{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__earth_sciences","archetype_slug":"computability_boundary_mapping","domain_slug":"earth_sciences","title":"Model-Relative Decidability Boundaries for Earth-System Hazard Reachability","opportunity_summary":"On a frozen Earth-model language, determine whether unrestricted hazard reachability admits a total exact analyzer, prove and enforce any useful decidable fragment, and preserve UNKNOWN and failure states outside proven guarantees. The opportunity is safety-relevant but remains conditional on the production language's expressiveness and the scientific fidelity of the restricted fragment.","adopter_authorizer":"The Earth-model platform owner can adopt guarantee labels, fragment enforcement, and result-state handling; domain hazard authorities must authorize any operational use in hazard decisions.","scores":{"meaningful_impact":{"score":4,"rationale":"The proposal could prevent incomplete computation from becoming a false no-hazard verdict and could stop futile pursuit of an impossible universal analyzer. The frequency and operational consequence of such failures are not established in the sealed candidate, preventing a 5."},"stakeholder_pull":{"score":2,"rationale":"The candidate identifies model authors, analysts, platform engineers, agencies, and exposed communities, but supplies no evidence that any stakeholder has requested the intervention, experiences the stated failure in production, or will accept restricted expressiveness."},"incremental_advantage":{"score":4,"rationale":"Relative to timeout-based Boolean handling and solver scaling alone, the proposal adds model-relative proofs, enforceable scope boundaries, typed unresolved states, and versioned reclassification. Advantage remains conditional on producing valid proofs and a scientifically useful fragment."},"distinctiveness_plausibility":{"score":3,"rationale":"The composition of formal reduction, constructive fragment analysis, enforced routing, and interface-state preservation is coherent and specifically testable, but prior art is unsearched and world distinctiveness is explicitly unmeasured."},"technical_implementability":{"score":3,"rationale":"Freezing semantics, testing synthetic encodings, and constructing a bounded finite-state analyzer are technically bounded activities. Production implementation is uncertain because the language may lack stable semantics, a valid reduction may fail, fragment membership may be unenforceable, and state-space explosion may defeat practical use."},"adoption_authority_feasibility":{"score":4,"rationale":"The candidate assigns guarantee labeling and analyzer routing to the platform owner while preserving operational decisions for hazard authorities, providing a plausible authority split. Feasibility is reduced by the need for coordination across model authors, analysts, consuming systems, and domain reviewers."},"evidence_readiness":{"score":2,"rationale":"The candidate provides explicit falsifiers, safety boundaries, and a sandboxed test design, but supplies neither a checked impossibility reduction nor a proved-total, semantically faithful analyzer, production-language audit, or user-interpretation evidence."},"safety_net_benefit":{"score":5,"rationale":"Preserving UNKNOWN, timeout, numerical failure, and out-of-scope states directly addresses the stated false-clearance pathway, and the authorized first step uses only synthetic sandbox models without changing public hazard classifications."},"scalability":{"score":3,"rationale":"The boundary-and-routing pattern could be reused across model versions and hazard predicates, but each language or semantic change requires renewed formalization and evidence, while state-space explosion and scientifically essential plugins may limit usable coverage."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"Freeze one representative model language; specify syntax, semantics, quantifiers, and hazard predicates; attempt a checked reduction and a proved-total bounded-fragment analyzer; obtain independent formal and Earth-science review; and run synthetic status-preservation tests.","confidence":"LOW","assumptions":["One representative language and hazard predicate are examined.","Existing model documentation and sandbox infrastructure are available.","Work requires specialist formal-methods, Earth-science, platform-engineering, and evaluation labor.","No live hazard classification or production deployment occurs."]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"For one platform, implement enforceable fragment membership, analysis routing, typed result states, evidence versioning, audit records, integration tests, and analyst-facing interface changes.","confidence":"LOW","assumptions":["A valid proof artifact and scientifically acceptable fragment are obtained first.","The existing platform can expose stable parser, plugin, and result-interface boundaries.","The scope is one platform rather than a multi-agency ecosystem.","Major model-language redesign and new compute infrastructure are excluded."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Validate and launch the qualified analyzer workflow on one platform, including independent assurance, user-comprehension testing, consuming-system integration, documentation, training, governance approval, and monitored rollback readiness.","confidence":"LOW","assumptions":["Launch retains hazard-authority control and does not itself issue hazard clearances.","Only proven guarantee labels are introduced.","A limited number of analyst teams and downstream integrations are included.","No broad public-sector procurement or migration of all historical models is assumed."]