{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__material_culture_museum_studies","archetype_slug":"computability_boundary_mapping","domain_slug":"material_culture_museum_studies","title":"Guarantee-Labeled Routing for Executable Digital-Artefact Preservation","opportunity_summary":"Evaluate a museum preservation workflow that limits exact behavioral-verification claims to enforceable computable scopes, routes other cases to bounded or expert methods, and records UNKNOWN rather than converting incomplete evidence into an authoritative Boolean verdict. The potential value is substantial where unrestricted total verification is actually demanded, but that demand, the museum-specific reduction, semantic adequacy, and distinctiveness remain unverified.","adopter_authorizer":"A museum's delegated digital-conservation and collections-governance authorities, with curators defining significant properties and an independent reviewer gating formal claims.","scores":{"meaningful_impact":{"score":4,"rationale":"If museums currently rely on unsupported Boolean preservation verdicts, preventing false assurance could protect originals, dependencies, access, and evidentiary integrity. The sealed candidate does not establish how often such verdicts occur."},"stakeholder_pull":{"score":2,"rationale":"The problem states that museums may seek a universal verifier but provides no evidence that any museum, staff member, procurement process, or existing system actually requires total exact answers over an open-ended class."},"incremental_advantage":{"score":4,"rationale":"Relative to ad hoc testing or an always-answering heuristic, enforceable scope admission, explicit UNKNOWN, guarantee labels, versioned records, and independent proof review directly reduce overclaiming. The advantage depends on institutions preserving those distinctions downstream."},"distinctiveness_plausibility":{"score":3,"rationale":"The proof-to-routing-to-governance combination is sufficiently specific to merit comparison, but prior art is unsearched and the packet supplies no evidence that similar digital-preservation or software-verification workflows are absent."},"technical_implementability":{"score":3,"rationale":"Labels, routing, bounded analyses, logs, and shadow evaluation appear implementable, while faithful formalization of significant behaviors, enforceable fragment membership, sound abstractions, and a valid reduction are substantial unresolved technical requirements."},"adoption_authority_feasibility":{"score":4,"rationale":"The candidate identifies joint conservation and collections-governance authority, separates curator and independent-review roles, excludes irreversible uses, and supplies halt and rollback rules. Actual willingness and institutional fit are untested."},"evidence_readiness":{"score":3,"rationale":"The candidate provides observable failure modes, separate problem and intervention falsifiers, a 30-object offline pilot, and explicit halt criteria. It supplies no stakeholder evidence, validated reduction, empirical comparison, or demonstrated formalization method."},"safety_net_benefit":{"score":5,"rationale":"Explicit UNKNOWN, non-dispositive shadow operation, retention of originals and logs, prohibition of destructive migration and deaccession, and rollback to curator-led assessment provide strong safeguards against unsupported automated conclusions."},"scalability":{"score":2,"rationale":"Each object may require bespoke significant-property formalization, environment modeling, dependency analysis, and expert or independent review. High UNKNOWN rates and heterogeneous collections could prevent economical scaling."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"A bounded requirements audit and offline shadow study using the specified 30 already-accessioned objects, including curator time, formalization, comparison with existing assessments, one independently reviewed reduction, secure execution, analysis, and reporting.","confidence":"LOW","assumptions":["Objects and lawful internal access are already available.","No preservation status or production workflow is changed.","The study formalizes only one narrow property per object.","Specialist formal-methods and conservation labor are required.","No major emulator or infrastructure procurement is needed."]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Design and validation of admission rules, analysis routing, guarantee labels, UNKNOWN handling, versioned records, reviewer procedures, training, and integration with one museum's preservation workflow.","confidence":"LOW","assumptions":["Deployment is limited to one institution and executable digital artefacts.","Existing collection-management and secure-compute infrastructure can be extended.","Multiple analysis modes and independent formal review are necessary.","Rights, security, and governance review are included.","The pilot establishes adequate semantic representation and technical validity."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Production launch for a bounded collection segment, including workflow integration, staff onboarding, initial object formalizations, security and compliance work, quality assurance, evaluation, and contingency capacity for expert review.","confidence":"LOW","assumptions":["Launch does not attempt universal collection coverage.","Originals and dependencies remain retained.","Human review remains mandatory for claims outside exact verified fragments.","Object heterogeneity creates material onboarding labor.","No building-scale capital equipment is required."]