{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__organizational_management","archetype_slug":"computability_boundary_mapping","domain_slug":"organizational_management","title":"Governed Solvability Boundaries for Programmable Workflow Assurance","opportunity_summary":"Evaluate whether a governance function is promising universal exact approval for an effectively encoded, sufficiently expressive workflow language, then replace any unsupported guarantee with a reviewed decidable fragment, enforced admission controls, and explicitly labeled bounded, UNKNOWN, or human-governed fallbacks. The opportunity remains conditional because the actual workflow scope, semantic stability, expressiveness, and organizational demand are hypotheses.","adopter_authorizer":"The governance and compliance office is the likely adopter. The executive risk owner may authorize scope, policy owners must approve breach semantics, and independent proof reviewers must accept the formal boundary evidence.","scores":{"meaningful_impact":{"score":3,"rationale":"Avoiding unsafe approvals, unjustified rejections, concealed assurance limits, and continued investment in an impossible unrestricted analyzer could materially improve governance. The sealed candidate provides no evidence that these failures occur or affect a large share of workflows."},"stakeholder_pull":{"score":2,"rationale":"Governance, compliance, policy, and risk roles have plausible reasons to value accountable assurance, but no stakeholder request, observed pain, adoption commitment, or demonstrated dissatisfaction with the baseline is supplied."},"incremental_advantage":{"score":4,"rationale":"Relative to example review, simulation, timeouts, and undocumented exceptions, the proposed combination adds a formally reviewed assurance boundary, enforceable fragment membership, explicit UNKNOWN handling, and versioned guarantees. Its realized advantage depends on semantic fidelity and operational enforceability."},"distinctiveness_plausibility":{"score":2,"rationale":"The composition is specific, but prior art is explicitly unsearched and the packet identifies novelty evidence as weak. No closed-book basis establishes distinctiveness from existing workflow verification or governance systems."},"technical_implementability":{"score":3,"rationale":"A 12-model non-production study, fragment checker, seeded-breach testing, and labeled routing are bounded and technically conceivable. Stable semantics, a valid reduction or constructive decider, analyzer correctness, and enforceable admission may each prove difficult."},"adoption_authority_feasibility":{"score":4,"rationale":"The candidate assigns scope authority, semantic approval, and proof acceptance to named roles and prohibits production approval from pilot results. Feasibility is reduced by the need for agreement across risk, policy, engineering, and independent review functions."},"evidence_readiness":{"score":4,"rationale":"The packet specifies a non-production 12-model comparison, historical and synthetic cases, known-breach seeds, independent proof review, falsifiers, and halt conditions. It lacks actual models, baseline records, and confirmed reviewer access."},"safety_net_benefit":{"score":5,"rationale":"The proposal explicitly preserves baseline review, separates UNKNOWN and timeout from approval or rejection, forbids bounded-result generalization, requires guarantee revocation, and halts on semantic mismatch, proof gaps, unenforceable membership, or clearance of a seeded breach."},"scalability":{"score":3,"rationale":"Enforced fragment admission and versioned automated decisions could scale repeated submissions, but excluded expressiveness, bypass into ungoverned channels, policy changes, false-alarm review load, and repeated proof maintenance may limit scale."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"Non-production study of 12 versioned synthetic and historical workflow models, including semantic formalization, baseline comparison, candidate-fragment testing, seeded-breach checks, reduction review, and a decision record.","confidence":"LOW","assumptions":["The organization can provide usable historical models and baseline decisions without extensive remediation.","The workflow language and breach predicate can be formalized within a limited study.","Independent formal-methods review is available for a bounded engagement.","No production integration or employee-facing policy change occurs."]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Build and validate a restricted analyzer, fragment-membership enforcement, guarantee-aware result schema, versioning, audit records, and integration for an initial organizational scope.","confidence":"LOW","assumptions":["The pilot identifies a useful decidable fragment and closes proof obligations.","Existing submission and workflow systems expose integration points.","The estimate covers an initial bounded scope rather than an enterprise-wide migration.","No specialized hardware or unusually costly data licensing is required."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Launch within the authorized initial scope, including policy approval, independent assurance review, submission controls, human escalation procedures, training, monitoring, and rollback preparation.","confidence":"LOW","assumptions":["Initial deployment artifacts can be reused without major redesign.","Policy owners accept the formal breach semantics and routing labels.","Baseline human review remains available for UNKNOWN and excluded cases.","The launch does not require immediate conversion of all organizational workflows."]},"annual_recurring":{"band_2026_usd":"250K_TO_1M","scope":"Ongoing analyzer operation, proof and policy maintenance, version reclassification, independent review, exception handling, human escalation, monitoring for bypass and Boolean coercion, and periodic evaluation.","confidence":"LOW","assumptions":["Workflow-language and policy changes occur but do not require continuous foundational redesign.","UNKNOWN volume remains manageable for the retained review function.","Independent review is periodic rather than permanently embedded at full-time scale.","The covered scope remains limited to the initially authorized program or business unit."