{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__medicine_healthcare","archetype_slug":"computability_boundary_mapping","domain_slug":"medicine_healthcare","title":"Computability-Bounded Safety Preclearance for Clinical Decision-Support Modules","opportunity_summary":"Replace unsupported universal-safety clearance of unrestricted executable CDS modules with an enforceable decidable fragment, explicit guarantee labels, and governed UNKNOWN fallbacks. The proposal could improve auditability and prevent false reassurance, but the sealed packet does not establish that the target health system actually uses an unrestricted module class, that the formal prohibitions faithfully represent clinical safety, or that the approach improves decisions over existing review.","adopter_authorizer":"A health system's accountable CDS governance and clinical-safety committee, with implementation participation from EHR/CDS runtime owners and module developers; the committee retains release authority.","scores":{"meaningful_impact":{"score":4,"rationale":"Preventing false universal-safety claims could materially protect patients and reduce erroneous rejection of useful modules while improving auditability. Impact remains conditional because the packet supplies no evidence about how often such overclaims occur or affect deployment decisions."},"stakeholder_pull":{"score":3,"rationale":"The candidate states that a health system wants the verifier and identifies patients, clinicians, developers, and governance reviewers, but provides no observed requests, adoption commitments, workflow data, or evidence of problem prevalence."},"incremental_advantage":{"score":4,"rationale":"Relative to binary approve/reject decisions based on testing and timeouts, enforceable fragment membership, proved verifier scope, explicit UNKNOWN, and unresolved-obligation labels offer a clear and testable improvement in epistemic honesty. Whether they improve real governance outcomes is untested."},"distinctiveness_plausibility":{"score":2,"rationale":"The composition is coherent, but formal verification, restricted languages, abstraction, bounded search, safety cases, and abstaining outputs are recognizable approach categories. Prior art is explicitly unsearched, so a distinctive incremental contribution is not established."},"technical_implementability":{"score":3,"rationale":"Retrospective classification and bounded analysis appear feasible, and a restricted fragment could in principle support a total verifier. Implementation is materially constrained by enforceable fragment membership, faithful runtime and record semantics, sound abstraction, clinical-property formalization, and proof review."},"adoption_authority_feasibility":{"score":4,"rationale":"The candidate identifies an accountable governance and clinical-safety committee with release authority and keeps the analyzer advisory. Production adoption would still require cooperation from runtime owners, developers, clinicians, compliance functions, and proof reviewers."},"evidence_readiness":{"score":3,"rationale":"A safe retrospective comparison, explicit problem and intervention falsifiers, and false-SAFE stop rule are supplied. Readiness is limited by the absence of preregistered endpoints, acceptance thresholds, module-selection rules, validated ground truth, and a completed semantic or computability proof."},"safety_net_benefit":{"score":5,"rationale":"Explicit UNKNOWN and out-of-scope states, prohibition on treating UNKNOWN as SAFE, retained human release authority, version-frozen retrospective testing, and halt conditions for false SAFE or scope bypass directly reduce false-reassurance risk."},"scalability":{"score":3,"rationale":"Guarantee labels and a restricted fragment could be reused across modules within a stable runtime, but proofs and boundary records must be revisited when languages, schemas, terminology, safety properties, or execution environments change. Cross-system reuse is therefore uncertain."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"A bounded retrospective study at one health system using a small, version-frozen set of nondeployed modules, including semantic inventory, ordinary-review comparison, fragment classification, bounded analysis, proof review, labeling assessment, and reporting.","confidence":"LOW","assumptions":["The partner can provide lawful access to module code, runtime specifications, and synthetic or appropriately governed records.","No live clinical deployment or patient-outcome experiment occurs.","Existing tools can support bounded execution and prototype checks without building a production platform.","Clinical-safety, CDS engineering, formal-methods, governance, and evaluation labor are included."]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Create a pilot-ready implementation for one environment: formalize the supported fragment and prohibited behaviors, implement fragment and scope enforcement, build the verifier and fallback labeling path, conduct independent proof review, and integrate with a nonproduction governance workflow.","confidence":"LOW","assumptions":["The initial scope covers one CDS runtime and a limited property set.","No major EHR platform replacement is required.","The health system already has CDS governance, security, and test environments.","Costs include partner coordination, compliance review, software engineering, validation, and training."]},"operational_launch":{"band_2026_usd":"1M_TO_5M","scope":"Production launch within one health system, including hardened EHR/CDS integration, access controls, monitoring, audit records, change-control enforcement, safety validation, reviewer training, operational support, and staged governance adoption.","confidence":"LOW","assumptions":["Launch spans multiple module teams but remains within one health system.","Production integration and organizational change are substantial.","The supported fragment and formal safety properties survive retrospective validation.","The analyzer remains advisory and does not independently authorize care."]