},"annual_recurring":{"band_2026_usd":"250K_TO_1M","scope":"Ongoing specialist staffing, curator and reviewer time, environment maintenance, re-analysis after scope or dependency changes, software and compute, audit logging, training, governance, and outcome evaluation for one institution.","confidence":"LOW","assumptions":["The service handles a bounded annual case volume.","Substantial per-object formalization remains necessary.","Independent review and versioned reassessment continue.","Compute is not the dominant cost; expert labor and coordination are.","The institution maintains rather than outsources the core workflow."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"UNCERTAIN","reason":"The candidate specifies a coherent observable failure and serious consequences, but says museums may seek the universal verifier and supplies no affirmative evidence that an open-ended total requirement or misleading Boolean output exists in practice."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The museum's delegated digital-conservation and collections-governance authorities are explicitly identified, with defined curator and independent-review responsibilities."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal makes a testable claim that enforceable scope routing, guarantee labels, and UNKNOWN will reduce unsupported Boolean verdicts compared with the existing curator-led workflow or an always-answering heuristic."},"bounded_next_evidence_step":{"status":"YES","reason":"A 30-object offline shadow study is specified with one narrow property per object, independent review of one reduction, measurable UNKNOWN and disagreement rates, no status changes, and explicit failure conditions."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The first step is non-dispositive; irreversible migration, disposal, deaccession, and access denial are excluded, and defined halt and rollback rules retain originals, dependencies, and logs."},"implementation_cost_scope_and_range":{"status":"UNCERTAIN","reason":"The candidate bounds the pilot and names workflow components, but provides no empirical staffing, integration, object-complexity, data-access, or review burden from which an implementation range can be verified."}},"blocking_evidence":["Evidence that a stakeholder or existing system actually requires a total exact answer over an open-ended class rather than finite, bounded, or instance-specific claims.","A faithful formal specification of executable objects, environments, and curator-selected significant behaviors without implying coverage of omitted cultural meanings.","Independent confirmation that the proposed reduction is valid under the declared computation model and preserves the target answer.","Demonstration that fragment membership and guarantee labels remain enforceable throughout downstream museum decisions.","Comparison with existing workflows and relevant prior art, which are unsearched in the sealed packet.","Observed UNKNOWN, disagreement, false-verdict, staff-effort, and per-object formalization rates sufficient to assess usefulness and cost."],"next_evidence_step":"Conduct the specified offline study on 30 already-accessioned executable objects, preceded by a documented check of whether each associated workflow makes an open-ended total claim. Compare guarantee-labeled routing with the existing curator-led assessment on unsupported Boolean outputs, UNKNOWN and disagreement rates, staff effort, and semantic omissions; independently review one reduction. Stop or reject the problem premise if all operational claims are finite, bounded, or instance-specific, and reject the intervention if the reduction fails or routing still induces Boolean verdicts outside verified scope.","research_questions":["Do any museum stakeholders or systems require total exact verification over an open-ended executable class?","Can curator-defined significant properties and relevant environmental capabilities be formalized without materially narrowing the preservation claim?","Is the museum-specific reduction valid under the declared computation model and independently reproducible?","Can fragment membership, abstraction soundness, guarantee labels, and UNKNOWN handling be technically and procedurally enforced?","How does routed assessment compare with existing curator-led assessment in unsupported Boolean verdicts, disagreement, effort, and decision usefulness?","What UNKNOWN rate remains operationally acceptable to conservation and collections-governance authorities?","Do existing digital-preservation, emulation, significant-properties, or software-verification workflows already implement materially similar controls?","What recurring per-object labor, secure-compute, rights, integration, and independent-review burden would bounded operation require? "],"recommendation":"VALIDATE_PROBLEM_FIRST","uncertainty_constraints":["Closed-book assessment with no external evidence.","Problem prevalence, stakeholder demand, market size, and realized impact are unmeasured.","Prior art and distinctiveness are unverified.","The computability claim is conditional on faithful formalization and a valid checked reduction.","The method cannot assess cultural meanings or significant behaviors omitted from the formal model.","Cost bands are resource-equivalent planning ranges, not observed prices or point estimates.","A finite, fixed collection with bounded traces could make the central issue cost or semantic adequacy rather than computability."],"closed_book_prior_art_boundary":"Prior art is unsearched and unverified in this closed-book assessment; no claim is made about novelty, prevalence, comparative uniqueness, or the absence of similar museum-preservation or software-verification workflows."}