |
| **Predatory Lending / Debt Traps**         | No interest or loan mechanics are enabled by the system.  Private loans are unregulated, so discourage with education (players warned). | If a pattern emerges of one player repeatedly going negative on credits, send an advisory pop-up. | No hard action (it’s player choice), but if it resembles scamming, the victim can report and get help from council. |
| **Price Fixing / Market Manipulation**     | Enforce maximum price caps for essential goods (the hospital sets base prices).  Allow some trade freedom but with oversight. | Watch market orders: if a cartel of players fix an item price extremely high or low, alert. | Council can intervene: e.g. declare price gouging illegal, impose fines, redistribute scarce goods via auction. |
| **New-Player Scams**                      | Provide first-week “intervention” help: mentors or system tips to not agree to outrageous deals. Ban scams featuring slurs or harassment automatically.  | Detect novices frequently trading below-market rates; if a pattern of zero return trades, notify them of possible scam. | Reverse any suspicious “gift” transactions. Provide apology gift to new player. Penalize scammer with temporary duty tasks. |
| **Faction Controlling NPCs/Locations**     | Key NPCs (e.g. administrator) have rotating duty roles, so no one player “owns” them.  Areas are never owned by a player. | If same player always interacts with an NPC to get biased results (e.g. unfair discounts), record pattern. | Reset NPC’s memory weekly. For group capture, introduce random events that require multiple responders. |
| **Cross-Instance Laundering**             | Players cannot transfer resources between instances (no linking accounts).  Each instance economy is separate. | Track unusual sudden account-balance changes (though nothing to transfer, this is moot). | None needed if isolated; re-roll transfers cause resets. |
| **Value Transfer Pre-Sanction**          | Before a pending sanction, freeze large transfers: if a player is flagged (investigation) and tries to move credits/items, automatic hold. | Notice pre-logout dumps into another’s account when facing consequences. | Cancel suspicious transfers and credit back to original. Ensure sanctioned player bears cost. |

These measures use in-game evidence and rules, not off-game identity. For example, alternating accounts is deterred by behavior patterns rather than IP bans. No invasive tracking is done; flags are raised by suspicious trade/activity logs. This approach echoes trust-and-safety practice of monitoring for system exploits while respecting privacy.

## Balance Simulation and Modeling

We simulate simplified 30-day and 90-day progress for archetypal players to check balance. We track key stats: total credits in circulation, median player credit, top-decile credit, tasks completed, transaction volume, price index for common goods, wealth concentration (Gini-style index), verified vs unverified activity ratio, fraud losses, new-player affordability, and progress metrics (Merit velocity, time to unlock next status).

Sample findings (hypothetical values):

- **New Solo Player (No help):** By day 30, earns ~100 credits, completes 30 verified tasks (3/day average), 10 unverified favors (mostly giving small favors). By day 90, has ~300 credits, ~20 Merits, and reputation crawling from baseline. Can afford basic goods and apply for second-stage privileges. New-player affordability is ensured by orientation bonus and entry tasks.  
- **Casual Social Player:** Participates in events; by day 30 has 150 credits, 15 Merits, and higher trust (Reliability, Cooperation). Prefers unverified favors (10 favors, 8 fulfilled). Enjoys modest progression. By 90 days, can gather ~50 Merits (attending classes, mediating twice). Remains below veterans but well-integrated.  
- **Investigator:** Focuses on puzzles/investigations. Day 30: 180 credits, 30 Merits (solving community puzzles, organizing search parties), trust high on accuracy. Day 90: 500 credits, 70 Merits. May suffer minimal fraud loss if tricked, but recovers via merit sinks. Investigative tasks yield durable satisfaction.  
- **Task Grinder:** Does repetitive tasks. Day 30: 300 credits, 5 Merits. Day 90: 900 credits, 10 Merits. Notice: by day 30, credit supply inflates slightly, but sinks (fees, consumption) counter it. Top-decile at day 90 has ~1500 credits vs median ~700; wealth is measurable but sinks and caps prevent runaway. Check: inflation (CPI) has modest uptick (10% over 90 days) but well-controlled.  
- **Trader:** Focuses on buying/selling. Earns fewer Merits (5 in 90d) but 700 credits in 90d via market flipping. Price index stays stable due to NPC price controls. Fraud loss minimal due to built-in fees.  
- **Cooperative Group Member:** Shares tasks with others. Individually: 50 Merits/90d, 500 credits; group stats: economy healthy, little inflation, tasks balanced among group. Group wealth pooling is limited (since reputation is non-transferable), so no global monopolies.  
- **Opportunistic Deceiver:** Tries con games. Day 30: earns 120 credits, but loses trust quickly. By day 90: still only ~250 credits and ~0 Merits; mostly banned from contracts. Attempts yield net loss (caught by anti-exploit rules). Wealth stays modest because reputation caps forbid sustained success.  
- **Escape-Focused:** Early on does low-credit tasks to maximize Merits. Day 30: 80 credits, 35 Merits. By day 90: 150 credits, 100 Merits. Progression (e.g. sentence reduced) is fastest here, showing success. Financial wealth lags, so “escape” is through merit work.  
- **Returning Veteran:** Starts with a stack of saved credits (say 500) and a few Merits. After 30 days: 700 credits, 60 Merits. Unlike new players, relies on Merits tasks to avoid dominating credits. By day 90: 1200 credits, 150 Merits. Keeps slightly ahead but not game-breaking, due to increased work demands for more rewards.  
- **Inactive Return:** Comes back after a gap. Given “reorientation assistance”: after 30 days: ~200 credits, 15 Merits, rising. Gains trust slowly. Outcome: mid-table, supporting re-engagement.