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"UNCERTAIN","reason":"The candidate clearly specifies observable symptoms and falsifiers, but labels the organizational failure as a hypothesis and supplies no evidence that the target governance function actually makes the universal claim or encounters the stated failures."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The governance and compliance office is identifiable as adopter, while the executive risk owner, policy owners, and independent proof reviewers have explicitly separated authorization roles."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal makes a testable incremental claim that a reviewed decidable fragment plus enforced admission and labeled fallbacks can avoid unsupported Boolean assurance while retaining useful automation, compared with baseline example, simulation, and timeout review."},"bounded_next_evidence_step":{"status":"YES","reason":"The sealed candidate authorizes a non-production pilot on 12 versioned models with baseline comparison, seeded breaches, fragment testing, reduction checking, and explicit halt conditions."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The first step is non-production; production approval, unsafe interpretation of UNKNOWN, unauthorized policy restriction, and unreviewed impossibility claims are excluded. Named halt and rollback conditions preserve baseline review."},"implementation_cost_scope_and_range":{"status":"YES","reason":"The candidate defines a bounded pilot and identifiable deployment components, permitting broad resource-equivalent ranges for evidence, analyzer construction, controlled launch, and recurring review, although confidence remains low without system details."}},"blocking_evidence":["Whether the required organizational scope is open-ended rather than a fixed finite catalog that can be exhaustively decided.","Whether proposed workflows have effective encodings and execution semantics with the iteration, recursion, or invocation capabilities needed for the computability mapping.","Whether policy owners can define a stable breach predicate that faithfully represents the real governance task.","Independent confirmation of the constructive decider's totality and correctness or of the unrestricted reduction's direction, preservation properties, and assumptions.","Whether fragment membership can be enforced without routine bypass or displacement into ungoverned channels.","Whether labeled UNKNOWN, timeout, and conservative outputs remain distinct downstream rather than being coerced into approve or reject.","Comparative evidence that the proposed approach improves assurance behavior over baseline review without unacceptable false alarms or escalation burden.","Prior-art evidence concerning whether the full mechanism composition is distinct from existing workflow-verification and governance practice."],"next_evidence_step":"Run the authorized non-production study on 12 versioned synthetic and historical workflow models. Compare the candidate fragment and labeled fallback outputs with baseline committee or analyzer decisions, include known-breach seeds and cases outside the fragment, and obtain independent review of semantic fidelity and any reduction or total-decider claim. Stop and retain baseline review if any seeded breach is cleared, the semantics fail to represent the policy task, fragment admission is unenforceable, a proof obligation remains open, or UNKNOWN is coerced into a Boolean decision.","research_questions":["Does the actual governance function promise exact, terminating approval across an open-ended workflow class, and what documented timeouts, exclusions, redesigns, or forced decisions result?","Is the governed catalog fixed and finite, or does the admitted language support effective encodings and unbounded constructs relevant to the claimed assurance scope?","Can policy owners define a stable, reviewable breach predicate without stripping away material ambiguity or legitimacy judgments?","What useful share of real workflows fits an enforceable fragment with a reviewed total and correct decider?","Does independent review validate the proposed reduction or constructive proof, including semantic preservation and model assumptions?","How do baseline and proposed processes compare on seeded-breach clearance, false alarms, decision latency, UNKNOWN frequency, reviewer effort, and downstream label preservation?","Do authors bypass restrictions or move necessary work into ungoverned channels when excluded expressiveness is required?","What documented systems already combine formal boundary evidence, enforceable fragments, guarantee-aware routing, authority allocation, and versioned rechecking?"] ,"recommendation":"VALIDATE_PROBLEM_FIRST","uncertainty_constraints":["The problem, observable state, and workflow-language expressiveness are explicitly hypotheses.","Problem prevalence, stakeholder demand, affected volume, and realized organizational impact are unsupported.","The computability mapping applies only to effectively encoded workflows with suitable execution semantics, not to tacit judgment, political legitimacy, or changing policy meaning.","A finite fixed catalog or an existing enforceable total decider would falsify the alleged solvability-boundary problem.","Stable semantic formalization may fail, making ontology or policy ambiguity the primary issue.","Distinctiveness, prior-art position, implementation prevalence, market size, and exact costs are unmeasured.","Cost bands are resource-equivalent planning ranges based only on the candidate's bounded activities, not vendor quotes or observed deployments."],"closed_book_prior_art_boundary":"Prior art is explicitly UNSEARCHED. This assessment makes no claim that the mechanism composition is novel, uncommon, commercially differentiated, or absent from workflow verification, policy analysis, formal methods, or governance systems. External comparison is required before any distinctiveness claim."}