{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__computer_science","archetype_slug":"computability_boundary_mapping","domain_slug":"computer_science","title":"Model-Relative Termination Routing for Workflow Admission","opportunity_summary":"The candidate replaces an asserted total, exact Boolean termination gate for unrestricted workflows with an enforced exact fragment, bounded or sound-incomplete handling for other workflows, and explicit UNKNOWN states. It could prevent misleading admission guarantees and wasted implementation effort, but the sealed packet does not establish that the platform is actually unrestricted, that the problem is prevalent, or that a useful share of workflows fits a practical decidable fragment.","adopter_authorizer":"The workflow-platform owner can authorize a non-production sandboxed pilot; production guarantee changes require engineering, reliability, and security sign-off following independent proof review.","scores":{"meaningful_impact":{"score":4,"rationale":"The proposal directly addresses false authoritative verdicts, nontermination exposure, wrongful rejection, and downstream ambiguity. These consequences could be material for platform reliability, although their frequency and realized magnitude are unsupported."},"stakeholder_pull":{"score":3,"rationale":"Workflow authors, operators, downstream owners, and platform reviewers have identifiable reasons to value truthful guarantees, and a platform owner is named. The packet provides no evidence of expressed demand, incident frequency, budget commitment, or willingness to accept UNKNOWN outcomes."},"incremental_advantage":{"score":4,"rationale":"Unlike the Boolean timeout baseline and the heuristic-resource rival, the proposal changes the guarantee structure by enforcing an exact lane and preserving UNKNOWN elsewhere. Advantage remains contingent on enforceable membership, semantic fidelity, useful coverage, and downstream respect for the weaker label."},"distinctiveness_plausibility":{"score":2,"rationale":"The candidate is explicitly marked UNSEARCHED, and novelty evidence is its named weak dimension. The packet supports a coherent mechanism composition but supplies no affirmative basis for distinctiveness relative to existing termination-analysis, sandboxing, or routing approaches."},"technical_implementability":{"score":4,"rationale":"A non-production interpreter snapshot, one formalized subset, finite bounds, exhaustive tiny-program tests, explicit fallbacks, and rollback triggers make the first implementation technically bounded. Difficulty may rise sharply if interpreter semantics, external calls, or fragment enforcement cannot be represented faithfully."},"adoption_authority_feasibility":{"score":4,"rationale":"The platform owner, sandbox authority, production signatories, proof-review requirement, exclusions, and rollback conditions are all explicit. Feasibility is reduced by the need for multidisciplinary approval and possible author resistance to restricted coverage or frequent UNKNOWN results."},"evidence_readiness":{"score":4,"rationale":"The packet supplies independent problem and intervention falsifiers, a strongest counterhypothesis, a bounded pilot, exact-lane counterexample tests, and comparison with the current Boolean gate. Evidence is not fully ready because the actual admitted language and interpreter semantics have not been audited."},"safety_net_benefit":{"score":5,"rationale":"The intervention explicitly separates UNKNOWN, timeout, out-of-scope status, and observed nontermination; confines initial work to non-production; prohibits claims beyond enforced bounds; and defines concrete stop and rollback conditions."},"scalability":{"score":3,"rationale":"Versioned guarantees and routing could be extended across workflow classes, but the packet does not establish useful-workload coverage, analyzer performance, manageable UNKNOWN rates, resistance to unrestricted extensions, or tractable re-verification as semantics change."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"Audit one non-production interpreter snapshot, formalize one enforced workflow subset, check the reduction, implement an exact lane with YES/UNKNOWN routing, and exhaustively test tiny bounded programs.","confidence":"LOW","assumptions":["A small cross-functional engineering and formal-methods team can access the interpreter specification and test harness.","The first step covers one subset and fixed finite bounds, not production deployment.","No new specialized hardware or extensive third-party data acquisition is required."]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Turn a successful evidence prototype into a hardened, enforceable analyzer and routing component with versioned guarantees, telemetry, integration tests, reviewer documentation, and bypass controls.","confidence":"LOW","assumptions":["The platform has an integration boundary where fragment membership and fuel limits can be enforced.","Existing workflow APIs can represent UNKNOWN and scope metadata without complete replacement.","Semantic formalization does not expose a need to redesign the interpreter."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Conduct independent proof review, security and reliability validation, staged production integration, consumer migration from Boolean verdicts, operator training, and rollback preparation.","confidence":"LOW","assumptions":["Launch is staged within one workflow platform.","Downstream services can be updated to handle non-Boolean outcomes.","No major compliance regime or safety-critical certification is introduced beyond the packet's sign-off process."]