{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"computability_boundary_mapping__systems_cybernetics","archetype_slug":"computability_boundary_mapping","domain_slug":"systems_cybernetics","title":"Scope-Explicit Viability Assurance for Adaptive Feedback Systems","opportunity_summary":"Evaluate a sandboxed assurance workflow that replaces unsupported universal SAFE/UNSAFE prediction with explicit model contracts, enforced decidable fragments, independently reviewed boundary claims, and UNKNOWN or OUT_OF_SCOPE routing. The opportunity is conditional on confirming that the diagnosed universal-verdict problem exists and that the proposed routing reduces guarantee mislabelling without introducing abstraction-based false confidence.","adopter_authorizer":"The accountable system owner can authorize the bounded evaluation; any production assurance change requires the designated safety authority and an independent proof reviewer.","scores":{"meaningful_impact":{"score":4,"rationale":"If the diagnosed interface is used, preventing an unsound SAFE verdict could protect operators, affected people, communities, and environments from viability-envelope violations. Impact is potentially substantial, but the sealed candidate does not establish how often such universal claims occur or how many decisions they affect."},"stakeholder_pull":{"score":3,"rationale":"Operators, assurance engineers, system owners, and exposed parties have proposal-specific reasons to value trustworthy scope labels and terminating behavior. No adopter interviews, observed incidents, procurement interest, or evidence of dissatisfaction with current practice is supplied, so actual pull remains uncertain."},"incremental_advantage":{"score":4,"rationale":"Relative to simulation, stress testing, and longer timeouts, enforced fragment membership plus UNKNOWN and OUT_OF_SCOPE directly addresses the invalid conversion of bounded non-observation into a universal Boolean verdict. The advantage depends on the actual assurance task making the class-wide claim diagnosed by the candidate."},"distinctiveness_plausibility":{"score":2,"rationale":"The integrated boundary-record, fragment-routing, and abstention workflow could be distinctive, but prior art is explicitly unsearched and its elements resemble general formal-assurance, scope-enforcement, and abstention patterns. Closed-book evidence cannot support a strong novelty claim."},"technical_implementability":{"score":3,"rationale":"A non-actuating pilot for one formalized language, viability predicate, and claimed decidable fragment appears implementable. However, the unrestricted impossibility reduction, abstraction soundness, unambiguous fragment membership, and agreement of the exact mode with reference results are unresolved load-bearing obligations."},"adoption_authority_feasibility":{"score":4,"rationale":"The proposal names both the accountable system owner for bounded evaluation and the safety authority plus independent proof reviewer for production changes. Feasibility is favorable for research, although approval across those roles and downstream handling of UNKNOWN have not been demonstrated."},"evidence_readiness":{"score":3,"rationale":"The candidate supplies separate problem and intervention falsifiers, a bounded comparator, halt conditions, and a rollback path. It does not yet supply the corpus, executable semantics, exhaustive reference implementation, reduction certificate, abstraction proof, or independent review."},"safety_net_benefit":{"score":4,"rationale":"UNKNOWN and OUT_OF_SCOPE states, non-actuating evaluation, prohibition on relaxing controls, guarantee withdrawal, and explicit halt conditions create a meaningful safety net against false certification. Residual risk remains because downstream users may coerce UNKNOWN into SAFE or apply a correct result to a mismatched physical system."},"scalability":{"score":3,"rationale":"The contract-and-routing pattern may transfer across assurance programs, but each model language, viability semantics, abstraction relation, decidable fragment, and assumption change can require specialized proof and review. Boundary records may also become stale as expressiveness changes."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"Formalize one model language and viability predicate, construct a small non-actuating corpus and exhaustive bounded comparator, implement fragment and timeout routing, run the mislabelling comparison, and obtain an independent proof review of the claimed fragment and any boundary argument.","confidence":"LOW","assumptions":["One narrowly bounded symbolic model language and viability predicate are evaluated.","Existing computing infrastructure is sufficient for the bounded corpus.","The work requires formal-methods engineering, test construction, and independent review but no live-system integration.","Data access and contractual review are limited to sandbox artifacts."]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Harden the validated workflow for one assurance program, including enforceable parsing and fragment membership, guarantee-labelled routing, audit records, regression tests, access controls, documentation, and integration with the existing review process without changing live actuation.","confidence":"LOW","assumptions":["The bounded evidence step succeeds and proof gaps are closed for the admitted fragment.","Deployment covers one organization and one system family rather than unrestricted adaptive systems.","Existing safety controls remain in place.","Independent assurance, security review, and workflow integration are required."]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Authorize and launch the workflow within one governed safety program, including production validation, independent proof acceptance, reviewer and operator training, downstream UNKNOWN-handling controls, monitoring, incident procedures, and guarantee-withdrawal capability.","confidence":"LOW","assumptions":["Launch is limited to an approved fragment and does not claim a universal predictor.","No new specialized hardware or live-actuation connection is required.","The designated safety authority accepts the evidence package.","A single organizational deployment is in scope; multi-site or multi-domain rollout is excluded."]