Picture a film camera bolted to the side of one character’s head. Not on a dolly, not in the hands of an operator who can pan to the interesting thing across the room. Bolted. It films what that head faces. Nothing else. Someone has welded a warped lens over the front of it, tinted just enough that even the narrow cone it captures comes back a little wrong.
That is third person limited. The camera is your point of view, locked to one person. The lens is what that person believes about the world.
Now hand the footage to an AI that has read the entire script. Every character’s chapter. The whole board. The parts this narrator never walks through. It knows what stands behind the camera, and two rooms over, and in a book this character never appears in, and it holds every bit of that ready the instant you ask it for a scene. And it will not stop trying to unbolt the thing and swing it around to show you.
That pull is the subject of this piece. Not a prompting slip. It is a structural leak that lives in the model itself, and what follows is the stored boundary you build so the camera cannot be swung loose no matter how badly the model wants the wider shot.
Unreliable, or Just Relative?
Reach for the obvious word first, because it is almost right, and the almost is the whole problem. Are these narrators unreliable?
Wayne C. Booth coined the term in The Rhetoric of Fiction in 1961. His definition is still the cleanest one: “I have called a narrator reliable when he speaks for or acts in accordance with the norms of the work (which is to say, the implied author’s norms), unreliable when he does not.” The load-bearing word is norms. Booth assumes an objective record, the work’s own truth, and unreliability is measured as distance from it.
Hold onto that. The objective record exists. It is the one thing the AI can see in full and the narrator, locked inside a single head with a lens welded over the eye, cannot.
Here is the reframe. Every point of view narrator is unreliable, but not in the con-artist sense of a narrator lying to your face. Each one’s ground truth is true only relative to them, which is why Vera’s account of her own club is flawless as a portrait of Vera and worthless as a map of anyone else. It is just not the account the whole board would give, because Vera cannot see the whole board, and the board is precisely the thing the narrator never gets to read. Nobody living inside a single head can.
James Phelan sharpened this in Living to Tell About It in 2005. He splits unreliability into six types across three axes: reporting facts, reading or perceiving, and regarding or judging. Each axis has a “mis-” version, where the narrator gets it actively wrong, and an “under-” version, where the narrator simply does not have enough. A narrator who withholds or omits is underreporting, and Phelan files that under the unreliability umbrella too. So the tidy line some writers draw, “my narrator is not unreliable, only limited,” does not survive contact with the theory. Limited is a species of unreliable.
The distinction that matters is Phelan’s other one. In a 2007 essay on Lolita he separates estranging unreliability from bonding unreliability. Estranging pushes the reader away. Bonding pulls the reader closer. A limited narrator is the bonding kind: you trust the report as an honest account of what this person perceives, even as you see what they cannot.
Kazuo Ishiguro’s butler Stevens tells you exactly what he saw at Darlington Hall, and you believe every word of the seeing even as you watch him miss the one thing the whole book is about, the life he spent inside that house and never once let himself have. The report is trustworthy. The camera is just bolted to one head.
The Camera and the Lens
Four writers each installed one piece of this rig. Keep their jobs separate.
Booth built the frame. An objective record exists, and unreliability is measured as distance from it. Orson Scott Card bolted the camera. In Characters and Viewpoint in 1988 he described third person limited as a cinematic distance, where the narration sees and hears only what the viewpoint character does, with the writer choosing how deep to penetrate that character’s thoughts. The camera goes where the head goes. It cannot cut away.
K.M. Weiland welded the lens. In Creating Character Arcs in 2016 she named the thing that distorts the view: the Lie the Character Believes, the false relative truth born from the character’s Ghost, the old wound, and challenged across the arc by the story’s Truth. Weiland is careful that the Lie and the Truth are relative within the story, not a fixed moral black and white. That is the lens. Not smudged glass you wipe clean. It is the character’s whole way of reading events, ground down from the wound and welded permanently over the eye, so that every scene arrives already bent.
The Vampires of Tucson writing room stores this per character in a field called character_state: a record of what a character knows, what they believe, and the Lie they run everything through. Take Babydoll. Her Ghost is her father’s conditioning. Her Lie, in her own words, is that some part of her still thinks that is what she is supposed to be. That belief is not a mood she can be talked out of. It is the ground she stands on.