},"annual_recurring":{"band_2026_usd":"50K_TO_250K","scope":"Maintain proofs and analyzers, recheck guarantees after semantic changes, monitor coverage and overrides, investigate counterexamples, and support downstream consumers.","confidence":"LOW","assumptions":["Interpreter changes are periodic rather than continuous.","The decidable fragment remains stable enough to avoid repeated redevelopment.","Monitoring and proof tooling can use existing platform infrastructure."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"YES","reason":"The sealed candidate identifies a concrete contradiction between an unrestricted total-exact termination requirement and the proposed halting reduction, along with observable Boolean collapse and specific downstream failure modes. Whether this describes the actual platform still requires audit."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The platform owner is identified as sandbox authorizer, while engineering, reliability, and security are identified as required production authorizers."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal makes a testable claim that an enforced terminating fragment can receive exact verdicts while all other cases retain weaker labels, compared with the baseline's collapsed Boolean result. A bounded counterexample or stronger-than-supported route falsifies the claim."},"bounded_next_evidence_step":{"status":"YES","reason":"The authorized non-production step limits the interpreter snapshot, workflow subset, syntax, inputs, steps, and states; includes a baseline comparison; and has explicit counterexample, abstraction, labeling, and bypass stop conditions."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The first step stays non-production, excludes unrestricted admission and relabeling UNKNOWN as NO, requires rollback on specified failures, and lies within the platform owner's stated pilot authority."},"implementation_cost_scope_and_range":{"status":"UNCERTAIN","reason":"The packet bounds the pilot activities but provides no staffing, platform-complexity, semantic-documentation, integration, compliance, or workload information. Broad resource bands can be assigned only with low confidence."}},"blocking_evidence":["An audit of whether admitted workflows are genuinely unrestricted or already governed by enforced finite-fuel or structurally terminating semantics.","A faithful, reviewable specification of the interpreter, external-call behavior, scheduler assumptions, and exact meaning of operational completion.","Proof or mechanically checkable evidence that fragment membership and runtime bounds cannot be bypassed.","Measured coverage and analysis cost on a representative, non-production workflow corpus, including the resulting UNKNOWN rate.","Evidence that downstream consumers preserve UNKNOWN and scope metadata rather than converting them into Boolean admission decisions.","Independent review that the exact-lane proof matches the concrete implementation and that bounded counterexample testing finds no advertised-guarantee violation."],"next_evidence_step":"On one non-production interpreter snapshot, first audit the currently enforced computation model against the problem falsifier; then formalize one enforceable subset, check the unrestricted halting reduction, and implement exact-fragment versus YES/UNKNOWN routing. Compare it with the current Boolean gate over all tiny programs within fixed syntax, input, step, and state bounds, stopping if any exact-lane counterexample, missing concrete behavior, stronger-than-supported label, or enforcement bypass appears.","research_questions":["Is the current admission class actually unrestricted, or is the candidate's computability diagnosis falsified by existing enforced bounds?","Can the concrete interpreter semantics, including external calls and scheduling, be modeled without omitting behavior relevant to termination?","What enforceable fragment provides enough representative workload coverage to justify adoption?","What runtime and proof-maintenance burden does exact classification impose as the interpreter evolves?","How often does routing return UNKNOWN, and do reviewers and downstream systems handle that state without unsafe overrides?","Does independent proof and implementation review confirm that every advertised guarantee is limited to its enforced model and version?"],"recommendation":"VALIDATE_PROBLEM_FIRST","uncertainty_constraints":["Closed-book assessment: no prior-art, prevalence, market-size, realized-impact, or exact-cost claims were verified.","The candidate is a hypothesis and explicitly classifies prior art as UNSEARCHED.","The strongest counterevidence could eliminate the stated problem if all admitted workflows are already mechanically bounded or structurally terminating.","Operational completion involving humans, sensors, nondeterministic scheduling, or changing external services may not match the formal halting model.","Cost bands are resource-equivalent planning ranges with low confidence, not estimates derived from platform data.","Scalability and stakeholder pull depend on unknown useful-workload coverage, UNKNOWN rates, integration burden, and override behavior."],"closed_book_prior_art_boundary":"No external search or prior-art comparison was performed. The assessment treats distinctiveness, prevalence, market size, realized impact, and competitive availability as unmeasured; it evaluates only the internal coherence, testability, authority, safety, and implementation implications stated in the sealed candidate."}