},"annual_recurring":{"band_2026_usd":"250K_TO_1M","scope":"Ongoing engineering, clinical-safety review, proof and boundary maintenance, terminology and schema updates, audit, label-quality monitoring, incident response, developer support, and periodic revalidation.","confidence":"LOW","assumptions":["A limited specialist team maintains one health-system implementation.","Runtime and clinical terminology changes require recurring review.","Material expansions of the language or property set would be separately funded.","No exact staffing levels or vendor prices are available in the sealed packet."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"UNCERTAIN","reason":"The logical problem is clearly specified, including the collapse of timeout and unknown states into universal-safety labels, but the packet does not establish that an actual deployment environment is computationally unrestricted or that this clearance failure occurs in practice."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The health system's accountable CDS governance and clinical-safety committee is explicitly assigned release authority, with EHR/CDS owners and developers as identifiable implementation participants."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal can be compared with ordinary binary review on detection of guarantee overreach, separation of inconclusive cases, coverage, and false-SAFE behavior under a declared model."},"bounded_next_evidence_step":{"status":"YES","reason":"The candidate authorizes retrospective analysis of a small, version-frozen, nondeployed module set and comparison of bounded results, fragment-verifier verdicts, and fallback labels without affecting care."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The analyzer cannot authorize care, UNKNOWN cannot be treated as SAFE, live deployment is excluded, and false SAFE, scope bypass, mislabeled UNKNOWN, or proof-review failure triggers a stop and rollback."},"implementation_cost_scope_and_range":{"status":"UNCERTAIN","reason":"A one-system retrospective pilot and production pathway can be broadly scoped, but the packet lacks module counts, runtime complexity, staffing requirements, integration architecture, compliance obligations, and vendor constraints needed to substantiate resource ranges."}},"blocking_evidence":["Whether the deployed CDS language, execution environment, and admissible longitudinal record histories are actually unbounded rather than finite and enumerable.","A semantics-matched computability argument for the unrestricted class and independently reviewed totality and correctness proofs for the proposed decidable fragment.","Evidence that formal prohibited behaviors faithfully capture decision-relevant clinical-safety requirements rather than only program-semantic conformance.","A preregistered comparison protocol with observable measures for guarantee overreach, false SAFE, UNKNOWN accuracy, coverage loss, label adherence, reviewer burden, and governance delay.","Evidence that fragment membership and runtime scope can be enforced without bypasses and that boundary records remain synchronized with system changes.","Bounded prior-art evidence establishing whether the mechanism composition offers a meaningful incremental contribution over existing verification and safety-governance approaches."],"next_evidence_step":"At one willing health-system partner, preregister and retrospectively assess a capped, version-frozen set of nondeployed modules. First determine whether each module's language, environment, record horizon, and claimed safety properties are genuinely unbounded; then compare ordinary binary review with fragment-verifier and explicit fallback labels using bounded exhaustive results where available. Falsify the problem if the full claimed class is demonstrably finite and already covered by a total correct verifier; stop the intervention assessment on any false SAFE verdict, scope-enforcement bypass, or failure to separate inconclusive cases better than ordinary review.","research_questions":["Are the actual CDS language, environment, and patient-record histories unrestricted enough for the proposed undecidability boundary to apply?","Which prohibited recommendations can be formalized faithfully, and who approves the clinical adequacy of those formal properties?","Can fragment membership and execution scope be enforced across compilation, configuration, external calls, data access, and runtime updates?","How often does current review overstate universal guarantees or collapse timeout, unknown, and out-of-scope results into binary decisions?","Compared with ordinary review, does the proposed process improve overclaim detection and inconclusive-case separation without producing false SAFE verdicts?","What proportion of useful modules remains inside the decidable fragment, and how much governance burden results from UNKNOWN outputs?","Do developers and governance reviewers understand, preserve, and act correctly on guarantee labels and unresolved obligations?","What relevant prior work already combines restricted executable languages, formal verification, explicit abstention, and CDS release governance?"],"recommendation":"VALIDATE_PROBLEM_FIRST","uncertainty_constraints":["This is a closed-book assessment with no external verification of prior art, prevalence, stakeholder demand, market size, realized impact, regulation, or current technical practice.","The candidate is a hypothesis and supplies no completed proof, prototype, pilot data, validated measurement protocol, or production integration evidence.","The computability claim depends on a precise match among the module language, runtime semantics, record encoding, quantifiers, and prohibited behavior.","Program-semantic conformance does not establish that the encoded clinical prohibition is complete or medically correct.","All cost bands are broad resource-equivalent judgments rather than quotes or point estimates and are especially sensitive to runtime access, integration complexity, proof obligations, and staffing.","The earliest horizon refers to credible retrospective evidence, not safe production deployment or demonstrated patient benefit."],"closed_book_prior_art_boundary":"Prior art is explicitly unsearched. This assessment makes no claim that the proposed computability classification, restricted fragment, verifier, UNKNOWN contract, or governance composition is novel, rare, commercially distinct, or absent from existing CDS, formal-verification, or clinical-safety practice."}