Her character_state carries a standing note. She reads every new horror through the lens of the first one. When a scene renders from Babydoll, the lens is not optional set dressing. It is the ceiling. Nothing above it reaches the page. She reads a kindness as a setup, because the record says she must.
That is the camera and the lens. One authority locked the frame to a head. The other ground a wound into glass, bolted it over the eye, and left it there so nothing this character sees again ever arrives unbent. Now watch what a model does when it can see past both.
What the Model Does With a Whole Canon
Give an AI the entire canon and ask it to narrate a scene from one character, and its instinct is to make the scene cohere with everything it knows. That instinct is the leak.
Call it sycophancy toward coherence. The model would rather your character quietly know everything than let a single scene feel unfinished. So it unbolts the camera. It reaches across the board for a fact the narrator never earned and drops it into the prose to smooth the seam.
Now the girl is alive two miles away, the narrator somehow senses it, and your dramatic irony is dead on the page before anyone noticed the body. Gone. Dramatic irony, the gap where the reader knows what the character does not, is the exact thing the leak destroys. Every time.
Here is the load-bearing example. Straight from the manuscript. In Crimson Cabaret, Vera does not know that Azul, a girl who slipped her operation years back, is alive and building a family roughly two miles from the club, a daughter and a husband and a quiet life the ledger has no column for. Vera reads that old loss as intercepted merchandise, a debt the ledger never settled.
The reader knows the truth. The reader has been inside Azul’s book. Watched her live.
In the writing room this is tracked two ways: canon holds the objective fact that Azul is alive and free, and an open_threads record, tagged information_withheld, marks that the reader holds a fact Vera does not. open_threads is just the table of unfinished business, the questions and secrets still in play.
Watch the boundary change the prose. First, the leak. This is the model unbolting the camera:
She thought of the girl sometimes. Azul. Out past the reservation road she was alive, a daughter on her hip and a husband asleep down the hall, two miles from the Cabaret and free. Vera did not know that, of course. She only knew the ledger showed a loss.
Every word after Azul’s name is contraband. The narration reaches across the board, states that the girl is alive and free, and then tries to launder the theft with “Vera did not know that, of course.” The hedge is the tell. The camera swung. The disclaimer only admits it.
Now the sealed version, the camera bolted back down:
She thought of the girl sometimes. The one who slipped the leash and cost her a buyer and a season’s standing. Somewhere the merchandise was rotting in a ditch or working a worse house than hers, and either way the ledger stayed short a name. Vera did not chase losses. She noted them, the way she noted weather, and made the room pay for them twice.
Same memory, same character, opposite epistemics. The sealed version asserts only what Vera knows and believes. Nothing more. The gap stays open. The reader still holds the truth Vera cannot, the dramatic irony survives untouched, and the scene keeps the tension the leak would have quietly drained out of it.
The boundary that produces the second paragraph is not a hope that this session’s prompt remembers the rule. It is a stored instruction. Here is the one the writing room hands the model on every limited scene:
Narrate this scene in third person limited. The camera is bolted to [POV]'s head.
GROUND TRUTH (canon, for your reference only, NOT the narrator's knowledge):
[what actually happened, the objective record of this moment across all characters]
WHAT [POV] KNOWS AND BELIEVES (character_state, this is the narration's ceiling):
- Knows: [the facts this character actually has]
- Believes / their Lie: [the wound-born relative truth they read events through]
- Does NOT know: [canon facts beyond this character's reach right now]
RULES:
1. The prose may only assert what [POV] knows or believes. Never state a ground-truth
fact [POV] has not earned.
2. Render events through their Lie. Where the objective record and their belief disagree,
write the belief. Do not correct it, hedge it, or explain it away.
3. Where [POV] lacks knowledge, let the gap stand. Do not foreshadow, hint, or have them
"sense," "somehow know," or "feel in their bones" the truth.
4. Report back any gap between GROUND TRUTH and what [POV] believes, so it can be logged as
an information_withheld thread.