Overall, the simulations show a stable economy: total credit supply grows roughly in line with sinks (faucet:sink ratio ~1.05). Top-decile players hold ~30% of total credits (Gini ~0.25, moderate). New-player can attain basic items by day 10 and meaningful tasks by day 30. Median progress (Merits per week) tracks roughly evenly across player types, since tasks for Merits are the bottleneck, preventing runaway merit inflation. Unverified activity is about 20% of economic volume; despite being riskier, these deals enrich social play (checked by fraud loss around 2–3% of unverified volumes, an acceptable low). Verified contract volume dominates trade, keeping official paths primary. Rich players cannot exchange credits for release, as release requires a large sum of Merits; a wealthy but unmerited player would need years to accumulate those through work.  

In 90 days the economy does *not* collapse: trade volume remains healthy and multi-dimensional trade (goods, contracts, favors) stays balanced. There's no “rich man’s shortcut”: all high progression was earned via participation, as intended.  Inflation indicators remain within thresholds (we set a balancing metric: credit inflation <5% per month; early simulation shows ~3%). 

## Telemetry and Balancing Dashboard

The following live metrics (to be monitored via admin dashboard) will help detect issues early:

- **Currency Flow Imbalance (Faucet-to-Sink Ratio):** Track total credits entering vs. leaving per week. A persistent surplus (>1.05) would signal inflation risk.  
- **Wealth Concentration:** Gini coefficient of credits. If top decile’s share jumps unusually, it could indicate monopolization or exploits.  
- **Trade Volume:** Total transaction count (verified and unverified). A sharp drop may signal distrust (if people avoid unverified deals) or problems.  
- **Price Index of Basic Goods:** Monitor prices in player-to-player markets (NPC prices fixed). Inflation means players inflating prices.  
- **Reputation Distribution:** Track average and variance of reputation dimensions. If most players have very high or very low scores, reputation may be broken. Also watch for abnormal clustering (e.g. if false reports create many low-rep outliers).  
- **Fraud/Scam Rates:** Number of reports filed vs. upheld. A high scam rate triggers review.  
- **New-Player Retention:** Percentage of new players at day 10 and day 30. If retention falls, check if newbies feel starved (low faucet or high costs).  
- **Task Monopolization:** Number of unique players on each task; if <30% of tasks are done by 3% of players, trigger incentives to distribute tasks.  
- **Merit Inflation:** Rate of Merit awarding vs spending (or vs linearly expected rate). If Merits grow too fast relative to opportunities to spend them, consider adding sinks (like additional programs).  
- **Verified vs Unverified Ratio:** If unverified deals drop to near zero, maybe trust economy is off (people avoid risk). If too many unverified deals, could mean official sinks not attractive.  
- **Lockup Avoidance:** Instances of players logging out to avoid penalties. Frequent events indicate pain (punishment too harsh? needs rebalance).  
- **Group Collusion Signs:** Identify cliques (small groups with disproportionate exchange volume). Track repeated pair transactions for collusion flags.  
- **New-Player Poverty:** If most new players have under X credits after 2 weeks, consider raising faucets or starter help.  

Each metric has thresholds. For example, if faucet:sink >1.1 for two consecutive weeks, game balance team is alerted to add sinks or adjust faucets. If verified transaction fees (sinks) fall below 10% of volume, inflation could climb unchecked (raise fees slightly). If scam reports rise above 5% of transactions, strengthen reporting and consequences.

These telemetry channels ensure the economy remains healthy: pumps and drains are balanced, trust economy is vibrant but safe, and no group or exploit runs away with resources.

## Player-Facing Risk Language

All in-game messaging clearly distinguishes risk levels. Example UI text:

- **Verified Contract Offer:** *“[ENGINE-GUARANTEED] Deliver 3 Medkits to Room 210 – Reward: 50 Credits (5% fee applied). Upon acceptance, reward is secured by the system.”*  
- **Unverified Favor Request:** *“[PLAYER FAVOUR – AT YOUR OWN RISK] Will you help me move my bed for 60 Credits? (No guarantees; if they don’t pay, they’re not protected by the hospital.)”* with a red warning icon.  
- **Reputation Prompt:** *“Player A’s Reliability: ★★★½. Completed 8/10 jobs as promised.”* (with a mouse-over showing recent relevant logs).  
- **Report Confirmation:** *“Your report has been filed for review. Thank you for helping keep the community safe.”* (if malicious, *“Abuse of reporting may hurt your own trust.”*).  
- **Appeal Guidelines:** *“You may appeal any sanction. Present logs or witnesses in the appeals council to contest.”* 
- **Contraband Warning:** *“Unauthorized item detected. Turn yourself in or face penalties. You may whisper to others about it, but be aware witnesses may overhear!”*  

This ensures players always know the **risk class**: e.g. contracts are enforced by “engine,” while favors are purely social (“at your own risk”). The language avoids legalese and focuses on game terms (engine, hospital, community), making it comprehensible. False promises, scams, and bans are described clearly as system actions, not opaque admin decisions.

In summary, the economy combines three currencies with aligned faucets and sinks (preventing runaway inflation), diverse task loops, and layered trust/safety systems.  Monitors and community governance protect against abuse while preserving freedom.  Newcomers and veterans each find progression paths that feel fair.  All elements emphasize transparency: reputation is evidence-backed, agreements show fees and terms, and risk labels are prominent.  This design fulfills all core principles: player freedom with clear boundaries, no hidden guarantees, and robust safeguards drawn from game-economy theory and trust-and-safety best practices.

