{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__material_culture_museum_studies","archetype_slug":"computability_boundary_mapping","domain_slug":"material_culture_museum_studies","title":"Guarantee-Labeled Verification Routing for Executable Museum Artefacts","opportunity_summary":"The candidate proposes replacing unconditional Boolean preservation verdicts with scope-enforced exact verification where justified, labeled weaker methods elsewhere, and explicit UNKNOWN outcomes. It could prevent incomplete computational evidence from authorizing harmful collection decisions, but the sealed packet does not establish that museums actually demand universal exact verification rather than finite, bounded, or instance-specific assessment.","adopter_authorizer":"A museum's delegated digital-conservation and collections-governance authorities, with curators defining significant properties and an independent reviewer approving formal claims.","scores":{"meaningful_impact":{"score":4,"rationale":"If the described Boolean overclaim occurs, avoiding false assurance could protect originals, dependencies, access, and evidentiary integrity. The magnitude is potentially high, although the packet does not establish how often such decisions occur."},"stakeholder_pull":{"score":2,"rationale":"The problem says museums may seek a universal verifier but supplies no observed request, workflow record, budget commitment, or adopter testimony. The stated problem falsifier could eliminate the demand premise entirely."},"incremental_advantage":{"score":4,"rationale":"Compared with ad hoc testing or an always-answering heuristic, enforced scope, guarantee labels, explicit UNKNOWN, versioned records, and independent review directly address the conversion of timeouts or sampled traces into unsupported verdicts. Advantage depends on institutions preserving those distinctions downstream."},"distinctiveness_plausibility":{"score":3,"rationale":"The proof-to-routing-to-governance combination is coherent and proposal-specific, but prior art is explicitly unsearched. Distinctiveness relative to existing digital-preservation, significant-properties, emulation, and software-heritage workflows is therefore unresolved."},"technical_implementability":{"score":3,"rationale":"An offline 30-object pilot, scope classification, bounded analysis, and labeled outputs appear implementable in principle. Faithful property formalization, enforceable fragment membership, sound abstractions, and a valid checked reduction remain substantial technical uncertainties."},"adoption_authority_feasibility":{"score":4,"rationale":"The packet identifies joint conservation and collections-governance authority, assigns curatorial and independent-review roles, excludes dispositive pilot use, and provides halt and rollback rules. Multi-party approval and the risk that labels acquire excessive authority prevent the highest score."},"evidence_readiness":{"score":3,"rationale":"The candidate supplies observable outputs, separate problem and intervention falsifiers, a comparison baseline, and a bounded shadow pilot. It lacks evidence that the target requirement exists, a completed formal reduction, validated abstractions, or demonstrated representational adequacy."},"safety_net_benefit":{"score":5,"rationale":"Explicit UNKNOWN, labeled guarantees, retention of originals and logs, prohibition of irreversible pilot actions, independent review, and reversion to curator-led assessment provide strong safeguards against both computational overclaim and pilot-induced collection harm."},"scalability":{"score":2,"rationale":"Each heterogeneous artefact may require curator-defined properties, environment modeling, dependency analysis, scope enforcement, and expert review. High UNKNOWN rates or labor-intensive formalization could make collection-wide operation impractical."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"Offline shadow pilot on 30 already-accessioned executable objects, including one property formalization per object, environment containment, routing, baseline comparison, logging, analysis of UNKNOWN and disagreement rates, and independent review of one proposed reduction.","confidence":"LOW","assumptions":["Existing objects and preservation records are accessible without new rights acquisition.","The pilot reuses existing museum computing infrastructure and does not restore severely degraded dependencies.","Formal-methods, conservation, curatorial, and independent-review labor are included.","No pilot output changes preservation or access status."]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Design and integration of scope admission, labeled analysis modes, UNKNOWN handling, versioned records, review workflows, staff training, security controls, and governance documentation for one institution.","confidence":"LOW","assumptions":["Deployment covers one museum rather than a multi-institution platform.","Existing collection-management and preservation systems expose usable integration points.","The institution limits initial coverage to selected executable-object classes and properties.","Specialized formal-verification and digital-conservation expertise must be contracted or allocated."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Controlled launch for a selected collection segment, including object intake, property formalization, environment capture, abstraction validation, independent claim review, user training, evaluation, and incident-response preparation.","confidence":"LOW","assumptions":["Launch remains advisory and guarantee-labeled rather than automatically dispositive.","A material fraction of objects requires individualized technical and curatorial work.","Originals, dependencies, and prior records remain retained.","No major custom emulator reconstruction is required for most launch objects."]