},"annual_recurring":{"band_2026_usd":"250K_TO_1M","scope":"Maintain model and predicate definitions, re-review boundaries after language changes, run regression and mislabelling audits, monitor downstream treatment of UNKNOWN, preserve independent review capacity, and update or withdraw stale guarantee records.","confidence":"LOW","assumptions":["A formal-methods maintainer and periodic independent reviewer remain available.","Model expressiveness and operational assumptions change often enough to require recurring reclassification.","The estimate covers one safety program and a limited set of admitted fragments.","Major redevelopment for a new system class is excluded and would be additional startup work."]}},"research_burden":"HIGH","earliest_credible_horizon":"3_TO_12_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"YES","reason":"The sealed candidate specifies an auditable problem signature: unrestricted SAFE/UNSAFE outputs, timeout conversion, absent UNKNOWN and OUT_OF_SCOPE states, and simulation cited as class-wide evidence. External audit must still establish that this signature occurs in a target program."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The accountable system owner is identified for the bounded evaluation, while production changes are assigned to the designated safety authority with independent proof review."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The proposal makes a separable claim that formal routing and fragment enforcement will reduce guarantee mislabelling relative to simulation-plus-timeout Boolean judgment while matching exhaustive reference results on every admitted bounded case."},"bounded_next_evidence_step":{"status":"YES","reason":"One viability predicate, one model language, one claimed fragment, a non-actuating corpus, and an exhaustive bounded comparator define a finite test with explicit rejection and halt criteria."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"The first step is explicitly authorized only as a sandbox evaluation, cannot relax existing controls or connect to live actuation, and must halt on mislabelling, ambiguous membership, unwitnessed timeout verdicts, or a proof gap."},"implementation_cost_scope_and_range":{"status":"YES","reason":"The candidate bounds the first step to one language, predicate, fragment, corpus, comparator, and independent review, permitting broad resource bands. Production costs remain low-confidence because integration scale, compliance demands, and system complexity are unspecified."}},"blocking_evidence":["An audit showing that a target assurance requirement or interface actually claims, or operationally implies, an exact terminating class-wide Boolean viability verdict without preserved scope or UNKNOWN states.","A precise contract for the chosen adaptive-system language, encoding, quantifiers, computation model, viability predicate, and permitted external information.","An independently checked proof for the selected decidable fragment and, before making an unrestricted impossibility claim, an answer-preserving reduction with verified totality and preservation.","A justified abstraction relation between concrete and abstract transition semantics sufficient for the proposed viability guarantee.","Bounded comparative results showing fewer guarantee mislabels than the simulation-plus-timeout baseline and zero disagreement with exhaustive reference results on admitted cases.","Evidence that fragment membership is mechanically enforceable and that downstream workflows preserve UNKNOWN and OUT_OF_SCOPE rather than coercing them into SAFE."],"next_evidence_step":"In a non-actuating sandbox, audit one candidate assurance interface, formalize one model language and viability predicate, and evaluate one claimed decidable fragment on a fixed bounded corpus. Compare fragment-enforced, guarantee-labelled routing against the existing simulation-plus-timeout Boolean baseline using exhaustive reference results; reject the intervention if it fails to reduce mislabelling, disagrees on any admitted case, ambiguously classifies membership, or converts any timeout into SAFE or UNSAFE without a witness.","research_questions":["Does a target assurance program actually make or operationally infer the unrestricted exact terminating verdict diagnosed by the proposal?","Can the selected fragment's membership, totality, and correctness be specified and independently verified under one explicit computation model?","Can an answer-preserving reduction establish the claimed unrestricted boundary under exactly the same system and viability contracts?","Does the abstraction soundly preserve the viability property required for every admitted case?","Does formal routing reduce guarantee mislabelling relative to simulation-plus-timeout Boolean judgment on the bounded corpus?","Will downstream operators and systems preserve UNKNOWN and OUT_OF_SCOPE without converting them into authorization?","How does the integrated boundary-record, fragment-routing, and abstention workflow compare with existing assurance practice?","How sensitive are recurring review effort and deployment cost to changes in model expressiveness and operational assumptions?"],"recommendation":"PARTNERED_RESEARCH","uncertainty_constraints":["The assessment is closed-book; problem prevalence, adopter demand, market size, realized impact, and prior art are unmeasured.","The unrestricted impossibility diagnosis remains a hypothesis until an answer-preserving reduction is exhibited and independently checked.","The abstraction-to-deployment mapping may fail for finite hardware, stochastic or continuous dynamics, sensor information, or human intervention.","The diagnosed problem is absent if the real task is one fixed bounded model or already preserves enforceable scope and UNKNOWN states.","Passing bounded exhaustive tests validates only the tested implementation and does not prove soundness beyond the corpus.","Cost bands are resource-equivalent planning ranges conditioned on a single organization, system family, and admitted fragment; exact integration and compliance scope are unspecified."],"closed_book_prior_art_boundary":"Prior art is explicitly unsearched. This assessment makes no claim that computability-boundary analysis, decidable-fragment enforcement, guarantee-labelled routing, abstention states, or their proposed combination is novel, rare, or commercially differentiated."}