Rule three is the one that saves Vera. Every leak I have caught wore the same costume: a character who suddenly sensed, or somehow knew, or felt in her bones the precise thing the model wanted on the page and the narrator had no way to reach. The prompt bans the costume.
Naming the Distortion
Not every leak looks the same. Different distortions sit on different axes. Phelan’s six types earn their keep here. Each one tells you which field in the store is doing the work.
Two more canon cases, fast. Bill, early in Crimson Cabaret, is fed a lie by Ochoa about a woman named Cecilia. What Bill knows and what happened do not match, and the mismatch is tracked as information_withheld, because the reader will eventually learn the truth Bill was denied. That is an “under” distortion on the facts axis. An omission weaponized.
Betsy, in the Babydoll book, is told there will be clemency while extermination is the actual order. Her own character_state carries a humanity_note that frames the killing as spiritual duty, which puts the distortion on the ethics axis: a wrong moral frame laid over a fact she reads correctly. Same architecture, different field, different axis.
That mapping is stable enough to write down. Each Phelan type lands on a specific place in the store, measured against canon:
| Phelan type | Axis | What the narrator does | Writing-room field that carries it |
|---|---|---|---|
| Misreporting | facts / events | states a wrong fact as true | character_state (belief) vs canon (record) |
| Misreading | knowledge / perception | misperceives or misinterprets | character_state.psychological_state (the lens) |
| Misregarding | ethics | wrong moral frame on a right fact | character_state.humanity_note (e.g. “genocide as spiritual duty”) |
| Underreporting | facts / events | omits or withholds | open_threads.information_withheld |
| Underreading | knowledge / perception | misses the significance | open_threads.unresolved_question |
| Underregarding | ethics | under-weighs the moral stakes | character_state.humanity_note / arc_markers |
The source of all six distortions is the same, the character’s Lie stored in character_state, and the thing every one of them is measured against is also the same, the objective board of canon. The table is not theory. It is the routing map. The writing room already runs on it.
Board Versus Fog
This is where the writing room does something the tools built for this market do not. Two layers, not one.
The AI worldbuilding tools store a world well. NovelCrafter’s Codex keeps a structured database of your world and injects the relevant entries into the prompt so the model stays consistent. Sudowrite’s World Bible stores your worldbuilding, and its Novel feature lets you set point of view to first or third and name the main character. Scrivener gives you a binder to organize every note and sketch in one place. Each is good at its job. None of them is the enemy here.
They store one thing. The writing room stores two. Codex, the World Bible, and Scrivener all hold what is true: one canonical layer the model treats as the world. Sudowrite’s Novel setting fixes the grammar of the narration, first person or third. Grammar is not knowledge. None of them holds a separate, per-character record of what each character believes is true, complete with the Lie they believe it through.
They store the board. The writing room stores the board and the fog: one objective record, plus N relative truths, one per head the camera can bolt to.
That gap is the whole reason the leak is a solved problem on one manuscript and an open one everywhere else. If the store only knows what is true, the model has nothing to check itself against when it wants to leak, but if the store also knows what each narrator is allowed to know, the boundary becomes queryable and holds across context resets, new sessions, and eleven books of accumulated canon.
The Camera Stays Bolted
An earlier piece in this series argued that you must give the AI the facts, because a model that cannot query your world will invent it. That was Your Docs Are for You. Your Database Is for the AI. This is the corollary that faces the other way, the same rule turned around to point at what the model must never say. You must also deny the AI the facts the narrator has not earned, which means handing it the whole world to read and then forbidding it to narrate from the very board you just let it see.
That is not a contradiction. It is one architecture, read from both ends. Canon is one thing, an objective record the model reads freely. character_state is a different thing, a per-character ceiling the model narrates under, set at the exact height of what this narrator has earned and not one fact higher.
The tools that store only the first will always let a coherent narrator turn quietly omniscient. The one that stores both can keep a secret. Even from its own storyteller.
The camera stays bolted. That is the whole job.
You may also like:
- Your Docs Are for You. Your Database Is for the AI.
- The location Field or How Your Setting Drifts When Nobody’s Watching
- Defining Character Voice