},"annual_recurring":{"band_2026_usd":"250K_TO_1M","scope":"Ongoing specialist staffing, curator and reviewer time, environment and dependency maintenance, reruns triggered by scope changes, audit-log retention, software upkeep, training, governance review, and outcome evaluation for one institution.","confidence":"LOW","assumptions":["Coverage is limited to a selected executable collection rather than every digital holding.","Expert review remains mandatory for formal claims and exceptional cases.","Environment changes trigger reassessment rather than silent inheritance of prior guarantees.","Recurring cost excludes unusually complex one-off restoration projects."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"UNCERTAIN","reason":"The packet presents a precise and consequential failure mode, but states only that museums may seek a universal verifier and provides no evidence that an institution currently makes the open-ended total claim."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The candidate identifies delegated digital-conservation and collections-governance authorities, curators, and an independent formal-claim reviewer with differentiated responsibilities."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal can test whether scope enforcement, guarantee labels, routing, and explicit UNKNOWN reduce unlabeled Boolean verdicts outside verified scope relative to current curator-led testing."},"bounded_next_evidence_step":{"status":"YES","reason":"The authorized 30-object offline shadow pilot is non-dispositive, defines one narrow property per object, measures UNKNOWN and disagreement, and independently reviews a proposed reduction."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The pilot excludes destructive or status-changing actions, retains originals and logs, specifies joint authority, and mandates halt and rollback for failed review, unsupported soundness, unsafe execution, or out-of-scope Boolean output."},"implementation_cost_scope_and_range":{"status":"UNCERTAIN","reason":"The candidate bounds pilot scope and names core components, but supplies no institutional system inventory, staffing model, object-complexity distribution, integration requirements, or observed formalization effort sufficient to validate implementation ranges."}},"blocking_evidence":["Evidence that at least one target institution or workflow requires, promises, or implicitly treats results as a total exact answer over an open-ended executable class.","A faithful formalization of the executable artefact, environment, and significant behavioral property that does not silently broaden the claim to cultural meaning.","Independent confirmation that the proposed reduction preserves the target answer under the declared computation model.","Evidence that fragment admission is enforceable and that any abstraction labeled sound has a substantiated soundness basis.","Pilot evidence that guarantee distinctions and UNKNOWN remain visible in downstream governance rather than collapsing into a single preservation status.","A closed-book-unavailable comparison with existing preservation and software-heritage workflows before any distinctiveness claim."],"next_evidence_step":"Run the authorized offline shadow pilot on 30 already-accessioned executable objects and compare the existing curator-led conclusion with the guarantee-labeled routed assessment for each object. Record whether either process emits an unsupported Boolean after timeout, bounded traces, or scope failure; measure UNKNOWN and expert disagreement; and independently check one reduction. Stop or reject the opportunity if all actual claims are explicitly finite or instance-specific, the reduction fails review, sound routing cannot be enforced, or labeled outputs still induce false out-of-scope Boolean verdicts.","research_questions":["Do any actual institutional requirements demand a total exact answer over an open-ended class, or are all preservation claims finite, bounded, or instance-specific?","Which significant properties can curators formalize without omitting behavior essential to the museum's intended claim?","Can fragment membership and environment assumptions be checked automatically and enforced before an exact guarantee is issued?","Is the museum-specific reduction valid under the declared computation model and independently reproducible?","What UNKNOWN and disagreement rates occur relative to current curator-led assessment?","Do staff and governance systems preserve guarantee labels in later decisions, reports, and scope changes?","How much specialist labor is required per object, and which object classes make that burden operationally unacceptable?","How does the proposal differ from existing digital-preservation verification, emulation, significant-properties, and software-heritage assessment practices?"],"recommendation":"VALIDATE_PROBLEM_FIRST","uncertainty_constraints":["Closed-book assessment provides no evidence of problem prevalence, stakeholder demand, realized impact, market size, or institutional budgets.","Prior art is unsearched, so novelty and comparative distinctiveness cannot be established.","Cost bands are resource-equivalent planning ranges, not observed prices or estimates from a specified institution.","The computability claim is conditional on faithful formalization and a valid reduction; it does not apply directly to cultural interpretation or meanings outside the model.","Technical feasibility may vary sharply with object type, dependency condition, rights constraints, and available source or environment information."],"closed_book_prior_art_boundary":"No conclusion is made about novelty, prevalence, or superiority to real-world practice. The sealed packet identifies relevant comparison areas but contains no external evidence about existing digital-preservation verification, significant-properties, emulation, or software-heritage assessment workflows."}