},"annual_recurring":{"band_2026_usd":"50K_TO_250K","scope":"Maintain proof and semantics records, reclassify after language or plugin changes, monitor result-state interpretation, rerun regression and soundness checks, support users, and preserve auditability for one platform.","confidence":"LOW","assumptions":["Language changes are controlled and infrequent.","No continuous redevelopment of the formal analyzer is required.","The platform already funds ordinary hosting and baseline operations.","Material scope expansion or multi-platform certification would raise the band."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"YES","reason":"The candidate identifies a concrete observable failure mode: Boolean outputs can collapse timeout, numerical failure, and unresolved analysis into apparent no-hazard conclusions. Whether this occurs frequently in production remains unverified."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The model-platform owner is identified as able to classify analyzer guarantees and enforce interfaces, while domain hazard authorities retain operational decision authority."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal claims that formal boundary classification plus enforced result states can provide justified guarantees for a restricted fragment and prevent unresolved computation from being represented as no hazard, relative to timeout-based Boolean handling or solver scaling alone."},"bounded_next_evidence_step":{"status":"YES","reason":"The sealed candidate authorizes a frozen, synthetic sandbox study that compares a checked unrestricted-language reduction with a constructive bounded-fragment procedure and forbids publication of hazard clearance."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The first step is synthetic and sandboxed, excludes changes to public classifications, preserves hazard-authority responsibility, and includes explicit halt and rollback conditions."},"implementation_cost_scope_and_range":{"status":"UNCERTAIN","reason":"A broad one-platform resource range can be framed, but the sealed candidate does not specify language size, proof-tooling readiness, integration count, compliance requirements, model inventory, or operational compute needs."}},"blocking_evidence":["A frozen specification of the actual admitted production language, including plugin boundaries, transition semantics, horizons, quantifiers, and hazard predicates.","Independent verification of either a property-preserving impossibility reduction for the unrestricted class or evidence that the required encoding is unavailable.","A mechanically enforceable restricted fragment with a proved-total, correct analyzer.","Earth-science review showing that the restricted fragment retains behavior necessary for the intended hazard task.","Evidence that interfaces, analysts, and consuming systems keep UNKNOWN, timeout, numerical failure, out-of-scope, witnessed reachability, and qualified safety distinct.","Operational feasibility evidence addressing state-space explosion and the usefulness of the decidable fragment."],"next_evidence_step":"On a frozen sandbox copy of one representative model language, audit all admitted constructs and compare two explicit hypotheses: either produce an independently checked hazard-property-preserving halting-style encoding for the unrestricted language, or falsify that branch by showing the required encoding is unavailable; in parallel, construct and verify a finite-state, bounded-horizon analyzer and test whether membership is enforceable and Earth-science reviewers judge the fragment semantically useful. Stop if preservation, totality, membership enforcement, or soundness cannot be established, and use only synthetic models with no hazard clearance.","research_questions":["What exact production syntax, semantics, plugin powers, time horizons, and hazard quantifiers define the admitted decision problem?","Can the unrestricted language encode arbitrary computation while preserving the specified hazard-reachability property?","If not, is the complete admitted production class already finite, bounded, and total in a way that falsifies the computability-boundary premise?","Can a useful restricted fragment be mechanically recognized and supported by a proved-total, correct analyzer?","Do excluded constructs remove scientifically essential Earth-process behavior or materially change the hazard predicate?","Is the decidable fragment computationally usable at representative state sizes, or does state-space explosion eliminate operational value?","Do users and downstream systems preserve all qualified and unresolved result states without interpreting them as no hazard?","What governance event triggers re-verification when semantics, plugins, abstractions, or hazard predicates change?"],"recommendation":"PARTNERED_RESEARCH","uncertainty_constraints":["No external evidence establishes that the stated Boolean-collapse problem occurs in a deployed Earth-model platform or how prevalent it is.","The actual model language may already be finite-state and bounded, in which case the central issue is complexity or numerical engineering rather than undecidability.","No valid impossibility reduction has been supplied.","No totality or correctness proof has been supplied for a scientifically faithful restricted fragment.","Prior art, current practice, comparative prevalence, market size, realized impact, and world novelty are unmeasured.","Cost bands are resource-equivalent planning ranges based only on the proposed scope, not platform-specific estimates.","A theorem about an executable model language would not establish that the physical Earth itself is computationally undecidable.","A formally correct backend may still be unsafe if interfaces or users collapse qualified outcomes."],"closed_book_prior_art_boundary":"Prior art status is UNSearched. This assessment makes no claim that formal decidability analysis, bounded model checking, typed UNKNOWN states, proof-carrying analyzers, or their proposed composition is novel, rare, or absent from Earth-science platforms; those questions require external research."}